Bug 1170107 - (CVE-2020-6458) VUL-0: CVE-2020-6458,CVE-2020-6459,CVE-2020-6460: chromium: multiple security issues fixed in 81.0.4044.122
(CVE-2020-6458)
VUL-0: CVE-2020-6458,CVE-2020-6459,CVE-2020-6460: chromium: multiple security...
Status: RESOLVED FIXED
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 15.1
Other Other
: P3 - Medium : Normal (vote)
: ---
Assigned To: Security Team bot
E-mail List
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2020-04-21 20:19 UTC by Andreas Stieger
Modified: 2021-12-15 09:40 UTC (History)
1 user (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Stieger 2020-04-21 20:19:20 UTC
https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_21.html

Fixed in chromium 81.0.4044.122: 8 security fixes

CVE-2020-6459: Use after free in payments
CVE-2020-6460: Insufficient data validation in URL formatting
CVE-2020-6458: Out of bounds read and write in PDFium
Comment 1 Tomáš Chvátal 2020-04-22 06:31:20 UTC
Andreas already sent the sr to develprj and maint-update. Thanks.
Reassigning to sec-team.
Comment 2 Swamp Workflow Management 2020-04-22 06:40:06 UTC
This is an autogenerated message for OBS integration:
This bug (1170107) was mentioned in
https://build.opensuse.org/request/show/796157 15.1 / chromium
Comment 3 Swamp Workflow Management 2020-04-29 12:40:09 UTC
This is an autogenerated message for OBS integration:
This bug (1170107) was mentioned in
https://build.opensuse.org/request/show/798875 15.1+Backports:SLE-15-SP1 / chromium
Comment 4 Swamp Workflow Management 2020-05-03 04:14:00 UTC
openSUSE-SU-2020:0604-1: An update that fixes 5 vulnerabilities is now available.

Category: security (important)
Bug References: 1170107
CVE References: CVE-2020-0561,CVE-2020-6458,CVE-2020-6459,CVE-2020-6460,CVE-2020-6462
Sources used:
openSUSE Leap 15.1 (src):    chromium-81.0.4044.129-lp151.2.85.1
openSUSE Backports SLE-15-SP1 (src):    chromium-81.0.4044.129-bp151.3.75.1
Comment 5 Andreas Stieger 2020-05-03 13:18:54 UTC
done
Comment 6 Swamp Workflow Management 2020-05-06 13:18:27 UTC
openSUSE-SU-2020:0615-1: An update that fixes 5 vulnerabilities is now available.

Category: security (important)
Bug References: 1170107
CVE References: CVE-2020-0561,CVE-2020-6458,CVE-2020-6459,CVE-2020-6460,CVE-2020-6462
Sources used:
openSUSE Backports SLE-15-SP1 (src):    chromium-81.0.4044.129-bp151.3.79.1
Comment 7 Swamp Workflow Management 2020-06-17 22:12:54 UTC
openSUSE-SU-2020:0823-1: An update that fixes 32 vulnerabilities is now available.

Category: security (important)
Bug References: 1170107,1171910,1171975,1172496
CVE References: CVE-2020-6463,CVE-2020-6465,CVE-2020-6466,CVE-2020-6467,CVE-2020-6468,CVE-2020-6469,CVE-2020-6470,CVE-2020-6471,CVE-2020-6472,CVE-2020-6473,CVE-2020-6474,CVE-2020-6475,CVE-2020-6476,CVE-2020-6477,CVE-2020-6478,CVE-2020-6479,CVE-2020-6480,CVE-2020-6481,CVE-2020-6482,CVE-2020-6483,CVE-2020-6484,CVE-2020-6485,CVE-2020-6486,CVE-2020-6487,CVE-2020-6488,CVE-2020-6489,CVE-2020-6490,CVE-2020-6491,CVE-2020-6493,CVE-2020-6494,CVE-2020-6495,CVE-2020-6496
Sources used:
openSUSE Leap 15.1 (src):    chromium-83.0.4103.97-lp151.2.96.1
Comment 8 Swamp Workflow Management 2020-06-18 22:15:26 UTC
openSUSE-SU-2020:0832-1: An update that fixes 32 vulnerabilities is now available.

Category: security (important)
Bug References: 1170107,1171910,1171975,1172496
CVE References: CVE-2020-6463,CVE-2020-6465,CVE-2020-6466,CVE-2020-6467,CVE-2020-6468,CVE-2020-6469,CVE-2020-6470,CVE-2020-6471,CVE-2020-6472,CVE-2020-6473,CVE-2020-6474,CVE-2020-6475,CVE-2020-6476,CVE-2020-6477,CVE-2020-6478,CVE-2020-6479,CVE-2020-6480,CVE-2020-6481,CVE-2020-6482,CVE-2020-6483,CVE-2020-6484,CVE-2020-6485,CVE-2020-6486,CVE-2020-6487,CVE-2020-6488,CVE-2020-6489,CVE-2020-6490,CVE-2020-6491,CVE-2020-6493,CVE-2020-6494,CVE-2020-6495,CVE-2020-6496
Sources used:
openSUSE Backports SLE-15-SP1 (src):    chromium-83.0.4103.97-bp151.3.85.1
Comment 9 OBSbugzilla Bot 2021-12-15 09:40:07 UTC
This is an autogenerated message for OBS integration:
This bug (1170107) was mentioned in
https://build.opensuse.org/request/show/940663 Backports:SLE-12-SP3 / chromium