openSUSE: 2019:1666-1: important: chromium
Description
This update for chromium fixes the following issues: Chromium was updated to 75.0.3770.90 (boo#1137332 boo#1138287): * CVE-2019-5842: Use-after-free in Blink. Also updated to 75.0.3770.80 boo#1137332: * CVE-2019-5828: Use after free in ServiceWorker * CVE-2019-5829: Use after free in Download Manager * CVE-2019-5830: Incorrectly credentialed requests in CORS * CVE-2019-5831: Incorrect map processing in V8 * CVE-2019-5832: Incorrect CORS handling in XHR * CVE-2019-5833: Inconsistent security UI placemen * CVE-2019-5835: Out of bounds read in Swiftshader * CVE-2019-5836: Heap buffer overflow in Angle * CVE-2019-5837: Cross-origin resources size disclosure in Appcache * CVE-2019-5838: Overly permissive tab access in Extensions * CVE-2019-5839: Incorrect handling of certain code points in Blink * CVE-2019-5840: Popup blocker bypass * Various fixes from internal audits, fuzzing and other initiatives * CVE-2019-5834: URL spoof in Omnib...
Read the Full Advisory
Patch
Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 42.3: zypper in -t patch openSUSE-2019-1666=1 - openSUSE Leap 15.1: zypper in -t patch openSUSE-2019-1666=1 - openSUSE Leap 15.0: zypper in -t patch openSUSE-2019-1666=1 - openSUSE Backports SLE-15: zypper in -t patch openSUSE-2019-1666=1
Package List
- openSUSE Leap 42.3 (x86_64): chromedriver-75.0.3770.90-217.1 chromedriver-debuginfo-75.0.3770.90-217.1 chromium-75.0.3770.90-217.1 chromium-debuginfo-75.0.3770.90-217.1 chromium-debugsource-75.0.3770.90-217.1 - openSUSE Leap 15.1 (x86_64): chromedriver-75.0.3770.90-lp151.2.9.3 chromedriver-debuginfo-75.0.3770.90-lp151.2.9.3 chromium-75.0.3770.90-lp151.2.9.3 chromium-debuginfo-75.0.3770.90-lp151.2.9.3 chromium-debugsource-75.0.3770.90-lp151.2.9.3 - openSUSE Leap 15.0 (x86_64): chromedriver-75.0.3770.90-lp150.218.4 chromedriver-debuginfo-75.0.3770.90-lp150.218.4 chromium-75.0.3770.90-lp150.218.4 chromium-debuginfo-75.0.3770.90-lp150.218.4 chromium-debugsource-75.0.3770.90-lp150.218.4 - openSUSE Backports SLE-15 (aarch64 x86_64): chromedriver-75.0.3770.90-bp150.213.3 chromedriver-debuginfo-75.0.3770.90-bp150.213.3 chromium-75.0.3770.90-bp150.213.3 chromium-debuginfo-75.0.3770.90-bp150.213.3 chromium-debugsource-75.0.3770.90-bp150.213.3
References
https://www.suse.com/security/cve/CVE-2019-5787.html https://www.suse.com/security/cve/CVE-2019-5788.html https://www.suse.com/security/cve/CVE-2019-5789.html https://www.suse.com/security/cve/CVE-2019-5790.html https://www.suse.com/security/cve/CVE-2019-5791.html https://www.suse.com/security/cve/CVE-2019-5792.html https://www.suse.com/security/cve/CVE-2019-5793.html https://www.suse.com/security/cve/CVE-2019-5794.html https://www.suse.com/security/cve/CVE-2019-5795.html https://www.suse.com/security/cve/CVE-2019-5796.html https://www.suse.com/security/cve/CVE-2019-5797.html https://www.suse.com/security/cve/CVE-2019-5798.html https://www.suse.com/security/cve/CVE-2019-5799.html https://www.suse.com/security/cve/CVE-2019-5800.html https://www.suse.com/security/cve/CVE-2019-5801.html https://www.suse.com/security/cve/CVE-2019-5802.html https://www.suse.com/security/cve/CVE-2019-5803.html https://www.suse.com/security/cve/CVE-2019-5804.html https://www.suse.com/security/cve/CVE-2019-5805.html https://www.suse.com/security/cve/CVE-2019-5806.html https://www.suse.com/security/cve/CVE-2019-5807.html https://www.suse.com/security/cve/CVE-2019-5808.html https://www.suse.com/security/cve/CVE-2019-5809.html https://www.suse.com/security/cve/CVE-2019-5810.html https://www.suse.com/security/cve/CVE-2019-5811.html https://www.suse.com/security/cve/CVE-2019-5812.html https://www.suse.com/security/cve/CVE-2019-5813.html https://www.suse.com/security/cve/CVE-2019-5814.html https://www.suse.com/security/cve/CVE-2019-5815.html https://www.suse.com/security/cve/CVE-2019-5816.html https://www.suse.com/security/cve/CVE-2019-5817.html https://www.suse.com/security/cve/CVE-2019-5818.html https://www.suse.com/security/cve/CVE-2019-5819.html https://www.suse.com/security/cve/CVE-2019-5820.html https://www.suse.com/security/cve/CVE-2019-5821.html https://www.suse.com/security/cve/CVE-2019-5822.html https://www.suse.com/security/cve/CVE-2019-5823.html https://www.suse.com/security/cve/CVE-2019-5824.html https://www.suse.com/security/cve/CVE-2019-5827.html https://www.suse.com/security/cve/CVE-2019-5828.html https://www.suse.com/security/cve/CVE-2019-5829.html https://www.suse.com/security/cve/CVE-2019-5830.html https://www.suse.com/security/cve/CVE-2019-5831.html https://www.suse.com/security/cve/CVE-2019-5832.html https://www.suse.com/security/cve/CVE-2019-5833.html https://www.suse.com/security/cve/CVE-2019-5834.html https://www.suse.com/security/cve/CVE-2019-5835.html https://www.suse.com/security/cve/CVE-2019-5836.html https://www.suse.com/security/cve/CVE-2019-5837.html https://www.suse.com/security/cve/CVE-2019-5838.html https://www.suse.com/security/cve/CVE-2019-5839.html https://www.suse.com/security/cve/CVE-2019-5840.html https://www.suse.com/security/cve/CVE-2019-5842.html https://bugzilla.suse.com/1129059 https://bugzilla.suse.com/1133313 https://bugzilla.suse.com/1134218 https://bugzilla.suse.com/1137332 https://bugzilla.suse.com/1138287--