Bug 1213803 - VUL-0: chromium: multiple security issues fixed in 111.0.5563.64
Summary: VUL-0: chromium: multiple security issues fixed in 111.0.5563.64
Status: RESOLVED FIXED
Alias: None
Product: openSUSE Distribution
Classification: openSUSE
Component: Security (show other bugs)
Version: Leap 15.5
Hardware: Other Other
: P3 - Medium : Normal (vote)
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2023-07-31 06:56 UTC by Thomas Leroy
Modified: 2023-07-31 07:19 UTC (History)
0 users

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Thomas Leroy 2023-07-31 06:56:52 UTC
https://chromereleases.googleblog.com/2023/03/stable-channel-update-for-desktop.html

CVE-2023-1213: Use after free in Swiftshader.
CVE-2023-1214: Type Confusion in V8.
CVE-2023-1215: Type Confusion in CSS.
CVE-2023-1216: Use after free in DevTools.
CVE-2023-1217: Stack buffer overflow in Crash reporting.
CVE-2023-1218: Use after free in WebRTC.
CVE-2023-1219: Heap buffer overflow in Metrics.
CVE-2023-1220: Heap buffer overflow in UMA.
CVE-2023-1221: Insufficient policy enforcement in Extensions API.
CVE-2023-1222: Heap buffer overflow in Web Audio API.
CVE-2023-1223: Insufficient policy enforcement in Autofill.
CVE-2023-1224: Insufficient policy enforcement in Web Payments API.
CVE-2023-1225: Insufficient policy enforcement in Navigation.
CVE-2023-1226: Insufficient policy enforcement in Web Payments API.
CVE-2023-1227: Use after free in Core.
CVE-2023-1228: Insufficient policy enforcement in Intents.
CVE-2023-1229: Inappropriate implementation in Permission prompts.
CVE-2023-1230: Inappropriate implementation in WebApp Installs.
CVE-2023-1231: Inappropriate implementation in Autofill.
CVE-2023-2314: Insufficient data validation in DevTools.
CVE-2023-1232: Insufficient policy enforcement in
CVE-2023-1233: Insufficient policy enforcement in
CVE-2023-1234: Inappropriate implementation in Intents.
CVE-2023-1235: Type Confusion in DevTools.
CVE-2023-1236: Inappropriate implementation in Internals.
Comment 1 Thomas Leroy 2023-07-31 07:19:37 UTC
Already fixed