openSUSE Security Update : chromium (openSUSE-SU-2014:0783-1)

High Nessus Plugin ID 75387


The remote openSUSE host is missing a security update.


chromium was updated to version 35.0.1916.114 to fix various security issues. Security fixes :

- CVE-2014-1743: Use-after-free in styles

- CVE-2014-1744: Integer overflow in audio

- CVE-2014-1745: Use-after-free in SVG

- CVE-2014-1746: Out-of-bounds read in media filters

- CVE-2014-1747: UXSS with local MHTML file

- CVE-2014-1748: UI spoofing with scrollbar

- CVE-2014-1749: Various fixes from internal audits, fuzzing and other initiatives

- CVE-2014-3152: Integer underflow in V8 fixed

- CVE-2014-1740: Use-after-free in WebSockets

- CVE-2014-1741: Integer overflow in DOM range

- CVE-2014-1742: Use-after-free in editing and 17 more for which no detailed information is given.


Update the affected chromium packages.

See Also

Plugin Details

Severity: High

ID: 75387

File Name: openSUSE-2014-420.nasl

Version: $Revision: 1.3 $

Type: local

Agent: unix

Published: 2014/06/13

Modified: 2014/12/05

Dependencies: 12634

Risk Information

Risk Factor: High


Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:ND/RL:OF/RC:C

Vulnerability Information

CPE: p-cpe:/a:novell:opensuse:chromedriver, p-cpe:/a:novell:opensuse:chromedriver-debuginfo, p-cpe:/a:novell:opensuse:chromium, p-cpe:/a:novell:opensuse:chromium-debuginfo, p-cpe:/a:novell:opensuse:chromium-debugsource, p-cpe:/a:novell:opensuse:chromium-desktop-gnome, p-cpe:/a:novell:opensuse:chromium-desktop-kde, p-cpe:/a:novell:opensuse:chromium-ffmpegsumo, p-cpe:/a:novell:opensuse:chromium-ffmpegsumo-debuginfo, p-cpe:/a:novell:opensuse:chromium-suid-helper, p-cpe:/a:novell:opensuse:chromium-suid-helper-debuginfo, p-cpe:/a:novell:opensuse:ninja, p-cpe:/a:novell:opensuse:ninja-debuginfo, p-cpe:/a:novell:opensuse:ninja-debugsource, cpe:/o:novell:opensuse:12.3, cpe:/o:novell:opensuse:13.1

Required KB Items: Host/local_checks_enabled, Host/SuSE/release, Host/SuSE/rpm-list, Host/cpu

Exploit Available: false

Exploit Ease: No known exploits are available

Patch Publication Date: 2014/06/05

Reference Information

CVE: CVE-2014-1740, CVE-2014-1741, CVE-2014-1742, CVE-2014-1743, CVE-2014-1744, CVE-2014-1745, CVE-2014-1746, CVE-2014-1747, CVE-2014-1748, CVE-2014-1749, CVE-2014-3152

BID: 67374, 67375, 67376, 67517, 71464