Alerts This Week
Warning Icon 1 640
Alerts This Week
Warning Icon 1 640

openSUSE: 2018:4142-1 Important: Chromium Security Fixes

opensuse
Calendar Grey December 15, 2018
Dist Opensuse Esm H88
openSUSE Security Update: Security update for Chromium _____________________________________________
An update that fixes 27 vulnerabilities is now available.

Description

This update to Chromium 71.0.3578.98 fixes the following issues:

Security issues fixed (boo#1118529):

- CVE-2018-17480: Out of bounds write in V8

- CVE-2018-17481: Use after frees in PDFium

- CVE-2018-18335: Heap buffer overflow in Skia

- CVE-2018-18336: Use after free in PDFium

- CVE-2018-18337: Use after free in Blink

- CVE-2018-18338: Heap buffer overflow in Canvas

- CVE-2018-18339: Use after free in WebAudio

- CVE-2018-18340: Use after free in MediaRecorder

- CVE-2018-18341: Heap buffer overflow in Blink

- CVE-2018-18342: Out of bounds write in V8

- CVE-2018-18343: Use after free in Skia

- CVE-2018-18344: Inappropriate implementation in Extensions

- Multiple issues in SQLite via WebSQL

- CVE-2018-18345: Inappropriate implementation in Site Isolation

- CVE-2018-18346: Incorrect security UI in Blink

- CVE-2018-18347: Inappropriate implementation in Navigation

- CVE-2018-18348: Inappropriate implementation in Omnibox

-...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.3:

zypper in -t patch openSUSE-2018-1557=1

Package List

- openSUSE Leap 42.3 (x86_64):

chromedriver-71.0.3578.98-189.1

chromedriver-debuginfo-71.0.3578.98-189.1

chromium-71.0.3578.98-189.1

chromium-debuginfo-71.0.3578.98-189.1

chromium-debugsource-71.0.3578.98-189.1

References

https://www.suse.com/security/cve/CVE-2018-17480.html

https://www.suse.com/security/cve/CVE-2018-17481.html

https://www.suse.com/security/cve/CVE-2018-18335.html

https://www.suse.com/security/cve/CVE-2018-18336.html

https://www.suse.com/security/cve/CVE-2018-18337.html

https://www.suse.com/security/cve/CVE-2018-18338.html

https://www.suse.com/security/cve/CVE-2018-18339.html

https://www.suse.com/security/cve/CVE-2018-18340.html

https://www.suse.com/security/cve/CVE-2018-18341.html

https://www.suse.com/security/cve/CVE-2018-18342.html

https://www.suse.com/security/cve/CVE-2018-18343.html

https://www.suse.com/security/cve/CVE-2018-18344.html

https://www.suse.com/security/cve/CVE-2018-18345.html

https://www.suse.com/security/cve/CVE-2018-18346.html

https://www.suse.com/security/cve/CVE-2018-18347.html

https://www.suse.com/security/cve/CVE-2018-18348.html

https://www.suse.com/security/cve/CVE-2018-18349.html

https://www.suse.com/security/cve/CVE-2018-18350.html

https://www.suse.com/security/cve/CVE-2018-183...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2018:4142-1
Rating: important
Affected Products: openSUSE Leap 42.3

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here