Bug 1160337 - (CVE-2020-6377) VUL-0: CVE-2020-6377: chromium: multiple security issues fixed in 79.0.3945.117
(CVE-2020-6377)
VUL-0: CVE-2020-6377: chromium: multiple security issues fixed in 79.0.3945.117
Status: RESOLVED FIXED
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 15.1
Other Other
: P3 - Medium : Normal (vote)
: ---
Assigned To: Security Team bot
Security Team bot
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2020-01-07 21:49 UTC by Andreas Stieger
Modified: 2020-05-04 10:00 UTC (History)
3 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Stieger 2020-01-07 21:49:01 UTC
https://chromereleases.googleblog.com/2020/01/stable-channel-update-for-desktop.html

3 security fixes in Chromium 79.0.3945.117:

* CVE-TBD: Use after free in audio
* Various fixes from internal audits, fuzzing and other initiatives

https://bugs.chromium.org/p/chromium/issues/detail?id=1029462
https://bugs.chromium.org/p/chromium/issues/detail?id=1039803
Comment 1 Tomáš Chvátal 2020-01-08 08:16:13 UTC
Maintenance requests sent. When the CVEs are published please just send me a SR adjusting the changelog :)
Comment 2 Swamp Workflow Management 2020-01-08 09:10:09 UTC
This is an autogenerated message for OBS integration:
This bug (1160337) was mentioned in
https://build.opensuse.org/request/show/761744 Factory / chromium
https://build.opensuse.org/request/show/761745 15.1 / chromium
https://build.opensuse.org/request/show/761746 Backports:SLE-12-SP3 / chromium
https://build.opensuse.org/request/show/761747 Backports:SLE-15-SP1 / chromium
Comment 3 Andreas Stieger 2020-01-09 13:20:53 UTC
CVE-2020-6377
Comment 4 Swamp Workflow Management 2020-01-09 14:20:05 UTC
This is an autogenerated message for OBS integration:
This bug (1160337) was mentioned in
https://build.opensuse.org/request/show/762203 Factory / chromium
Comment 5 Swamp Workflow Management 2020-01-10 11:11:24 UTC
openSUSE-SU-2020:0004-1: An update that fixes four vulnerabilities is now available.

Category: security (important)
Bug References: 1160337
CVE References: CVE-2019-5844,CVE-2019-5845,CVE-2019-5846,CVE-2020-6377
Sources used:
openSUSE Backports SLE-15-SP1 (src):    chromium-79.0.3945.117-bp151.3.41.1
Comment 6 Swamp Workflow Management 2020-01-10 11:12:01 UTC
openSUSE-SU-2020:0004-1: An update that fixes four vulnerabilities is now available.

Category: security (important)
Bug References: 1160337
CVE References: CVE-2019-5844,CVE-2019-5845,CVE-2019-5846,CVE-2020-6377
Sources used:
openSUSE Backports SLE-15-SP1 (src):    chromium-79.0.3945.117-bp151.3.41.1
SUSE Package Hub for SUSE Linux Enterprise 12 (src):    chromium-79.0.3945.117-25.1
Comment 7 Swamp Workflow Management 2020-01-11 14:10:52 UTC
openSUSE-SU-2020:0006-1: An update that fixes four vulnerabilities is now available.

Category: security (important)
Bug References: 1160337
CVE References: CVE-2019-5844,CVE-2019-5845,CVE-2019-5846,CVE-2020-6377
Sources used:
openSUSE Leap 15.1 (src):    chromium-79.0.3945.117-lp151.2.57.2, re2-20200101-lp151.10.6.1
Comment 8 Swamp Workflow Management 2020-01-12 11:10:57 UTC
openSUSE-SU-2020:0009-1: An update that fixes four vulnerabilities is now available.

Category: security (important)
Bug References: 1160337
CVE References: CVE-2019-5844,CVE-2019-5845,CVE-2019-5846,CVE-2020-6377
Sources used:
openSUSE Backports SLE-15-SP1 (src):    chromium-79.0.3945.117-bp151.3.47.1, re2-20200101-bp151.6.6.1
Comment 9 Swamp Workflow Management 2020-01-14 17:14:38 UTC
openSUSE-SU-2020:0053-1: An update that fixes four vulnerabilities is now available.

Category: security (important)
Bug References: 1160337
CVE References: CVE-2019-5844,CVE-2019-5845,CVE-2019-5846,CVE-2020-6377
Sources used:
openSUSE Backports SLE-15-SP1 (src):    chromium-79.0.3945.117-bp151.3.53.3, re2-20200101-bp151.6.12.1
Comment 10 Alexandros Toptsoglou 2020-05-04 10:00:35 UTC
Done