[openSUSE-SU-2019:1062-1] Security update for chromium

Severity Important
Affected Packages 2
CVEs 18

Security update for chromium

This update for chromium to version 73.0.3683.75 fixes the following issues:

Security issues fixed (bsc#1129059):

  • CVE-2019-5787: Fixed a use after free in Canvas.
  • CVE-2019-5788: Fixed a use after free in FileAPI.
  • CVE-2019-5789: Fixed a use after free in WebMIDI.
  • CVE-2019-5790: Fixed a heap buffer overflow in V8.
  • CVE-2019-5791: Fixed a type confusion in V8.
  • CVE-2019-5792: Fixed an integer overflow in PDFium.
  • CVE-2019-5793: Fixed excessive permissions for private API in Extensions.
  • CVE-2019-5794: Fixed security UI spoofing.
  • CVE-2019-5795: Fixed an integer overflow in PDFium.
  • CVE-2019-5796: Fixed a race condition in Extensions.
  • CVE-2019-5797: Fixed a race condition in DOMStorage.
  • CVE-2019-5798: Fixed an out of bounds read in Skia.
  • CVE-2019-5799: Fixed a CSP bypass with blob URL.
  • CVE-2019-5800: Fixed a CSP bypass with blob URL.
  • CVE-2019-5801: Fixed an incorrect Omnibox display on iOS.
  • CVE-2019-5802: Fixed security UI spoofing.
  • CVE-2019-5803: Fixed a CSP bypass with Javascript URLs'.
  • CVE-2019-5804: Fixed a command line injection on Windows.

Release notes: https://chromereleases.googleblog.com/2019/03/stable-channel-update-for-desktop_12.html

Source # ID Name URL
Suse SUSE ratings https://www.suse.com/support/security/rating/
Suse URL of this CSAF notice https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2019_1062-1.json
Suse URL for openSUSE-SU-2019:1062-1 https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/UEJ3CRVCTM23JSBBSLBH5OMPDHJF2SQK/#UEJ3CRVCTM23JSBBSLBH5OMPDHJF2SQK
Suse E-Mail link for openSUSE-SU-2019:1062-1 https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/UEJ3CRVCTM23JSBBSLBH5OMPDHJF2SQK/#UEJ3CRVCTM23JSBBSLBH5OMPDHJF2SQK
Bugzilla SUSE Bug 1129059 https://bugzilla.suse.com/1129059
CVE SUSE CVE CVE-2019-5787 page https://www.suse.com/security/cve/CVE-2019-5787/
CVE SUSE CVE CVE-2019-5788 page https://www.suse.com/security/cve/CVE-2019-5788/
CVE SUSE CVE CVE-2019-5789 page https://www.suse.com/security/cve/CVE-2019-5789/
CVE SUSE CVE CVE-2019-5790 page https://www.suse.com/security/cve/CVE-2019-5790/
CVE SUSE CVE CVE-2019-5791 page https://www.suse.com/security/cve/CVE-2019-5791/
CVE SUSE CVE CVE-2019-5792 page https://www.suse.com/security/cve/CVE-2019-5792/
CVE SUSE CVE CVE-2019-5793 page https://www.suse.com/security/cve/CVE-2019-5793/
CVE SUSE CVE CVE-2019-5794 page https://www.suse.com/security/cve/CVE-2019-5794/
CVE SUSE CVE CVE-2019-5795 page https://www.suse.com/security/cve/CVE-2019-5795/
CVE SUSE CVE CVE-2019-5796 page https://www.suse.com/security/cve/CVE-2019-5796/
CVE SUSE CVE CVE-2019-5797 page https://www.suse.com/security/cve/CVE-2019-5797/
CVE SUSE CVE CVE-2019-5798 page https://www.suse.com/security/cve/CVE-2019-5798/
CVE SUSE CVE CVE-2019-5799 page https://www.suse.com/security/cve/CVE-2019-5799/
CVE SUSE CVE CVE-2019-5800 page https://www.suse.com/security/cve/CVE-2019-5800/
CVE SUSE CVE CVE-2019-5801 page https://www.suse.com/security/cve/CVE-2019-5801/
CVE SUSE CVE CVE-2019-5802 page https://www.suse.com/security/cve/CVE-2019-5802/
CVE SUSE CVE CVE-2019-5803 page https://www.suse.com/security/cve/CVE-2019-5803/
CVE SUSE CVE CVE-2019-5804 page https://www.suse.com/security/cve/CVE-2019-5804/
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/opensuse/chromium?arch=x86_64&distro=opensuse-leap-15.0 opensuse chromium < 73.0.3683.75-lp150.206.1 opensuse-leap-15.0 x86_64
Affected pkg:rpm/opensuse/chromedriver?arch=x86_64&distro=opensuse-leap-15.0 opensuse chromedriver < 73.0.3683.75-lp150.206.1 opensuse-leap-15.0 x86_64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date