Описание
Security update for chromium
This update for chromium fixes the following issue:
Chromium 122.0.6261.128 (boo#1221335)
- CVE-2024-2400: Use after free in Performance Manager
Chromium 122.0.6261.111 (boo#1220131,boo#1220604,boo#1221105)
- New upstream security release.
- CVE-2024-2173: Out of bounds memory access in V8.
- CVE-2024-2174: Inappropriate implementation in V8.
- CVE-2024-2176: Use after free in FedCM.
Chromium 122.0.6261.94
- CVE-2024-1669: Out of bounds memory access in Blink.
- CVE-2024-1670: Use after free in Mojo.
- CVE-2024-1671: Inappropriate implementation in Site Isolation.
- CVE-2024-1672: Inappropriate implementation in Content Security Policy.
- CVE-2024-1673: Use after free in Accessibility.
- CVE-2024-1674: Inappropriate implementation in Navigation.
- CVE-2024-1675: Insufficient policy enforcement in Download.
- CVE-2024-1676: Inappropriate implementation in Navigation.
- Type Confusion in V8
Список пакетов
SUSE Package Hub 15 SP5
openSUSE Leap 15.5
Ссылки
- E-Mail link for openSUSE-SU-2024:0084-1
- SUSE Security Ratings
- SUSE Bug 1220131
- SUSE Bug 1220604
- SUSE Bug 1221105
- SUSE Bug 1221335
- SUSE CVE CVE-2024-1669 page
- SUSE CVE CVE-2024-1670 page
- SUSE CVE CVE-2024-1671 page
- SUSE CVE CVE-2024-1672 page
- SUSE CVE CVE-2024-1673 page
- SUSE CVE CVE-2024-1674 page
- SUSE CVE CVE-2024-1675 page
- SUSE CVE CVE-2024-1676 page
- SUSE CVE CVE-2024-2173 page
- SUSE CVE CVE-2024-2174 page
- SUSE CVE CVE-2024-2176 page
- SUSE CVE CVE-2024-2400 page
Описание
Out of bounds memory access in Blink in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2024-1669
- SUSE Bug 1220131
Описание
Use after free in Mojo in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2024-1670
- SUSE Bug 1220131
Описание
Inappropriate implementation in Site Isolation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2024-1671
- SUSE Bug 1220131
Описание
Inappropriate implementation in Content Security Policy in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2024-1672
- SUSE Bug 1220131
Описание
Use after free in Accessibility in Google Chrome prior to 122.0.6261.57 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2024-1673
- SUSE Bug 1220131
Описание
Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2024-1674
- SUSE Bug 1220131
Описание
Insufficient policy enforcement in Download in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2024-1675
- SUSE Bug 1220131
Описание
Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2024-1676
- SUSE Bug 1220131
Описание
Out of bounds memory access in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2024-2173
- SUSE Bug 1221105
Описание
Inappropriate implementation in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2024-2174
- SUSE Bug 1221105
Описание
Use after free in FedCM in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2024-2176
- SUSE Bug 1221105
Описание
Use after free in Performance Manager in Google Chrome prior to 122.0.6261.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2024-2400
- SUSE Bug 1221335