Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

openSUSE: 2018:0313-1 Important: Chromium Security Issues Fixed

opensuse
Calendar Grey January 31, 2018
Dist Opensuse Esm H88
New patch released for openSUSE addressing 24 vulnerabilities in chromium, improving both system security and efficiency.
An update that fixes 24 vulnerabilities is now available.

Description

This update for chromium to 64.0.3282.119 fixes several issues.

These security issues were fixed:

- CVE-2018-6031: Use after free in PDFium (boo#1077571)

- CVE-2018-6032: Same origin bypass in Shared Worker (boo#1077571)

- CVE-2018-6033: Race when opening downloaded files (boo#1077571)

- CVE-2018-6034: Integer overflow in Blink (boo#1077571)

- CVE-2018-6035: Insufficient isolation of devtools from extensions

(boo#1077571)

- CVE-2018-6036: Integer underflow in WebAssembly (boo#1077571)

- CVE-2018-6037: Insufficient user gesture requirements in autofill

(boo#1077571)

- CVE-2018-6038: Heap buffer overflow in WebGL (boo#1077571)

- CVE-2018-6039: XSS in DevTools (boo#1077571)

- CVE-2018-6040: Content security policy bypass (boo#1077571)

- CVE-2018-6041: URL spoof in Navigation (boo#1077571)

- CVE-2018-6042: URL spoof in OmniBox (boo#1077571)

- CVE-2018-6043: Insufficient escaping with external URL handlers (boo#1077571)

-...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- SUSE Package Hub for SUSE Linux Enterprise 12:

zypper in -t patch openSUSE-2018-106=1

To bring your system up-to-date, use "zypper patch".

Package List

- SUSE Package Hub for SUSE Linux Enterprise 12 (aarch64 ppc64le s390x x86_64):

libre2-0-20180101-5.1

libre2-0-debuginfo-20180101-5.1

re2-debugsource-20180101-5.1

re2-devel-20180101-5.1

- SUSE Package Hub for SUSE Linux Enterprise 12 (x86_64):

chromedriver-64.0.3282.119-46.2

chromium-64.0.3282.119-46.2

References

https://www.suse.com/security/cve/CVE-2017-15420.html

https://www.suse.com/security/cve/CVE-2018-6031.html

https://www.suse.com/security/cve/CVE-2018-6032.html

https://www.suse.com/security/cve/CVE-2018-6033.html

https://www.suse.com/security/cve/CVE-2018-6034.html

https://www.suse.com/security/cve/CVE-2018-6035.html

https://www.suse.com/security/cve/CVE-2018-6036.html

https://www.suse.com/security/cve/CVE-2018-6037.html

https://www.suse.com/security/cve/CVE-2018-6038.html

https://www.suse.com/security/cve/CVE-2018-6039.html

https://www.suse.com/security/cve/CVE-2018-6040.html

https://www.suse.com/security/cve/CVE-2018-6041.html

https://www.suse.com/security/cve/CVE-2018-6042.html

https://www.suse.com/security/cve/CVE-2018-6043.html

https://www.suse.com/security/cve/CVE-2018-6045.html

https://www.suse.com/security/cve/CVE-2018-6046.html

https://www.suse.com/security/cve/CVE-2018-6047.html

https://www.suse.com/security/cve/CVE-2018-6048.html

https://www.suse.com/security/cve/CVE-2018-6049.html

https://www...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2018:0313-1
Rating: important
Affected Products: SUSE Package Hub for SUSE Linux Enterprise 12

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here