openSUSE Security Update: Security update for opera
______________________________________________________________________________

Announcement ID:    openSUSE-SU-2024:0156-1
Rating:             important
References:         
Cross-References:   CVE-2024-3832 CVE-2024-3833 CVE-2024-3834
                    CVE-2024-3837 CVE-2024-3838 CVE-2024-3839
                    CVE-2024-3840 CVE-2024-3841 CVE-2024-3843
                    CVE-2024-3844 CVE-2024-3845 CVE-2024-3846
                    CVE-2024-3847 CVE-2024-3914 CVE-2024-4671
                    CVE-2024-5274
CVSS scores:
                    CVE-2024-3834 (NVD) : 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
                    CVE-2024-3837 (NVD) : 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
                    CVE-2024-3838 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
                    CVE-2024-3839 (NVD) : 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
                    CVE-2024-4671 (NVD) : 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
                    CVE-2024-5274 (NVD) : 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products:
                    openSUSE Leap 15.6:NonFree
______________________________________________________________________________

   An update that fixes 16 vulnerabilities is now available.

Description:

   This update for opera fixes the following issues:

   Update to 110.0.5130.64

     * CHR-9748 Update Chromium on desktop-stable-124-5130 to 124.0.6367.243
     * DNA-116317 Create outline or shadow around emojis on tab strip
     * DNA-116320 Create animation for emoji disappearing from tab strip
     * DNA-116564 Assign custom emoji from emoji picker
     * DNA-116690 Make chrome://emoji-picker attachable by webdriver
     * DNA-116732 Introduce stat event for setting / unsetting emoji
       on a tab
     * DNA-116753 Emoji picker does not follow browser theme
     * DNA-116755 Record tab emojis added / removed
     * DNA-116777 Enable #tab-art on all streams

   Update to 110.0.5130.49

     * CHR-9416 Updating Chromium on desktop-stable-* branches
     * DNA-116706 [gpu-crash] Crash at SkGpuShaderImageFilter::
       onFilterImage(skif::Context const&)

   Update to 110.0.5130.39

     * DNA-115603 [Rich Hints] Pass trigger source to the Rich Hint
     * DNA-116680 Import 0-day fix for CVE-2024-5274

   Update to 110.0.5130.35

     * CHR-9721 Update Chromium on desktop-stable-124-5130 to 124.0.6367.202
     * DNA-114787 Crash at views::View::DoRemoveChildView(views:: View*,
       bool, bool, views::View*)
     * DNA-115640 Tab island is not properly displayed after drag&drop in
       light theme
     * DNA-116191 Fix link in RTV Euro CoS
     * DNA-116218 Crash at SkGpuShaderImageFilter::onFilterImage
       (skif::Context const&)
     * DNA-116241 Update affiliation link for media expert "Continue On"
     * DNA-116256 Crash at TabHoverCardController::UpdateHoverCard
       (opera::TabDataView*, TabHoverCardController::UpdateType, bool)
     * DNA-116270 Show 'Suggestions' inside expanding Speed Dial field
     * DNA-116474 Implement the no dynamic hover approach
     * DNA-116493 Make sure that additional elements like (Sync your browser)
       etc. doesn’t shift content down on page
     * DNA-116515 Import 0-day fix from Chromium "[wasm-gc] Only normalize
       JSObject targets in SetOrCopyDataProperties"
     * DNA-116543 Twitter migrate to x.com
     * DNA-116552 Change max width of the banner
     * DNA-116569 Twitter in Panel loading for the first time opens two Tabs
       automatically
     * DNA-116587 Translate settings strings for every language

   The update to chromium 124.0.6367.202 fixes following issues: CVE-2024-4671

   Update to 110.0.5130.23

     * CHR-9706 Update Chromium on desktop-stable-124-5130 to 124.0.6367.62
     * DNA-116450 Promote 110 to stable

   - Complete Opera 110 changelog at:
     https://blogs.opera.com/desktop/changelog-for-110/

   - The update to chromium 124.0.6367.62 fixes following issues:
     CVE-2024-3832, CVE-2024-3833, CVE-2024-3914, CVE-2024-3834,
     CVE-2024-3837, CVE-2024-3838, CVE-2024-3839, CVE-2024-3840,
     CVE-2024-3841, CVE-2024-3843, CVE-2024-3844, CVE-2024-3845,
     CVE-2024-3846, CVE-2024-3847

   - Update to 109.0.5097.80

     * DNA-115738 Crash at extensions::ExtensionRegistry::
       GetExtensionById(std::__Cr::basic_string const&, int)
     * DNA-115797 [Flow] Never ending loading while connecting to flow
     * DNA-116315 Chat GPT in Sidebar Panel doesn’t work

   - Update to 109.0.5097.59

     * CHR-9416 Updating Chromium on desktop-stable-* branches
     * DNA-115810 Enable #drag-multiple-tabs on all streams


Patch Instructions:

   To install this openSUSE Security Update use the SUSE recommended installation methods
   like YaST online_update or "zypper patch".

   Alternatively you can run the command listed for your product:

   - openSUSE Leap 15.6:NonFree:

      zypper in -t patch openSUSE-2024-156=1



Package List:

   - openSUSE Leap 15.6:NonFree (x86_64):

      opera-110.0.5130.64-lp156.2.6.1


References:

   https://www.suse.com/security/cve/CVE-2024-3832.html
   https://www.suse.com/security/cve/CVE-2024-3833.html
   https://www.suse.com/security/cve/CVE-2024-3834.html
   https://www.suse.com/security/cve/CVE-2024-3837.html
   https://www.suse.com/security/cve/CVE-2024-3838.html
   https://www.suse.com/security/cve/CVE-2024-3839.html
   https://www.suse.com/security/cve/CVE-2024-3840.html
   https://www.suse.com/security/cve/CVE-2024-3841.html
   https://www.suse.com/security/cve/CVE-2024-3843.html
   https://www.suse.com/security/cve/CVE-2024-3844.html
   https://www.suse.com/security/cve/CVE-2024-3845.html
   https://www.suse.com/security/cve/CVE-2024-3846.html
   https://www.suse.com/security/cve/CVE-2024-3847.html
   https://www.suse.com/security/cve/CVE-2024-3914.html
   https://www.suse.com/security/cve/CVE-2024-4671.html
   https://www.suse.com/security/cve/CVE-2024-5274.html

openSUSE: 2024:0156-1 important: opera Advisory Security Update

June 10, 2024
An update that fixes 16 vulnerabilities is now available

Description

This update for opera fixes the following issues: Update to 110.0.5130.64 * CHR-9748 Update Chromium on desktop-stable-124-5130 to 124.0.6367.243 * DNA-116317 Create outline or shadow around emojis on tab strip * DNA-116320 Create animation for emoji disappearing from tab strip * DNA-116564 Assign custom emoji from emoji picker * DNA-116690 Make chrome://emoji-picker attachable by webdriver * DNA-116732 Introduce stat event for setting / unsetting emoji on a tab * DNA-116753 Emoji picker does not follow browser theme * DNA-116755 Record tab emojis added / removed * DNA-116777 Enable #tab-art on all streams Update to 110.0.5130.49 * CHR-9416 Updating Chromium on desktop-stable-* branches * DNA-116706 [gpu-crash] Crash at SkGpuShaderImageFilter:: onFilterImage(skif::Context const&) Update to 110.0.5130.39 * DNA-115603 [Rich Hints] Pass trigger source to the Rich Hint * DNA-116680 Import 0-day fix for CVE-2024-5274 Update to 110.0.5130.35 * CHR-9721 Update Chromium on desktop-stable-124-5130 to 124.0.6367.202 * DNA-114787 Crash at views::View::DoRemoveChildView(views:: View*, bool, bool, views::View*) * DNA-115640 Tab island is not properly displayed after drag&drop in light theme * DNA-116191 Fix link in RTV Euro CoS * DNA-116218 Crash at SkGpuShaderImageFilter::onFilterImage (skif::Context const&) * DNA-116241 Update affiliation link for media expert "Continue On" * DNA-116256 Crash at TabHoverCardController::UpdateHoverCard (opera::TabDataView*, TabHoverCardController::UpdateType, bool) * DNA-116270 Show 'Suggestions' inside expanding Speed Dial field * DNA-116474 Implement the no dynamic hover approach * DNA-116493 Make sure that additional elements like (Sync your browser) etc. doesn’t shift content down on page * DNA-116515 Import 0-day fix from Chromium "[wasm-gc] Only normalize JSObject targets in SetOrCopyDataProperties" * DNA-116543 Twitter migrate to x.com * DNA-116552 Change max width of the banner * DNA-116569 Twitter in Panel loading for the first time opens two Tabs automatically * DNA-116587 Translate settings strings for every language The update to chromium 124.0.6367.202 fixes following issues: CVE-2024-4671 Update to 110.0.5130.23 * CHR-9706 Update Chromium on desktop-stable-124-5130 to 124.0.6367.62 * DNA-116450 Promote 110 to stable - Complete Opera 110 changelog at: https://blogs.opera.com/desktop/changelog-for-110/ - The update to chromium 124.0.6367.62 fixes following issues: CVE-2024-3832, CVE-2024-3833, CVE-2024-3914, CVE-2024-3834, CVE-2024-3837, CVE-2024-3838, CVE-2024-3839, CVE-2024-3840, CVE-2024-3841, CVE-2024-3843, CVE-2024-3844, CVE-2024-3845, CVE-2024-3846, CVE-2024-3847 - Update to 109.0.5097.80 * DNA-115738 Crash at extensions::ExtensionRegistry:: GetExtensionById(std::__Cr::basic_string const&, int) * DNA-115797 [Flow] Never ending loading while connecting to flow * DNA-116315 Chat GPT in Sidebar Panel doesn’t work - Update to 109.0.5097.59 * CHR-9416 Updating Chromium on desktop-stable-* branches * DNA-115810 Enable #drag-multiple-tabs on all streams

 

Patch

Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.6:NonFree: zypper in -t patch openSUSE-2024-156=1


Package List

- openSUSE Leap 15.6:NonFree (x86_64): opera-110.0.5130.64-lp156.2.6.1


References

https://www.suse.com/security/cve/CVE-2024-3832.html https://www.suse.com/security/cve/CVE-2024-3833.html https://www.suse.com/security/cve/CVE-2024-3834.html https://www.suse.com/security/cve/CVE-2024-3837.html https://www.suse.com/security/cve/CVE-2024-3838.html https://www.suse.com/security/cve/CVE-2024-3839.html https://www.suse.com/security/cve/CVE-2024-3840.html https://www.suse.com/security/cve/CVE-2024-3841.html https://www.suse.com/security/cve/CVE-2024-3843.html https://www.suse.com/security/cve/CVE-2024-3844.html https://www.suse.com/security/cve/CVE-2024-3845.html https://www.suse.com/security/cve/CVE-2024-3846.html https://www.suse.com/security/cve/CVE-2024-3847.html https://www.suse.com/security/cve/CVE-2024-3914.html https://www.suse.com/security/cve/CVE-2024-4671.html https://www.suse.com/security/cve/CVE-2024-5274.html


Severity
Announcement ID: openSUSE-SU-2024:0156-1
Rating: important
Affected Products: openSUSE Leap 15.6:NonFree .

Related News