Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

openSUSE: 2023:0061-1 Important: Security Issues in Chromium

opensuse
Calendar Grey February 27, 2023
Dist Opensuse Esm H88
The latest openSUSE patch effectively resolves significant vulnerabilities in Chromium that impact various elements, tackling 8 severe security risks.
An update that fixes 8 vulnerabilities is now available

Description

This update for chromium fixes the following issues:

Chromium 110.0.5481.177 (boo#1208589)

* CVE-2023-0927: Use after free in Web Payments API

* CVE-2023-0928: Use after free in SwiftShader

* CVE-2023-0929: Use after free in Vulkan

* CVE-2023-0930: Heap buffer overflow in Video

* CVE-2023-0931: Use after free in Video

* CVE-2023-0932: Use after free in WebRTC

* CVE-2023-0933: Integer overflow in PDF

* CVE-2023-0941: Use after free in Prompts

* Various fixes from internal audits, fuzzing and other initiatives

Chromium 110.0.5481.100

* fix regression on SAP Business Objects web UI

* fix date formatting behavior change from ICU 72

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP4:

zypper in -t patch openSUSE-2023-61=1

Package List

- openSUSE Backports SLE-15-SP4 (aarch64 x86_64):

chromedriver-110.0.5481.177-bp154.2.70.1

chromium-110.0.5481.177-bp154.2.70.1

References

https://www.suse.com/security/cve/CVE-2023-0927.html

https://www.suse.com/security/cve/CVE-2023-0928.html

https://www.suse.com/security/cve/CVE-2023-0929.html

https://www.suse.com/security/cve/CVE-2023-0930.html

https://www.suse.com/security/cve/CVE-2023-0931.html

https://www.suse.com/security/cve/CVE-2023-0932.html

https://www.suse.com/security/cve/CVE-2023-0933.html

https://www.suse.com/security/cve/CVE-2023-0941.html

https://bugzilla.suse.com/1208589

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2023:0061-1
Rating: important
Affected Products: openSUSE Backports SLE-15-SP4 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here