Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2023:0277-1

Опубликовано: 29 сент. 2023
Источник: suse-cvrf

Описание

Security update for chromium

This update for chromium fixes the following issues:

  • Chromium 117.0.5938.132 (boo#1215776):

    • CVE-2023-5217: Heap buffer overflow in vp8 encoding in libvpx (boo#1215778)
    • CVE-2023-5186: Use after free in Passwords
    • CVE-2023-5187: Use after free in Extensions
  • Chromium 117.0.5938.92:

    • stability improvements

Список пакетов

SUSE Package Hub 15 SP4
chromedriver-117.0.5938.132-bp155.2.40.1
chromium-117.0.5938.132-bp155.2.40.1
SUSE Package Hub 15 SP5
chromedriver-117.0.5938.132-bp155.2.40.1
chromium-117.0.5938.132-bp155.2.40.1
openSUSE Leap 15.4
chromedriver-117.0.5938.132-bp155.2.40.1
chromium-117.0.5938.132-bp155.2.40.1
openSUSE Leap 15.5
chromedriver-117.0.5938.132-bp155.2.40.1
chromium-117.0.5938.132-bp155.2.40.1

Описание

Use after free in Passwords in Google Chrome prior to 117.0.5938.132 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via crafted UI interaction. (Chromium security severity: High)


Затронутые продукты
SUSE Package Hub 15 SP4:chromedriver-117.0.5938.132-bp155.2.40.1
SUSE Package Hub 15 SP4:chromium-117.0.5938.132-bp155.2.40.1
SUSE Package Hub 15 SP5:chromedriver-117.0.5938.132-bp155.2.40.1
SUSE Package Hub 15 SP5:chromium-117.0.5938.132-bp155.2.40.1

Ссылки

Описание

Use after free in Extensions in Google Chrome prior to 117.0.5938.132 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
SUSE Package Hub 15 SP4:chromedriver-117.0.5938.132-bp155.2.40.1
SUSE Package Hub 15 SP4:chromium-117.0.5938.132-bp155.2.40.1
SUSE Package Hub 15 SP5:chromedriver-117.0.5938.132-bp155.2.40.1
SUSE Package Hub 15 SP5:chromium-117.0.5938.132-bp155.2.40.1

Ссылки

Описание

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
SUSE Package Hub 15 SP4:chromedriver-117.0.5938.132-bp155.2.40.1
SUSE Package Hub 15 SP4:chromium-117.0.5938.132-bp155.2.40.1
SUSE Package Hub 15 SP5:chromedriver-117.0.5938.132-bp155.2.40.1
SUSE Package Hub 15 SP5:chromium-117.0.5938.132-bp155.2.40.1

Ссылки