Bug 1177936 - VUL-0: chromium: update to 86.0.4240.111
VUL-0: chromium: update to 86.0.4240.111
Status: RESOLVED FIXED
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 15.1
Other Other
: P2 - High : Major (vote)
: ---
Assigned To: Security Team bot
E-mail List
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2020-10-20 20:47 UTC by Wolfgang Frisch
Modified: 2021-12-15 09:40 UTC (History)
3 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Wolfgang Frisch 2020-10-20 20:47:33 UTC
CVE-2020-15999: Heap buffer overflow in Freetype
CVE-2020-16000: Inappropriate implementation in Blink
CVE-2020-16001: Use after free in media
CVE-2020-16002: Use after free in PDFium
CVE-2020-16003: Use after free in printing

https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop_20.html
Comment 2 Marcus Meissner 2020-10-22 08:10:30 UTC
i am already building this.

currently it looks like just throwing in the new tarball works.

SR 843351 against network:chromium done
Comment 3 OBSbugzilla Bot 2020-10-22 10:20:07 UTC
This is an autogenerated message for OBS integration:
This bug (1177936) was mentioned in
https://build.opensuse.org/request/show/843389 Factory / chromium
https://build.opensuse.org/request/show/843390 15.2 / chromium
https://build.opensuse.org/request/show/843391 15.1 / chromium
Comment 4 Swamp Workflow Management 2020-10-24 04:13:35 UTC
openSUSE-SU-2020:1718-1: An update that fixes 5 vulnerabilities is now available.

Category: security (important)
Bug References: 1177936
CVE References: CVE-2020-15999,CVE-2020-16000,CVE-2020-16001,CVE-2020-16002,CVE-2020-16003
JIRA References: 
Sources used:
openSUSE Leap 15.1 (src):    chromium-86.0.4240.111-lp151.2.147.1
Comment 5 Swamp Workflow Management 2020-10-25 17:15:31 UTC
openSUSE-SU-2020:1731-1: An update that fixes 5 vulnerabilities is now available.

Category: security (important)
Bug References: 1177936
CVE References: CVE-2020-15999,CVE-2020-16000,CVE-2020-16001,CVE-2020-16002,CVE-2020-16003
JIRA References: 
Sources used:
openSUSE Backports SLE-15-SP1 (src):    chromium-86.0.4240.111-bp151.3.116.1
Comment 6 Swamp Workflow Management 2020-10-25 23:15:44 UTC
openSUSE-SU-2020:1737-1: An update that fixes 5 vulnerabilities is now available.

Category: security (important)
Bug References: 1177936
CVE References: CVE-2020-15999,CVE-2020-16000,CVE-2020-16001,CVE-2020-16002,CVE-2020-16003
JIRA References: 
Sources used:
openSUSE Leap 15.2 (src):    chromium-86.0.4240.111-lp152.2.42.1
Comment 7 OBSbugzilla Bot 2020-11-03 11:40:13 UTC
This is an autogenerated message for OBS integration:
This bug (1177936) was mentioned in
https://build.opensuse.org/request/show/845668 Backports:SLE-15-SP2 / chromium+gn
Comment 8 Swamp Workflow Management 2020-11-05 14:15:17 UTC
openSUSE-SU-2020:1829-1: An update that fixes 39 vulnerabilities is now available.

Category: security (important)
Bug References: 1177408,1177936,1178375
CVE References: CVE-2020-15967,CVE-2020-15968,CVE-2020-15969,CVE-2020-15970,CVE-2020-15971,CVE-2020-15972,CVE-2020-15973,CVE-2020-15974,CVE-2020-15975,CVE-2020-15976,CVE-2020-15977,CVE-2020-15978,CVE-2020-15979,CVE-2020-15980,CVE-2020-15981,CVE-2020-15982,CVE-2020-15983,CVE-2020-15984,CVE-2020-15985,CVE-2020-15986,CVE-2020-15987,CVE-2020-15988,CVE-2020-15989,CVE-2020-15990,CVE-2020-15991,CVE-2020-15992,CVE-2020-15999,CVE-2020-16000,CVE-2020-16001,CVE-2020-16002,CVE-2020-16003,CVE-2020-16004,CVE-2020-16005,CVE-2020-16006,CVE-2020-16007,CVE-2020-16008,CVE-2020-16009,CVE-2020-16011,CVE-2020-6557
JIRA References: 
Sources used:
openSUSE Backports SLE-15-SP2 (src):    chromium-86.0.4240.183-bp152.2.26.1, gn-0.1807-bp152.2.3.4
Comment 9 Alexandros Toptsoglou 2020-11-05 14:21:00 UTC
Fixed
Comment 10 OBSbugzilla Bot 2021-12-15 09:40:54 UTC
This is an autogenerated message for OBS integration:
This bug (1177936) was mentioned in
https://build.opensuse.org/request/show/940663 Backports:SLE-12-SP3 / chromium