Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

openSUSE: 2016:1207-1 important: Chromium Memory Corruption

opensuse
Calendar Grey May 4, 2016
Scroller Opensuse
Crucial security patch released for openSUSE Chromium, addressing major vulnerabilities and improving overall system protection.
An update that fixes 7 vulnerabilities is now available

Description

Chromium was updated to 50.0.2661.94 to fix a number of vulnerabilities

(boo#977830):

- CVE-2016-1660: Out-of-bounds write in Blink

- CVE-2016-1661: Memory corruption in cross-process frames

- CVE-2016-1662: Use-after-free in extensions

- CVE-2016-1663: Use-after-free in Blink’s V8 bindings

- CVE-2016-1664: Address bar spoofing

- CVE-2016-1665: Information leak in V8

- CVE-2016-1666: Various fixes from internal audits, fuzzing and other

initiatives

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- SUSE Package Hub for SUSE Linux Enterprise 12:

zypper in -t patch openSUSE-2016-540=1

To bring your system up-to-date, use "zypper patch".

Package List

- SUSE Package Hub for SUSE Linux Enterprise 12 (x86_64):

chromedriver-50.0.2661.94-71.1

chromium-50.0.2661.94-71.1

chromium-desktop-gnome-50.0.2661.94-71.1

chromium-desktop-kde-50.0.2661.94-71.1

chromium-ffmpegsumo-50.0.2661.94-71.1

References

https://www.suse.com/security/cve/CVE-2016-1660.html

https://www.suse.com/security/cve/CVE-2016-1661.html

https://www.suse.com/security/cve/CVE-2016-1662.html

https://www.suse.com/security/cve/CVE-2016-1663.html

https://www.suse.com/security/cve/CVE-2016-1664.html

https://www.suse.com/security/cve/CVE-2016-1665.html

https://www.suse.com/security/cve/CVE-2016-1666.html

https://bugzilla.suse.com/977830

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2016:1207-1
Rating: important
Affected Products: SUSE Package Hub for SUSE Linux Enterprise 12 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.