openSUSE Security Update : chromium (openSUSE-SU-2014:1626-1)

critical Nessus Plugin ID 79997
New! Plugin Severity Now Using CVSS v3

The calculated severity for Plugins has been updated to use CVSS v3 by default. Plugins that do not have a CVSS v3 score will fall back to CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Synopsis

The remote openSUSE host is missing a security update.

Description

chromium was updated to version 39.0.2171.65 to fix 13 security issues.

These security issues were fixed :

- Use-after-free in pepper plugins (CVE-2014-7906).

- Buffer overflow in OpenJPEG before r2911 in PDFium, as used in Google Chromebefore 39.0.2171.65, al...
(CVE-2014-7903).

- Uninitialized memory read in Skia (CVE-2014-7909).

- Unspecified security issues (CVE-2014-7910).

- Integer overflow in media (CVE-2014-7908).

- Integer overflow in the opj_t2_read_packet_data function infxcodec/fx_libopenjpeg/libopenjpeg20/t2....
(CVE-2014-7901).

- Use-after-free in blink (CVE-2014-7907).

- Address bar spoofing (CVE-2014-7899).

- Buffer overflow in Skia (CVE-2014-7904).

- Use-after-free vulnerability in the CPDF_Parser (CVE-2014-7900).

- Use-after-free vulnerability in PDFium allows DoS (CVE-2014-7902).

- Flaw allowing navigation to intents that do not have the BROWSABLE category (CVE-2014-7905).

- Double-free in Flash (CVE-2014-0574).

Solution

Update the affected chromium packages.

See Also

https://bugzilla.opensuse.org/show_bug.cgi?id=906317

https://bugzilla.opensuse.org/show_bug.cgi?id=906318

https://bugzilla.opensuse.org/show_bug.cgi?id=906319

https://bugzilla.opensuse.org/show_bug.cgi?id=906320

https://bugzilla.opensuse.org/show_bug.cgi?id=906321

https://bugzilla.opensuse.org/show_bug.cgi?id=906322

https://bugzilla.opensuse.org/show_bug.cgi?id=906323

https://bugzilla.opensuse.org/show_bug.cgi?id=906324

https://bugzilla.opensuse.org/show_bug.cgi?id=906326

https://bugzilla.opensuse.org/show_bug.cgi?id=906327

https://bugzilla.opensuse.org/show_bug.cgi?id=906328

https://bugzilla.opensuse.org/show_bug.cgi?id=906330

https://lists.opensuse.org/opensuse-updates/2014-12/msg00048.html

Plugin Details

Severity: Critical

ID: 79997

File Name: openSUSE-2014-764.nasl

Version: 1.4

Type: local

Agent: unix

Published: 12/15/2014

Updated: 1/19/2021

Dependencies: ssh_get_info.nasl

Risk Information

VPR

Risk Factor: Medium

Score: 6.6

CVSS v2

Risk Factor: Critical

Base Score: 10

Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:novell:opensuse:chromedriver, p-cpe:/a:novell:opensuse:chromedriver-debuginfo, p-cpe:/a:novell:opensuse:chromium, p-cpe:/a:novell:opensuse:chromium-debuginfo, p-cpe:/a:novell:opensuse:chromium-debugsource, p-cpe:/a:novell:opensuse:chromium-desktop-gnome, p-cpe:/a:novell:opensuse:chromium-desktop-kde, p-cpe:/a:novell:opensuse:chromium-ffmpegsumo, p-cpe:/a:novell:opensuse:chromium-ffmpegsumo-debuginfo, cpe:/o:novell:opensuse:13.1, cpe:/o:novell:opensuse:13.2

Required KB Items: Host/local_checks_enabled, Host/SuSE/release, Host/SuSE/rpm-list, Host/cpu

Patch Publication Date: 12/1/2014

Reference Information

CVE: CVE-2014-0574, CVE-2014-7899, CVE-2014-7900, CVE-2014-7901, CVE-2014-7902, CVE-2014-7903, CVE-2014-7904, CVE-2014-7905, CVE-2014-7906, CVE-2014-7907, CVE-2014-7908, CVE-2014-7909, CVE-2014-7910