Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

openSUSE: 2022:10119-1 Important Update - Chromium Buffer Overflows

opensuse
Calendar Grey September 12, 2022
Dist Opensuse Esm H88
Important revision for openSUSE addressing significant chromium vulnerabilities and bolstering security measures throughout the platform.
An update that fixes 23 vulnerabilities is now available

Description

This update for chromium fixes the following issues:

Chromium 105.0.5195.102 (boo#1203102):

* CVE-2022-3075: Insufficient data validation in Mojo

Chromium 105.0.5195.52 (boo#1202964):

* CVE-2022-3038: Use after free in Network Service

* CVE-2022-3039: Use after free in WebSQL

* CVE-2022-3040: Use after free in Layout

* CVE-2022-3041: Use after free in WebSQL

* CVE-2022-3042: Use after free in PhoneHub

* CVE-2022-3043: Heap buffer overflow in Screen Capture

* CVE-2022-3044: Inappropriate implementation in Site Isolation

* CVE-2022-3045: Insufficient validation of untrusted input in V8

* CVE-2022-3046: Use after free in Browser Tag

* CVE-2022-3071: Use after free in Tab Strip

* CVE-2022-3047: Insufficient policy enforcement in Extensions API

* CVE-2022-3048: Inappropriate implementation in Chrome OS lockscreen

* CVE-2022-3049: Use after free in SplitScreen

* CVE-2022-3050: Heap buffer overflow in WebUI

* CVE-2022-3051: Heap...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP4:

zypper in -t patch openSUSE-2022-10119=1

Package List

- openSUSE Backports SLE-15-SP4 (aarch64 x86_64):

chromedriver-105.0.5195.102-bp154.2.26.1

chromium-105.0.5195.102-bp154.2.26.1

References

https://www.suse.com/security/cve/CVE-2022-3038.html

https://www.suse.com/security/cve/CVE-2022-3039.html

https://www.suse.com/security/cve/CVE-2022-3040.html

https://www.suse.com/security/cve/CVE-2022-3041.html

https://www.suse.com/security/cve/CVE-2022-3042.html

https://www.suse.com/security/cve/CVE-2022-3043.html

https://www.suse.com/security/cve/CVE-2022-3044.html

https://www.suse.com/security/cve/CVE-2022-3045.html

https://www.suse.com/security/cve/CVE-2022-3046.html

https://www.suse.com/security/cve/CVE-2022-3047.html

https://www.suse.com/security/cve/CVE-2022-3048.html

https://www.suse.com/security/cve/CVE-2022-3049.html

https://www.suse.com/security/cve/CVE-2022-3050.html

https://www.suse.com/security/cve/CVE-2022-3051.html

https://www.suse.com/security/cve/CVE-2022-3052.html

https://www.suse.com/security/cve/CVE-2022-3053.html

https://www.suse.com/security/cve/CVE-2022-3054.html

https://www.suse.com/security/cve/CVE-2022-3055.html

https://www.suse.com/security/cve/CVE-2022-3056.html

https://www....

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2022:10119-1
Rating: important
Affected Products: openSUSE Backports SLE-15-SP4 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here