Bug 1215023 (CVE-2023-4761) - VUL-0: chromium,ungoogled-chromium: multiple vulnerabilities fixed in 116.0.5845.179
Summary: VUL-0: chromium,ungoogled-chromium: multiple vulnerabilities fixed in 116.0.5...
Status: RESOLVED FIXED
Alias: CVE-2023-4761
Product: openSUSE Distribution
Classification: openSUSE
Component: Security (show other bugs)
Version: Leap 15.5
Hardware: Other Other
: P3 - Medium : Normal (vote)
Target Milestone: ---
Assignee: Security Team bot
QA Contact: E-mail List
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2023-09-06 05:07 UTC by Andreas Stieger
Modified: 2023-09-12 13:15 UTC (History)
2 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Stieger 2023-09-06 05:07:54 UTC
Fixed in 116.0.5845.179

* CVE-2023-4761: Out of bounds memory access in FedCM
* CVE-2023-4762: Type Confusion in V8
* CVE-2023-4763: Use after free in Networks
* CVE-2023-4764: Incorrect security UI in BFCache

References:
https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop.html
Comment 1 Andreas Stieger 2023-09-06 05:40:40 UTC
over to you for ungoogled-chromium
Comment 2 OBSbugzilla Bot 2023-09-06 06:25:03 UTC
This is an autogenerated message for OBS integration:
This bug (1215023) was mentioned in
https://build.opensuse.org/request/show/1109167 Factory / chromium
https://build.opensuse.org/request/show/1109168 Backports:SLE-15-SP4+Backports:SLE-15-SP5 / chromium
Comment 3 Michał Szczepaniak 2023-09-06 07:13:42 UTC
Thanks might take some time as I'm on vacation now
Comment 4 Andreas Stieger 2023-09-12 12:40:30 UTC
done
Comment 5 OBSbugzilla Bot 2023-09-12 13:05:03 UTC
This is an autogenerated message for OBS integration:
This bug (1215023) was mentioned in
https://build.opensuse.org/request/show/1110604 Factory / ungoogled-chromium
Comment 6 Marcus Meissner 2023-09-12 13:15:16 UTC
openSUSE-SU-2023:0245-1: An update that fixes four vulnerabilities is now available.

Category: security (important)
Bug References: 1215023
CVE References: CVE-2023-4761,CVE-2023-4762,CVE-2023-4763,CVE-2023-4764
JIRA References: 
Sources used:
openSUSE Backports SLE-15-SP5 (src):    chromium-116.0.5845.179-bp155.2.28.1
openSUSE Backports SLE-15-SP4 (src):    chromium-116.0.5845.179-bp154.2.114.1