An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for chromium ______________________________________________________________________________ Announcement ID: openSUSE-SU-2023:0246-1 Rating: important References: #1215231 Cross-References: CVE-2023-4863 CVSS scores: CVE-2023-4863 (SUSE): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: openSUSE Backports SLE-15-SP4 openSUSE Backports SLE-15-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for chromium fixes the following issues: Update to version 116.0.5845.187 (boo#1215231): * CVE-2023-4863: Heap buffer overflow in WebP Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP5: zypper in -t patch openSUSE-2023-246=1 - openSUSE Backports SLE-15-SP4: zypper in -t patch openSUSE-2023-246=1 Package List: - openSUSE Backports SLE-15-SP5 (aarch64 x86_64): chromedriver-116.0.5845.187-bp155.2.31.1 chromedriver-debuginfo-116.0.5845.187-bp155.2.31.1 chromium-116.0.5845.187-bp155.2.31.1 chromium-debuginfo-116.0.5845.187-bp155.2.31.1 - openSUSE Backports SLE-15-SP4 (aarch64 x86_64): chromedriver-116.0.5845.187-bp154.2.117.1 chromium-116.0.5845.187-bp154.2.117.1 References: https://www.suse.com/security/cve/CVE-2023-4863.html https://bugzilla.suse.com/1215231 . Essential security upgrade for openSUSE tackling heap overflow vulnerabilities in chromium, rectifies CVE-2023-4863.. openSUSE Security Update, Chromium Patch, Heap Overflow Fix. . Severity: Important. LinuxSecurity.com Team
An update that fixes 10 vulnerabilities is now available. . openSUSE Security Update: Security update for chromium ______________________________________________________________________________ Announcement ID: openSUSE-SU-2023:0045-1 Rating: important References: #1208029 Cross-References: CVE-2023-0696 CVE-2023-0697 CVE-2023-0698 CVE-2023-0699 CVE-2023-0700 CVE-2023-0701 CVE-2023-0702 CVE-2023-0703 CVE-2023-0704 CVE-2023-0705 Affected Products: openSUSE Backports SLE-15-SP4 ______________________________________________________________________________ An update that fixes 10 vulnerabilities is now available. Description: This update for chromium fixes the following issues: Chromium 110.0.5481.77 (boo#1208029): * CVE-2023-0696: Type Confusion in V8 * CVE-2023-0697: Inappropriate implementation in Full screen mode * CVE-2023-0698: Out of bounds read in WebRTC * CVE-2023-0699: Use after free in GPU * CVE-2023-0700: Inappropriate implementation in Download * CVE-2023-0701: Heap buffer overflow in WebUI * CVE-2023-0702: Type Confusion in Data Transfer * CVE-2023-0703: Type Confusion in DevTools * CVE-2023-0704: Insufficient policy enforcement in DevTools * CVE-2023-0705: Integer overflow in Core * Various fixes from internal audits, fuzzing and other initiatives - build with bundled libavif Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP4: zypper in -t patch openSUSE-2023-45=1 Package List: - openSUSE Backports SLE-15-SP4 (aarch64 x86_64): chromedriver-110.0.5481.77-bp154.2.67.1 chromium-110.0.5481.77-bp154.2.67.1 References: https://www.suse.com/security/cve/CVE-2023-0696.html https://www.suse.com/security/cve/CVE-2023-0697.html https://www.suse.com/security/cve/CVE-2023-0698.html https://www.suse.com/security/cve/CVE-2023-0699.html https://www.suse.com/security/cve/CVE-2023-0700.html https://www.suse.com/security/cve/CVE-2023-0701.html https://www.suse.com/security/cve/CVE-2023-0702.html https://www.suse.com/security/cve/CVE-2023-0703.html https://www.suse.com/security/cve/CVE-2023-0704.html https://www.suse.com/security/cve/CVE-2023-0705.html https://bugzilla.suse.com/1208029 . A significant update for Fedora addresses 12 major Firefox vulnerabilities, boosting overall application performance.. openSUSE Chromium Patches, Critical Browser Security Update, Important Software Fix. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for chromium ______________________________________________________________________________ Announcement ID: openSUSE-SU-2022:10221-1 Rating: important References: #1205736 Cross-References: CVE-2022-4135 Affected Products: openSUSE Backports SLE-15-SP3 openSUSE Backports SLE-15-SP4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for chromium fixes the following issues: Chromium 107.0.5304.121 (boo#1205736) * CVE-2022-4135: Heap buffer overflow in GPU Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP4: zypper in -t patch openSUSE-2022-10221=1 - openSUSE Backports SLE-15-SP3: zypper in -t patch openSUSE-2022-10221=1 Package List: - openSUSE Backports SLE-15-SP4 (aarch64 x86_64): chromedriver-107.0.5304.121-bp154.2.46.1 chromedriver-debuginfo-107.0.5304.121-bp154.2.46.1 chromium-107.0.5304.121-bp154.2.46.1 chromium-debuginfo-107.0.5304.121-bp154.2.46.1 - openSUSE Backports SLE-15-SP3 (aarch64 x86_64): chromedriver-107.0.5304.121-bp153.2.139.1 chromium-107.0.5304.121-bp153.2.139.1 References: https://www.suse.com/security/cve/CVE-2022-4135.html https://bugzilla.suse.com/1205736 . Important release for Chromium addresses serious heap buffer overflow issue on openSUSE Backports along with detailed installation steps.. openSUSE Backports, security update, chromium patch, heap overflow fix. . Severity: Important. LinuxSecurity.com Team
Chromium 59. Add smaller logo files. Fix lots of security bugs: Security fix for CVE-2017-5070, CVE-2017-5071, CVE-2017-5072, CVE-2017-5073, CVE-2017-5074, CVE-2017-5075, CVE-2017-5086, CVE-2017-5076, CVE-2017-5077, CVE-2017-5078, CVE-2017-5079, CVE-2017-5080, CVE-2017-5081, CVE-2017-5082, CVE-2017-5083, CVE-2017-5085. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-c11d7ef69a 2017-06-26 19:08:28.704542 --------------------------------------------------------------------------------Name : chromium-native_client Product : Fedora 26 Version : 59.0.3071.86 Release : 1.20170607gitaac1de2.fc26 URL : https://src.chromium.org/ Summary : Google Native Client Toolchain Description : Google's "pnacl" toolchain for native client support in Chromium. Depends on their older "nacl" toolchain, packaged separately. --------------------------------------------------------------------------------Update Information: Chromium 59. Add smaller logo files. Fix lots of security bugs: Security fix for CVE-2017-5070, CVE-2017-5071, CVE-2017-5072, CVE-2017-5073, CVE-2017-5074, CVE-2017-5075, CVE-2017-5086, CVE-2017-5076, CVE-2017-5077, CVE-2017-5078, CVE-2017-5079, CVE-2017-5080, CVE-2017-5081, CVE-2017-5082, CVE-2017-5083, CVE-2017-5085 --------------------------------------------------------------------------------References: [ 1 ] Bug #1459037 - CVE-2017-5085 chromium-browser: inappropriate javascript execution on webui pages https://bugzilla.redhat.com/show_bug.cgi?id=1459037 [ 2 ] Bug #1459036 - CVE-2017-5083 chromium-browser: ui spoofing in blink https://bugzilla.redhat.com/show_bug.cgi?id=1459036 [ 3 ] Bug #1459035 - CVE-2017-5082 chromium-browser: insufficient hardening in credit card editor https://bugzilla.redhat.com/show_bug.cgi?id=1459035 [ 4 ] Bug #1459034 - CVE-2017-5081 chromium-browser: extension verification bypass https://bugzilla.redhat.com/show_bug.cgi?id=1459034 [ 5 ] Bug #1459033 - CVE-2017-5080 chromium-browser: use after free in credit card autofill https://bugzilla.redhat.com/show_bug.cgi?id=1459033 [ 6 ] Bug #1459032 - CVE-2017-5079 chromium-browser: ui spoofing in blink https://bugzilla.redhat.com/show_bug.cgi?id=1459032 [ 7 ] Bug #1459031 - CVE-2017-5078 chromium-browser: possible command injection in mailto handling https://bugzilla.redhat.com/show_bug.cgi?id=1459031 [ 8 ] Bug #1459030 - CVE-2017-5077 chromium-browser: heap buffer overflow in skia https://bugzilla.redhat.com/show_bug.cgi?id=1459030 [ 9 ] Bug #1459029 - CVE-2017-5076 chromium-browser: address spoofing in omnibox https://bugzilla.redhat.com/show_bug.cgi?id=1459029 [ 10 ] Bug #1459028 - CVE-2017-5086 chromium-browser: address spoofing in omnibox https://bugzilla.redhat.com/show_bug.cgi?id=1459028 [ 11 ] Bug #1459027 - CVE-2017-5075 chromium-browser: information leak in csp reporting https://bugzilla.redhat.com/show_bug.cgi?id=1459027 [ 12 ] Bug #1459025 - CVE-2017-5074 chromium-browser: use after free in apps bluetooth https://bugzilla.redhat.com/show_bug.cgi?id=1459025 [ 13 ] Bug #1459024 - CVE-2017-5073 chromium-browser: use after free in print preview https://bugzilla.redhat.com/show_bug.cgi?id=1459024 [ 14 ] Bug #1459023 - CVE-2017-5072 chromium-browser: address spoofing in omnibox https://bugzilla.redhat.com/show_bug.cgi?id=1459023 [ 15 ] Bug #1459022 - CVE-2017-5071 chromium-browser: out of bounds read in v8 https://bugzilla.redhat.com/show_bug.cgi?id=1459022 [ 16 ] Bug #1459021 - CVE-2017-5070 chromium-browser: type confusion in v8 https://bugzilla.redhat.com/show_bug.cgi?id=1459021 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade chromium-native_client' at the command line. For moreinformation, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.