openSUSE-SU-2019:1325-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2019:1325-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2019:1325-1
Related
Published
2019-05-04T08:20:05Z
Modified
2019-05-04T08:20:05Z
Summary
Security update for chromium
Details

This update for chromium fixes the following issues:

Chromium was updated to 74.0.3729.108 boo#1133313:

  • CVE-2019-5805: Use after free in PDFium
  • CVE-2019-5806: Integer overflow in Angle
  • CVE-2019-5807: Memory corruption in V8
  • CVE-2019-5808: Use after free in Blink
  • CVE-2019-5809: Use after free in Blink
  • CVE-2019-5810: User information disclosure in Autofill
  • CVE-2019-5811: CORS bypass in Blink
  • CVE-2019-5813: Out of bounds read in V8
  • CVE-2019-5814: CORS bypass in Blink
  • CVE-2019-5815: Heap buffer overflow in Blink
  • CVE-2019-5818: Uninitialized value in media reader
  • CVE-2019-5819: Incorrect escaping in developer tools
  • CVE-2019-5820: Integer overflow in PDFium
  • CVE-2019-5821: Integer overflow in PDFium
  • CVE-2019-5822: CORS bypass in download manager
  • CVE-2019-5823: Forced navigation from service worker
  • CVE-2019-5812: URL spoof in Omnibox on iOS
  • CVE-2019-5816: Exploit persistence extension on Android
  • CVE-2019-5817: Heap buffer overflow in Angle on Windows

  • Update conditions to use system harfbuzz on TW+

  • Require java during build
  • Enable using pipewire when available
References

Affected packages

openSUSE:Leap 15.0 / chromium

Package

Name
chromium
Purl
pkg:rpm/opensuse/chromium&distro=openSUSE%20Leap%2015.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
74.0.3729.108-lp150.209.2

Ecosystem specific

{
    "binaries": [
        {
            "chromedriver": "74.0.3729.108-lp150.209.2",
            "chromium": "74.0.3729.108-lp150.209.2"
        }
    ]
}