Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2024:0212-1

Опубликовано: 22 июл. 2024
Источник: suse-cvrf

Описание

Security update for chromium

This update for chromium fixes the following issues:

Chromium 126.0.6478.182 (boo#1227979):

  • CVE-2024-6772: Inappropriate implementation in V8
  • CVE-2024-6773: Type Confusion in V8
  • CVE-2024-6774: Use after free in Screen Capture
  • CVE-2024-6775: Use after free in Media Stream
  • CVE-2024-6776: Use after free in Audio
  • CVE-2024-6777: Use after free in Navigation
  • CVE-2024-6778: Race in DevTools
  • CVE-2024-6779: Out of bounds memory access in V8

Список пакетов

SUSE Package Hub 15 SP5
chromedriver-126.0.6478.182-bp156.2.11.1
chromium-126.0.6478.182-bp156.2.11.1
SUSE Package Hub 15 SP6
chromedriver-126.0.6478.182-bp156.2.11.1
chromium-126.0.6478.182-bp156.2.11.1
openSUSE Leap 15.5
chromedriver-126.0.6478.182-bp156.2.11.1
chromium-126.0.6478.182-bp156.2.11.1
openSUSE Leap 15.6
chromedriver-126.0.6478.182-bp156.2.11.1
chromium-126.0.6478.182-bp156.2.11.1

Описание

Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
SUSE Package Hub 15 SP5:chromedriver-126.0.6478.182-bp156.2.11.1
SUSE Package Hub 15 SP5:chromium-126.0.6478.182-bp156.2.11.1
SUSE Package Hub 15 SP6:chromedriver-126.0.6478.182-bp156.2.11.1
SUSE Package Hub 15 SP6:chromium-126.0.6478.182-bp156.2.11.1

Ссылки

Описание

Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
SUSE Package Hub 15 SP5:chromedriver-126.0.6478.182-bp156.2.11.1
SUSE Package Hub 15 SP5:chromium-126.0.6478.182-bp156.2.11.1
SUSE Package Hub 15 SP6:chromedriver-126.0.6478.182-bp156.2.11.1
SUSE Package Hub 15 SP6:chromium-126.0.6478.182-bp156.2.11.1

Ссылки

Описание

Use after free in Screen Capture in Google Chrome prior to 126.0.6478.182 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
SUSE Package Hub 15 SP5:chromedriver-126.0.6478.182-bp156.2.11.1
SUSE Package Hub 15 SP5:chromium-126.0.6478.182-bp156.2.11.1
SUSE Package Hub 15 SP6:chromedriver-126.0.6478.182-bp156.2.11.1
SUSE Package Hub 15 SP6:chromium-126.0.6478.182-bp156.2.11.1

Ссылки

Описание

Use after free in Media Stream in Google Chrome prior to 126.0.6478.182 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
SUSE Package Hub 15 SP5:chromedriver-126.0.6478.182-bp156.2.11.1
SUSE Package Hub 15 SP5:chromium-126.0.6478.182-bp156.2.11.1
SUSE Package Hub 15 SP6:chromedriver-126.0.6478.182-bp156.2.11.1
SUSE Package Hub 15 SP6:chromium-126.0.6478.182-bp156.2.11.1

Ссылки

Описание

Use after free in Audio in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
SUSE Package Hub 15 SP5:chromedriver-126.0.6478.182-bp156.2.11.1
SUSE Package Hub 15 SP5:chromium-126.0.6478.182-bp156.2.11.1
SUSE Package Hub 15 SP6:chromedriver-126.0.6478.182-bp156.2.11.1
SUSE Package Hub 15 SP6:chromium-126.0.6478.182-bp156.2.11.1

Ссылки

Описание

Use after free in Navigation in Google Chrome prior to 126.0.6478.182 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)


Затронутые продукты
SUSE Package Hub 15 SP5:chromedriver-126.0.6478.182-bp156.2.11.1
SUSE Package Hub 15 SP5:chromium-126.0.6478.182-bp156.2.11.1
SUSE Package Hub 15 SP6:chromedriver-126.0.6478.182-bp156.2.11.1
SUSE Package Hub 15 SP6:chromium-126.0.6478.182-bp156.2.11.1

Ссылки

Описание

Race in DevTools in Google Chrome prior to 126.0.6478.182 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: High)


Затронутые продукты
SUSE Package Hub 15 SP5:chromedriver-126.0.6478.182-bp156.2.11.1
SUSE Package Hub 15 SP5:chromium-126.0.6478.182-bp156.2.11.1
SUSE Package Hub 15 SP6:chromedriver-126.0.6478.182-bp156.2.11.1
SUSE Package Hub 15 SP6:chromium-126.0.6478.182-bp156.2.11.1

Ссылки

Описание

Out of bounds memory access in V8 in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
SUSE Package Hub 15 SP5:chromedriver-126.0.6478.182-bp156.2.11.1
SUSE Package Hub 15 SP5:chromium-126.0.6478.182-bp156.2.11.1
SUSE Package Hub 15 SP6:chromedriver-126.0.6478.182-bp156.2.11.1
SUSE Package Hub 15 SP6:chromium-126.0.6478.182-bp156.2.11.1

Ссылки