Описание
Security update for chromium
This security update for Chromium to version 131.0.6778.204 (boo#1234704) fixes:
- CVE-2024-12692: Type Confusion in V8
- CVE-2024-12693: Out of bounds memory access in V8
- CVE-2024-12694: Use after free in Compositing
- CVE-2024-12695: Out of bounds write in V8
- Various fixes from internal audits, fuzzing and other initiatives
Список пакетов
SUSE Package Hub 15 SP5
SUSE Package Hub 15 SP6
openSUSE Leap 15.5
openSUSE Leap 15.6
Ссылки
- E-Mail link for openSUSE-SU-2024:0417-1
- SUSE Security Ratings
- SUSE CVE CVE-2024-12692 page
- SUSE CVE CVE-2024-12693 page
- SUSE CVE CVE-2024-12694 page
- SUSE CVE CVE-2024-12695 page
Описание
Type Confusion in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2024-12692
- SUSE Bug 1234704
Описание
Out of bounds memory access in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2024-12693
- SUSE Bug 1234704
Описание
Use after free in Compositing in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2024-12694
- SUSE Bug 1234704
Описание
Out of bounds write in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2024-12695
- SUSE Bug 1234704