Alerts This Week
Warning Icon 1 933
Alerts This Week
Warning Icon 1 933

openSUSE Leap 15.1: 2020:0189-1 Important: Chromium Security Advisory

opensuse
Calendar Grey February 9, 2020
Dist Opensuse Esm H88
openSUSE announces significant Firefox security patch: 42 vulnerabilities addressed, detailed installation steps included.
An update that fixes 38 vulnerabilities is now available.

Description

This update for chromium fixes the following issues:

Chromium was updated to version 80.0.3987.87 (boo#1162833).

Security issues fixed:

- CVE-2020-6381: Integer overflow in JavaScript (boo#1162833).

- CVE-2020-6382: Type Confusion in JavaScript (boo#1162833).

- CVE-2019-18197: Multiple vulnerabilities in XML (boo#1162833).

- CVE-2019-19926: Inappropriate implementation in SQLite (boo#1162833).

- CVE-2020-6385: Insufficient policy enforcement in storage (boo#1162833).

- CVE-2019-19880, CVE-2019-19925: Multiple vulnerabilities in SQLite

(boo#1162833).

- CVE-2020-6387: Out of bounds write in WebRTC (boo#1162833).

- CVE-2020-6388: Out of bounds memory access in WebAudio (boo#1162833).

- CVE-2020-6389: Out of bounds write in WebRTC (boo#1162833).

- CVE-2020-6390: Out of bounds memory access in streams (boo#1162833).

- CVE-2020-6391: Insufficient validation of untrusted input in Blink

(boo#1162833).

- CVE-2020-6392: Insufficient...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.1:

zypper in -t patch openSUSE-2020-189=1

Package List

- openSUSE Leap 15.1 (x86_64):

chromedriver-80.0.3987.87-lp151.2.63.1

chromedriver-debuginfo-80.0.3987.87-lp151.2.63.1

chromium-80.0.3987.87-lp151.2.63.1

chromium-debuginfo-80.0.3987.87-lp151.2.63.1

chromium-debugsource-80.0.3987.87-lp151.2.63.1

References

https://www.suse.com/security/cve/CVE-2019-18197.html

https://www.suse.com/security/cve/CVE-2019-19880.html

https://www.suse.com/security/cve/CVE-2019-19923.html

https://www.suse.com/security/cve/CVE-2019-19925.html

https://www.suse.com/security/cve/CVE-2019-19926.html

https://www.suse.com/security/cve/CVE-2020-6381.html

https://www.suse.com/security/cve/CVE-2020-6382.html

https://www.suse.com/security/cve/CVE-2020-6385.html

https://www.suse.com/security/cve/CVE-2020-6387.html

https://www.suse.com/security/cve/CVE-2020-6388.html

https://www.suse.com/security/cve/CVE-2020-6389.html

https://www.suse.com/security/cve/CVE-2020-6390.html

https://www.suse.com/security/cve/CVE-2020-6391.html

https://www.suse.com/security/cve/CVE-2020-6392.html

https://www.suse.com/security/cve/CVE-2020-6393.html

https://www.suse.com/security/cve/CVE-2020-6394.html

https://www.suse.com/security/cve/CVE-2020-6395.html

https://www.suse.com/security/cve/CVE-2020-6396.html

https://www.suse.com/security/cve/CVE-2020-6397.html

https:/...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2020:0189-1
Rating: important
Affected Products: openSUSE Leap 15.1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here