Bugzilla – Bug 1164828
VUL-0: CVE-2020-6407, CVE-2020-6418: chromium: update to 80.0.3987.122
Last modified: 2020-03-02 14:04:20 UTC
This update includes CVE-2020-6418 that Google is aware of reports that an exploit exists in the wild. High CVE-2020-6418: Type confusion in V8 High CVE-2020-6407: Out of bounds memory access in streams. High: Integer overflow in ICU Reference https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop_24.html
MU to Backports and Leap was sent. SR to Tumbleweed was sent too.
This is an autogenerated message for OBS integration: This bug (1164828) was mentioned in https://build.opensuse.org/request/show/779107 Factory / chromium https://build.opensuse.org/request/show/779108 15.1 / chromium https://build.opensuse.org/request/show/779109 Backports:SLE-12-SP3 / chromium
openSUSE-SU-2020:0245-1: An update that solves two vulnerabilities and has one errata is now available. Category: security (important) Bug References: 1163484,1163588,1164828 CVE References: CVE-2020-6407,CVE-2020-6418 Sources used: SUSE Package Hub for SUSE Linux Enterprise 12 (src): chromium-80.0.3987.122-34.1
openSUSE-SU-2020:0259-1: An update that solves two vulnerabilities and has one errata is now available. Category: security (important) Bug References: 1163484,1163588,1164828 CVE References: CVE-2020-6407,CVE-2020-6418 Sources used: openSUSE Leap 15.1 (src): chromium-80.0.3987.122-lp151.2.66.1
released