Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

openSUSE Leap 15.0: 2019:1062-1 Important: Chromium Buffer Overflow

opensuse
Calendar Grey March 28, 2019
Dist Opensuse Esm H88
This enhancement resolves various vulnerabilities in Firefox for Fedora, providing a more secure internet surfing environment.

An update that fixes 18 vulnerabilities is now available.

Description

This update for chromium to version 73.0.3683.75 fixes the following

issues:

Security issues fixed (bsc#1129059):

- CVE-2019-5787: Fixed a use after free in Canvas.

- CVE-2019-5788: Fixed a use after free in FileAPI.

- CVE-2019-5789: Fixed a use after free in WebMIDI.

- CVE-2019-5790: Fixed a heap buffer overflow in V8.

- CVE-2019-5791: Fixed a type confusion in V8.

- CVE-2019-5792: Fixed an integer overflow in PDFium.

- CVE-2019-5793: Fixed excessive permissions for private API in Extensions.

- CVE-2019-5794: Fixed security UI spoofing.

- CVE-2019-5795: Fixed an integer overflow in PDFium.

- CVE-2019-5796: Fixed a race condition in Extensions.

- CVE-2019-5797: Fixed a race condition in DOMStorage.

- CVE-2019-5798: Fixed an out of bounds read in Skia.

- CVE-2019-5799: Fixed a CSP bypass with blob URL.

- CVE-2019-5800: Fixed a CSP bypass with blob URL.

- CVE-2019-5801: Fixed an incorrect Omnibox display on...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.0:

zypper in -t patch openSUSE-2019-1062=1

Package List

- openSUSE Leap 15.0 (x86_64):

chromedriver-73.0.3683.75-lp150.206.1

chromedriver-debuginfo-73.0.3683.75-lp150.206.1

chromium-73.0.3683.75-lp150.206.1

chromium-debuginfo-73.0.3683.75-lp150.206.1

chromium-debugsource-73.0.3683.75-lp150.206.1

References

https://www.suse.com/security/cve/CVE-2019-5787.html

https://www.suse.com/security/cve/CVE-2019-5788.html

https://www.suse.com/security/cve/CVE-2019-5789.html

https://www.suse.com/security/cve/CVE-2019-5790.html

https://www.suse.com/security/cve/CVE-2019-5791.html

https://www.suse.com/security/cve/CVE-2019-5792.html

https://www.suse.com/security/cve/CVE-2019-5793.html

https://www.suse.com/security/cve/CVE-2019-5794.html

https://www.suse.com/security/cve/CVE-2019-5795.html

https://www.suse.com/security/cve/CVE-2019-5796.html

https://www.suse.com/security/cve/CVE-2019-5797.html

https://www.suse.com/security/cve/CVE-2019-5798.html

https://www.suse.com/security/cve/CVE-2019-5799.html

https://www.suse.com/security/cve/CVE-2019-5800.html

https://www.suse.com/security/cve/CVE-2019-5801.html

https://www.suse.com/security/cve/CVE-2019-5802.html

https://www.suse.com/security/cve/CVE-2019-5803.html

https://www.suse.com/security/cve/CVE-2019-5804.html

https://bugzilla.suse.com/1129059

--

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2019:1062-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here