Alerts This Week
Warning Icon 1 562
Alerts This Week
Warning Icon 1 562

openSUSE 13.1: 2013:1861-1 Important: Chromium Memory Fixes

opensuse
Calendar Grey December 12, 2013
Dist Opensuse Esm H88
An essential patch for Fedora tackles various vulnerabilities in firefox to boost security measures.

An update that fixes 36 vulnerabilities is now available.

Description

Chromium was updated to 31.0.1650.57: Stable channel update:

- Security Fixes:

* CVE-2013-6632: Multiple memory corruption issues.

- Update to Chromium 31.0.1650.48 Stable Channel update:

- Security fixes:

* CVE-2013-6621: Use after free related to speech input

elements..

* CVE-2013-6622: Use after free related to media

elements.

* CVE-2013-6623: Out of bounds read in SVG.

* CVE-2013-6624: Use after free related to “id”

attribute strings.

* CVE-2013-6625: Use after free in DOM ranges.

* CVE-2013-6626: Address bar spoofing related to

interstitial warnings.

* CVE-2013-6627: Out of bounds read in HTTP parsing.

* CVE-2013-6628: Issue with certificates not being

checked during TLS renegotiation.

* CVE-2013-2931: Various fixes from internal audits,

fuzzing and other initiatives.

* CVE-2013-6629: Read of uninitialized memory in

libjpeg and libjpeg-turbo.

* CVE-2013-6630: Read of uninitialized...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 13.1:

zypper in -t patch openSUSE-2013-961

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 13.1 (i586 x86_64):

chromedriver-31.0.1650.57-8.2

chromedriver-debuginfo-31.0.1650.57-8.2

chromium-31.0.1650.57-8.2

chromium-debuginfo-31.0.1650.57-8.2

chromium-debugsource-31.0.1650.57-8.2

chromium-desktop-gnome-31.0.1650.57-8.2

chromium-desktop-kde-31.0.1650.57-8.2

chromium-ffmpegsumo-31.0.1650.57-8.2

chromium-ffmpegsumo-debuginfo-31.0.1650.57-8.2

chromium-suid-helper-31.0.1650.57-8.2

chromium-suid-helper-debuginfo-31.0.1650.57-8.2

References

https://www.suse.com/security/cve/CVE-2013-2906.html

https://www.suse.com/security/cve/CVE-2013-2907.html

https://www.suse.com/security/cve/CVE-2013-2908.html

https://www.suse.com/security/cve/CVE-2013-2909.html

https://www.suse.com/security/cve/CVE-2013-2910.html

https://www.suse.com/security/cve/CVE-2013-2911.html

https://www.suse.com/security/cve/CVE-2013-2912.html

https://www.suse.com/security/cve/CVE-2013-2913.html

https://www.suse.com/security/cve/CVE-2013-2914.html

https://www.suse.com/security/cve/CVE-2013-2915.html

https://www.suse.com/security/cve/CVE-2013-2916.html

https://www.suse.com/security/cve/CVE-2013-2917.html

https://www.suse.com/security/cve/CVE-2013-2918.html

https://www.suse.com/security/cve/CVE-2013-2919.html

https://www.suse.com/security/cve/CVE-2013-2920.html

https://www.suse.com/security/cve/CVE-2013-2921.html

https://www.suse.com/security/cve/CVE-2013-2922.html

https://www.suse.com/security/cve/CVE-2013-2923.html

https://www.suse.com/security/cve/CVE-2013-2924.html

https://www....

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2013:1861-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here