Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2024:0302-1

Опубликовано: 16 сент. 2024
Источник: suse-cvrf

Описание

Security update for chromium

This update for chromium fixes the following issues:

Chromium 128.0.6613.137 (released 2024-09-10) (boo#1230391)

  • CVE-2024-8636: Heap buffer overflow in Skia
  • CVE-2024-8637: Use after free in Media Router
  • CVE-2024-8638: Type Confusion in V8
  • CVE-2024-8639: Use after free in Autofill

Список пакетов

SUSE Package Hub 15 SP5
chromedriver-128.0.6613.137-bp156.2.26.1
chromium-128.0.6613.137-bp156.2.26.1
SUSE Package Hub 15 SP6
chromedriver-128.0.6613.137-bp156.2.26.1
chromium-128.0.6613.137-bp156.2.26.1
openSUSE Leap 15.5
chromedriver-128.0.6613.137-bp156.2.26.1
chromium-128.0.6613.137-bp156.2.26.1
openSUSE Leap 15.6
chromedriver-128.0.6613.137-bp156.2.26.1
chromium-128.0.6613.137-bp156.2.26.1

Описание

Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
SUSE Package Hub 15 SP5:chromedriver-128.0.6613.137-bp156.2.26.1
SUSE Package Hub 15 SP5:chromium-128.0.6613.137-bp156.2.26.1
SUSE Package Hub 15 SP6:chromedriver-128.0.6613.137-bp156.2.26.1
SUSE Package Hub 15 SP6:chromium-128.0.6613.137-bp156.2.26.1

Ссылки

Описание

Use after free in Media Router in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
SUSE Package Hub 15 SP5:chromedriver-128.0.6613.137-bp156.2.26.1
SUSE Package Hub 15 SP5:chromium-128.0.6613.137-bp156.2.26.1
SUSE Package Hub 15 SP6:chromedriver-128.0.6613.137-bp156.2.26.1
SUSE Package Hub 15 SP6:chromium-128.0.6613.137-bp156.2.26.1

Ссылки

Описание

Type Confusion in V8 in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
SUSE Package Hub 15 SP5:chromedriver-128.0.6613.137-bp156.2.26.1
SUSE Package Hub 15 SP5:chromium-128.0.6613.137-bp156.2.26.1
SUSE Package Hub 15 SP6:chromedriver-128.0.6613.137-bp156.2.26.1
SUSE Package Hub 15 SP6:chromium-128.0.6613.137-bp156.2.26.1

Ссылки

Описание

Use after free in Autofill in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
SUSE Package Hub 15 SP5:chromedriver-128.0.6613.137-bp156.2.26.1
SUSE Package Hub 15 SP5:chromium-128.0.6613.137-bp156.2.26.1
SUSE Package Hub 15 SP6:chromedriver-128.0.6613.137-bp156.2.26.1
SUSE Package Hub 15 SP6:chromium-128.0.6613.137-bp156.2.26.1

Ссылки