openSUSE-SU-2019:1062-1
Dashboard / Vulnerabilities / openSUSE-SU-2019:1062-1
openSUSE-SU-2019:1062-1
Summary: Security update for chromium
Details: This update for chromium to version 73.0.3683.75 fixes the following issues: Security issues fixed (bsc#1129059): - CVE-2019-5787: Fixed a use after free in Canvas. - CVE-2019-5788: Fixed a use after free in FileAPI. - CVE-2019-5789: Fixed a use after free in WebMIDI. - CVE-2019-5790: Fixed a heap buffer overflow in V8. - CVE-2019-5791: Fixed a type confusion in V8. - CVE-2019-5792: Fixed an integer overflow in PDFium. - CVE-2019-5793: Fixed excessive permissions for private API in Extensions. - CVE-2019-5794: Fixed security UI spoofing. - CVE-2019-5795: Fixed an integer overflow in PDFium. - CVE-2019-5796: Fixed a race condition in Extensions. - CVE-2019-5797: Fixed a race condition in DOMStorage. - CVE-2019-5798: Fixed an out of bounds read in Skia. - CVE-2019-5799: Fixed a CSP bypass with blob URL. - CVE-2019-5800: Fixed a CSP bypass with blob URL. - CVE-2019-5801: Fixed an incorrect Omnibox display on iOS. - CVE-2019-5802: Fixed security UI spoofing. - CVE-2019-5803: Fixed a CSP bypass with Javascript URLs'. - CVE-2019-5804: Fixed a command line injection on Windows. Release notes: https://chromereleases.googleblog.com/2019/03/stable-channel-update-for-desktop_12.html
References: https://lists.opensuse.org/archives/list/[email protected]/thread/UEJ3CRVCTM23JSBBSLBH5OMPDHJF2SQK/#UEJ3CRVCTM23JSBBSLBH5OMPDHJF2SQK, https://bugzilla.suse.com/1129059, https://www.suse.com/security/cve/CVE-2019-5787, https://www.suse.com/security/cve/CVE-2019-5788, https://www.suse.com/security/cve/CVE-2019-5789, https://www.suse.com/security/cve/CVE-2019-5790, https://www.suse.com/security/cve/CVE-2019-5791, https://www.suse.com/security/cve/CVE-2019-5792, https://www.suse.com/security/cve/CVE-2019-5793, https://www.suse.com/security/cve/CVE-2019-5794, https://www.suse.com/security/cve/CVE-2019-5795, https://www.suse.com/security/cve/CVE-2019-5796, https://www.suse.com/security/cve/CVE-2019-5797, https://www.suse.com/security/cve/CVE-2019-5798, https://www.suse.com/security/cve/CVE-2019-5799, https://www.suse.com/security/cve/CVE-2019-5800, https://www.suse.com/security/cve/CVE-2019-5801, https://www.suse.com/security/cve/CVE-2019-5802, https://www.suse.com/security/cve/CVE-2019-5803, https://www.suse.com/security/cve/CVE-2019-5804
Affected packages
Package
Name: chromium
Purl: pkg:rpm/opensuse/chromium&distro=openSUSE%20Leap%2015.0
Affected ranges
Type: ECOSYSTEM
Events:
