openSUSE Security Update : chromium (openSUSE-2021-825)

high Nessus Plugin ID 150269

Synopsis

The remote openSUSE host is missing a security update.

Description

This update for chromium fixes the following issues :

Chromium 91.0.4472.77 (boo#1186458) :

- Support Managed configuration API for Web Applications

- WebOTP API: cross-origin iframe support

- CSS custom counter styles

- Support JSON Modules

- Clipboard: read-only files support

- Remove webkitBeforeTextInserted & webkitEditableCOntentChanged JS events

- Honor media HTML attribute for link icon

- Import Assertions

- Class static initializer blocks

- Ergonomic brand checks for private fields

- Expose WebAssembly SIMD

- New Feature: WebTransport

- ES Modules for service workers ('module' type option)

- Suggested file name and location for the File System Access API

- adaptivePTime property for RTCRtpEncodingParameters

- Block HTTP port 10080 - mitigation for NAT Slipstream 2.0 attack

- Support WebSockets over HTTP/2

- Support 103 Early Hints for Navigation

- CVE-2021-30521: Heap buffer overflow in Autofill

- CVE-2021-30522: Use after free in WebAudio

- CVE-2021-30523: Use after free in WebRTC

- CVE-2021-30524: Use after free in TabStrip

- CVE-2021-30525: Use after free in TabGroups

- CVE-2021-30526: Out of bounds write in TabStrip

- CVE-2021-30527: Use after free in WebUI

- CVE-2021-30528: Use after free in WebAuthentication

- CVE-2021-30529: Use after free in Bookmarks

- CVE-2021-30530: Out of bounds memory access in WebAudio

- CVE-2021-30531: Insufficient policy enforcement in Content Security Policy

- CVE-2021-30532: Insufficient policy enforcement in Content Security Policy

- CVE-2021-30533: Insufficient policy enforcement in PopupBlocker

- CVE-2021-30534: Insufficient policy enforcement in iFrameSandbox

- CVE-2021-30535: Double free in ICU

- CVE-2021-21212: Insufficient data validation in networking

- CVE-2021-30536: Out of bounds read in V8

- CVE-2021-30537: Insufficient policy enforcement in cookies

- CVE-2021-30538: Insufficient policy enforcement in content security policy

- CVE-2021-30539: Insufficient policy enforcement in content security policy

- CVE-2021-30540: Incorrect security UI in payments

- Various fixes from internal audits, fuzzing and other initiatives

Solution

Update the affected chromium packages.

See Also

https://bugzilla.opensuse.org/show_bug.cgi?id=1186458

Plugin Details

Severity: High

ID: 150269

File Name: openSUSE-2021-825.nasl

Version: 1.3

Type: local

Agent: unix

Published: 6/4/2021

Updated: 6/14/2021

Supported Sensors: Nessus Agent

Risk Information

CVSS Score Source: CVE-2021-30535

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Temporal Vector: E:U/RL:OF/RC:C

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: E:U/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:novell:opensuse:chromedriver, p-cpe:/a:novell:opensuse:chromedriver-debuginfo, p-cpe:/a:novell:opensuse:chromium, p-cpe:/a:novell:opensuse:chromium-debuginfo, cpe:/o:novell:opensuse:15.2

Required KB Items: Host/local_checks_enabled, Host/SuSE/release, Host/SuSE/rpm-list, Host/cpu

Exploit Ease: No known exploits are available

Patch Publication Date: 6/2/2021

Vulnerability Publication Date: 4/26/2021

Reference Information

CVE: CVE-2021-21212, CVE-2021-30521, CVE-2021-30522, CVE-2021-30523, CVE-2021-30524, CVE-2021-30525, CVE-2021-30526, CVE-2021-30527, CVE-2021-30528, CVE-2021-30529, CVE-2021-30530, CVE-2021-30531, CVE-2021-30532, CVE-2021-30533, CVE-2021-30534, CVE-2021-30535, CVE-2021-30536, CVE-2021-30537, CVE-2021-30538, CVE-2021-30539, CVE-2021-30540