Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

openSUSE: 2021:1016-1 important: libqt5-qtwebengine heap overflow

opensuse
Calendar Grey July 9, 2021
Dist Opensuse Esm H88
A security patch for libqt5-qtwebengine has been released, resolving 29 vulnerabilities including critical heap and buffer overflow concerns.
An update that fixes 29 vulnerabilities is now available

Description

This update for libqt5-qtwebengine fixes the following issues:

Update to version 5.15.3

CVE fixes backported in chromium updates:

- CVE-2020-16044: Use after free in WebRTC

- CVE-2021-21118: Heap buffer overflow in Blink

- CVE-2021-21119: Use after free in Media

- CVE-2021-21120: Use after free in WebSQL

- CVE-2021-21121: Use after free in Omnibox

- CVE-2021-21122: Use after free in Blink

- CVE-2021-21123: Insufficient data validation in File System API

- CVE-2021-21125: Insufficient policy enforcement in File System API

- CVE-2021-21126: Insufficient policy enforcement in extensions

- CVE-2021-21127: Insufficient policy enforcement in extensions

- CVE-2021-21128: Heap buffer overflow in Blink

- CVE-2021-21129: Insufficient policy enforcement in File System API

- CVE-2021-21130: Insufficient policy enforcement in File System API

- CVE-2021-21131: Insufficient policy enforcement in File System API

- CVE-2021-21132: Inappropriate...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended

installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP2:

zypper in -t patch openSUSE-2021-1016=1

Package List

- openSUSE Backports SLE-15-SP2 (aarch64 x86_64):

libQt5Pdf5-5.15.3-bp152.3.3.1

libQt5PdfWidgets5-5.15.3-bp152.3.3.1

libqt5-qtpdf-devel-5.15.3-bp152.3.3.1

libqt5-qtpdf-examples-5.15.3-bp152.3.3.1

libqt5-qtpdf-imports-5.15.3-bp152.3.3.1

libqt5-qtwebengine-5.15.3-bp152.3.3.1

libqt5-qtwebengine-devel-5.15.3-bp152.3.3.1

libqt5-qtwebengine-examples-5.15.3-bp152.3.3.1

- openSUSE Backports SLE-15-SP2 (noarch):

libqt5-qtpdf-private-headers-devel-5.15.3-bp152.3.3.1

libqt5-qtwebengine-private-headers-devel-5.15.3-bp152.3.3.1

References

https://www.suse.com/security/cve/CVE-2020-16044.html

https://www.suse.com/security/cve/CVE-2021-21118.html

https://www.suse.com/security/cve/CVE-2021-21119.html

https://www.suse.com/security/cve/CVE-2021-21120.html

https://www.suse.com/security/cve/CVE-2021-21121.html

https://www.suse.com/security/cve/CVE-2021-21122.html

https://www.suse.com/security/cve/CVE-2021-21123.html

https://www.suse.com/security/cve/CVE-2021-21125.html

https://www.suse.com/security/cve/CVE-2021-21126.html

https://www.suse.com/security/cve/CVE-2021-21127.html

https://www.suse.com/security/cve/CVE-2021-21128.html

https://www.suse.com/security/cve/CVE-2021-21129.html

https://www.suse.com/security/cve/CVE-2021-21130.html

https://www.suse.com/security/cve/CVE-2021-21131.html

https://www.suse.com/security/cve/CVE-2021-21132.html

https://www.suse.com/security/cve/CVE-2021-21135.html

https://www.suse.com/security/cve/CVE-2021-21137.html

https://www.suse.com/security/cve/CVE-2021-21140.html

https://www.suse.com/security/cve/CVE-2021-211...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2021:1016-1
Rating: important
Affected Products: openSUSE Backports SLE-15-SP2 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here