Chromium was updated to 50.0.2661.94 to fix a number of vulnerabilities
(boo#977830):
- CVE-2016-1660: Out-of-bounds write in Blink
- CVE-2016-1661: Memory corruption in cross-process frames
- CVE-2016-1662: Use-after-free in extensions
- CVE-2016-1663: Use-after-free in Blink’s V8 bindings
- CVE-2016-1664: Address bar spoofing
- CVE-2016-1665: Information leak in V8
- CVE-2016-1666: Various fixes from internal audits, fuzzing and other
initiatives
Patch Instructions:
To install this openSUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:
- SUSE Package Hub for SUSE Linux Enterprise 12:
zypper in -t patch openSUSE-2016-540=1
To bring your system up-to-date, use "zypper patch".
- SUSE Package Hub for SUSE Linux Enterprise 12 (x86_64):
chromedriver-50.0.2661.94-71.1
chromium-50.0.2661.94-71.1
chromium-desktop-gnome-50.0.2661.94-71.1
chromium-desktop-kde-50.0.2661.94-71.1
chromium-ffmpegsumo-50.0.2661.94-71.1
https://www.suse.com/security/cve/CVE-2016-1660.html
https://www.suse.com/security/cve/CVE-2016-1661.html
https://www.suse.com/security/cve/CVE-2016-1662.html
https://www.suse.com/security/cve/CVE-2016-1663.html
https://www.suse.com/security/cve/CVE-2016-1664.html
https://www.suse.com/security/cve/CVE-2016-1665.html
https://www.suse.com/security/cve/CVE-2016-1666.html
https://bugzilla.suse.com/977830
Get the latest Linux and open source security news straight to your inbox.