Alerts This Week
Warning Icon 1 609
Alerts This Week
Warning Icon 1 609

openSUSE: 2017:1994-1 Important: Chromium Security Issues Fixed

opensuse
Calendar Grey July 28, 2017
Dist Opensuse Esm H88
Update dispatched for chromium addressing 21 security vulnerabilities, among them critical flaws. Ensure your openSUSE environment remains protected.
An update that fixes 21 vulnerabilities is now available

Description

This update Chromium to version 60.0.3112.78 fixes security issue and bugs.

The following security issues were fixed:

* CVE-2017-5091: Use after free in IndexedDB

* CVE-2017-5092: Use after free in PPAPI

* CVE-2017-5093: UI spoofing in Blink

* CVE-2017-5094: Type confusion in extensions

* CVE-2017-5095: Out-of-bounds write in PDFium

* CVE-2017-5096: User information leak via Android intents

* CVE-2017-5097: Out-of-bounds read in Skia

* CVE-2017-5098: Use after free in V8

* CVE-2017-5099: Out-of-bounds write in PPAPI

* CVE-2017-5100: Use after free in Chrome Apps

* CVE-2017-5101: URL spoofing in OmniBox

* CVE-2017-5102: Uninitialized use in Skia

* CVE-2017-5103: Uninitialized use in Skia

* CVE-2017-5104: UI spoofing in browser

* CVE-2017-7000: Pointer disclosure in SQLite

* CVE-2017-5105: URL spoofing in OmniBox

* CVE-2017-5106: URL spoofing in OmniBox

* CVE-2017-5107: User information...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- SUSE Package Hub for SUSE Linux Enterprise 12:

zypper in -t patch openSUSE-2017-854=1

To bring your system up-to-date, use "zypper patch".

Package List

- SUSE Package Hub for SUSE Linux Enterprise 12 (x86_64):

chromedriver-60.0.3112.78-26.1

chromedriver-debuginfo-60.0.3112.78-26.1

chromium-60.0.3112.78-26.1

chromium-debuginfo-60.0.3112.78-26.1

chromium-debugsource-60.0.3112.78-26.1

References

https://www.suse.com/security/cve/CVE-2017-5091.html

https://www.suse.com/security/cve/CVE-2017-5092.html

https://www.suse.com/security/cve/CVE-2017-5093.html

https://www.suse.com/security/cve/CVE-2017-5094.html

https://www.suse.com/security/cve/CVE-2017-5095.html

https://www.suse.com/security/cve/CVE-2017-5096.html

https://www.suse.com/security/cve/CVE-2017-5097.html

https://www.suse.com/security/cve/CVE-2017-5098.html

https://www.suse.com/security/cve/CVE-2017-5099.html

https://www.suse.com/security/cve/CVE-2017-5100.html

https://www.suse.com/security/cve/CVE-2017-5101.html

https://www.suse.com/security/cve/CVE-2017-5102.html

https://www.suse.com/security/cve/CVE-2017-5103.html

https://www.suse.com/security/cve/CVE-2017-5104.html

https://www.suse.com/security/cve/CVE-2017-5105.html

https://www.suse.com/security/cve/CVE-2017-5106.html

https://www.suse.com/security/cve/CVE-2017-5107.html

https://www.suse.com/security/cve/CVE-2017-5108.html

https://www.suse.com/security/cve/CVE-2017-5109.html

https://www....

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2017:1994-1
Rating: important
Affected Products: SUSE Package Hub for SUSE Linux Enterprise 12 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here