Bug 1216783 - VUL-0: chromium: multiple security issues fixed in version 119.0.6045.105
Summary: VUL-0: chromium: multiple security issues fixed in version 119.0.6045.105
Status: RESOLVED FIXED
: 1216924 (view as bug list)
Alias: None
Product: openSUSE Distribution
Classification: openSUSE
Component: Security (show other bugs)
Version: Leap 15.6
Hardware: Other Other
: P3 - Medium : Normal (vote)
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/383769/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2023-11-01 10:02 UTC by SMASH SMASH
Modified: 2023-11-14 20:24 UTC (History)
4 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description SMASH SMASH 2023-11-01 10:02:01 UTC
This update includes 15 security fixes. Below, we highlight fixes that were contributed by external researchers. Please see the Chrome Security Page for more information.

[$16000][1492698] High CVE-2023-5480: Inappropriate implementation in Payments. Reported by Vsevolod Kokorin (Slonser) of Solidlab on 2023-10-14

[$11000][1492381] High CVE-2023-5482: Insufficient data validation in USB. Reported by DarkNavy on 2023-10-13

[$TBD][1492384] High CVE-2023-5849: Integer overflow in USB. Reported by DarkNavy on 2023-10-13

[$3000][1281972] Medium CVE-2023-5850: Incorrect security UI in Downloads. Reported by Mohit Raj (shadow2639)  on 2021-12-22

[$3000][1473957] Medium CVE-2023-5851: Inappropriate implementation in Downloads. Reported by Shaheen Fazim on 2023-08-18

[$2000][1480852] Medium CVE-2023-5852: Use after free in Printing. Reported by [pwn2car] on 2023-09-10

[$1000][1456876] Medium CVE-2023-5853: Incorrect security UI in Downloads. Reported by Hafiizh on 2023-06-22

[$1000][1488267] Medium CVE-2023-5854: Use after free in Profiles. Reported by Dohyun Lee (@l33d0hyun) of SSD-Disclosure Labs & DNSLab, Korea Univ on 2023-10-01

[$TBD][1492396] Medium CVE-2023-5855: Use after free in Reading Mode. Reported by ChaobinZhang on 2023-10-13

[$TBD][1493380] Medium CVE-2023-5856: Use after free in Side Panel. Reported by Weipeng Jiang (@Krace) of VRI on 2023-10-17

[N/A][1493435] Medium CVE-2023-5857: Inappropriate implementation in Downloads. Reported by Will Dormann on 2023-10-18

[$3000][1457704] Low CVE-2023-5858: Inappropriate implementation in WebApp Provider. Reported by Axel Chong on 2023-06-24

[$500][1482045] Low CVE-2023-5859: Incorrect security UI in Picture In Picture. Reported by Junsung Lee on 2023-09-13

We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.

References:
https://sites.google.com/a/chromium.org/dev/Home/chromium-security
Comment 1 OBSbugzilla Bot 2023-11-10 19:35:03 UTC
This is an autogenerated message for OBS integration:
This bug (1216783) was mentioned in
https://build.opensuse.org/request/show/1125107 Factory / chromium
Comment 2 OBSbugzilla Bot 2023-11-11 08:15:01 UTC
This is an autogenerated message for OBS integration:
This bug (1216783) was mentioned in
https://build.opensuse.org/request/show/1125147 Backports:SLE-15-SP4+Backports:SLE-15-SP5 / chromium+gn
Comment 3 Andreas Stieger 2023-11-11 16:10:53 UTC
*** Bug 1216924 has been marked as a duplicate of this bug. ***
Comment 4 Marcus Meissner 2023-11-14 20:05:06 UTC
openSUSE-SU-2023:0368-1: An update that fixes 14 vulnerabilities is now available.

Category: security (important)
Bug References: 1216783,1216978
CVE References: CVE-2023-5480,CVE-2023-5482,CVE-2023-5849,CVE-2023-5850,CVE-2023-5851,CVE-2023-5852,CVE-2023-5853,CVE-2023-5854,CVE-2023-5855,CVE-2023-5856,CVE-2023-5857,CVE-2023-5858,CVE-2023-5859,CVE-2023-5996
JIRA References: 
Sources used:
openSUSE Backports SLE-15-SP5 (src):    chromium-119.0.6045.123-bp155.2.55.1, gn-0.20231023-bp155.5.3.1
openSUSE Backports SLE-15-SP4 (src):    chromium-119.0.6045.123-bp154.2.141.1, gn-0.20231023-bp154.3.6.1
Comment 5 Andreas Stieger 2023-11-14 20:24:06 UTC
done