Bug 1151229 - (CVE-2019-13685) VUL-0: CVE-2019-13685,CVE-2019-13686,CVE-2019-13687,CVE-2019-13688: chromium: multiple use-after-free issues fixed in 77.0.3865.90
(CVE-2019-13685)
VUL-0: CVE-2019-13685,CVE-2019-13686,CVE-2019-13687,CVE-2019-13688: chromium:...
Status: RESOLVED FIXED
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 15.1
Other Other
: P3 - Medium : Major (vote)
: ---
Assigned To: Security Team bot
Security Team bot
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2019-09-18 19:24 UTC by Andreas Stieger
Modified: 2019-11-07 07:45 UTC (History)
1 user (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Stieger 2019-09-18 19:24:24 UTC
https://chromereleases.googleblog.com/2019/09/stable-channel-update-for-desktop_18.html

* CVE-2019-13685: Use-after-free in UI
* CVE-2019-13688: Use-after-free in media
* CVE-2019-13687: Use-after-free in media
* CVE-2019-13686: Use-after-free in offline pages
Comment 1 Swamp Workflow Management 2019-09-19 02:40:06 UTC
This is an autogenerated message for OBS integration:
This bug (1151229) was mentioned in
https://build.opensuse.org/request/show/731820 15.0+15.1+Backports:SLE-15+Backports:SLE-15-SP1 / chromium+re2
Comment 2 Swamp Workflow Management 2019-09-19 08:50:09 UTC
This is an autogenerated message for OBS integration:
This bug (1151229) was mentioned in
https://build.opensuse.org/request/show/731875 15.0+15.1 / chromium
Comment 3 Swamp Workflow Management 2019-09-25 13:13:44 UTC
openSUSE-SU-2019:2186-1: An update that fixes four vulnerabilities is now available.

Category: security (important)
Bug References: 1151229
CVE References: CVE-2019-13685,CVE-2019-13686,CVE-2019-13687,CVE-2019-13688
Sources used:
openSUSE Leap 15.1 (src):    chromium-77.0.3865.90-lp151.2.33.1
openSUSE Leap 15.0 (src):    chromium-77.0.3865.90-lp150.242.1
Comment 4 Swamp Workflow Management 2019-10-01 13:10:54 UTC
openSUSE-SU-2019:2229-1: An update that fixes four vulnerabilities is now available.

Category: security (important)
Bug References: 1151229
CVE References: CVE-2019-13685,CVE-2019-13686,CVE-2019-13687,CVE-2019-13688
Sources used:
openSUSE Backports SLE-15-SP1 (src):    chromium-77.0.3865.90-bp151.3.15.1
Comment 5 Swamp Workflow Management 2019-10-01 13:12:00 UTC
openSUSE-SU-2019:2228-1: An update that fixes four vulnerabilities is now available.

Category: security (important)
Bug References: 1151229
CVE References: CVE-2019-13685,CVE-2019-13686,CVE-2019-13687,CVE-2019-13688
Sources used:
openSUSE Backports SLE-15 (src):    chromium-77.0.3865.90-bp150.234.1
Comment 6 Andreas Stieger 2019-10-01 14:23:24 UTC
done
Comment 7 Swamp Workflow Management 2019-11-04 13:40:29 UTC
This is an autogenerated message for OBS integration:
This bug (1151229) was mentioned in
https://build.opensuse.org/request/show/745163 Backports:SLE-12-SP3 / chromium
Comment 8 Swamp Workflow Management 2019-11-06 23:12:29 UTC
openSUSE-SU-2019:2447-1: An update that fixes 86 vulnerabilities is now available.

Category: security (important)
Bug References: 1143492,1144625,1145242,1146219,1149143,1150425,1151229,1153660,1154806,1155643
CVE References: CVE-2019-13659,CVE-2019-13660,CVE-2019-13661,CVE-2019-13662,CVE-2019-13663,CVE-2019-13664,CVE-2019-13665,CVE-2019-13666,CVE-2019-13667,CVE-2019-13668,CVE-2019-13669,CVE-2019-13670,CVE-2019-13671,CVE-2019-13673,CVE-2019-13674,CVE-2019-13675,CVE-2019-13676,CVE-2019-13677,CVE-2019-13678,CVE-2019-13679,CVE-2019-13680,CVE-2019-13681,CVE-2019-13682,CVE-2019-13683,CVE-2019-13685,CVE-2019-13686,CVE-2019-13687,CVE-2019-13688,CVE-2019-13693,CVE-2019-13694,CVE-2019-13695,CVE-2019-13696,CVE-2019-13697,CVE-2019-13699,CVE-2019-13700,CVE-2019-13701,CVE-2019-13702,CVE-2019-13703,CVE-2019-13704,CVE-2019-13705,CVE-2019-13706,CVE-2019-13707,CVE-2019-13708,CVE-2019-13709,CVE-2019-13710,CVE-2019-13711,CVE-2019-13713,CVE-2019-13714,CVE-2019-13715,CVE-2019-13716,CVE-2019-13717,CVE-2019-13718,CVE-2019-13719,CVE-2019-13720,CVE-2019-13721,CVE-2019-15903,CVE-2019-5850,CVE-2019-5851,CVE-2019-5852,CVE-2019-5853,CVE-2019-5854,CVE-2019-5855,CVE-2019-5856,CVE-2019-5857,CVE-2019-5858,CVE-2019-5859,CVE-2019-5860,CVE-2019-5861,CVE-2019-5862,CVE-2019-5863,CVE-2019-5864,CVE-2019-5865,CVE-2019-5867,CVE-2019-5868,CVE-2019-5869,CVE-2019-5870,CVE-2019-5871,CVE-2019-5872,CVE-2019-5874,CVE-2019-5875,CVE-2019-5876,CVE-2019-5877,CVE-2019-5878,CVE-2019-5879,CVE-2019-5880,CVE-2019-5881
Sources used:
SUSE Package Hub for SUSE Linux Enterprise 12 (src):    chromium-78.0.3904.87-10.1