openSUSE Security Update : Chromium (openSUSE-2018-1521)

Medium Nessus Plugin ID 119549

New! Vulnerability Priority Rating (VPR)

Tenable calculates a dynamic VPR for every vulnerability. VPR combines vulnerability information with threat intelligence and machine learning algorithms to predict which vulnerabilities are most likely to be exploited in attacks. Read more about what VPR is and how it's different from CVSS.

VPR Score: 6.7


The remote openSUSE host is missing a security update.


This update to Chromium version 71.0.3578.80 fixes security issues and bugs.

Security issues fixed (boo#1118529) :

- CVE-2018-17480: Out of bounds write in V8

- CVE-2018-17481: Use after frees in PDFium

- CVE-2018-18335: Heap buffer overflow in Skia

- CVE-2018-18336: Use after free in PDFium

- CVE-2018-18337: Use after free in Blink

- CVE-2018-18338: Heap buffer overflow in Canvas

- CVE-2018-18339: Use after free in WebAudio

- CVE-2018-18340: Use after free in MediaRecorder

- CVE-2018-18341: Heap buffer overflow in Blink

- CVE-2018-18342: Out of bounds write in V8

- CVE-2018-18343: Use after free in Skia

- CVE-2018-18344: Inappropriate implementation in Extensions

- Multiple issues in SQLite via WebSQL

- CVE-2018-18345: Inappropriate implementation in Site Isolation

- CVE-2018-18346: Incorrect security UI in Blink

- CVE-2018-18347: Inappropriate implementation in Navigation

- CVE-2018-18348: Inappropriate implementation in Omnibox

- CVE-2018-18349: Insufficient policy enforcement in Blink

- CVE-2018-18350: Insufficient policy enforcement in Blink

- CVE-2018-18351: Insufficient policy enforcement in Navigation

- CVE-2018-18352: Inappropriate implementation in Media

- CVE-2018-18353: Inappropriate implementation in Network Authentication

- CVE-2018-18354: Insufficient data validation in Shell Integration

- CVE-2018-18355: Insufficient policy enforcement in URL Formatter

- CVE-2018-18356: Use after free in Skia

- CVE-2018-18357: Insufficient policy enforcement in URL Formatter

- CVE-2018-18358: Insufficient policy enforcement in Proxy

- CVE-2018-18359: Out of bounds read in V8

- Inappropriate implementation in PDFium

- Use after free in Extensions

- Inappropriate implementation in Navigation

- Insufficient policy enforcement in Navigation

- Insufficient policy enforcement in URL Formatter

- Various fixes from internal audits, fuzzing and other initiatives

The following changes are included :

- advertisements posing as error messages are now blocked

- Automatic playing of content at page load mostly disabled

- New JavaScript API for relative time display


Update the affected Chromium packages.

See Also

Plugin Details

Severity: Medium

ID: 119549

File Name: openSUSE-2018-1521.nasl

Version: 1.4

Type: local

Agent: unix

Published: 2018/12/10

Updated: 2021/01/19

Dependencies: 12634

Risk Information

Risk Factor: Medium

VPR Score: 6.7

CVSS v2.0

Base Score: 6.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS v3.0

Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: p-cpe:/a:novell:opensuse:chromedriver, p-cpe:/a:novell:opensuse:chromedriver-debuginfo, p-cpe:/a:novell:opensuse:chromium, p-cpe:/a:novell:opensuse:chromium-debuginfo, p-cpe:/a:novell:opensuse:chromium-debugsource, cpe:/o:novell:opensuse:15.0

Required KB Items: Host/local_checks_enabled, Host/SuSE/release, Host/SuSE/rpm-list, Host/cpu

Patch Publication Date: 2018/12/08

Reference Information

CVE: CVE-2018-17480, CVE-2018-17481, CVE-2018-18335, CVE-2018-18336, CVE-2018-18337, CVE-2018-18338, CVE-2018-18339, CVE-2018-18340, CVE-2018-18341, CVE-2018-18342, CVE-2018-18343, CVE-2018-18344, CVE-2018-18345, CVE-2018-18346, CVE-2018-18347, CVE-2018-18348, CVE-2018-18349, CVE-2018-18350, CVE-2018-18351, CVE-2018-18352, CVE-2018-18353, CVE-2018-18354, CVE-2018-18355, CVE-2018-18356, CVE-2018-18357, CVE-2018-18358, CVE-2018-18359