openSUSE Security Update : chromium (openSUSE-2019-204)

high Nessus Plugin ID 122304

Language:

Synopsis

The remote openSUSE host is missing a security update.

Description

This update for Chromium to version 72.0.3626.96 fixes the following issues :

Security issues fixed (bsc#1123641 and bsc#1124936) :

- CVE-2019-5784: Inappropriate implementation in V8

- CVE-2019-5754: Inappropriate implementation in QUIC Networking.

- CVE-2019-5782: Inappropriate implementation in V8.

- CVE-2019-5755: Inappropriate implementation in V8.

- CVE-2019-5756: Use after free in PDFium.

- CVE-2019-5757: Type Confusion in SVG.

- CVE-2019-5758: Use after free in Blink.

- CVE-2019-5759: Use after free in HTML select elements.

- CVE-2019-5760: Use after free in WebRTC.

- CVE-2019-5761: Use after free in SwiftShader.

- CVE-2019-5762: Use after free in PDFium.

- CVE-2019-5763: Insufficient validation of untrusted input in V8.

- CVE-2019-5764: Use after free in WebRTC.

- CVE-2019-5765: Insufficient policy enforcement in the browser.

- CVE-2019-5766: Insufficient policy enforcement in Canvas.

- CVE-2019-5767: Incorrect security UI in WebAPKs.

- CVE-2019-5768: Insufficient policy enforcement in DevTools.

- CVE-2019-5769: Insufficient validation of untrusted input in Blink.

- CVE-2019-5770: Heap buffer overflow in WebGL.

- CVE-2019-5771: Heap buffer overflow in SwiftShader.

- CVE-2019-5772: Use after free in PDFium.

- CVE-2019-5773: Insufficient data validation in IndexedDB.

- CVE-2019-5774: Insufficient validation of untrusted input in SafeBrowsing.

- CVE-2019-5775: Insufficient policy enforcement in Omnibox.

- CVE-2019-5776: Insufficient policy enforcement in Omnibox.

- CVE-2019-5777: Insufficient policy enforcement in Omnibox.

- CVE-2019-5778: Insufficient policy enforcement in Extensions.

- CVE-2019-5779: Insufficient policy enforcement in ServiceWorker.

- CVE-2019-5780: Insufficient policy enforcement.

- CVE-2019-5781: Insufficient policy enforcement in Omnibox.

For a full list of changes refer to https://chromereleases.googleblog.com/2019/02/stable-channel-update-fo r-desktop.html

Solution

Update the affected chromium packages.

See Also

https://bugzilla.opensuse.org/show_bug.cgi?id=1123641

https://bugzilla.opensuse.org/show_bug.cgi?id=1124936

http://www.nessus.org/u?861498a3

Plugin Details

Severity: High

ID: 122304

File Name: openSUSE-2019-204.nasl

Version: 1.6

Type: local

Agent: unix

Published: 2/19/2019

Updated: 1/19/2021

Supported Sensors: Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: High

Score: 8.9

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2019-5782

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:novell:opensuse:chromedriver, p-cpe:/a:novell:opensuse:chromedriver-debuginfo, p-cpe:/a:novell:opensuse:chromium, p-cpe:/a:novell:opensuse:chromium-debuginfo, p-cpe:/a:novell:opensuse:chromium-debugsource, cpe:/o:novell:opensuse:15.0

Required KB Items: Host/local_checks_enabled, Host/SuSE/release, Host/SuSE/rpm-list, Host/cpu

Exploit Ease: No known exploits are available

Patch Publication Date: 3/23/2019

Vulnerability Publication Date: 2/19/2019

Reference Information

CVE: CVE-2019-5754, CVE-2019-5755, CVE-2019-5756, CVE-2019-5757, CVE-2019-5758, CVE-2019-5759, CVE-2019-5760, CVE-2019-5761, CVE-2019-5762, CVE-2019-5763, CVE-2019-5764, CVE-2019-5765, CVE-2019-5766, CVE-2019-5767, CVE-2019-5768, CVE-2019-5769, CVE-2019-5770, CVE-2019-5771, CVE-2019-5772, CVE-2019-5773, CVE-2019-5774, CVE-2019-5775, CVE-2019-5776, CVE-2019-5777, CVE-2019-5778, CVE-2019-5779, CVE-2019-5780, CVE-2019-5781, CVE-2019-5782, CVE-2019-5784