[openSUSE-SU-2020:2021-1] Security update for chromium

Severity Important
Affected Packages 2
CVEs 23

Security update for chromium

This update for chromium fixes the following issues:

  • Update to 87.0.4280.66 (boo#1178923)
    • Wayland support by default
    • CVE-2020-16018: Use after free in payments.
    • CVE-2020-16019: Inappropriate implementation in filesystem.
    • CVE-2020-16020: Inappropriate implementation in cryptohome.
    • CVE-2020-16021: Race in ImageBurner.
    • CVE-2020-16022: Insufficient policy enforcement in networking.
    • CVE-2020-16015: Insufficient data validation in WASM. R
    • CVE-2020-16014: Use after free in PPAPI.
    • CVE-2020-16023: Use after free in WebCodecs.
    • CVE-2020-16024: Heap buffer overflow in UI.
    • CVE-2020-16025: Heap buffer overflow in clipboard.
    • CVE-2020-16026: Use after free in WebRTC.
    • CVE-2020-16027: Insufficient policy enforcement in developer tools. R
    • CVE-2020-16028: Heap buffer overflow in WebRTC.
    • CVE-2020-16029: Inappropriate implementation in PDFium.
    • CVE-2020-16030: Insufficient data validation in Blink.
    • CVE-2019-8075: Insufficient data validation in Flash.
    • CVE-2020-16031: Incorrect security UI in tab preview.
    • CVE-2020-16032: Incorrect security UI in sharing.
    • CVE-2020-16033: Incorrect security UI in WebUSB.
    • CVE-2020-16034: Inappropriate implementation in WebRTC.
    • CVE-2020-16035: Insufficient data validation in cros-disks.
    • CVE-2020-16012: Side-channel information leakage in graphics.
    • CVE-2020-16036: Inappropriate implementation in cookies.
Source # ID Name URL
Suse SUSE ratings https://www.suse.com/support/security/rating/
Suse URL of this CSAF notice https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2020_2021-1.json
Suse URL for openSUSE-SU-2020:2021-1 https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/FVE6T2JL6PI433CTW6BAFC3ROZDJMVMC/
Suse E-Mail link for openSUSE-SU-2020:2021-1 https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/FVE6T2JL6PI433CTW6BAFC3ROZDJMVMC/
Bugzilla SUSE Bug 1178923 https://bugzilla.suse.com/1178923
CVE SUSE CVE CVE-2019-8075 page https://www.suse.com/security/cve/CVE-2019-8075/
CVE SUSE CVE CVE-2020-16012 page https://www.suse.com/security/cve/CVE-2020-16012/
CVE SUSE CVE CVE-2020-16014 page https://www.suse.com/security/cve/CVE-2020-16014/
CVE SUSE CVE CVE-2020-16015 page https://www.suse.com/security/cve/CVE-2020-16015/
CVE SUSE CVE CVE-2020-16018 page https://www.suse.com/security/cve/CVE-2020-16018/
CVE SUSE CVE CVE-2020-16019 page https://www.suse.com/security/cve/CVE-2020-16019/
CVE SUSE CVE CVE-2020-16020 page https://www.suse.com/security/cve/CVE-2020-16020/
CVE SUSE CVE CVE-2020-16021 page https://www.suse.com/security/cve/CVE-2020-16021/
CVE SUSE CVE CVE-2020-16022 page https://www.suse.com/security/cve/CVE-2020-16022/
CVE SUSE CVE CVE-2020-16023 page https://www.suse.com/security/cve/CVE-2020-16023/
CVE SUSE CVE CVE-2020-16024 page https://www.suse.com/security/cve/CVE-2020-16024/
CVE SUSE CVE CVE-2020-16025 page https://www.suse.com/security/cve/CVE-2020-16025/
CVE SUSE CVE CVE-2020-16026 page https://www.suse.com/security/cve/CVE-2020-16026/
CVE SUSE CVE CVE-2020-16027 page https://www.suse.com/security/cve/CVE-2020-16027/
CVE SUSE CVE CVE-2020-16028 page https://www.suse.com/security/cve/CVE-2020-16028/
CVE SUSE CVE CVE-2020-16029 page https://www.suse.com/security/cve/CVE-2020-16029/
CVE SUSE CVE CVE-2020-16030 page https://www.suse.com/security/cve/CVE-2020-16030/
CVE SUSE CVE CVE-2020-16031 page https://www.suse.com/security/cve/CVE-2020-16031/
CVE SUSE CVE CVE-2020-16032 page https://www.suse.com/security/cve/CVE-2020-16032/
CVE SUSE CVE CVE-2020-16033 page https://www.suse.com/security/cve/CVE-2020-16033/
CVE SUSE CVE CVE-2020-16034 page https://www.suse.com/security/cve/CVE-2020-16034/
CVE SUSE CVE CVE-2020-16035 page https://www.suse.com/security/cve/CVE-2020-16035/
CVE SUSE CVE CVE-2020-16036 page https://www.suse.com/security/cve/CVE-2020-16036/
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/opensuse/chromium?arch=x86_64&distro=opensuse-leap-15.2 opensuse chromium < 87.0.4280.66-lp152.2.51.1 opensuse-leap-15.2 x86_64
Affected pkg:rpm/opensuse/chromedriver?arch=x86_64&distro=opensuse-leap-15.2 opensuse chromedriver < 87.0.4280.66-lp152.2.51.1 opensuse-leap-15.2 x86_64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date