This update for Chromium to version 66.0.3359.139 fixes the following
issues:
- CVE-2018-6118: Use after free in Media Cache (bsc#1091288)
- CVE-2018-6085: Use after free in Disk Cache
- CVE-2018-6086: Use after free in Disk Cache
- CVE-2018-6087: Use after free in WebAssembly
- CVE-2018-6088: Use after free in PDFium
- CVE-2018-6089: Same origin policy bypass in Service Worker
- CVE-2018-6090: Heap buffer overflow in Skia
- CVE-2018-6091: Incorrect handling of plug-ins by Service Worker
- CVE-2018-6092: Integer overflow in WebAssembly
- CVE-2018-6093: Same origin bypass in Service Worker
- CVE-2018-6094: Exploit hardening regression in Oilpan
- CVE-2018-6095: Lack of meaningful user interaction requirement before
file upload
- CVE-2018-6096: Fullscreen UI spoof
- CVE-2018-6097: Fullscreen UI spoof
- CVE-2018-6098: URL spoof in Omnibox
- CVE-2018-6099: CORS bypass in ServiceWorker
- CVE-2018-6100: URL spoof in Omnibox
...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- SUSE Package Hub for SUSE Linux Enterprise 12:
zypper in -t patch openSUSE-2018-436=1
- SUSE Package Hub for SUSE Linux Enterprise 12 (x86_64):
chromedriver-66.0.3359.139-2.1
chromedriver-debuginfo-66.0.3359.139-2.1
chromium-66.0.3359.139-2.1
chromium-debuginfo-66.0.3359.139-2.1
chromium-debugsource-66.0.3359.139-2.1
https://www.suse.com/security/cve/CVE-2017-11215.html
https://www.suse.com/security/cve/CVE-2017-11225.html
https://www.suse.com/security/cve/CVE-2018-6057.html
https://www.suse.com/security/cve/CVE-2018-6060.html
https://www.suse.com/security/cve/CVE-2018-6061.html
https://www.suse.com/security/cve/CVE-2018-6062.html
https://www.suse.com/security/cve/CVE-2018-6063.html
https://www.suse.com/security/cve/CVE-2018-6064.html
https://www.suse.com/security/cve/CVE-2018-6065.html
https://www.suse.com/security/cve/CVE-2018-6066.html
https://www.suse.com/security/cve/CVE-2018-6067.html
https://www.suse.com/security/cve/CVE-2018-6068.html
https://www.suse.com/security/cve/CVE-2018-6069.html
https://www.suse.com/security/cve/CVE-2018-6070.html
https://www.suse.com/security/cve/CVE-2018-6071.html
https://www.suse.com/security/cve/CVE-2018-6072.html
https://www.suse.com/security/cve/CVE-2018-6073.html
https://www.suse.com/security/cve/CVE-2018-6074.html
https://www.suse.com/security/cve/CVE-2018-6075.html
https://ww...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.