Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

openSUSE 42.1: 2015:2290-1 Important: Chromium Security Issues Fixed

opensuse
Calendar Grey December 17, 2015
Dist Opensuse Esm H88
openSUSE Security Notice: Critical Chromium update addresses 28 vulnerabilities. Access detailed patch guidelines and CVE references.
An update that fixes 28 vulnerabilities is now available

Description

Chromium was updated to 47.0.2526.80 to fix security issues and bugs.

The following vulnerabilities were fixed:

* CVE-2015-6788: Type confusion in extensions

* CVE-2015-6789: Use-after-free in Blink

* CVE-2015-6790: Escaping issue in saved pages

* CVE-2015-6791: Various fixes from internal audits, fuzzing and other

initiatives

The following vulnerabilities were fixed in 47.0.2526.73:

* CVE-2015-6765: Use-after-free in AppCache

* CVE-2015-6766: Use-after-free in AppCache

* CVE-2015-6767: Use-after-free in AppCache

* CVE-2015-6768: Cross-origin bypass in DOM

* CVE-2015-6769: Cross-origin bypass in core

* CVE-2015-6770: Cross-origin bypass in DOM

* CVE-2015-6771: Out of bounds access in v8

* CVE-2015-6772: Cross-origin bypass in DOM

* CVE-2015-6764: Out of bounds access in v8

* CVE-2015-6773: Out of bounds access in Skia

* CVE-2015-6774: Use-after-free in Extensions

* CVE-2015-6775: Type confusion in PDFium

*...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.1:

zypper in -t patch openSUSE-2015-912=1

- openSUSE 13.2:

zypper in -t patch openSUSE-2015-912=1

- openSUSE 13.1:

zypper in -t patch openSUSE-2015-912=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE Leap 42.1 (i586 x86_64):

chromedriver-47.0.2526.80-7.1

chromedriver-debuginfo-47.0.2526.80-7.1

chromium-47.0.2526.80-7.1

chromium-debuginfo-47.0.2526.80-7.1

chromium-debugsource-47.0.2526.80-7.1

chromium-desktop-gnome-47.0.2526.80-7.1

chromium-desktop-kde-47.0.2526.80-7.1

chromium-ffmpegsumo-47.0.2526.80-7.1

chromium-ffmpegsumo-debuginfo-47.0.2526.80-7.1

- openSUSE 13.2 (i586 x86_64):

chromedriver-47.0.2526.80-61.1

chromedriver-debuginfo-47.0.2526.80-61.1

chromium-47.0.2526.80-61.1

chromium-debuginfo-47.0.2526.80-61.1

chromium-debugsource-47.0.2526.80-61.1

chromium-desktop-gnome-47.0.2526.80-61.1

chromium-desktop-kde-47.0.2526.80-61.1

chromium-ffmpegsumo-47.0.2526.80-61.1

chromium-ffmpegsumo-debuginfo-47.0.2526.80-61.1

- openSUSE 13.1 (i586 x86_64):

chromedriver-47.0.2526.80-116.1

chromedriver-debuginfo-47.0.2526.80-116.1

chromium-47.0.2526.80-116.1

chromium-debuginfo-47.0.2526.80-116.1

chromium-debugsource-47.0.2526.80-116.1

chromium-desktop-gnome-47.0.2526.80-116.1

chromium-desktop-kde-47.0.2526.80-...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2015-6764.html

https://www.suse.com/security/cve/CVE-2015-6765.html

https://www.suse.com/security/cve/CVE-2015-6766.html

https://www.suse.com/security/cve/CVE-2015-6767.html

https://www.suse.com/security/cve/CVE-2015-6768.html

https://www.suse.com/security/cve/CVE-2015-6769.html

https://www.suse.com/security/cve/CVE-2015-6770.html

https://www.suse.com/security/cve/CVE-2015-6771.html

https://www.suse.com/security/cve/CVE-2015-6772.html

https://www.suse.com/security/cve/CVE-2015-6773.html

https://www.suse.com/security/cve/CVE-2015-6774.html

https://www.suse.com/security/cve/CVE-2015-6775.html

https://www.suse.com/security/cve/CVE-2015-6776.html

https://www.suse.com/security/cve/CVE-2015-6777.html

https://www.suse.com/security/cve/CVE-2015-6778.html

https://www.suse.com/security/cve/CVE-2015-6779.html

https://www.suse.com/security/cve/CVE-2015-6780.html

https://www.suse.com/security/cve/CVE-2015-6781.html

https://www.suse.com/security/cve/CVE-2015-6782.html

https://www....

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2015:2290-1
Rating: important
Affected Products: openSUSE Leap 42.1 openSUSE 13.2 openSUSE 13.1 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here