Bug 1060019 - (CVE-2017-5121) VUL-0: CVE-2017-5121,CVE-2017-5122: chromium: multiple vulnerabilities fixed in 61.0.3163.100
(CVE-2017-5121)
VUL-0: CVE-2017-5121,CVE-2017-5122: chromium: multiple vulnerabilities fixed ...
Status: RESOLVED FIXED
: 1060020 (view as bug list)
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 42.3
Other Other
: P3 - Medium : Normal (vote)
: ---
Assigned To: Security Team bot
E-mail List
https://bugzilla.opensuse.org/show_bu...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2017-09-22 14:50 UTC by Andreas Stieger
Modified: 2017-09-23 14:35 UTC (History)
4 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---
astieger: needinfo? (normand)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Stieger 2017-09-22 14:50:22 UTC
https://chromereleases.googleblog.com/2017/09/stable-channel-update-for-desktop_21.html

- Update to 61.0.3163.100:
  * CVE-2017-5121: Out-of-bounds access in V8
  * CVE-2017-5122: Out-of-bounds access in V8
  * Various fixes from internal audits, fuzzing and other initiatives
Comment 1 Bernhard Wiedemann 2017-09-22 16:01:08 UTC
This is an autogenerated message for OBS integration:
This bug (1060019) was mentioned in
https://build.opensuse.org/request/show/528312 42.2+42.3+Backports:SLE-12-SP2 / chromium
Comment 2 Tomáš Chvátal 2017-09-22 16:46:08 UTC
*** Bug 1060020 has been marked as a duplicate of this bug. ***
Comment 3 Marcus Meissner 2017-09-22 21:26:51 UTC
move aliases here if you considers this the primary bug
Comment 4 Andreas Stieger 2017-09-23 07:06:33 UTC
release Chromium.

I noticed that we still carry a standalone v8 which has since been dropped from Factory. I do not remember the community maintainer responding to bugs, but maybe there is a plan for v8 maintenance, or having it in the distribution altogether?
Comment 5 Swamp Workflow Management 2017-09-23 10:07:40 UTC
openSUSE-SU-2017:2557-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 1060019
CVE References: CVE-2017-5121,CVE-2017-5122
Sources used:
openSUSE Leap 42.3 (src):    chromium-61.0.3163.100-113.1
openSUSE Leap 42.2 (src):    chromium-61.0.3163.100-104.27.1
Comment 6 Swamp Workflow Management 2017-09-23 10:07:55 UTC
openSUSE-SU-2017:2558-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 1060019
CVE References: CVE-2017-5121,CVE-2017-5122
Sources used:
SUSE Package Hub for SUSE Linux Enterprise 12 (src):    chromium-61.0.3163.100-32.1