{"schema_version":"1.7.3","id":"openSUSE-SU-2020:1061-1","published":"2020-07-26T04:20:05Z","modified":"2025-05-07T18:12:12.483338Z","related":["CVE-2020-6510","CVE-2020-6511","CVE-2020-6512","CVE-2020-6513","CVE-2020-6514","CVE-2020-6515","CVE-2020-6516","CVE-2020-6517","CVE-2020-6518","CVE-2020-6519","CVE-2020-6520","CVE-2020-6521","CVE-2020-6522","CVE-2020-6523","CVE-2020-6524","CVE-2020-6525","CVE-2020-6526","CVE-2020-6527","CVE-2020-6528","CVE-2020-6529","CVE-2020-6530","CVE-2020-6531","CVE-2020-6533","CVE-2020-6534","CVE-2020-6535","CVE-2020-6536"],"upstream":["CVE-2020-6510","CVE-2020-6511","CVE-2020-6512","CVE-2020-6513","CVE-2020-6514","CVE-2020-6515","CVE-2020-6516","CVE-2020-6517","CVE-2020-6518","CVE-2020-6519","CVE-2020-6520","CVE-2020-6521","CVE-2020-6522","CVE-2020-6523","CVE-2020-6524","CVE-2020-6525","CVE-2020-6526","CVE-2020-6527","CVE-2020-6528","CVE-2020-6529","CVE-2020-6530","CVE-2020-6531","CVE-2020-6533","CVE-2020-6534","CVE-2020-6535","CVE-2020-6536"],"summary":"Security update for chromium","details":"This update for chromium fixes the following issues:\n\n- Update to 84.0.4147.89 boo#1174189:\n  * Critical CVE-2020-6510: Heap buffer overflow in background fetch. \n  * High CVE-2020-6511: Side-channel information leakage in content security policy. \n  * High CVE-2020-6512: Type Confusion in V8. \n  * High CVE-2020-6513: Heap buffer overflow in PDFium. \n  * High CVE-2020-6514: Inappropriate implementation in WebRTC. \n  * High CVE-2020-6515: Use after free in tab strip. \n  * High CVE-2020-6516: Policy bypass in CORS. \n  * High CVE-2020-6517: Heap buffer overflow in history. \n  * Medium CVE-2020-6518: Use after free in developer tools. \n  * Medium CVE-2020-6519: Policy bypass in CSP. \n  * Medium CVE-2020-6520: Heap buffer overflow in Skia. \n  * Medium CVE-2020-6521: Side-channel information leakage in autofill.\n  * Medium CVE-2020-6522: Inappropriate implementation in external protocol handlers. \n  * Medium CVE-2020-6523: Out of bounds write in Skia. \n  * Medium CVE-2020-6524: Heap buffer overflow in WebAudio. \n  * Medium CVE-2020-6525: Heap buffer overflow in Skia. \n  * Low CVE-2020-6526: Inappropriate implementation in iframe sandbox. \n  * Low CVE-2020-6527: Insufficient policy enforcement in CSP. \n  * Low CVE-2020-6528: Incorrect security UI in basic auth. \n  * Low CVE-2020-6529: Inappropriate implementation in WebRTC. \n  * Low CVE-2020-6530: Out of bounds memory access in developer tools. \n  * Low CVE-2020-6531: Side-channel information leakage in scroll to text. \n  * Low CVE-2020-6533: Type Confusion in V8. \n  * Low CVE-2020-6534: Heap buffer overflow in WebRTC. \n  * Low CVE-2020-6535: Insufficient data validation in WebUI. \n  * Low CVE-2020-6536: Incorrect security UI in PWAs.\n- Use bundled xcb-proto as we need to generate py2 bindings\n- Try to fix non-wayland build for Leap builds\n\nThis update was imported from the openSUSE:Leap:15.1:Update update project.","affected":[{"package":{"name":"chromium","ecosystem":"SUSE:Package Hub 15 SP1","purl":"pkg:rpm/suse/chromium&distro=SUSE%20Package%20Hub%2015%20SP1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"84.0.4147.89-bp151.3.94.1"}]}],"ecosystem_specific":{"binaries":[{"chromedriver":"84.0.4147.89-bp151.3.94.1","chromium":"84.0.4147.89-bp151.3.94.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2020:1061-1.json"}}],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/GONT67H2PPPIF3W6X5ZYIIS6IY5KH7EO/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1174189"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6510"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6511"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6512"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6513"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6514"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6515"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6516"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6517"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6518"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6519"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6520"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6521"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6522"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6523"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6524"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6525"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6526"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6527"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6528"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6529"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6530"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6531"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6533"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6534"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6535"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6536"}]}