Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 442
Alerts This Week
Warning Icon 1 442

openSUSE: 2023:0368-1 Important Chromium Update For 14 Security Issues

opensuse
Calendar Grey November 14, 2023
Scroller Opensuse
Addresses 14 critical vulnerabilities within Chromium for openSUSE along with detailed security patches and step-by-step upgrade guidance.
An update that fixes 14 vulnerabilities is now available

Description

This update for chromium fixes the following issues:

Chromium 119.0.6045.123 (boo#1216978)

* CVE-2023-5996: Use after free in WebAudio

Chromium 119.0.6045.105 (boo#1216783)

* CVE-2023-5480: Inappropriate implementation in Payments

* CVE-2023-5482: Insufficient data validation in USB

* CVE-2023-5849: Integer overflow in USB

* CVE-2023-5850: Incorrect security UI in Downloads

* CVE-2023-5851: Inappropriate implementation in Downloads

* CVE-2023-5852: Use after free in Printing

* CVE-2023-5853: Incorrect security UI in Downloads

* CVE-2023-5854: Use after free in Profiles

* CVE-2023-5855: Use after free in Reading Mode

* CVE-2023-5856: Use after free in Side Panel

* CVE-2023-5857: Inappropriate implementation in Downloads

* CVE-2023-5858: Inappropriate implementation in WebApp Provider

* CVE-2023-5859: Incorrect security UI in Picture In Picture

gn was updated to version 0.20231023:

* many updates to support Chromium 119...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP5:

zypper in -t patch openSUSE-2023-368=1

- openSUSE Backports SLE-15-SP4:

zypper in -t patch openSUSE-2023-368=1

Package List

- openSUSE Backports SLE-15-SP5 (aarch64 i586 ppc64le s390x x86_64):

gn-0.20231023-bp155.5.3.1

gn-debuginfo-0.20231023-bp155.5.3.1

gn-debugsource-0.20231023-bp155.5.3.1

- openSUSE Backports SLE-15-SP5 (aarch64 x86_64):

chromedriver-119.0.6045.123-bp155.2.55.1

chromedriver-debuginfo-119.0.6045.123-bp155.2.55.1

chromium-119.0.6045.123-bp155.2.55.1

chromium-debuginfo-119.0.6045.123-bp155.2.55.1

- openSUSE Backports SLE-15-SP4 (aarch64 i586 ppc64le s390x x86_64):

gn-0.20231023-bp154.3.6.1

gn-debuginfo-0.20231023-bp154.3.6.1

gn-debugsource-0.20231023-bp154.3.6.1

- openSUSE Backports SLE-15-SP4 (aarch64 x86_64):

chromedriver-119.0.6045.123-bp154.2.141.1

chromium-119.0.6045.123-bp154.2.141.1

References

https://www.suse.com/security/cve/CVE-2023-5480.html

https://www.suse.com/security/cve/CVE-2023-5482.html

https://www.suse.com/security/cve/CVE-2023-5849.html

https://www.suse.com/security/cve/CVE-2023-5850.html

https://www.suse.com/security/cve/CVE-2023-5851.html

https://www.suse.com/security/cve/CVE-2023-5852.html

https://www.suse.com/security/cve/CVE-2023-5853.html

https://www.suse.com/security/cve/CVE-2023-5854.html

https://www.suse.com/security/cve/CVE-2023-5855.html

https://www.suse.com/security/cve/CVE-2023-5856.html

https://www.suse.com/security/cve/CVE-2023-5857.html

https://www.suse.com/security/cve/CVE-2023-5858.html

https://www.suse.com/security/cve/CVE-2023-5859.html

https://www.suse.com/security/cve/CVE-2023-5996.html

https://bugzilla.suse.com/1216783

https://bugzilla.suse.com/1216978

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2023:0368-1
Rating: important
Affected Products: openSUSE Backports SLE-15-SP4 openSUSE Backports SLE-15-SP5 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.