Synopsis
The remote openSUSE host is missing a security update.
Description
chromium was updated to version 40.0.2214.111 to fix 31 vulnerabilities.
These security issues were fixed :
- CVE-2015-1209: Use-after-free in DOM (bnc#916841).
- CVE-2015-1210: Cross-origin-bypass in V8 bindings (bnc#916843).
- CVE-2015-1211: Privilege escalation using service workers (bnc#916838).
- CVE-2015-1212: Various fixes from internal audits, fuzzing and other initiatives (bnc#916840).
- CVE-2014-7923: Memory corruption in ICU (bnc#914468).
- CVE-2014-7924: Use-after-free in IndexedDB (bnc#914468).
- CVE-2014-7925: Use-after-free in WebAudio (bnc#914468).
- CVE-2014-7926: Memory corruption in ICU (bnc#914468).
- CVE-2014-7927: Memory corruption in V8 (bnc#914468).
- CVE-2014-7928: Memory corruption in V8 (bnc#914468).
- CVE-2014-7930: Use-after-free in DOM (bnc#914468).
- CVE-2014-7931: Memory corruption in V8 (bnc#914468).
- CVE-2014-7929: Use-after-free in DOM (bnc#914468).
- CVE-2014-7932: Use-after-free in DOM (bnc#914468).
- CVE-2014-7933: Use-after-free in FFmpeg (bnc#914468).
- CVE-2014-7934: Use-after-free in DOM (bnc#914468).
- CVE-2014-7935: Use-after-free in Speech (bnc#914468).
- CVE-2014-7936: Use-after-free in Views (bnc#914468).
- CVE-2014-7937: Use-after-free in FFmpeg (bnc#914468).
- CVE-2014-7938: Memory corruption in Fonts (bnc#914468).
- CVE-2014-7939: Same-origin-bypass in V8 (bnc#914468).
- CVE-2014-7940: Uninitialized-value in ICU (bnc#914468).
- CVE-2014-7941: Out-of-bounds read in UI (bnc#914468).
- CVE-2014-7942: Uninitialized-value in Fonts (bnc#914468).
- CVE-2014-7943: Out-of-bounds read in Skia
- CVE-2014-7944: Out-of-bounds read in PDFium
- CVE-2014-7945: Out-of-bounds read in PDFium
- CVE-2014-7946: Out-of-bounds read in Fonts
- CVE-2014-7947: Out-of-bounds read in PDFium
- CVE-2014-7948: Caching error in AppCache
- CVE-2015-1205: Various fixes from internal audits, fuzzing and other initiatives
These non-security issues were fixed :
- Fix using 'echo' command in chromium-browser.sh script
Solution
Update the affected chromium packages.
Plugin Details
File Name: openSUSE-2015-204.nasl
Agent: unix
Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Nessus
Risk Information
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P
Vulnerability Information
CPE: p-cpe:/a:novell:opensuse:chromedriver, p-cpe:/a:novell:opensuse:chromedriver-debuginfo, p-cpe:/a:novell:opensuse:chromium, p-cpe:/a:novell:opensuse:chromium-debuginfo, p-cpe:/a:novell:opensuse:chromium-debugsource, p-cpe:/a:novell:opensuse:chromium-desktop-gnome, p-cpe:/a:novell:opensuse:chromium-desktop-kde, p-cpe:/a:novell:opensuse:chromium-ffmpegsumo, p-cpe:/a:novell:opensuse:chromium-ffmpegsumo-debuginfo, cpe:/o:novell:opensuse:13.1, cpe:/o:novell:opensuse:13.2
Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list
Patch Publication Date: 3/4/2015
Reference Information
CVE: CVE-2014-7923, CVE-2014-7924, CVE-2014-7925, CVE-2014-7926, CVE-2014-7927, CVE-2014-7928, CVE-2014-7929, CVE-2014-7930, CVE-2014-7931, CVE-2014-7932, CVE-2014-7933, CVE-2014-7934, CVE-2014-7935, CVE-2014-7936, CVE-2014-7937, CVE-2014-7938, CVE-2014-7939, CVE-2014-7940, CVE-2014-7941, CVE-2014-7942, CVE-2014-7943, CVE-2014-7944, CVE-2014-7945, CVE-2014-7946, CVE-2014-7947, CVE-2014-7948, CVE-2015-1205, CVE-2015-1209, CVE-2015-1210, CVE-2015-1211, CVE-2015-1212