Bug 1203419 - VUL-0: chromium: multiple security issues fixed in 105.0.5195.125 - 105.0.5195.127
VUL-0: chromium: multiple security issues fixed in 105.0.5195.125 - 105.0.519...
Status: RESOLVED FIXED
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 15.4
Other Other
: P3 - Medium : Normal (vote)
: ---
Assigned To: Security Team bot
Security Team bot
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2022-09-14 18:11 UTC by Andreas Stieger
Modified: 2023-01-03 07:26 UTC (History)
3 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Stieger 2022-09-14 18:11:18 UTC
https://chromereleases.googleblog.com/2022/09/stable-channel-update-for-desktop_14.html

Fixed in 105.0.5195.125 / 105.0.5195.125/126/127

  * CVE-2022-3195: Out of bounds write in Storage
  * CVE-2022-3196: Use after free in PDF
  * CVE-2022-3197: Use after free in PDF
  * CVE-2022-3198: Use after free in PDF
  * CVE-2022-3199: Use after free in Frames
  * CVE-2022-3200: Heap buffer overflow in Internals
  * CVE-2022-3201: Insufficient validation of untrusted input in DevTools
  * Various fixes from internal audits, fuzzing and other initiatives
Comment 1 Andreas Stieger 2022-09-14 18:51:23 UTC
submitted
Comment 2 OBSbugzilla Bot 2022-09-14 19:35:03 UTC
This is an autogenerated message for OBS integration:
This bug (1203419) was mentioned in
https://build.opensuse.org/request/show/1003596 Factory / chromium
https://build.opensuse.org/request/show/1003599 Backports:SLE-15-SP3+Backports:SLE-15-SP4 / chromium
https://build.opensuse.org/request/show/1003601 Backports:SLE-15-SP5 / chromium
Comment 3 OBSbugzilla Bot 2022-09-16 22:15:03 UTC
This is an autogenerated message for OBS integration:
This bug (1203419) was mentioned in
https://build.opensuse.org/request/show/1004207 Backports:SLE-15-SP5 / chromium
Comment 4 Swamp Workflow Management 2022-09-17 04:19:47 UTC
openSUSE-SU-2022:10123-1: An update that fixes 7 vulnerabilities is now available.

Category: security (important)
Bug References: 1203419
CVE References: CVE-2022-3195,CVE-2022-3196,CVE-2022-3197,CVE-2022-3198,CVE-2022-3199,CVE-2022-3200,CVE-2022-3201
JIRA References: 
Sources used:
openSUSE Backports SLE-15-SP4 (src):    chromium-105.0.5195.127-bp154.2.29.1
openSUSE Backports SLE-15-SP3 (src):    chromium-105.0.5195.127-bp153.2.122.1
Comment 5 Andreas Stieger 2022-09-17 05:46:48 UTC
done
Comment 6 Thomas Leroy 2023-01-03 07:26:54 UTC
New reference:
 * CVE-2022-3842: Use after free in Passwords.