{"schema_version":"1.7.3","id":"openSUSE-SU-2016:1868-1","published":"2016-07-25T09:41:24Z","modified":"2026-02-04T03:27:00.315453Z","related":["CVE-2016-1705","CVE-2016-1706","CVE-2016-1707","CVE-2016-1708","CVE-2016-1709","CVE-2016-1710","CVE-2016-1711","CVE-2016-5127","CVE-2016-5128","CVE-2016-5129","CVE-2016-5130","CVE-2016-5131","CVE-2016-5132","CVE-2016-5133","CVE-2016-5134","CVE-2016-5135","CVE-2016-5136","CVE-2016-5137"],"upstream":["CVE-2016-1705","CVE-2016-1706","CVE-2016-1707","CVE-2016-1708","CVE-2016-1709","CVE-2016-1710","CVE-2016-1711","CVE-2016-5127","CVE-2016-5128","CVE-2016-5129","CVE-2016-5130","CVE-2016-5131","CVE-2016-5132","CVE-2016-5133","CVE-2016-5134","CVE-2016-5135","CVE-2016-5136","CVE-2016-5137"],"summary":"Security update for Chromium","details":"Chromium was updated to 52.0.2743.82 to fix the following security issues (boo#989901):\n\n- CVE-2016-1706: Sandbox escape in PPAPI\n- CVE-2016-1707: URL spoofing on iOS\n- CVE-2016-1708: Use-after-free in Extensions\n- CVE-2016-1709: Heap-buffer-overflow in sfntly\n- CVE-2016-1710: Same-origin bypass in Blink\n- CVE-2016-1711: Same-origin bypass in Blink\n- CVE-2016-5127: Use-after-free in Blink\n- CVE-2016-5128: Same-origin bypass in V8\n- CVE-2016-5129: Memory corruption in V8\n- CVE-2016-5130: URL spoofing\n- CVE-2016-5131: Use-after-free in libxml\n- CVE-2016-5132: Limited same-origin bypass in Service Workers\n- CVE-2016-5133: Origin confusion in proxy authentication\n- CVE-2016-5134: URL leakage via PAC script\n- CVE-2016-5135: Content-Security-Policy bypass\n- CVE-2016-5136: Use after free in extensions\n- CVE-2016-5137: History sniffing with HSTS and CSP\n- CVE-2016-1705: Various fixes from internal audits, fuzzing and other initiatives\n","affected":[{"package":{"name":"chromium","ecosystem":"SUSE:Package Hub 12","purl":"pkg:rpm/suse/chromium&distro=SUSE%20Package%20Hub%2012"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"52.0.2743.82-89.1"}]}],"ecosystem_specific":{"binaries":[{"chromedriver":"52.0.2743.82-89.1","chromium":"52.0.2743.82-89.1","chromium-desktop-gnome":"52.0.2743.82-89.1","chromium-desktop-kde":"52.0.2743.82-89.1","chromium-ffmpegsumo":"52.0.2743.82-89.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2016:1868-1.json"}}],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/EFOAQPOUMGPNDVB5ZWHMMBG27GEBJHC6/#EFOAQPOUMGPNDVB5ZWHMMBG27GEBJHC6"},{"type":"REPORT","url":"https://bugzilla.suse.com/989901"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-1705"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-1706"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-1707"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-1708"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-1709"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-1710"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-1711"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-5127"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-5128"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-5129"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-5130"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-5131"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-5132"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-5133"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-5134"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-5135"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-5136"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-5137"}]}