openSUSE Security Update: Security update for chromium
______________________________________________________________________________
Announcement ID: openSUSE-SU-2019:1325-1
Rating: important
References: #1133313
Cross-References: CVE-2019-5805 CVE-2019-5806 CVE-2019-5807
CVE-2019-5808 CVE-2019-5809 CVE-2019-5810
CVE-2019-5811 CVE-2019-5812 CVE-2019-5813
CVE-2019-5814 CVE-2019-5815 CVE-2019-5816
CVE-2019-5817 CVE-2019-5818 CVE-2019-5819
CVE-2019-5820 CVE-2019-5821 CVE-2019-5822
CVE-2019-5823
Affected Products:
openSUSE Leap 15.0
______________________________________________________________________________
An update that fixes 19 vulnerabilities is now available.
Description:
This update for chromium fixes the following issues:
Chromium was updated to 74.0.3729.108 boo#1133313:
* CVE-2019-5805: Use after free in PDFium
* CVE-2019-5806: Integer overflow in Angle
* CVE-2019-5807: Memory corruption in V8
* CVE-2019-5808: Use after free in Blink
* CVE-2019-5809: Use after free in Blink
* CVE-2019-5810: User information disclosure in Autofill
* CVE-2019-5811: CORS bypass in Blink
* CVE-2019-5813: Out of bounds read in V8
* CVE-2019-5814: CORS bypass in Blink
* CVE-2019-5815: Heap buffer overflow in Blink
* CVE-2019-5818: Uninitialized value in media reader
* CVE-2019-5819: Incorrect escaping in developer tools
* CVE-2019-5820: Integer overflow in PDFium
* CVE-2019-5821: Integer overflow in PDFium
* CVE-2019-5822: CORS bypass in download manager
* CVE-2019-5823: Forced navigation from service worker
* CVE-2019-5812: URL spoof in Omnibox on iOS
* CVE-2019-5816: Exploit persistence extension on Android
* CVE-2019-5817: Heap buffer overflow in Angle on Windows
– Update conditions to use system harfbuzz on TW+
– Require java during build
– Enable using pipewire when available
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or “zypper patch”.
Alternatively you can run the command listed for your product:
– openSUSE Leap 15.0:
zypper in -t patch openSUSE-2019-1325=1
Package List:
– openSUSE Leap 15.0 (x86_64):
chromedriver-74.0.3729.108-lp150.209.2
chromedriver-debuginfo-74.0.3729.108-lp150.209.2
chromium-74.0.3729.108-lp150.209.2
chromium-debuginfo-74.0.3729.108-lp150.209.2
chromium-debugsource-74.0.3729.108-lp150.209.2
References:
https://www.suse.com/security/cve/CVE-2019-5805.html
https://www.suse.com/security/cve/CVE-2019-5806.html
https://www.suse.com/security/cve/CVE-2019-5807.html
https://www.suse.com/security/cve/CVE-2019-5808.html
https://www.suse.com/security/cve/CVE-2019-5809.html
https://www.suse.com/security/cve/CVE-2019-5810.html
https://www.suse.com/security/cve/CVE-2019-5811.html
https://www.suse.com/security/cve/CVE-2019-5812.html
https://www.suse.com/security/cve/CVE-2019-5813.html
https://www.suse.com/security/cve/CVE-2019-5814.html
https://www.suse.com/security/cve/CVE-2019-5815.html
https://www.suse.com/security/cve/CVE-2019-5816.html
https://www.suse.com/security/cve/CVE-2019-5817.html
https://www.suse.com/security/cve/CVE-2019-5818.html
https://www.suse.com/security/cve/CVE-2019-5819.html
https://www.suse.com/security/cve/CVE-2019-5820.html
https://www.suse.com/security/cve/CVE-2019-5821.html
https://www.suse.com/security/cve/CVE-2019-5822.html
https://www.suse.com/security/cve/CVE-2019-5823.html
https://bugzilla.suse.com/1133313
—
To unsubscribe, e-mail: opensuse-security-announce+unsubscribe@opensuse.org
For additional commands, e-mail: opensuse-security-announce+help@opensuse.org
openSUSE Security Update: Security update for chromium
______________________________________________________________________________
Announcement ID: openSUSE-SU-2019:1324-1
Rating: important
References: #1133313
Cross-References: CVE-2019-5805 CVE-2019-5806 CVE-2019-5807
CVE-2019-5808 CVE-2019-5809 CVE-2019-5810
CVE-2019-5811 CVE-2019-5813 CVE-2019-5814
CVE-2019-5815 CVE-2019-5818 CVE-2019-5819
CVE-2019-5820 CVE-2019-5821 CVE-2019-5822
CVE-2019-5823
Affected Products:
openSUSE Leap 42.3
______________________________________________________________________________
An update that fixes 16 vulnerabilities is now available.
Description:
This update for chromium fixes the following issues:
Security update to version 74.0.3729.108 (boo#1133313).
Security issues fixed:
– CVE-2019-5805: Use after free in PDFium
– CVE-2019-5806: Integer overflow in Angle
– CVE-2019-5807: Memory corruption in V8
– CVE-2019-5808: Use after free in Blink
– CVE-2019-5809: Use after free in Blink
– CVE-2019-5810: User information disclosure in Autofill
– CVE-2019-5811: CORS bypass in Blink
– CVE-2019-5813: Out of bounds read in V8
– CVE-2019-5814: CORS bypass in Blink
– CVE-2019-5815: Heap buffer overflow in Blink
– CVE-2019-5818: Uninitialized value in media reader
– CVE-2019-5819: Incorrect escaping in developer tools
– CVE-2019-5820: Integer overflow in PDFium
– CVE-2019-5821: Integer overflow in PDFium
– CVE-2019-5822: CORS bypass in download manager
– CVE-2019-5823: Forced navigation from service worker
Bug fixes:
– Update to 73.0.3686.103:
* Various feature fixes
– Update to 73.0.3683.86:
* Various feature fixes
– Update conditions to use system harfbuzz on TW+
– Require java during build
– Enable using pipewire when available
– Rebase chromium-vaapi.patch to match up the Fedora one
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or “zypper patch”.
Alternatively you can run the command listed for your product:
– openSUSE Leap 42.3:
zypper in -t patch openSUSE-2019-1324=1
Package List:
– openSUSE Leap 42.3 (x86_64):
chromedriver-74.0.3729.108-208.1
chromedriver-debuginfo-74.0.3729.108-208.1
chromium-74.0.3729.108-208.1
chromium-debuginfo-74.0.3729.108-208.1
chromium-debugsource-74.0.3729.108-208.1
References:
https://www.suse.com/security/cve/CVE-2019-5805.html
https://www.suse.com/security/cve/CVE-2019-5806.html
https://www.suse.com/security/cve/CVE-2019-5807.html
https://www.suse.com/security/cve/CVE-2019-5808.html
https://www.suse.com/security/cve/CVE-2019-5809.html
https://www.suse.com/security/cve/CVE-2019-5810.html
https://www.suse.com/security/cve/CVE-2019-5811.html
https://www.suse.com/security/cve/CVE-2019-5813.html
https://www.suse.com/security/cve/CVE-2019-5814.html
https://www.suse.com/security/cve/CVE-2019-5815.html
https://www.suse.com/security/cve/CVE-2019-5818.html
https://www.suse.com/security/cve/CVE-2019-5819.html
https://www.suse.com/security/cve/CVE-2019-5820.html
https://www.suse.com/security/cve/CVE-2019-5821.html
https://www.suse.com/security/cve/CVE-2019-5822.html
https://www.suse.com/security/cve/CVE-2019-5823.html
https://bugzilla.suse.com/1133313
—
To unsubscribe, e-mail: opensuse-security-announce+unsubscribe@opensuse.org
For additional commands, e-mail: opensuse-security-announce+help@opensuse.org