{"schema_version":"1.7.3","id":"openSUSE-SU-2020:0233-1","published":"2020-02-19T09:14:43Z","modified":"2026-02-04T02:17:33.919754Z","related":["CVE-2019-18197","CVE-2019-19880","CVE-2019-19923","CVE-2019-19925","CVE-2019-19926","CVE-2020-6381","CVE-2020-6382","CVE-2020-6385","CVE-2020-6387","CVE-2020-6388","CVE-2020-6389","CVE-2020-6390","CVE-2020-6391","CVE-2020-6392","CVE-2020-6393","CVE-2020-6394","CVE-2020-6395","CVE-2020-6396","CVE-2020-6397","CVE-2020-6398","CVE-2020-6399","CVE-2020-6400","CVE-2020-6401","CVE-2020-6402","CVE-2020-6403","CVE-2020-6404","CVE-2020-6405","CVE-2020-6406","CVE-2020-6408","CVE-2020-6409","CVE-2020-6410","CVE-2020-6411","CVE-2020-6412","CVE-2020-6413","CVE-2020-6414","CVE-2020-6415","CVE-2020-6416","CVE-2020-6417"],"upstream":["CVE-2019-18197","CVE-2019-19880","CVE-2019-19923","CVE-2019-19925","CVE-2019-19926","CVE-2020-6381","CVE-2020-6382","CVE-2020-6385","CVE-2020-6387","CVE-2020-6388","CVE-2020-6389","CVE-2020-6390","CVE-2020-6391","CVE-2020-6392","CVE-2020-6393","CVE-2020-6394","CVE-2020-6395","CVE-2020-6396","CVE-2020-6397","CVE-2020-6398","CVE-2020-6399","CVE-2020-6400","CVE-2020-6401","CVE-2020-6402","CVE-2020-6403","CVE-2020-6404","CVE-2020-6405","CVE-2020-6406","CVE-2020-6408","CVE-2020-6409","CVE-2020-6410","CVE-2020-6411","CVE-2020-6412","CVE-2020-6413","CVE-2020-6414","CVE-2020-6415","CVE-2020-6416","CVE-2020-6417"],"summary":"Security update for chromium, re2","details":"This update for chromium, re2 fixes the following issues:\n\n- Update to 80.0.3987.87 boo#1162833:\n  * CVE-2020-6381: Integer overflow in JavaScript\n  * CVE-2020-6382: Type Confusion in JavaScript\n  * CVE-2019-18197: Multiple vulnerabilities in XML\n  * CVE-2019-19926: Inappropriate implementation in SQLite\n  * CVE-2020-6385: Insufficient policy enforcement in storage\n  * CVE-2019-19880, CVE-2019-19925: Multiple vulnerabilities in SQLite\n  * CVE-2020-6387: Out of bounds write in WebRTC\n  * CVE-2020-6388: Out of bounds memory access in WebAudio\n  * CVE-2020-6389: Out of bounds write in WebRTC\n  * CVE-2020-6390: Out of bounds memory access in streams\n  * CVE-2020-6391: Insufficient validation of untrusted input in Blink\n  * CVE-2020-6392: Insufficient policy enforcement in extensions\n  * CVE-2020-6393: Insufficient policy enforcement in Blink\n  * CVE-2020-6394: Insufficient policy enforcement in Blink\n  * CVE-2020-6395: Out of bounds read in JavaScript\n  * CVE-2020-6396: Inappropriate implementation in Skia\n  * CVE-2020-6397: Incorrect security UI in sharing\n  * CVE-2020-6398: Uninitialized use in PDFium\n  * CVE-2020-6399: Insufficient policy enforcement in AppCache\n  * CVE-2020-6400: Inappropriate implementation in CORS\n  * CVE-2020-6401: Insufficient validation of untrusted input in Omnibox\n  * CVE-2020-6402: Insufficient policy enforcement in downloads\n  * CVE-2020-6403: Incorrect security UI in Omnibox\n  * CVE-2020-6404: Inappropriate implementation in Blink\n  * CVE-2020-6405: Out of bounds read in SQLite\n  * CVE-2020-6406: Use after free in audio\n  * CVE-2019-19923: Out of bounds memory access in SQLite\n  * CVE-2020-6408: Insufficient policy enforcement in CORS\n  * CVE-2020-6409: Inappropriate implementation in Omnibox\n  * CVE-2020-6410: Insufficient policy enforcement in navigation\n  * CVE-2020-6411: Insufficient validation of untrusted input in Omnibox\n  * CVE-2020-6412: Insufficient validation of untrusted input in Omnibox\n  * CVE-2020-6413: Inappropriate implementation in Blink\n  * CVE-2020-6414: Insufficient policy enforcement in Safe Browsing\n  * CVE-2020-6415: Inappropriate implementation in JavaScript\n  * CVE-2020-6416: Insufficient data validation in streams\n  * CVE-2020-6417: Inappropriate implementation in installer\n\nre2 was updated to fix:\n\nUpdate to 2020-01-01:\n\n* various developer visible changes\n\nUpdate to 2019-12-01:\n\n* fix latent bugs and undefined behavior\n\nUpdate to 2019-11-01:\n\n* new benchmark API\n\nUpdate to 2019-09-01:\n\n* build system fixes\n\nUpdate to 2019-08-01:\n\n* Update Unicode data to 12.1.0\n* Various developer visible changes\n\nUpdate to 2019-07-01:\n\n* developer visible changes\n","affected":[{"package":{"name":"chromium","ecosystem":"SUSE:Package Hub 12","purl":"pkg:rpm/suse/chromium&distro=SUSE%20Package%20Hub%2012"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"80.0.3987.87-31.1"}]}],"ecosystem_specific":{"binaries":[{"chromedriver":"80.0.3987.87-31.1","chromium":"80.0.3987.87-31.1","libre2-0":"20200101-25.1","re2-devel":"20200101-25.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2020:0233-1.json"}},{"package":{"name":"re2","ecosystem":"SUSE:Package Hub 12","purl":"pkg:rpm/suse/re2&distro=SUSE%20Package%20Hub%2012"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"20200101-25.1"}]}],"ecosystem_specific":{"binaries":[{"chromedriver":"80.0.3987.87-31.1","chromium":"80.0.3987.87-31.1","libre2-0":"20200101-25.1","re2-devel":"20200101-25.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2020:0233-1.json"}},{"package":{"name":"chromium","ecosystem":"SUSE:Package Hub 12 SP3","purl":"pkg:rpm/suse/chromium&distro=SUSE%20Package%20Hub%2012%20SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"80.0.3987.87-31.1"}]}],"ecosystem_specific":{"binaries":[{"chromedriver":"80.0.3987.87-31.1","chromium":"80.0.3987.87-31.1","libre2-0":"20200101-25.1","re2-devel":"20200101-25.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2020:0233-1.json"}},{"package":{"name":"re2","ecosystem":"SUSE:Package Hub 12 SP3","purl":"pkg:rpm/suse/re2&distro=SUSE%20Package%20Hub%2012%20SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"20200101-25.1"}]}],"ecosystem_specific":{"binaries":[{"chromedriver":"80.0.3987.87-31.1","chromium":"80.0.3987.87-31.1","libre2-0":"20200101-25.1","re2-devel":"20200101-25.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2020:0233-1.json"}}],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/7II7R5BUNZZ5ZN2QJ3UC33I67Y7HE4J2/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1162833"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-18197"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-19880"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-19923"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-19925"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-19926"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6381"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6382"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6385"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6387"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6388"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6389"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6390"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6391"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6392"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6393"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6394"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6395"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6396"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6397"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6398"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6399"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6400"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6401"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6402"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6403"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6404"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6405"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6406"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6408"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6409"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6410"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6411"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6412"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6413"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6414"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6415"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6416"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6417"}]}