Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 501
Alerts This Week
Warning Icon 1 501

openSUSE: 2016:1319-1 Important: Chromium Four Fixes for Security

opensuse
Calendar Grey May 17, 2016
Scroller Opensuse
A security patch for openSUSE Chromium addresses four critical vulnerabilities. Detailed steps for applying updates are provided for users.
An update that fixes four vulnerabilities is now available

Description

Chromium was updated to 50.0.2661.102 to fix four vulnerabilities

(boo#979859):

- CVE-2016-1667: Same origin bypass in DOM

- CVE-2016-1668: Same origin bypass in Blink V8 bindings

- CVE-2016-1669: Buffer overflow in V8

- CVE-2016-1670: Race condition in loader

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- SUSE Package Hub for SUSE Linux Enterprise 12:

zypper in -t patch openSUSE-2016-598=1

To bring your system up-to-date, use "zypper patch".

Package List

- SUSE Package Hub for SUSE Linux Enterprise 12 (x86_64):

chromedriver-50.0.2661.102-75.1

chromium-50.0.2661.102-75.1

chromium-desktop-gnome-50.0.2661.102-75.1

chromium-desktop-kde-50.0.2661.102-75.1

chromium-ffmpegsumo-50.0.2661.102-75.1

References

https://www.suse.com/security/cve/CVE-2016-1667.html

https://www.suse.com/security/cve/CVE-2016-1668.html

https://www.suse.com/security/cve/CVE-2016-1669.html

https://www.suse.com/security/cve/CVE-2016-1670.html

https://bugzilla.suse.com/show_bug.cgi?id=979859

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2016:1319-1
Rating: important
Affected Products: SUSE Package Hub for SUSE Linux Enterprise 12 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.