openSUSE Security Update : chromium (openSUSE-2015-204)

High Nessus Plugin ID 81692


The remote openSUSE host is missing a security update.


chromium was updated to version 40.0.2214.111 to fix 31 vulnerabilities.

These security issues were fixed :

- CVE-2015-1209: Use-after-free in DOM (bnc#916841).

- CVE-2015-1210: Cross-origin-bypass in V8 bindings (bnc#916843).

- CVE-2015-1211: Privilege escalation using service workers (bnc#916838).

- CVE-2015-1212: Various fixes from internal audits, fuzzing and other initiatives (bnc#916840).

- CVE-2014-7923: Memory corruption in ICU (bnc#914468).

- CVE-2014-7924: Use-after-free in IndexedDB (bnc#914468).

- CVE-2014-7925: Use-after-free in WebAudio (bnc#914468).

- CVE-2014-7926: Memory corruption in ICU (bnc#914468).

- CVE-2014-7927: Memory corruption in V8 (bnc#914468).

- CVE-2014-7928: Memory corruption in V8 (bnc#914468).

- CVE-2014-7930: Use-after-free in DOM (bnc#914468).

- CVE-2014-7931: Memory corruption in V8 (bnc#914468).

- CVE-2014-7929: Use-after-free in DOM (bnc#914468).

- CVE-2014-7932: Use-after-free in DOM (bnc#914468).

- CVE-2014-7933: Use-after-free in FFmpeg (bnc#914468).

- CVE-2014-7934: Use-after-free in DOM (bnc#914468).

- CVE-2014-7935: Use-after-free in Speech (bnc#914468).

- CVE-2014-7936: Use-after-free in Views (bnc#914468).

- CVE-2014-7937: Use-after-free in FFmpeg (bnc#914468).

- CVE-2014-7938: Memory corruption in Fonts (bnc#914468).

- CVE-2014-7939: Same-origin-bypass in V8 (bnc#914468).

- CVE-2014-7940: Uninitialized-value in ICU (bnc#914468).

- CVE-2014-7941: Out-of-bounds read in UI (bnc#914468).

- CVE-2014-7942: Uninitialized-value in Fonts (bnc#914468).

- CVE-2014-7943: Out-of-bounds read in Skia

- CVE-2014-7944: Out-of-bounds read in PDFium

- CVE-2014-7945: Out-of-bounds read in PDFium

- CVE-2014-7946: Out-of-bounds read in Fonts

- CVE-2014-7947: Out-of-bounds read in PDFium

- CVE-2014-7948: Caching error in AppCache

- CVE-2015-1205: Various fixes from internal audits, fuzzing and other initiatives

These non-security issues were fixed :

- Fix using 'echo' command in script


Update the affected chromium packages.

See Also

Plugin Details

Severity: High

ID: 81692

File Name: openSUSE-2015-204.nasl

Version: $Revision: 1.8 $

Type: local

Agent: unix

Published: 2015/03/09

Modified: 2015/04/11

Dependencies: 12634

Risk Information

Risk Factor: High


Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:novell:opensuse:chromedriver, p-cpe:/a:novell:opensuse:chromedriver-debuginfo, p-cpe:/a:novell:opensuse:chromium, p-cpe:/a:novell:opensuse:chromium-debuginfo, p-cpe:/a:novell:opensuse:chromium-debugsource, p-cpe:/a:novell:opensuse:chromium-desktop-gnome, p-cpe:/a:novell:opensuse:chromium-desktop-kde, p-cpe:/a:novell:opensuse:chromium-ffmpegsumo, p-cpe:/a:novell:opensuse:chromium-ffmpegsumo-debuginfo, cpe:/o:novell:opensuse:13.1, cpe:/o:novell:opensuse:13.2

Required KB Items: Host/local_checks_enabled, Host/SuSE/release, Host/SuSE/rpm-list, Host/cpu

Patch Publication Date: 2015/03/04

Reference Information

CVE: CVE-2014-7923, CVE-2014-7924, CVE-2014-7925, CVE-2014-7926, CVE-2014-7927, CVE-2014-7928, CVE-2014-7929, CVE-2014-7930, CVE-2014-7931, CVE-2014-7932, CVE-2014-7933, CVE-2014-7934, CVE-2014-7935, CVE-2014-7936, CVE-2014-7937, CVE-2014-7938, CVE-2014-7939, CVE-2014-7940, CVE-2014-7941, CVE-2014-7942, CVE-2014-7943, CVE-2014-7944, CVE-2014-7945, CVE-2014-7946, CVE-2014-7947, CVE-2014-7948, CVE-2015-1205, CVE-2015-1209, CVE-2015-1210, CVE-2015-1211, CVE-2015-1212