Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

openSUSE: 2019:1815-1 Important: Chromium Crash and Leakage Issues

opensuse
Calendar Grey July 30, 2019
Dist Opensuse Esm H88
The latest openSUSE update tackles three critical vulnerabilities within Chromium; comprehensive instructions for installation and patching are provided.
An update that fixes three vulnerabilities is now available.

Description

This update for chromium to version 75.0.3770.142 fixes the following

issues:

Security issue fixed:

- CVE-2019-5847: V8 sealed/frozen elements cause crash (boo#1141649).

- CVE-2019-5848: Font sizes may expose sensitive information (boo#1141649).

- CVE-2018-20073: Fixed information leaks of URL metadata nad passwords

via extended filesystem attributes (boo#1120892).

Non-security fix:

- Fixed a segfault on startup (boo#1141102).

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- SUSE Package Hub for SUSE Linux Enterprise 12:

zypper in -t patch openSUSE-2019-1815=1

Package List

- SUSE Package Hub for SUSE Linux Enterprise 12 (x86_64):

chromedriver-75.0.3770.142-7.1

chromedriver-debuginfo-75.0.3770.142-7.1

chromium-75.0.3770.142-7.1

chromium-debuginfo-75.0.3770.142-7.1

chromium-debugsource-75.0.3770.142-7.1

References

https://www.suse.com/security/cve/CVE-2018-20073.html

https://www.suse.com/security/cve/CVE-2019-5847.html

https://www.suse.com/security/cve/CVE-2019-5848.html

https://bugzilla.suse.com/1120892

https://bugzilla.suse.com/1141102

https://bugzilla.suse.com/1141649

--

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2019:1815-1
Rating: important
Affected Products: SUSE Package Hub for SUSE Linux Enterprise 12

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here