Bugzilla – Bug 1022049
VUL-0: chromium: multiple vulnerabilities fixed in 56.0.2924.76
Last modified: 2017-03-11 11:01:07 UTC
https://chromereleases.googleblog.com/2017/01/stable-channel-update-for-desktop.html - CVE-2017-5007: Universal XSS in Blink - CVE-2017-5006: Universal XSS in Blink - CVE-2017-5008: Universal XSS in Blink - CVE-2017-5010: Universal XSS in Blink - CVE-2017-5011: Unauthorised file access in Devtools - CVE-2017-5009: Out of bounds memory access in WebRTC - CVE-2017-5012: Heap overflow in V8 - CVE-2017-5013: Address spoofing in Omnibox - CVE-2017-5014: Heap overflow in Skia - CVE-2017-5015: Address spoofing in Omnibox - CVE-2017-5019: Use after free in Renderer - CVE-2017-5016: UI spoofing in Blink - CVE-2017-5017: Uninitialised memory access in webm video - CVE-2017-5018: Universal XSS in chrome://apps - CVE-2017-5020: Universal XSS in chrome://downloads - CVE-2017-5021: Use after free in Extensions - CVE-2017-5022: Bypass of Content Security Policy in Blink - CVE-2017-5023: Type confusion in metrics - CVE-2017-5024: Heap overflow in FFmpeg - CVE-2017-5025: Heap overflow in FFmpeg - CVE-2017-5026: UI spoofing. Credit to Ronni Skansing
openSUSE and SUSE Package Hub only. openSUSE:Leap:42.1:Update/chromium openSUSE:Leap:42.2:Update/chromium Will not be fixed: openSUSE:Backports:SLE-12/chromium New dependency challenge: openSUSE:Backports:SLE-12-SP2/chromium
Submissions were done. I noticed the bug was not mentioned in changelog so I amended that for the next update that will be done.
Looks like they've extended the security advisory with - CVE-2017-5027: Bypass of Content Security Policy in Blink. http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5027
releasing, done
openSUSE-SU-2017:0499-1: An update that fixes 21 vulnerabilities is now available. Category: security (important) Bug References: 1022049 CVE References: CVE-2017-5006,CVE-2017-5007,CVE-2017-5008,CVE-2017-5009,CVE-2017-5010,CVE-2017-5011,CVE-2017-5012,CVE-2017-5013,CVE-2017-5014,CVE-2017-5015,CVE-2017-5016,CVE-2017-5017,CVE-2017-5018,CVE-2017-5019,CVE-2017-5020,CVE-2017-5021,CVE-2017-5022,CVE-2017-5023,CVE-2017-5024,CVE-2017-5025,CVE-2017-5026 Sources used: openSUSE Leap 42.2 (src): chromium-56.0.2924.87-102.1, harfbuzz-1.4.2-3.1 openSUSE Leap 42.1 (src): chromium-56.0.2924.87-102.1, ffmpeg3-3.2.2-2.1
openSUSE-SU-2017:0565-1: An update that fixes 21 vulnerabilities is now available. Category: security (important) Bug References: 1022049 CVE References: CVE-2017-5006,CVE-2017-5007,CVE-2017-5008,CVE-2017-5009,CVE-2017-5010,CVE-2017-5011,CVE-2017-5012,CVE-2017-5013,CVE-2017-5014,CVE-2017-5015,CVE-2017-5016,CVE-2017-5017,CVE-2017-5018,CVE-2017-5019,CVE-2017-5020,CVE-2017-5021,CVE-2017-5022,CVE-2017-5023,CVE-2017-5024,CVE-2017-5025,CVE-2017-5026 Sources used: SUSE Package Hub for SUSE Linux Enterprise 12 (src): chromium-56.0.2924.87-5.1
This is an autogenerated message for OBS integration: This bug (1022049) was mentioned in https://build.opensuse.org/request/show/478470 42.2 / chromium https://build.opensuse.org/request/show/478471 42.1 / chromium
This is an autogenerated message for OBS integration: This bug (1022049) was mentioned in https://build.opensuse.org/request/show/478650 Backports:SLE-12-SP2 / chromium