Bug 1161252 - (CVE-2020-6378) VUL-0: CVE-2020-6378,CVE-2020-6379,CVE-2020-6380: chromium: multiple security issues fixed in 79.0.3945.130
(CVE-2020-6378)
VUL-0: CVE-2020-6378,CVE-2020-6379,CVE-2020-6380: chromium: multiple security...
Status: RESOLVED FIXED
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 15.1
Other Other
: P3 - Medium : Major (vote)
: ---
Assigned To: Security Team bot
Security Team bot
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2020-01-18 19:35 UTC by Andreas Stieger
Modified: 2020-01-22 18:34 UTC (History)
1 user (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Stieger 2020-01-18 19:35:37 UTC
https://chromereleases.googleblog.com/2020/01/stable-channel-update-for-desktop_16.html

Fixed in 79.0.3945.130:

CVE-2020-6378: Use-after-free in speech recognizer
CVE-2020-6379: Use-after-free in speech recognizer
CVE-2020-6380: Extension message verification error
Various fixes from internal audits, fuzzing and other initiatives
Comment 2 Swamp Workflow Management 2020-01-19 09:50:06 UTC
This is an autogenerated message for OBS integration:
This bug (1161252) was mentioned in
https://build.opensuse.org/request/show/765547 15.1+Backports:SLE-12-SP3+Backports:SLE-15-SP1 / chromium
Comment 3 Swamp Workflow Management 2020-01-22 17:12:03 UTC
openSUSE-SU-2020:0093-1: An update that fixes three vulnerabilities is now available.

Category: security (important)
Bug References: 1161252
CVE References: CVE-2020-6378,CVE-2020-6379,CVE-2020-6380
Sources used:
openSUSE Leap 15.1 (src):    chromium-79.0.3945.130-lp151.2.60.4
openSUSE Backports SLE-15-SP1 (src):    chromium-79.0.3945.130-bp151.3.56.3
Comment 4 Swamp Workflow Management 2020-01-22 17:13:27 UTC
openSUSE-SU-2020:0093-1: An update that fixes three vulnerabilities is now available.

Category: security (important)
Bug References: 1161252
CVE References: CVE-2020-6378,CVE-2020-6379,CVE-2020-6380
Sources used:
openSUSE Leap 15.1 (src):    chromium-79.0.3945.130-lp151.2.60.4
openSUSE Backports SLE-15-SP1 (src):    chromium-79.0.3945.130-bp151.3.56.3
SUSE Package Hub for SUSE Linux Enterprise 12 (src):    chromium-79.0.3945.130-28.1
Comment 5 Andreas Stieger 2020-01-22 18:34:29 UTC
done