openSUSE Security Update : chromium (openSUSE-2017-854)

Medium Nessus Plugin ID 102054


The remote openSUSE host is missing a security update.


This update Chromium to version 60.0.3112.78 fixes security issue and bugs.

The following security issues were fixed :

- CVE-2017-5091: Use after free in IndexedDB

- CVE-2017-5092: Use after free in PPAPI

- CVE-2017-5093: UI spoofing in Blink

- CVE-2017-5094: Type confusion in extensions

- CVE-2017-5095: Out-of-bounds write in PDFium

- CVE-2017-5096: User information leak via Android intents

- CVE-2017-5097: Out-of-bounds read in Skia

- CVE-2017-5098: Use after free in V8

- CVE-2017-5099: Out-of-bounds write in PPAPI

- CVE-2017-5100: Use after free in Chrome Apps

- CVE-2017-5101: URL spoofing in OmniBox

- CVE-2017-5102: Uninitialized use in Skia

- CVE-2017-5103: Uninitialized use in Skia

- CVE-2017-5104: UI spoofing in browser

- CVE-2017-7000: Pointer disclosure in SQLite

- CVE-2017-5105: URL spoofing in OmniBox

- CVE-2017-5106: URL spoofing in OmniBox

- CVE-2017-5107: User information leak via SVG

- CVE-2017-5108: Type confusion in PDFium

- CVE-2017-5109: UI spoofing in browser

- CVE-2017-5110: UI spoofing in payments dialog

- Various fixes from internal audits, fuzzing and other initiatives

A number of upstream bugfixes are also included in this release.


Update the affected chromium packages.

See Also

Plugin Details

Severity: Medium

ID: 102054

File Name: openSUSE-2017-854.nasl

Version: $Revision: 3.3 $

Type: local

Agent: unix

Published: 2017/07/31

Modified: 2018/01/26

Dependencies: 12634

Risk Information

Risk Factor: Medium


Base Score: 6.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P


Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: p-cpe:/a:novell:opensuse:chromedriver, p-cpe:/a:novell:opensuse:chromedriver-debuginfo, p-cpe:/a:novell:opensuse:chromium, p-cpe:/a:novell:opensuse:chromium-debuginfo, p-cpe:/a:novell:opensuse:chromium-debugsource, cpe:/o:novell:opensuse:42.2, cpe:/o:novell:opensuse:42.3

Required KB Items: Host/local_checks_enabled, Host/SuSE/release, Host/SuSE/rpm-list, Host/cpu

Patch Publication Date: 2017/07/28

Reference Information

CVE: CVE-2017-5091, CVE-2017-5092, CVE-2017-5093, CVE-2017-5094, CVE-2017-5095, CVE-2017-5096, CVE-2017-5097, CVE-2017-5098, CVE-2017-5099, CVE-2017-5100, CVE-2017-5101, CVE-2017-5102, CVE-2017-5103, CVE-2017-5104, CVE-2017-5105, CVE-2017-5106, CVE-2017-5107, CVE-2017-5108, CVE-2017-5109, CVE-2017-5110, CVE-2017-7000