Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

openSUSE 12.3: 2013:1556-1 Critical Update: Chromium Multiple Fixes

opensuse
Calendar Grey October 16, 2013
Dist Opensuse Esm H88
Essential openSUSE patch for firefox 93.0 that tackles 15 security vulnerabilities and enhances overall functionality.
An update that fixes 19 vulnerabilities is now available

Description

Update to Chromium 30.0.1599.66:

- Easier searching by image

- A number of new apps/extension APIs

- Lots of under the hood changes for stability and

performance

- Security fixes:

+ CVE-2013-2906: Races in Web Audio

+ CVE-2013-2907: Out of bounds read in Window.prototype

object

+ CVE-2013-2908: Address bar spoofing related to the

“204 No Content” status code

+ CVE-2013-2909: Use after free in inline-block rendering

+ CVE-2013-2910: Use-after-free in Web Audio

+ CVE-2013-2911: Use-after-free in XSLT

+ CVE-2013-2912: Use-after-free in PPAPI

+ CVE-2013-2913: Use-after-free in XML document parsing

+ CVE-2013-2914: Use after free in the Windows color

chooser dialog

+ CVE-2013-2915: Address bar spoofing via a malformed

scheme

+ CVE-2013-2916: Address bar spoofing related to the “204

No Content” status code

+ CVE-2013-2917: Out of bounds read in Web Audio

+ CVE-2013-2918: Use-after-free in...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 12.3:

zypper in -t patch openSUSE-2013-769

- openSUSE 12.2:

zypper in -t patch openSUSE-2013-769

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 12.3 (i586 x86_64):

chromedriver-30.0.1599.66-1.11.2

chromedriver-debuginfo-30.0.1599.66-1.11.2

chromium-30.0.1599.66-1.11.2

chromium-debuginfo-30.0.1599.66-1.11.2

chromium-debugsource-30.0.1599.66-1.11.2

chromium-desktop-gnome-30.0.1599.66-1.11.2

chromium-desktop-kde-30.0.1599.66-1.11.2

chromium-ffmpegsumo-30.0.1599.66-1.11.2

chromium-ffmpegsumo-debuginfo-30.0.1599.66-1.11.2

chromium-suid-helper-30.0.1599.66-1.11.2

chromium-suid-helper-debuginfo-30.0.1599.66-1.11.2

- openSUSE 12.2 (i586 x86_64):

chromedriver-30.0.1599.66-1.46.1

chromedriver-debuginfo-30.0.1599.66-1.46.1

chromium-30.0.1599.66-1.46.1

chromium-debuginfo-30.0.1599.66-1.46.1

chromium-debugsource-30.0.1599.66-1.46.1

chromium-desktop-gnome-30.0.1599.66-1.46.1

chromium-desktop-kde-30.0.1599.66-1.46.1

chromium-ffmpegsumo-30.0.1599.66-1.46.1

chromium-ffmpegsumo-debuginfo-30.0.1599.66-1.46.1

chromium-suid-helper-30.0.1599.66-1.46.1

chromium-suid-helper-debuginfo-30.0.1599.66-1.46.1

References

https://www.suse.com/security/cve/CVE-2013-2906.html

https://www.suse.com/security/cve/CVE-2013-2907.html

https://www.suse.com/security/cve/CVE-2013-2908.html

https://www.suse.com/security/cve/CVE-2013-2909.html

https://www.suse.com/security/cve/CVE-2013-2910.html

https://www.suse.com/security/cve/CVE-2013-2911.html

https://www.suse.com/security/cve/CVE-2013-2912.html

https://www.suse.com/security/cve/CVE-2013-2913.html

https://www.suse.com/security/cve/CVE-2013-2914.html

https://www.suse.com/security/cve/CVE-2013-2915.html

https://www.suse.com/security/cve/CVE-2013-2916.html

https://www.suse.com/security/cve/CVE-2013-2917.html

https://www.suse.com/security/cve/CVE-2013-2918.html

https://www.suse.com/security/cve/CVE-2013-2919.html

https://www.suse.com/security/cve/CVE-2013-2920.html

https://www.suse.com/security/cve/CVE-2013-2921.html

https://www.suse.com/security/cve/CVE-2013-2922.html

https://www.suse.com/security/cve/CVE-2013-2923.html

https://www.suse.com/security/cve/CVE-2013-2924.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2013:1556-1
Rating: important
Affected Products: openSUSE 12.3 openSUSE 12.2 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here