openSUSE Security Update : chromium (openSUSE-2017-854)

high Nessus Plugin ID 102054

Language:

Synopsis

The remote openSUSE host is missing a security update.

Description

This update Chromium to version 60.0.3112.78 fixes security issue and bugs.

The following security issues were fixed :

- CVE-2017-5091: Use after free in IndexedDB

- CVE-2017-5092: Use after free in PPAPI

- CVE-2017-5093: UI spoofing in Blink

- CVE-2017-5094: Type confusion in extensions

- CVE-2017-5095: Out-of-bounds write in PDFium

- CVE-2017-5096: User information leak via Android intents

- CVE-2017-5097: Out-of-bounds read in Skia

- CVE-2017-5098: Use after free in V8

- CVE-2017-5099: Out-of-bounds write in PPAPI

- CVE-2017-5100: Use after free in Chrome Apps

- CVE-2017-5101: URL spoofing in OmniBox

- CVE-2017-5102: Uninitialized use in Skia

- CVE-2017-5103: Uninitialized use in Skia

- CVE-2017-5104: UI spoofing in browser

- CVE-2017-7000: Pointer disclosure in SQLite

- CVE-2017-5105: URL spoofing in OmniBox

- CVE-2017-5106: URL spoofing in OmniBox

- CVE-2017-5107: User information leak via SVG

- CVE-2017-5108: Type confusion in PDFium

- CVE-2017-5109: UI spoofing in browser

- CVE-2017-5110: UI spoofing in payments dialog

- Various fixes from internal audits, fuzzing and other initiatives

A number of upstream bugfixes are also included in this release.

Solution

Update the affected chromium packages.

See Also

https://bugzilla.opensuse.org/show_bug.cgi?id=1050537

Plugin Details

Severity: High

ID: 102054

File Name: openSUSE-2017-854.nasl

Version: 3.5

Type: local

Agent: unix

Published: 7/31/2017

Updated: 1/19/2021

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS v3

Risk Factor: High

Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: p-cpe:/a:novell:opensuse:chromedriver, p-cpe:/a:novell:opensuse:chromedriver-debuginfo, cpe:/o:novell:opensuse:42.2, p-cpe:/a:novell:opensuse:chromium-debugsource, p-cpe:/a:novell:opensuse:chromium-debuginfo, p-cpe:/a:novell:opensuse:chromium, cpe:/o:novell:opensuse:42.3

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Patch Publication Date: 7/28/2017

Reference Information

CVE: CVE-2017-5091, CVE-2017-5092, CVE-2017-5093, CVE-2017-5094, CVE-2017-5095, CVE-2017-5096, CVE-2017-5097, CVE-2017-5098, CVE-2017-5099, CVE-2017-5100, CVE-2017-5101, CVE-2017-5102, CVE-2017-5103, CVE-2017-5104, CVE-2017-5105, CVE-2017-5106, CVE-2017-5107, CVE-2017-5108, CVE-2017-5109, CVE-2017-5110, CVE-2017-7000