Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

openSUSE Leap 42.3: 2017:1993-1 Important: Chromium Security Update

opensuse
Calendar Grey July 28, 2017
Dist Opensuse Esm H88
This release addresses 18 security issues pertaining to Chromium on openSUSE. Follow the provided patch directives to mitigate risks.
An update that fixes 21 vulnerabilities is now available

Description

This update Chromium to version 60.0.3112.78 fixes security issue and bugs.

The following security issues were fixed:

* CVE-2017-5091: Use after free in IndexedDB

* CVE-2017-5092: Use after free in PPAPI

* CVE-2017-5093: UI spoofing in Blink

* CVE-2017-5094: Type confusion in extensions

* CVE-2017-5095: Out-of-bounds write in PDFium

* CVE-2017-5096: User information leak via Android intents

* CVE-2017-5097: Out-of-bounds read in Skia

* CVE-2017-5098: Use after free in V8

* CVE-2017-5099: Out-of-bounds write in PPAPI

* CVE-2017-5100: Use after free in Chrome Apps

* CVE-2017-5101: URL spoofing in OmniBox

* CVE-2017-5102: Uninitialized use in Skia

* CVE-2017-5103: Uninitialized use in Skia

* CVE-2017-5104: UI spoofing in browser

* CVE-2017-7000: Pointer disclosure in SQLite

* CVE-2017-5105: URL spoofing in OmniBox

* CVE-2017-5106: URL spoofing in OmniBox

* CVE-2017-5107: User information...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.3:

zypper in -t patch openSUSE-2017-854=1

- openSUSE Leap 42.2:

zypper in -t patch openSUSE-2017-854=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE Leap 42.3 (x86_64):

chromedriver-60.0.3112.78-107.1

chromedriver-debuginfo-60.0.3112.78-107.1

chromium-60.0.3112.78-107.1

chromium-debuginfo-60.0.3112.78-107.1

chromium-debugsource-60.0.3112.78-107.1

- openSUSE Leap 42.2 (x86_64):

chromedriver-60.0.3112.78-104.21.1

chromedriver-debuginfo-60.0.3112.78-104.21.1

chromium-60.0.3112.78-104.21.1

chromium-debuginfo-60.0.3112.78-104.21.1

chromium-debugsource-60.0.3112.78-104.21.1

References

https://www.suse.com/security/cve/CVE-2017-5091.html

https://www.suse.com/security/cve/CVE-2017-5092.html

https://www.suse.com/security/cve/CVE-2017-5093.html

https://www.suse.com/security/cve/CVE-2017-5094.html

https://www.suse.com/security/cve/CVE-2017-5095.html

https://www.suse.com/security/cve/CVE-2017-5096.html

https://www.suse.com/security/cve/CVE-2017-5097.html

https://www.suse.com/security/cve/CVE-2017-5098.html

https://www.suse.com/security/cve/CVE-2017-5099.html

https://www.suse.com/security/cve/CVE-2017-5100.html

https://www.suse.com/security/cve/CVE-2017-5101.html

https://www.suse.com/security/cve/CVE-2017-5102.html

https://www.suse.com/security/cve/CVE-2017-5103.html

https://www.suse.com/security/cve/CVE-2017-5104.html

https://www.suse.com/security/cve/CVE-2017-5105.html

https://www.suse.com/security/cve/CVE-2017-5106.html

https://www.suse.com/security/cve/CVE-2017-5107.html

https://www.suse.com/security/cve/CVE-2017-5108.html

https://www.suse.com/security/cve/CVE-2017-5109.html

https://www....

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2017:1993-1
Rating: important
Affected Products: openSUSE Leap 42.3 openSUSE Leap 42.2 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here