Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

openSUSE: 2023:0068-1 Important: Chromium Buffer Overflow

opensuse
Calendar Grey March 13, 2023
Dist Opensuse Esm H88
A significant update for openSUSE tackles 24 vulnerabilities in chromium. Safeguard your system by installing this essential patch.
An update that fixes 24 vulnerabilities is now available

Description

This update for chromium fixes the following issues:

Chromium 111.0.5563.64

* New View Transitions API

* CSS Color Level 4

* New developer tools in style panel for color functionality

* CSS added trigonometric functions, additional root font units and

extended the n-th child pseudo selector.

* previousslide and nextslide actions are now part of the Media Session API

* A number of security fixes (boo#1209040)

* CVE-2023-1213: Use after free in Swiftshader

* CVE-2023-1214: Type Confusion in V8

* CVE-2023-1215: Type Confusion in CSS

* CVE-2023-1216: Use after free in DevTools

* CVE-2023-1217: Stack buffer overflow in Crash reporting

* CVE-2023-1218: Use after free in WebRTC

* CVE-2023-1219: Heap buffer overflow in Metrics

* CVE-2023-1220: Heap buffer overflow in UMA

* CVE-2023-1221: Insufficient policy enforcement in Extensions API

* CVE-2023-1222: Heap buffer overflow in Web Audio API

* CVE-2023-1223: Insufficient policy...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP4:

zypper in -t patch openSUSE-2023-68=1

Package List

- openSUSE Backports SLE-15-SP4 (aarch64 x86_64):

chromedriver-111.0.5563.64-bp154.2.73.1

chromium-111.0.5563.64-bp154.2.73.1

References

https://www.suse.com/security/cve/CVE-2023-1213.html

https://www.suse.com/security/cve/CVE-2023-1214.html

https://www.suse.com/security/cve/CVE-2023-1215.html

https://www.suse.com/security/cve/CVE-2023-1216.html

https://www.suse.com/security/cve/CVE-2023-1217.html

https://www.suse.com/security/cve/CVE-2023-1218.html

https://www.suse.com/security/cve/CVE-2023-1219.html

https://www.suse.com/security/cve/CVE-2023-1220.html

https://www.suse.com/security/cve/CVE-2023-1221.html

https://www.suse.com/security/cve/CVE-2023-1222.html

https://www.suse.com/security/cve/CVE-2023-1223.html

https://www.suse.com/security/cve/CVE-2023-1224.html

https://www.suse.com/security/cve/CVE-2023-1225.html

https://www.suse.com/security/cve/CVE-2023-1226.html

https://www.suse.com/security/cve/CVE-2023-1227.html

https://www.suse.com/security/cve/CVE-2023-1228.html

https://www.suse.com/security/cve/CVE-2023-1229.html

https://https://www.suse.com/security/cve/CVE-2023-1230.html

https://www.suse.com/security/cve/CVE-2023-1231.html

http...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2023:0068-1
Rating: important
Affected Products: openSUSE Backports SLE-15-SP4 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here