openSUSE Security Update : chromium (openSUSE-SU-2014:0783-1)

high Nessus Plugin ID 75387

Synopsis

The remote openSUSE host is missing a security update.

Description

chromium was updated to version 35.0.1916.114 to fix various security issues. Security fixes :

- CVE-2014-1743: Use-after-free in styles

- CVE-2014-1744: Integer overflow in audio

- CVE-2014-1745: Use-after-free in SVG

- CVE-2014-1746: Out-of-bounds read in media filters

- CVE-2014-1747: UXSS with local MHTML file

- CVE-2014-1748: UI spoofing with scrollbar

- CVE-2014-1749: Various fixes from internal audits, fuzzing and other initiatives

- CVE-2014-3152: Integer underflow in V8 fixed

- CVE-2014-1740: Use-after-free in WebSockets

- CVE-2014-1741: Integer overflow in DOM range

- CVE-2014-1742: Use-after-free in editing and 17 more for which no detailed information is given.

Solution

Update the affected chromium packages.

See Also

https://lists.opensuse.org/opensuse-updates/2014-06/msg00023.html

Plugin Details

Severity: High

ID: 75387

File Name: openSUSE-2014-420.nasl

Version: 1.6

Type: local

Agent: unix

Published: 6/13/2014

Updated: 1/19/2021

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:novell:opensuse:chromedriver, p-cpe:/a:novell:opensuse:chromedriver-debuginfo, p-cpe:/a:novell:opensuse:chromium, p-cpe:/a:novell:opensuse:chromium-debuginfo, p-cpe:/a:novell:opensuse:chromium-debugsource, p-cpe:/a:novell:opensuse:chromium-desktop-gnome, p-cpe:/a:novell:opensuse:chromium-desktop-kde, p-cpe:/a:novell:opensuse:chromium-ffmpegsumo, p-cpe:/a:novell:opensuse:chromium-ffmpegsumo-debuginfo, p-cpe:/a:novell:opensuse:chromium-suid-helper, p-cpe:/a:novell:opensuse:chromium-suid-helper-debuginfo, p-cpe:/a:novell:opensuse:ninja, p-cpe:/a:novell:opensuse:ninja-debuginfo, p-cpe:/a:novell:opensuse:ninja-debugsource, cpe:/o:novell:opensuse:12.3, cpe:/o:novell:opensuse:13.1

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 6/5/2014

Reference Information

CVE: CVE-2014-1740, CVE-2014-1741, CVE-2014-1742, CVE-2014-1743, CVE-2014-1744, CVE-2014-1745, CVE-2014-1746, CVE-2014-1747, CVE-2014-1748, CVE-2014-1749, CVE-2014-3152

BID: 67374, 67375, 67376, 67517, 71464