An update that fixes 5 vulnerabilities is now available. . openSUSE Security Update: Security update for chromium ______________________________________________________________________________ Announcement ID: openSUSE-SU-2023:0237-1 Rating: important References: #1214487 Cross-References: CVE-2023-4427 CVE-2023-4428 CVE-2023-4429 CVE-2023-4430 CVE-2023-4431 CVSS scores: CVE-2023-4428 (NVD) : 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H CVE-2023-4429 (NVD) : 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2023-4430 (NVD) : 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2023-4431 (NVD) : 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H Affected Products: openSUSE Backports SLE-15-SP4 openSUSE Backports SLE-15-SP5 ______________________________________________________________________________ An update that fixes 5 vulnerabilities is now available. Description: This update for chromium fixes the following issues: Chromium 116.0.5845.110 (boo#1214487): * CVE-2023-4427: Out of bounds memory access in V8 * CVE-2023-4428: Out of bounds memory access in CSS * CVE-2023-4429: Use after free in Loader * CVE-2023-4430: Use after free in Vulkan * CVE-2023-4431: Out of bounds memory access in Fonts Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP5: zypper in -t patch openSUSE-2023-237=1 - openSUSE Backports SLE-15-SP4: zypper in -t patch openSUSE-2023-237=1 Package List: - openSUSE Backports SLE-15-SP5 (x86_64): chromedriver-116.0.5845.110-bp155.2.22.1 chromedriver-debuginfo-116.0.5845.110-bp155.2.22.1 chromium-116.0.5845.110-bp155.2.22.1 chromium-debuginfo-116.0.5845.110-bp155.2.22.1 - openSUSE Backports SLE-15-SP4 (x86_64): chromedriver-116.0.5845.110-bp154.2.108.1 chromium-116.0.5845.110-bp154.2.108.1 References: https://www.suse.com/security/cve/CVE-2023-4427.html https://www.suse.com/security/cve/CVE-2023-4428.html https://www.suse.com/security/cve/CVE-2023-4429.html https://www.suse.com/security/cve/CVE-2023-4430.html https://www.suse.com/security/cve/CVE-2023-4431.html https://bugzilla.suse.com/1214487 . This significant release for Fedora addresses several major vulnerabilities in Firefox, improving overall security and performance.. openSUSE Security, Chromium Patch, Memory Access Fix, Software Update. . Severity: Important. LinuxSecurity.com Team
An update that fixes 5 vulnerabilities is now available. . openSUSE Security Update: Security update for chromium ______________________________________________________________________________ Announcement ID: openSUSE-SU-2022:10245-1 Rating: important References: #1205433 Cross-References: CVE-2022-4436 CVE-2022-4437 CVE-2022-4438 CVE-2022-4439 CVE-2022-4440 Affected Products: openSUSE Backports SLE-15-SP3 ______________________________________________________________________________ An update that fixes 5 vulnerabilities is now available. Description: This update for chromium fixes the following issues: Update to version 108.0.5359.124 (boo#1206403): - CVE-2022-4436: Use after free in Blink Media - CVE-2022-4437: Use after free in Mojo IPC - CVE-2022-4438: Use after free in Blink Frames - CVE-2022-4439: Use after free in Aura - CVE-2022-4440: Use after free in Profiles Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP3: zypper in -t patch openSUSE-2022-10245=1 Package List: - openSUSE Backports SLE-15-SP3 (aarch64 x86_64): chromedriver-108.0.5359.124-bp153.2.148.1 chromium-108.0.5359.124-bp153.2.148.1 References: https://www.suse.com/security/cve/CVE-2022-4436.html https://www.suse.com/security/cve/CVE-2022-4437.html https://www.suse.com/security/cve/CVE-2022-4438.html https://www.suse.com/security/cve/CVE-2022-4439.html https://www.suse.com/security/cve/CVE-2022-4440.html https://bugzilla.suse.com/1205433 . A significant openSUSE patch resolves several vital vulnerabilities in Firefox, providing insights on deployment techniques and enhancements.. openSUSE Security Update, Chromium Issues, Software Patch. . Severity: Important. LinuxSecurity.com Team
An update that fixes 25 vulnerabilities is now available. . openSUSE Security Update: Security update for chromium ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:1350-1 Rating: important References: #1190765 #1191166 #1191204 #1191463 Cross-References: CVE-2021-37956 CVE-2021-37957 CVE-2021-37958 CVE-2021-37959 CVE-2021-37960 CVE-2021-37961 CVE-2021-37962 CVE-2021-37963 CVE-2021-37964 CVE-2021-37965 CVE-2021-37966 CVE-2021-37967 CVE-2021-37968 CVE-2021-37969 CVE-2021-37970 CVE-2021-37971 CVE-2021-37972 CVE-2021-37973 CVE-2021-37974 CVE-2021-37975 CVE-2021-37976 CVE-2021-37977 CVE-2021-37978 CVE-2021-37979 CVE-2021-37980 Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that fixes 25 vulnerabilities is now available. Description: This update for chromium fixes the following issues: Chromium 94.0.4606.81 (boo#1191463): * CVE-2021-37977: Use after free in Garbage Collection * CVE-2021-37978: Heap buffer overflow in Blink * CVE-2021-37979: Heap buffer overflow in WebRTC * CVE-2021-37980: Inappropriate implementation in Sandbox Chromium 94.0.4606.54 (boo#1190765): * CVE-2021-37956: Use after free in Offline use * CVE-2021-37957: Use after free in WebGPU * CVE-2021-37958: Inappropriate implementation in Navigation * CVE-2021-37959: Use after free in Task Manager * CVE-2021-37960: Inappropriate implementation in Blink graphics * CVE-2021-37961: Use after free in Tab Strip * CVE-2021-37962: Use after free in Performance Manager * CVE-2021-37963: Side-channel information leakage in DevTools * CVE-2021-37964: Inappropriate implementation in ChromeOS Networking * CVE-2021-37965: Inappropriate implementation inBackground Fetch API * CVE-2021-37966: Inappropriate implementation in Compositing * CVE-2021-37967: Inappropriate implementation in Background Fetch API * CVE-2021-37968: Inappropriate implementation in Background Fetch API * CVE-2021-37969: Inappropriate implementation in Google Updater * CVE-2021-37970: Use after free in File System API * CVE-2021-37971: Incorrect security UI in Web Browser UI * CVE-2021-37972: Out of bounds read in libjpeg-turbo Chromium 94.0.4606.61 (boo#1191166): * CVE-2021-37973: Use after free in Portals Chromium 94.0.4606.71 (boo#1191204): * CVE-2021-37974 : Use after free in Safe Browsing * CVE-2021-37975 : Use after free in V8 * CVE-2021-37976 : Information leak in core Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-1350=1 Package List: - openSUSE Leap 15.2 (x86_64): chromedriver-94.0.4606.81-lp152.2.132.1 chromedriver-debuginfo-94.0.4606.81-lp152.2.132.1 chromium-94.0.4606.81-lp152.2.132.1 chromium-debuginfo-94.0.4606.81-lp152.2.132.1 References: https://www.suse.com/security/cve/CVE-2021-37956.html https://www.suse.com/security/cve/CVE-2021-37957.html https://www.suse.com/security/cve/CVE-2021-37958.html https://www.suse.com/security/cve/CVE-2021-37959.html https://www.suse.com/security/cve/CVE-2021-37960.html https://www.suse.com/security/cve/CVE-2021-37961.html https://www.suse.com/security/cve/CVE-2021-37962.html https://www.suse.com/security/cve/CVE-2021-37963.html https://www.suse.com/security/cve/CVE-2021-37964.html https://www.suse.com/security/cve/CVE-2021-37965.html https://www.suse.com/security/cve/CVE-2021-37966.html https://www.suse.com/security/cve/CVE-2021-37967.html https://www.suse.com/security/cve/CVE-2021-37968.html https://www.suse.com/security/cve/CVE-2021-37969.html https://www.suse.com/security/cve/CVE-2021-37970.html https://www.suse.com/security/cve/CVE-2021-37971.html https://www.suse.com/security/cve/CVE-2021-37972.html https://www.suse.com/security/cve/CVE-2021-37973.html https://www.suse.com/security/cve/CVE-2021-37974.html https://www.suse.com/security/cve/CVE-2021-37975.html https://www.suse.com/security/cve/CVE-2021-37976.html https://www.suse.com/security/cve/CVE-2021-37977.html https://www.suse.com/security/cve/CVE-2021-37978.html https://www.suse.com/security/cve/CVE-2021-37979.html https://www.suse.com/security/cve/CVE-2021-37980.html https://bugzilla.suse.com/1190765 https://bugzilla.suse.com/1191166 https://bugzilla.suse.com/1191204 https://bugzilla.suse.com/1191463 . An enhancement for chromium resolves significant concerns within openSUSE Leap 15.2, fixing vulnerabilities present in the application.. openSUSE Update, chromium Security Fix, Linux Software Security. . Severity: Important. LinuxSecurity.com Team
The package chromium before version 61.0.3163.79-1 is vulnerable to multiple issues including arbitrary code execution, access restriction bypass, information disclosure and silent downgrade. . Arch Linux Security Advisory ASA-201709-1 ======================================== Severity: Critical Date : 2017-09-06 CVE-ID : CVE-2017-5111 CVE-2017-5112 CVE-2017-5113 CVE-2017-5114 CVE-2017-5115 CVE-2017-5116 CVE-2017-5117 CVE-2017-5118 CVE-2017-5119 CVE-2017-5120 Package : chromium Type : multiple issues Remote : Yes Link : https://security.archlinux.org/AVG-391 Summary ====== The package chromium before version 61.0.3163.79-1 is vulnerable to multiple issues including arbitrary code execution, access restriction bypass, information disclosure and silent downgrade. Resolution ========= Upgrade to 61.0.3163.79-1. # pacman -Syu "chromium> =61.0.3163.79-1" The problems have been fixed upstream in version 61.0.3163.79. Workaround ========= None. Description ========== - CVE-2017-5111 (arbitrary code execution) A use-after-free vulnerability has been found in the PDFium component of the Chromium browser < 61.0.3163.79. - CVE-2017-5112 (arbitrary code execution) A heap-based buffer overflow vulnerability has been found in the WebGL component of the Chromium browser < 61.0.3163.79. - CVE-2017-5113 (arbitrary code execution) A heap-based buffer overflow vulnerability has been found in the Skia component of the Chromium browser < 61.0.3163.79. - CVE-2017-5114 (arbitrary code execution) A memory lifecycle vulnerability has been found in the PDFium component of the Chromium browser < 61.0.3163.79. - CVE-2017-5115 (arbitrary code execution) A type confusion vulnerability has been found in the V8 component of the Chromium browser < 61.0.3163.79. - CVE-2017-5116 (arbitrary code execution) A type confusion vulnerability has been found in the V8 component of the Chromium browser < 61.0.3163.79. - CVE-2017-5117(information disclosure) A use of initialized value issue has been found in the Skia component of the Chromium browser < 61.0.3163.79. - CVE-2017-5118 (access restriction bypass) A content security policy bypass vulnerability has been found in the Blink component of the Chromium browser < 61.0.3163.79. - CVE-2017-5119 (information disclosure) A use of initialized value issue has been found in the Skia component of the Chromium browser < 61.0.3163.79. - CVE-2017-5120 (silent downgrade) A potential issue leading to HTTPS downgrade during redirect navigation has been found in the Chromium browser < 61.0.3163.79. Impact ===== A remote attacker can access sensitive information, bypass the content security policy, force a downgrade from HTTPS to HTTP and execute arbitrary code on the affected host. References ========= https://chromereleases.googleblog.com/2017/09/stable-channel-update-for-desktop.html https://bugs.chromium.org/p/chromium/issues/detail?id=737023 https://bugs.chromium.org/p/chromium/issues/detail?id=740603 https://bugs.chromium.org/p/chromium/issues/detail?id=747043 https://bugs.chromium.org/p/chromium/issues/detail?id=752829 https://bugs.chromium.org/p/chromium/issues/detail?id=744584 https://bugs.chromium.org/p/chromium/issues/detail?id=759624 https://bugs.chromium.org/p/chromium/issues/detail?id=739190 https://bugs.chromium.org/p/chromium/issues/detail?id=747847 https://bugs.chromium.org/p/chromium/issues/detail?id=725127 https://bugs.chromium.org/p/chromium/issues/detail?id=718676 https://security.archlinux.org/CVE-2017-5111 https://security.archlinux.org/CVE-2017-5112 https://security.archlinux.org/CVE-2017-5113 https://security.archlinux.org/CVE-2017-5114 https://security.archlinux.org/CVE-2017-5115 https://security.archlinux.org/CVE-2017-5116 https://security.archlinux.org/CVE-2017-5117 https://security.archlinux.org/CVE-2017-5118 https://security.archlinux.org/CVE-2017-5119 https://security.archlinux.org/CVE-2017-5120 . DebianSecurity Advisory DSA-2023-007 identifies severe vulnerabilities in firefox prior to version 93.0-1.. Arch Linux, Chromium Security, Code Execution, Access Restrictions. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.