Bug 1212755 - VUL-0: chromium: multiple security issues fixed in 114.0.5735.198
Summary: VUL-0: chromium: multiple security issues fixed in 114.0.5735.198
Status: RESOLVED FIXED
Alias: None
Product: openSUSE Distribution
Classification: openSUSE
Component: Security (show other bugs)
Version: Leap 15.5
Hardware: Other Other
: P3 - Medium : Normal (vote)
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2023-06-27 06:44 UTC by Thomas Leroy
Modified: 2023-06-29 16:29 UTC (History)
2 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Thomas Leroy 2023-06-27 06:44:59 UTC
Fixed in chromium 114.0.5735.198:

- CVE-2023-3420: Type Confusion in V8.
- CVE-2023-3421: Use after free in Media.
- CVE-2023-3422: Use after free in Guest View.


References:
https://chromereleases.googleblog.com/2023/06/stable-channel-update-for-desktop_26.html
Comment 1 OBSbugzilla Bot 2023-06-27 08:35:02 UTC
This is an autogenerated message for OBS integration:
This bug (1212755) was mentioned in
https://build.opensuse.org/request/show/1095537 Factory / chromium
https://build.opensuse.org/request/show/1095541 Backports:SLE-15-SP4+Backports:SLE-15-SP5 / chromium
Comment 2 Marcus Meissner 2023-06-29 16:05:37 UTC
openSUSE-SU-2023:0159-1: An update that fixes three vulnerabilities is now available.\n\nCategory: security (important)\nBug References: 1212755\nCVE References: CVE-2023-3420,CVE-2023-3421,CVE-2023-3422\nJIRA References: \nSources used:\nopenSUSE Backports SLE-15-SP5 (src):    chromium-114.0.5735.198-bp155.2.10.1\nopenSUSE Backports SLE-15-SP4 (src):    chromium-114.0.5735.198-bp154.2.96.1\n\n
Comment 3 Andreas Stieger 2023-06-29 16:29:13 UTC
done