Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

openSUSE: 2020:1829-1 Important: Chromium Security Update

opensuse
Calendar Grey November 5, 2020
Dist Opensuse Esm H88
openSUSE has released updates for Firefox addressing various vulnerabilities and enhancing security. Prompt action is advised for impacted users.
An update that fixes 39 vulnerabilities is now available.

Description

This update for chromium, gn fixes the following issues:

chromium was updated to 86.0.4240.183 boo#1178375

- CVE-2020-16004: Use after free in user interface.

- CVE-2020-16005: Insufficient policy enforcement in ANGLE.

- CVE-2020-16006: Inappropriate implementation in V8

- CVE-2020-16007: Insufficient data validation in installer.

- CVE-2020-16008: Stack buffer overflow in WebRTC.

- CVE-2020-16009: Inappropriate implementation in V8.

- CVE-2020-16011: Heap buffer overflow in UI on Windows.

Update to 86.0.4240.111 boo#1177936

- CVE-2020-16000: Inappropriate implementation in Blink.

- CVE-2020-16001: Use after free in media.

- CVE-2020-16002: Use after free in PDFium.

- CVE-2020-15999: Heap buffer overflow in Freetype.

- CVE-2020-16003: Use after free in printing.

- chromium-86-f_seal.patch: F_SEAL* definitions added for leap 15.1 and

15.2

- Remove vdpau->vaapi bridge as it breaks a lot: (fixes welcome by someone

else...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP2:

zypper in -t patch openSUSE-2020-1829=1

Package List

- openSUSE Backports SLE-15-SP2 (aarch64 ppc64le s390x x86_64):

gn-0.1807-bp152.2.3.4

gn-debuginfo-0.1807-bp152.2.3.4

gn-debugsource-0.1807-bp152.2.3.4

- openSUSE Backports SLE-15-SP2 (aarch64 x86_64):

chromedriver-86.0.4240.183-bp152.2.26.1

chromium-86.0.4240.183-bp152.2.26.1

References

https://www.suse.com/security/cve/CVE-2020-15967.html

https://www.suse.com/security/cve/CVE-2020-15968.html

https://www.suse.com/security/cve/CVE-2020-15969.html

https://www.suse.com/security/cve/CVE-2020-15970.html

https://www.suse.com/security/cve/CVE-2020-15971.html

https://www.suse.com/security/cve/CVE-2020-15972.html

https://www.suse.com/security/cve/CVE-2020-15973.html

https://www.suse.com/security/cve/CVE-2020-15974.html

https://www.suse.com/security/cve/CVE-2020-15975.html

https://www.suse.com/security/cve/CVE-2020-15976.html

https://www.suse.com/security/cve/CVE-2020-15977.html

https://www.suse.com/security/cve/CVE-2020-15978.html

https://www.suse.com/security/cve/CVE-2020-15979.html

https://www.suse.com/security/cve/CVE-2020-15980.html

https://www.suse.com/security/cve/CVE-2020-15981.html

https://www.suse.com/security/cve/CVE-2020-15982.html

https://www.suse.com/security/cve/CVE-2020-15983.html

https://www.suse.com/security/cve/CVE-2020-15984.html

https://www.suse.com/security/cve/CVE-2020-159...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2020:1829-1
Rating: important
Affected Products: openSUSE Backports SLE-15-SP2

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here