Bug 1022049 - VUL-0: chromium: multiple vulnerabilities fixed in 56.0.2924.76
VUL-0: chromium: multiple vulnerabilities fixed in 56.0.2924.76
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other openSUSE 42.2
: P5 - None : Major
: ---
Assigned To: Security Team bot
Security Team bot
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2017-01-26 10:21 UTC by Andreas Stieger
Modified: 2017-03-11 11:01 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Stieger 2017-01-26 10:21:36 UTC
https://chromereleases.googleblog.com/2017/01/stable-channel-update-for-desktop.html

- CVE-2017-5007: Universal XSS in Blink
- CVE-2017-5006: Universal XSS in Blink
- CVE-2017-5008: Universal XSS in Blink
- CVE-2017-5010: Universal XSS in Blink
- CVE-2017-5011: Unauthorised file access in Devtools
- CVE-2017-5009: Out of bounds memory access in WebRTC
- CVE-2017-5012: Heap overflow in V8
- CVE-2017-5013: Address spoofing in Omnibox
- CVE-2017-5014: Heap overflow in Skia
- CVE-2017-5015: Address spoofing in Omnibox
- CVE-2017-5019: Use after free in Renderer
- CVE-2017-5016: UI spoofing in Blink
- CVE-2017-5017: Uninitialised memory access in webm video
- CVE-2017-5018: Universal XSS in chrome://apps
- CVE-2017-5020: Universal XSS in chrome://downloads
- CVE-2017-5021: Use after free in Extensions
- CVE-2017-5022: Bypass of Content Security Policy in Blink
- CVE-2017-5023: Type confusion in metrics
- CVE-2017-5024: Heap overflow in FFmpeg
- CVE-2017-5025: Heap overflow in FFmpeg
- CVE-2017-5026: UI spoofing. Credit to Ronni Skansing
Comment 1 Andreas Stieger 2017-01-26 10:30:03 UTC
openSUSE and SUSE Package Hub only.

openSUSE:Leap:42.1:Update/chromium
openSUSE:Leap:42.2:Update/chromium

Will not be fixed:
openSUSE:Backports:SLE-12/chromium

New dependency challenge:
openSUSE:Backports:SLE-12-SP2/chromium
Comment 2 Tomáš Chvátal 2017-02-16 12:25:31 UTC
Submissions were done. I noticed the bug was not mentioned in changelog so I amended that for the next update that will be done.
Comment 3 Alexander Bergmann 2017-02-17 13:05:41 UTC
Looks like they've extended the security advisory with 

- CVE-2017-5027: Bypass of Content Security Policy in Blink.

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5027
Comment 4 Andreas Stieger 2017-02-18 10:40:24 UTC
releasing, done
Comment 5 Swamp Workflow Management 2017-02-18 14:08:43 UTC
openSUSE-SU-2017:0499-1: An update that fixes 21 vulnerabilities is now available.

Category: security (important)
Bug References: 1022049
CVE References: CVE-2017-5006,CVE-2017-5007,CVE-2017-5008,CVE-2017-5009,CVE-2017-5010,CVE-2017-5011,CVE-2017-5012,CVE-2017-5013,CVE-2017-5014,CVE-2017-5015,CVE-2017-5016,CVE-2017-5017,CVE-2017-5018,CVE-2017-5019,CVE-2017-5020,CVE-2017-5021,CVE-2017-5022,CVE-2017-5023,CVE-2017-5024,CVE-2017-5025,CVE-2017-5026
Sources used:
openSUSE Leap 42.2 (src):    chromium-56.0.2924.87-102.1, harfbuzz-1.4.2-3.1
openSUSE Leap 42.1 (src):    chromium-56.0.2924.87-102.1, ffmpeg3-3.2.2-2.1
Comment 6 Swamp Workflow Management 2017-02-27 11:09:14 UTC
openSUSE-SU-2017:0565-1: An update that fixes 21 vulnerabilities is now available.

Category: security (important)
Bug References: 1022049
CVE References: CVE-2017-5006,CVE-2017-5007,CVE-2017-5008,CVE-2017-5009,CVE-2017-5010,CVE-2017-5011,CVE-2017-5012,CVE-2017-5013,CVE-2017-5014,CVE-2017-5015,CVE-2017-5016,CVE-2017-5017,CVE-2017-5018,CVE-2017-5019,CVE-2017-5020,CVE-2017-5021,CVE-2017-5022,CVE-2017-5023,CVE-2017-5024,CVE-2017-5025,CVE-2017-5026
Sources used:
SUSE Package Hub for SUSE Linux Enterprise 12 (src):    chromium-56.0.2924.87-5.1
Comment 7 Bernhard Wiedemann 2017-03-10 13:00:52 UTC
This is an autogenerated message for OBS integration:
This bug (1022049) was mentioned in
https://build.opensuse.org/request/show/478470 42.2 / chromium
https://build.opensuse.org/request/show/478471 42.1 / chromium
Comment 8 Bernhard Wiedemann 2017-03-11 11:01:07 UTC
This is an autogenerated message for OBS integration:
This bug (1022049) was mentioned in
https://build.opensuse.org/request/show/478650 Backports:SLE-12-SP2 / chromium