openSUSE Security Update : chromium (openSUSE-2015-204)

high Nessus Plugin ID 81692

Synopsis

The remote openSUSE host is missing a security update.

Description

chromium was updated to version 40.0.2214.111 to fix 31 vulnerabilities.

These security issues were fixed :

- CVE-2015-1209: Use-after-free in DOM (bnc#916841).

- CVE-2015-1210: Cross-origin-bypass in V8 bindings (bnc#916843).

- CVE-2015-1211: Privilege escalation using service workers (bnc#916838).

- CVE-2015-1212: Various fixes from internal audits, fuzzing and other initiatives (bnc#916840).

- CVE-2014-7923: Memory corruption in ICU (bnc#914468).

- CVE-2014-7924: Use-after-free in IndexedDB (bnc#914468).

- CVE-2014-7925: Use-after-free in WebAudio (bnc#914468).

- CVE-2014-7926: Memory corruption in ICU (bnc#914468).

- CVE-2014-7927: Memory corruption in V8 (bnc#914468).

- CVE-2014-7928: Memory corruption in V8 (bnc#914468).

- CVE-2014-7930: Use-after-free in DOM (bnc#914468).

- CVE-2014-7931: Memory corruption in V8 (bnc#914468).

- CVE-2014-7929: Use-after-free in DOM (bnc#914468).

- CVE-2014-7932: Use-after-free in DOM (bnc#914468).

- CVE-2014-7933: Use-after-free in FFmpeg (bnc#914468).

- CVE-2014-7934: Use-after-free in DOM (bnc#914468).

- CVE-2014-7935: Use-after-free in Speech (bnc#914468).

- CVE-2014-7936: Use-after-free in Views (bnc#914468).

- CVE-2014-7937: Use-after-free in FFmpeg (bnc#914468).

- CVE-2014-7938: Memory corruption in Fonts (bnc#914468).

- CVE-2014-7939: Same-origin-bypass in V8 (bnc#914468).

- CVE-2014-7940: Uninitialized-value in ICU (bnc#914468).

- CVE-2014-7941: Out-of-bounds read in UI (bnc#914468).

- CVE-2014-7942: Uninitialized-value in Fonts (bnc#914468).

- CVE-2014-7943: Out-of-bounds read in Skia

- CVE-2014-7944: Out-of-bounds read in PDFium

- CVE-2014-7945: Out-of-bounds read in PDFium

- CVE-2014-7946: Out-of-bounds read in Fonts

- CVE-2014-7947: Out-of-bounds read in PDFium

- CVE-2014-7948: Caching error in AppCache

- CVE-2015-1205: Various fixes from internal audits, fuzzing and other initiatives

These non-security issues were fixed :

- Fix using 'echo' command in chromium-browser.sh script

Solution

Update the affected chromium packages.

See Also

https://bugzilla.opensuse.org/show_bug.cgi?id=914468

https://bugzilla.opensuse.org/show_bug.cgi?id=916838

https://bugzilla.opensuse.org/show_bug.cgi?id=916840

https://bugzilla.opensuse.org/show_bug.cgi?id=916841

https://bugzilla.opensuse.org/show_bug.cgi?id=916843

Plugin Details

Severity: High

ID: 81692

File Name: openSUSE-2015-204.nasl

Version: 1.10

Type: local

Agent: unix

Published: 3/9/2015

Updated: 1/19/2021

Supported Sensors: Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: High

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:novell:opensuse:chromedriver, p-cpe:/a:novell:opensuse:chromedriver-debuginfo, cpe:/o:novell:opensuse:13.2, p-cpe:/a:novell:opensuse:chromium-debugsource, p-cpe:/a:novell:opensuse:chromium-debuginfo, p-cpe:/a:novell:opensuse:chromium-desktop-kde, p-cpe:/a:novell:opensuse:chromium-ffmpegsumo, cpe:/o:novell:opensuse:13.1, p-cpe:/a:novell:opensuse:chromium, p-cpe:/a:novell:opensuse:chromium-desktop-gnome, p-cpe:/a:novell:opensuse:chromium-ffmpegsumo-debuginfo

Required KB Items: Host/local_checks_enabled, Host/SuSE/release, Host/SuSE/rpm-list, Host/cpu

Patch Publication Date: 3/4/2015

Reference Information

CVE: CVE-2014-7923, CVE-2014-7924, CVE-2014-7925, CVE-2014-7926, CVE-2014-7927, CVE-2014-7928, CVE-2014-7929, CVE-2014-7930, CVE-2014-7931, CVE-2014-7932, CVE-2014-7933, CVE-2014-7934, CVE-2014-7935, CVE-2014-7936, CVE-2014-7937, CVE-2014-7938, CVE-2014-7939, CVE-2014-7940, CVE-2014-7941, CVE-2014-7942, CVE-2014-7943, CVE-2014-7944, CVE-2014-7945, CVE-2014-7946, CVE-2014-7947, CVE-2014-7948, CVE-2015-1205, CVE-2015-1209, CVE-2015-1210, CVE-2015-1211, CVE-2015-1212