Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

SUSE 2016:2598-1 Important: Chromium XSS And Memory Issues

suse
Calendar Grey October 23, 2016
Dist Suse Esm H88
SUSE upgrade strengthens Chromium's safety by addressing multiple severe vulnerabilities that could lead to potential data leaks.
An update that fixes 13 vulnerabilities is now available

Summary

Chromium was updated to 54.0.2840.59 to fix security issues and bugs. The following security issues are fixed (bnc#1004465): - CVE-2016-5181: Universal XSS in Blink - CVE-2016-5182: Heap overflow in Blink - CVE-2016-5183: Use after free in PDFium - CVE-2016-5184: Use after free in PDFium - CVE-2016-5185: Use after free in Blink - CVE-2016-5187: URL spoofing - CVE-2016-5188: UI spoofing - CVE-2016-5192: Cross-origin bypass in Blink - CVE-2016-5189: URL spoofing - CVE-2016-5186: Out of bounds read in DevTools - CVE-2016-5191: Universal XSS in Bookmarks - CVE-2016-5190: Use after free in Internals - CVE-2016-5193: Scheme bypass The following bugs were fixed: - bnc#1000019: display issues in full screen mode, add --ui-disable-partial-swap to the launcher The following packaging changes are included:

References

#1000019 #1004465

Cross- CVE-2016-5181 CVE-2016-5182 CVE-2016-5183

CVE-2016-5184 CVE-2016-5185 CVE-2016-5186

CVE-2016-5187 CVE-2016-5188 CVE-2016-5189

CVE-2016-5190 CVE-2016-5191 CVE-2016-5192

CVE-2016-5193

Affected Products:

SUSE Package Hub for SUSE Linux Enterprise 12

https://www.suse.com/security/cve/CVE-2016-5181.html

https://www.suse.com/security/cve/CVE-2016-5182.html

https://www.suse.com/security/cve/CVE-2016-5183.html

https://www.suse.com/security/cve/CVE-2016-5184.html

https://www.suse.com/security/cve/CVE-2016-5185.html

https://www.suse.com/security/cve/CVE-2016-5186.html

https://www.suse.com/security/cve/CVE-2016-5187.html

https://www.suse.com/security/cve/CVE-2016-5188.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:2598-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here