Bug 1212755

Summary: VUL-0: chromium: multiple security issues fixed in 114.0.5735.198
Product: [openSUSE] openSUSE Distribution Reporter: Thomas Leroy <thomas.leroy>
Component: SecurityAssignee: Security Team bot <security-team>
Status: RESOLVED FIXED QA Contact: Security Team bot <security-team>
Severity: Normal    
Priority: P3 - Medium CC: Andreas.Stieger, gmbr3
Version: Leap 15.5   
Target Milestone: ---   
Hardware: Other   
OS: Other   
Whiteboard:
Found By: --- Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description Thomas Leroy 2023-06-27 06:44:59 UTC
Fixed in chromium 114.0.5735.198:

- CVE-2023-3420: Type Confusion in V8.
- CVE-2023-3421: Use after free in Media.
- CVE-2023-3422: Use after free in Guest View.


References:
https://chromereleases.googleblog.com/2023/06/stable-channel-update-for-desktop_26.html
Comment 1 OBSbugzilla Bot 2023-06-27 08:35:02 UTC
This is an autogenerated message for OBS integration:
This bug (1212755) was mentioned in
https://build.opensuse.org/request/show/1095537 Factory / chromium
https://build.opensuse.org/request/show/1095541 Backports:SLE-15-SP4+Backports:SLE-15-SP5 / chromium
Comment 2 Marcus Meissner 2023-06-29 16:05:37 UTC
openSUSE-SU-2023:0159-1: An update that fixes three vulnerabilities is now available.\n\nCategory: security (important)\nBug References: 1212755\nCVE References: CVE-2023-3420,CVE-2023-3421,CVE-2023-3422\nJIRA References: \nSources used:\nopenSUSE Backports SLE-15-SP5 (src):    chromium-114.0.5735.198-bp155.2.10.1\nopenSUSE Backports SLE-15-SP4 (src):    chromium-114.0.5735.198-bp154.2.96.1\n\n
Comment 3 Andreas Stieger 2023-06-29 16:29:13 UTC
done