Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

openSUSE: 2020:1527-1 Critical: Chromium Security Fixes

opensuse
Calendar Grey September 25, 2020
Dist Opensuse Esm H88
Fedora patches tackle various Firefox vulnerabilities, bolstering safety and efficiency for users of versions 34 and 35.
An update that fixes 7 vulnerabilities is now available.

Description

This update for chromium fixes the following issues:

Chromium was updated to 85.0.4183.121 (boo#1176791):

- CVE-2020-15960: Out of bounds read in storage

- CVE-2020-15961: Insufficient policy enforcement in extensions

- CVE-2020-15962: Insufficient policy enforcement in serial

- CVE-2020-15963: Insufficient policy enforcement in extensions

- CVE-2020-15965: Out of bounds write in V8

- CVE-2020-15966: Insufficient policy enforcement in extensions

- CVE-2020-15964: Insufficient data validation in media

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.2:

zypper in -t patch openSUSE-2020-1527=1

- openSUSE Leap 15.1:

zypper in -t patch openSUSE-2020-1527=1

Package List

- openSUSE Leap 15.2 (x86_64):

chromedriver-85.0.4183.121-lp152.2.33.1

chromedriver-debuginfo-85.0.4183.121-lp152.2.33.1

chromium-85.0.4183.121-lp152.2.33.1

chromium-debuginfo-85.0.4183.121-lp152.2.33.1

chromium-debugsource-85.0.4183.121-lp152.2.33.1

- openSUSE Leap 15.1 (x86_64):

chromedriver-85.0.4183.121-lp151.2.136.1

chromedriver-debuginfo-85.0.4183.121-lp151.2.136.1

chromium-85.0.4183.121-lp151.2.136.1

chromium-debuginfo-85.0.4183.121-lp151.2.136.1

chromium-debugsource-85.0.4183.121-lp151.2.136.1

References

https://www.suse.com/security/cve/CVE-2020-15960.html

https://www.suse.com/security/cve/CVE-2020-15961.html

https://www.suse.com/security/cve/CVE-2020-15962.html

https://www.suse.com/security/cve/CVE-2020-15963.html

https://www.suse.com/security/cve/CVE-2020-15964.html

https://www.suse.com/security/cve/CVE-2020-15965.html

https://www.suse.com/security/cve/CVE-2020-15966.html

https://bugzilla.suse.com/1176791

--

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2020:1527-1
Rating: important
Affected Products: openSUSE Leap 15.2 openSUSE Leap 15.1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here