Oval Definition:oval:org.opensuse.security:def:434
Revision Date:2022-09-12Version:1
Title:Security update for chromium (Important)
Description:

This update for chromium fixes the following issues:

Chromium 105.0.5195.102 (boo#1203102):

CVE-2022-3075: Insufficient data validation in Mojo

Chromium 105.0.5195.52 (boo#1202964):

CVE-2022-3038: Use after free in Network Service * CVE-2022-3039: Use after free in WebSQL * CVE-2022-3040: Use after free in Layout * CVE-2022-3041: Use after free in WebSQL * CVE-2022-3042: Use after free in PhoneHub * CVE-2022-3043: Heap buffer overflow in Screen Capture * CVE-2022-3044: Inappropriate implementation in Site Isolation * CVE-2022-3045: Insufficient validation of untrusted input in V8 * CVE-2022-3046: Use after free in Browser Tag * CVE-2022-3071: Use after free in Tab Strip * CVE-2022-3047: Insufficient policy enforcement in Extensions API * CVE-2022-3048: Inappropriate implementation in Chrome OS lockscreen * CVE-2022-3049: Use after free in SplitScreen * CVE-2022-3050: Heap buffer overflow in WebUI * CVE-2022-3051: Heap buffer overflow in Exosphere * CVE-2022-3052: Heap buffer overflow in Window Manager * CVE-2022-3053: Inappropriate implementation in Pointer Lock * CVE-2022-3054: Insufficient policy enforcement in DevTools * CVE-2022-3055: Use after free in Passwords * CVE-2022-3056: Insufficient policy enforcement in Content Security Policy * CVE-2022-3057: Inappropriate implementation in iframe Sandbox * CVE-2022-3058: Use after free in Sign-In Flow

- Update chromium-symbolic.svg: this fixes boo#1202403.

- Fix quoting in chrome-wrapper, don't put cwd on LD_LIBRARY_PATH
Family:unixClass:patch
Status:Reference(s):1202403
1202964
1203102
CVE-2010-4341
CVE-2010-4341
CVE-2011-1758
CVE-2011-1758
CVE-2013-0219
CVE-2013-0219
CVE-2013-0220
CVE-2013-0220
CVE-2013-0287
CVE-2013-0287
CVE-2014-0249
CVE-2014-0249
CVE-2017-12173
CVE-2017-12173
CVE-2018-10852
CVE-2018-10852
CVE-2019-3811
CVE-2019-3811
CVE-2022-3038
CVE-2022-3039
CVE-2022-3040
CVE-2022-3041
CVE-2022-3042
CVE-2022-3043
CVE-2022-3044
CVE-2022-3045
CVE-2022-3046
CVE-2022-3047
CVE-2022-3048
CVE-2022-3049
CVE-2022-3050
CVE-2022-3051
CVE-2022-3052
CVE-2022-3053
CVE-2022-3054
CVE-2022-3055
CVE-2022-3056
CVE-2022-3057
CVE-2022-3058
CVE-2022-3071
CVE-2022-3075
openSUSE-SU-2022:10119-1
Platform(s):openSUSE 12.3 Update
openSUSE 13.1
openSUSE Leap 15.4
SUSE Linux Enterprise Desktop 12 SP1
SUSE Linux Enterprise Desktop 15 SP1
SUSE Linux Enterprise for SAP 12
SUSE Linux Enterprise for SAP 12 SP1
SUSE Linux Enterprise High Availability 12
SUSE Linux Enterprise High Performance Computing 15 SP1
SUSE Linux Enterprise Live Patching 12
SUSE Linux Enterprise Module for Basesystem 15 SP1
SUSE Linux Enterprise Module for Containers 15
SUSE Linux Enterprise Module for Development Tools 15
SUSE Linux Enterprise Module for Legacy Software 12
SUSE Linux Enterprise Module for Public Cloud 12
SUSE Linux Enterprise Module for Web Scripting 12
SUSE Linux Enterprise Server 15 SP1
SUSE Linux Enterprise Server for SAP Applications 15 SP1
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Storage 6
SUSE Manager Proxy 4.0
SUSE Manager Server 4.0
Product(s):
Definition Synopsis
  • openSUSE Leap 15.4 is installed
  • AND Package Information
  • chromedriver-105.0.5195.102-bp154.2.26.1 is installed
  • OR chromium-105.0.5195.102-bp154.2.26.1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP1 is installed
  • AND Package Information
  • openslp-2.0.0-5 is installed
  • OR openslp-32bit-2.0.0-5 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Basesystem 15 SP1 is installed
  • AND Package Information
  • libipa_hbac-devel-1.16.1-3.18.1 is installed
  • OR libipa_hbac0-1.16.1-3.18.1 is installed
  • OR libsss_certmap-devel-1.16.1-3.18.1 is installed
  • OR libsss_certmap0-1.16.1-3.18.1 is installed
  • OR libsss_idmap-devel-1.16.1-3.18.1 is installed
  • OR libsss_idmap0-1.16.1-3.18.1 is installed
  • OR libsss_nss_idmap-devel-1.16.1-3.18.1 is installed
  • OR libsss_nss_idmap0-1.16.1-3.18.1 is installed
  • OR libsss_simpleifp-devel-1.16.1-3.18.1 is installed
  • OR libsss_simpleifp0-1.16.1-3.18.1 is installed
  • OR python3-sssd-config-1.16.1-3.18.1 is installed
  • OR sssd-1.16.1-3.18.1 is installed
  • OR sssd-32bit-1.16.1-3.18.1 is installed
  • OR sssd-ad-1.16.1-3.18.1 is installed
  • OR sssd-dbus-1.16.1-3.18.1 is installed
  • OR sssd-ipa-1.16.1-3.18.1 is installed
  • OR sssd-krb5-1.16.1-3.18.1 is installed
  • OR sssd-krb5-common-1.16.1-3.18.1 is installed
  • OR sssd-ldap-1.16.1-3.18.1 is installed
  • OR sssd-proxy-1.16.1-3.18.1 is installed
  • OR sssd-tools-1.16.1-3.18.1 is installed
  • OR sssd-wbclient-1.16.1-3.18.1 is installed
  • OR sssd-wbclient-devel-1.16.1-3.18.1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Basesystem 15 SP1 is installed
  • AND Package Information
  • libipa_hbac-devel-1.16.1-3.18 is installed
  • OR libipa_hbac0-1.16.1-3.18 is installed
  • OR libsss_certmap-devel-1.16.1-3.18 is installed
  • OR libsss_certmap0-1.16.1-3.18 is installed
  • OR libsss_idmap-devel-1.16.1-3.18 is installed
  • OR libsss_idmap0-1.16.1-3.18 is installed
  • OR libsss_nss_idmap-devel-1.16.1-3.18 is installed
  • OR libsss_nss_idmap0-1.16.1-3.18 is installed
  • OR libsss_simpleifp-devel-1.16.1-3.18 is installed
  • OR libsss_simpleifp0-1.16.1-3.18 is installed
  • OR python3-sssd-config-1.16.1-3.18 is installed
  • OR sssd-1.16.1-3.18 is installed
  • OR sssd-32bit-1.16.1-3.18 is installed
  • OR sssd-ad-1.16.1-3.18 is installed
  • OR sssd-dbus-1.16.1-3.18 is installed
  • OR sssd-ipa-1.16.1-3.18 is installed
  • OR sssd-krb5-1.16.1-3.18 is installed
  • OR sssd-krb5-common-1.16.1-3.18 is installed
  • OR sssd-ldap-1.16.1-3.18 is installed
  • OR sssd-proxy-1.16.1-3.18 is installed
  • OR sssd-tools-1.16.1-3.18 is installed
  • OR sssd-wbclient-1.16.1-3.18 is installed
  • OR sssd-wbclient-devel-1.16.1-3.18 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Containers 15 is installed
  • AND Package Information
  • containerd-1.2.6-5.16 is installed
  • OR docker-19.03.1_ce-6.26 is installed
  • OR docker-bash-completion-19.03.1_ce-6.26 is installed
  • OR docker-libnetwork-0.7.0.1+gitr2800_fc5a7d91d54c-4.15 is installed
  • OR docker-runc-1.0.0rc8+gitr3826_425e105d5a03-6.21 is installed
  • OR golang-github-docker-libnetwork-0.7.0.1+gitr2800_fc5a7d91d54c-4.15 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Development Tools 15 is installed
  • AND perl-Config-IniFiles-2.94-1 is installed
  • BACK