Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

openSUSE Leap 42.1 Security Update: 2016:2597-1 Important Chromium Fixes

opensuse
Calendar Grey October 23, 2016
Scroller Opensuse
Essential patch for Chromium on openSUSE: 14 resolutions for vital security vulnerabilities, addressing XSS flaws.
An update that fixes 13 vulnerabilities is now available

Description

Chromium was updated to 54.0.2840.59 to fix security issues and bugs.

The following security issues are fixed (bnc#1004465):

- CVE-2016-5181: Universal XSS in Blink

- CVE-2016-5182: Heap overflow in Blink

- CVE-2016-5183: Use after free in PDFium

- CVE-2016-5184: Use after free in PDFium

- CVE-2016-5185: Use after free in Blink

- CVE-2016-5187: URL spoofing

- CVE-2016-5188: UI spoofing

- CVE-2016-5192: Cross-origin bypass in Blink

- CVE-2016-5189: URL spoofing

- CVE-2016-5186: Out of bounds read in DevTools

- CVE-2016-5191: Universal XSS in Bookmarks

- CVE-2016-5190: Use after free in Internals

- CVE-2016-5193: Scheme bypass

The following bugs were fixed:

- bnc#1000019: display issues in full screen mode, add

--ui-disable-partial-swap to the launcher

The following packaging changes are included:

- The desktop sub-packages are no obsolete

- The package now uses the system variants of some bundled libraries

-...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.1:

zypper in -t patch 5717=1

- openSUSE 13.2:

zypper in -t patch 5717=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE Leap 42.1 (x86_64):

chromedriver-54.0.2840.59-82.1

chromedriver-debuginfo-54.0.2840.59-82.1

chromium-54.0.2840.59-82.1

chromium-debuginfo-54.0.2840.59-82.1

chromium-debugsource-54.0.2840.59-82.1

chromium-ffmpegsumo-54.0.2840.59-82.1

chromium-ffmpegsumo-debuginfo-54.0.2840.59-82.1

- openSUSE 13.2 (i586 x86_64):

chromedriver-54.0.2840.59-131.2

chromedriver-debuginfo-54.0.2840.59-131.2

chromium-54.0.2840.59-131.2

chromium-debuginfo-54.0.2840.59-131.2

chromium-debugsource-54.0.2840.59-131.2

chromium-ffmpegsumo-54.0.2840.59-131.2

chromium-ffmpegsumo-debuginfo-54.0.2840.59-131.2

References

https://www.suse.com/security/cve/CVE-2016-5181.html

https://www.suse.com/security/cve/CVE-2016-5182.html

https://www.suse.com/security/cve/CVE-2016-5183.html

https://www.suse.com/security/cve/CVE-2016-5184.html

https://www.suse.com/security/cve/CVE-2016-5185.html

https://www.suse.com/security/cve/CVE-2016-5186.html

https://www.suse.com/security/cve/CVE-2016-5187.html

https://www.suse.com/security/cve/CVE-2016-5188.html

https://www.suse.com/security/cve/CVE-2016-5189.html

https://www.suse.com/security/cve/CVE-2016-5190.html

https://www.suse.com/security/cve/CVE-2016-5191.html

https://www.suse.com/security/cve/CVE-2016-5192.html

https://www.suse.com/security/cve/CVE-2016-5193.html

https://bugzilla.suse.com/1000019

https://bugzilla.suse.com/1004465

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2016:2597-1
Rating: important
Affected Products: openSUSE Leap 42.1 openSUSE 13.2 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.