openSUSE Security Update : chromium / v8 (openSUSE-SU-2012:0466-1)

This script is Copyright (C) 2014 Tenable Network Security, Inc.

Synopsis :

The remote openSUSE host is missing a security update.

Description :

- Update to 19.0.1079 Security Fixes (bnc#754456) :

- High CVE-2011-3050: Use-after-free with first-letter

- High CVE-2011-3045: libpng integer issue from upstream

- High CVE-2011-3051: Use-after-free in CSS cross-fade

- High CVE-2011-3052: Memory corruption in WebGL canvas

- High CVE-2011-3053: Use-after-free in block splitting

- Low CVE-2011-3054: Apply additional isolations to webui

- Low CVE-2011-3055: Prompt in the browser native UI for
unpacked extension installation

- High CVE-2011-3056: Cross-origin violation with
“magic iframe”.

- Low CVE-2011-3049: Extension web request API can
interfere with system requests Other Fixes :

- The short-cut key for caps lock (Shift + Search) is
disabled when an accessibility screen reader is enabled

- Fixes an issue with files not being displayed in File
Manager when some file names contain UTF-8 characters
(generally accented characters)

- Fixed dialog boxes in settings. (Issue: 118031)

- Fixed flash videos turning white on mac when running

--disable-composited-core-animation-plugins (Issue:

- Change to look for correctly sized favicon when multiple
images are provided. (Issue: 118275)

- Fixed issues - 116044, 117470, 117068, 117668, 118620

- Update to 19.0.1077

- Update to 19.0.1074

- Build Chromium on openSUSE > 12.1 with the gold linker

- Fix build issues with GCC 4.7

- Update to 19.0.1071

- Several fixes and improvements in the new Settings,
Extensions, and Help pages.

- Fixed the flashing when switched between composited and
non-composited mode. [Issue: 116603]

- Fixed stability issues 116913, 117217, 117347, 117081

See also :

Solution :

Update the affected chromium / v8 packages.

Risk factor :

High / CVSS Base Score : 7.5

Family: SuSE Local Security Checks

Nessus Plugin ID: 74587 ()

Bugtraq ID:

CVE ID: CVE-2011-3045

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now