openSUSE Security Update : chromium (openSUSE-2019-204)

critical Nessus Plugin ID 122304

Language:

Synopsis

The remote openSUSE host is missing a security update.

Description

This update for Chromium to version 72.0.3626.96 fixes the following issues :

Security issues fixed (bsc#1123641 and bsc#1124936) :

- CVE-2019-5784: Inappropriate implementation in V8

- CVE-2019-5754: Inappropriate implementation in QUIC Networking.

- CVE-2019-5782: Inappropriate implementation in V8.

- CVE-2019-5755: Inappropriate implementation in V8.

- CVE-2019-5756: Use after free in PDFium.

- CVE-2019-5757: Type Confusion in SVG.

- CVE-2019-5758: Use after free in Blink.

- CVE-2019-5759: Use after free in HTML select elements.

- CVE-2019-5760: Use after free in WebRTC.

- CVE-2019-5761: Use after free in SwiftShader.

- CVE-2019-5762: Use after free in PDFium.

- CVE-2019-5763: Insufficient validation of untrusted input in V8.

- CVE-2019-5764: Use after free in WebRTC.

- CVE-2019-5765: Insufficient policy enforcement in the browser.

- CVE-2019-5766: Insufficient policy enforcement in Canvas.

- CVE-2019-5767: Incorrect security UI in WebAPKs.

- CVE-2019-5768: Insufficient policy enforcement in DevTools.

- CVE-2019-5769: Insufficient validation of untrusted input in Blink.

- CVE-2019-5770: Heap buffer overflow in WebGL.

- CVE-2019-5771: Heap buffer overflow in SwiftShader.

- CVE-2019-5772: Use after free in PDFium.

- CVE-2019-5773: Insufficient data validation in IndexedDB.

- CVE-2019-5774: Insufficient validation of untrusted input in SafeBrowsing.

- CVE-2019-5775: Insufficient policy enforcement in Omnibox.

- CVE-2019-5776: Insufficient policy enforcement in Omnibox.

- CVE-2019-5777: Insufficient policy enforcement in Omnibox.

- CVE-2019-5778: Insufficient policy enforcement in Extensions.

- CVE-2019-5779: Insufficient policy enforcement in ServiceWorker.

- CVE-2019-5780: Insufficient policy enforcement.

- CVE-2019-5781: Insufficient policy enforcement in Omnibox.

For a full list of changes refer to https://chromereleases.googleblog.com/2019/02/stable-channel-update-fo r-desktop.html

Solution

Update the affected chromium packages.

See Also

https://bugzilla.opensuse.org/show_bug.cgi?id=1123641

https://bugzilla.opensuse.org/show_bug.cgi?id=1124936

http://www.nessus.org/u?861498a3

Plugin Details

Severity: Critical

ID: 122304

File Name: openSUSE-2019-204.nasl

Version: 1.7

Type: local

Agent: unix

Published: 2/19/2019

Updated: 6/19/2024

Supported Sensors: Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Critical

Score: 9.0

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2019-5782

CVSS v3

Risk Factor: Critical

Base Score: 9.6

Temporal Score: 9.2

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C

CVSS Score Source: CVE-2019-5759

Vulnerability Information

CPE: cpe:/o:novell:opensuse:15.0, p-cpe:/a:novell:opensuse:chromedriver, p-cpe:/a:novell:opensuse:chromedriver-debuginfo, p-cpe:/a:novell:opensuse:chromium-debugsource, p-cpe:/a:novell:opensuse:chromium-debuginfo, p-cpe:/a:novell:opensuse:chromium

Required KB Items: Host/local_checks_enabled, Host/SuSE/release, Host/SuSE/rpm-list, Host/cpu

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 3/23/2019

Vulnerability Publication Date: 2/19/2019

Reference Information

CVE: CVE-2019-5754, CVE-2019-5755, CVE-2019-5756, CVE-2019-5757, CVE-2019-5758, CVE-2019-5759, CVE-2019-5760, CVE-2019-5761, CVE-2019-5762, CVE-2019-5763, CVE-2019-5764, CVE-2019-5765, CVE-2019-5766, CVE-2019-5767, CVE-2019-5768, CVE-2019-5769, CVE-2019-5770, CVE-2019-5771, CVE-2019-5772, CVE-2019-5773, CVE-2019-5774, CVE-2019-5775, CVE-2019-5776, CVE-2019-5777, CVE-2019-5778, CVE-2019-5779, CVE-2019-5780, CVE-2019-5781, CVE-2019-5782, CVE-2019-5784