openSUSE Security Update : chromium / v8 (openSUSE-SU-2012:0656-1)

critical Nessus Plugin ID 74634

Synopsis

The remote openSUSE host is missing a security update.

Description

Chromium update to 21.0.1145

- Fixed several issues around audio not playing with videos

- Crash Fixes

- Improvements to trackpad on Cr-48

- Security Fixes (bnc#762481)

- CVE-2011-3083: Browser crash with video + FTP

- CVE-2011-3084: Load links from internal pages in their own process.

- CVE-2011-3085: UI corruption with long autofilled values

- CVE-2011-3086: Use-after-free with style element.

- CVE-2011-3087: Incorrect window navigation

- CVE-2011-3088: Out-of-bounds read in hairline drawing

- CVE-2011-3089: Use-after-free in table handling.

- CVE-2011-3090: Race condition with workers.

- CVE-2011-3091: Use-after-free with indexed DB

- CVE-2011-3092: Invalid write in v8 regex

- CVE-2011-3093: Out-of-bounds read in glyph handling

- CVE-2011-3094: Out-of-bounds read in Tibetan handling

- CVE-2011-3095: Out-of-bounds write in OGG container.

- CVE-2011-3096: Use-after-free in GTK omnibox handling.

- CVE-2011-3098: Bad search path for Windows Media Player plug-in

- CVE-2011-3100: Out-of-bounds read drawing dash paths.

- CVE-2011-3101: Work around Linux Nvidia driver bug

- CVE-2011-3102: Off-by-one out-of-bounds write in libxml.

Solution

Update the affected chromium / v8 packages.

See Also

https://bugzilla.novell.com/show_bug.cgi?id=762481

https://lists.opensuse.org/opensuse-updates/2012-05/msg00040.html

Plugin Details

Severity: Critical

ID: 74634

File Name: openSUSE-2012-295.nasl

Version: 1.7

Type: local

Agent: unix

Published: 6/13/2014

Updated: 1/19/2021

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:novell:opensuse:chromium, p-cpe:/a:novell:opensuse:chromium-debuginfo, p-cpe:/a:novell:opensuse:chromium-debugsource, p-cpe:/a:novell:opensuse:chromium-desktop-gnome, p-cpe:/a:novell:opensuse:chromium-desktop-kde, p-cpe:/a:novell:opensuse:chromium-suid-helper, p-cpe:/a:novell:opensuse:chromium-suid-helper-debuginfo, p-cpe:/a:novell:opensuse:libv8-3, p-cpe:/a:novell:opensuse:libv8-3-debuginfo, p-cpe:/a:novell:opensuse:v8-debugsource, p-cpe:/a:novell:opensuse:v8-devel, p-cpe:/a:novell:opensuse:v8-private-headers-devel, cpe:/o:novell:opensuse:12.1

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 5/24/2012

Reference Information

CVE: CVE-2011-3083, CVE-2011-3084, CVE-2011-3085, CVE-2011-3086, CVE-2011-3087, CVE-2011-3088, CVE-2011-3089, CVE-2011-3090, CVE-2011-3091, CVE-2011-3092, CVE-2011-3093, CVE-2011-3094, CVE-2011-3095, CVE-2011-3096, CVE-2011-3098, CVE-2011-3100, CVE-2011-3101, CVE-2011-3102