{"schema_version":"1.7.3","id":"openSUSE-SU-2019:2447-1","published":"2019-11-06T17:25:26Z","modified":"2026-02-04T02:25:28.945823Z","related":["CVE-2019-13659","CVE-2019-13660","CVE-2019-13661","CVE-2019-13662","CVE-2019-13663","CVE-2019-13664","CVE-2019-13665","CVE-2019-13666","CVE-2019-13667","CVE-2019-13668","CVE-2019-13669","CVE-2019-13670","CVE-2019-13671","CVE-2019-13673","CVE-2019-13674","CVE-2019-13675","CVE-2019-13676","CVE-2019-13677","CVE-2019-13678","CVE-2019-13679","CVE-2019-13680","CVE-2019-13681","CVE-2019-13682","CVE-2019-13683","CVE-2019-13685","CVE-2019-13686","CVE-2019-13687","CVE-2019-13688","CVE-2019-13693","CVE-2019-13694","CVE-2019-13695","CVE-2019-13696","CVE-2019-13697","CVE-2019-13699","CVE-2019-13700","CVE-2019-13701","CVE-2019-13702","CVE-2019-13703","CVE-2019-13704","CVE-2019-13705","CVE-2019-13706","CVE-2019-13707","CVE-2019-13708","CVE-2019-13709","CVE-2019-13710","CVE-2019-13711","CVE-2019-13713","CVE-2019-13714","CVE-2019-13715","CVE-2019-13716","CVE-2019-13717","CVE-2019-13718","CVE-2019-13719","CVE-2019-13720","CVE-2019-13721","CVE-2019-15903","CVE-2019-5850","CVE-2019-5851","CVE-2019-5852","CVE-2019-5853","CVE-2019-5854","CVE-2019-5855","CVE-2019-5856","CVE-2019-5857","CVE-2019-5858","CVE-2019-5859","CVE-2019-5860","CVE-2019-5861","CVE-2019-5862","CVE-2019-5863","CVE-2019-5864","CVE-2019-5865","CVE-2019-5867","CVE-2019-5868","CVE-2019-5869","CVE-2019-5870","CVE-2019-5871","CVE-2019-5872","CVE-2019-5874","CVE-2019-5875","CVE-2019-5876","CVE-2019-5877","CVE-2019-5878","CVE-2019-5879","CVE-2019-5880","CVE-2019-5881"],"upstream":["CVE-2019-13659","CVE-2019-13660","CVE-2019-13661","CVE-2019-13662","CVE-2019-13663","CVE-2019-13664","CVE-2019-13665","CVE-2019-13666","CVE-2019-13667","CVE-2019-13668","CVE-2019-13669","CVE-2019-13670","CVE-2019-13671","CVE-2019-13673","CVE-2019-13674","CVE-2019-13675","CVE-2019-13676","CVE-2019-13677","CVE-2019-13678","CVE-2019-13679","CVE-2019-13680","CVE-2019-13681","CVE-2019-13682","CVE-2019-13683","CVE-2019-13685","CVE-2019-13686","CVE-2019-13687","CVE-2019-13688","CVE-2019-13693","CVE-2019-13694","CVE-2019-13695","CVE-2019-13696","CVE-2019-13697","CVE-2019-13699","CVE-2019-13700","CVE-2019-13701","CVE-2019-13702","CVE-2019-13703","CVE-2019-13704","CVE-2019-13705","CVE-2019-13706","CVE-2019-13707","CVE-2019-13708","CVE-2019-13709","CVE-2019-13710","CVE-2019-13711","CVE-2019-13713","CVE-2019-13714","CVE-2019-13715","CVE-2019-13716","CVE-2019-13717","CVE-2019-13718","CVE-2019-13719","CVE-2019-13720","CVE-2019-13721","CVE-2019-15903","CVE-2019-5850","CVE-2019-5851","CVE-2019-5852","CVE-2019-5853","CVE-2019-5854","CVE-2019-5855","CVE-2019-5856","CVE-2019-5857","CVE-2019-5858","CVE-2019-5859","CVE-2019-5860","CVE-2019-5861","CVE-2019-5862","CVE-2019-5863","CVE-2019-5864","CVE-2019-5865","CVE-2019-5867","CVE-2019-5868","CVE-2019-5869","CVE-2019-5870","CVE-2019-5871","CVE-2019-5872","CVE-2019-5874","CVE-2019-5875","CVE-2019-5876","CVE-2019-5877","CVE-2019-5878","CVE-2019-5879","CVE-2019-5880","CVE-2019-5881"],"summary":"Security update for chromium","details":"This update for chromium fixes the following issues:\n\t  \nChromium was updated to 78.0.3904.87: \n(boo#1155643,boo#1154806,boo#1153660, boo#1151229,boo#1149143,boo#1145242,boo#1143492)\n\nSecurity issues fixed with this version update: \n\n  * CVE-2019-13721: Use-after-free in PDFium\n  * CVE-2019-13720: Use-after-free in audio\n  * CVE-2019-13699: Use-after-free in media\n  * CVE-2019-13700: Buffer overrun in Blink\n  * CVE-2019-13701: URL spoof in navigation\n  * CVE-2019-13702: Privilege elevation in Installer\n  * CVE-2019-13703: URL bar spoofing\n  * CVE-2019-13704: CSP bypass\n  * CVE-2019-13705: Extension permission bypass\n  * CVE-2019-13706: Out-of-bounds read in PDFium\n  * CVE-2019-13707: File storage disclosure\n  * CVE-2019-13708: HTTP authentication spoof\n  * CVE-2019-13709: File download protection bypass\n  * CVE-2019-13710: File download protection bypass\n  * CVE-2019-13711: Cross-context information leak\n  * CVE-2019-15903: Buffer overflow in expat\n  * CVE-2019-13713: Cross-origin data leak\n  * CVE-2019-13714: CSS injection\n  * CVE-2019-13715: Address bar spoofing\n  * CVE-2019-13716: Service worker state error\n  * CVE-2019-13717: Notification obscured\n  * CVE-2019-13718: IDN spoof\n  * CVE-2019-13719: Notification obscured\n  * CVE-2019-13693: Use-after-free in IndexedDB\n  * CVE-2019-13694: Use-after-free in WebRTC\n  * CVE-2019-13695: Use-after-free in audio\n  * CVE-2019-13696: Use-after-free in V8\n  * CVE-2019-13697: Cross-origin size leak. \n  * CVE-2019-13685: Use-after-free in UI\n  * CVE-2019-13688: Use-after-free in media\n  * CVE-2019-13687: Use-after-free in media\n  * CVE-2019-13686: Use-after-free in offline pages\n  * CVE-2019-5870: Use-after-free in media\n  * CVE-2019-5871: Heap overflow in Skia\n  * CVE-2019-5872: Use-after-free in Mojo\n  * CVE-2019-5874: External URIs may trigger other browsers\n  * CVE-2019-5875: URL bar spoof via download redirect\n  * CVE-2019-5876: Use-after-free in media\n  * CVE-2019-5877: Out-of-bounds access in V8\n  * CVE-2019-5878: Use-after-free in V8\n  * CVE-2019-5879: Extension can bypass same origin policy\n  * CVE-2019-5880: SameSite cookie bypass\n  * CVE-2019-5881: Arbitrary read in SwiftShader\n  * CVE-2019-13659: URL spoof\n  * CVE-2019-13660: Full screen notification overlap\n  * CVE-2019-13661: Full screen notification spoof\n  * CVE-2019-13662: CSP bypass\n  * CVE-2019-13663: IDN spoof\n  * CVE-2019-13664: CSRF bypass\n  * CVE-2019-13665: Multiple file download protection bypass\n  * CVE-2019-13666: Side channel using storage size estimate\n  * CVE-2019-13667: URI bar spoof when using external app URIs\n  * CVE-2019-13668: Global window leak via console\n  * CVE-2019-13669: HTTP authentication spoof\n  * CVE-2019-13670: V8 memory corruption in regex\n  * CVE-2019-13671: Dialog box fails to show origin\n  * CVE-2019-13673: Cross-origin information leak using devtools\n  * CVE-2019-13674: IDN spoofing\n  * CVE-2019-13675: Extensions can be disabled by trailing slash\n  * CVE-2019-13676: Google URI shown for certificate warning\n  * CVE-2019-13677: Chrome web store origin needs to be isolated\n  * CVE-2019-13678: Download dialog spoofing\n  * CVE-2019-13679: User gesture needed for printing\n  * CVE-2019-13680: IP address spoofing to servers\n  * CVE-2019-13681: Bypass on download restrictions\n  * CVE-2019-13682: Site isolation bypass\n  * CVE-2019-13683: Exceptions leaked by devtools\n  * CVE-2019-5869: Use-after-free in Blink\n  * CVE-2019-5868: Use-after-free in PDFium ExecuteFieldAction\n  * CVE-2019-5867: Out-of-bounds read in V8\n  * CVE-2019-5850: Use-after-free in offline page fetcher\n  * CVE-2019-5860: Use-after-free in PDFium\n  * CVE-2019-5853: Memory corruption in regexp length check\n  * CVE-2019-5851: Use-after-poison in offline audio context\n  * CVE-2019-5859: res: URIs can load alternative browsers\n  * CVE-2019-5856: Insufficient checks on filesystem: URI permissions\n  * CVE-2019-5855: Integer overflow in PDFium\n  * CVE-2019-5865: Site isolation bypass from compromised renderer\n  * CVE-2019-5858: Insufficient filtering of Open URL service parameters\n  * CVE-2019-5864: Insufficient port filtering in CORS for extensions\n  * CVE-2019-5862: AppCache not robust to compromised renderers\n  * CVE-2019-5861: Click location incorrectly checked\n  * CVE-2019-5857: Comparison of -0 and null yields crash\n  * CVE-2019-5854: Integer overflow in PDFium text rendering\n  * CVE-2019-5852: Object leak of utility functions\n","affected":[{"package":{"name":"chromium","ecosystem":"SUSE:Package Hub 12 SP3","purl":"pkg:rpm/suse/chromium&distro=SUSE%20Package%20Hub%2012%20SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"78.0.3904.87-10.1"}]}],"ecosystem_specific":{"binaries":[{"chromedriver":"78.0.3904.87-10.1","chromium":"78.0.3904.87-10.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2019:2447-1.json"}}],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/QNJAWHUQKXHQBG3I7GI4ACW3CYHDJAHM/#QNJAWHUQKXHQBG3I7GI4ACW3CYHDJAHM"},{"type":"REPORT","url":"https://bugzilla.suse.com/1143492"},{"type":"REPORT","url":"https://bugzilla.suse.com/1144625"},{"type":"REPORT","url":"https://bugzilla.suse.com/1145242"},{"type":"REPORT","url":"https://bugzilla.suse.com/1146219"},{"type":"REPORT","url":"https://bugzilla.suse.com/1149143"},{"type":"REPORT","url":"https://bugzilla.suse.com/1150425"},{"type":"REPORT","url":"https://bugzilla.suse.com/1151229"},{"type":"REPORT","url":"https://bugzilla.suse.com/1153660"},{"type":"REPORT","url":"https://bugzilla.suse.com/1154806"},{"type":"REPORT","url":"https://bugzilla.suse.com/1155643"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13659"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13660"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13661"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13662"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13663"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13664"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13665"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13666"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13667"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13668"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13669"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13670"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13671"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13673"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13674"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13675"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13676"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13677"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13678"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13679"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13680"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13681"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13682"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13683"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13685"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13686"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13687"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13688"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13693"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13694"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13695"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13696"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13697"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13699"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13700"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13701"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13702"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13703"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13704"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13705"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13706"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13707"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13708"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13709"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13710"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13711"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13713"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13714"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13715"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13716"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13717"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13718"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13719"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13720"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13721"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-15903"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-5850"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-5851"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-5852"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-5853"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-5854"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-5855"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-5856"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-5857"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-5858"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-5859"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-5860"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-5861"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-5862"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-5863"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-5864"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-5865"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-5867"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-5868"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-5869"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-5870"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-5871"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-5872"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-5874"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-5875"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-5876"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-5877"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-5878"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-5879"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-5880"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-5881"}]}