{"schema_version":"1.7.3","id":"openSUSE-SU-2023:0068-1","published":"2023-03-13T17:04:22Z","modified":"2026-02-04T02:41:17.456556Z","related":["CVE-2023-1213","CVE-2023-1214","CVE-2023-1215","CVE-2023-1216","CVE-2023-1217","CVE-2023-1218","CVE-2023-1219","CVE-2023-1220","CVE-2023-1221","CVE-2023-1222","CVE-2023-1223","CVE-2023-1224","CVE-2023-1225","CVE-2023-1226","CVE-2023-1227","CVE-2023-1228","CVE-2023-1229","CVE-2023-1230","CVE-2023-1231","CVE-2023-1232","CVE-2023-1233","CVE-2023-1234","CVE-2023-1235","CVE-2023-1236"],"upstream":["CVE-2023-1213","CVE-2023-1214","CVE-2023-1215","CVE-2023-1216","CVE-2023-1217","CVE-2023-1218","CVE-2023-1219","CVE-2023-1220","CVE-2023-1221","CVE-2023-1222","CVE-2023-1223","CVE-2023-1224","CVE-2023-1225","CVE-2023-1226","CVE-2023-1227","CVE-2023-1228","CVE-2023-1229","CVE-2023-1230","CVE-2023-1231","CVE-2023-1232","CVE-2023-1233","CVE-2023-1234","CVE-2023-1235","CVE-2023-1236"],"summary":"Security update for chromium","details":"This update for chromium fixes the following issues:\n\nChromium 111.0.5563.64\n\n* New View Transitions API\n* CSS Color Level 4\n* New developer tools in style panel for color functionality\n* CSS added trigonometric functions, additional root font units\n  and extended the n-th child pseudo selector.\n* previousslide and nextslide actions are now part of the Media\n  Session API\n* A number of security fixes (boo#1209040)\n* CVE-2023-1213: Use after free in Swiftshader\n* CVE-2023-1214: Type Confusion in V8\n* CVE-2023-1215: Type Confusion in CSS\n* CVE-2023-1216: Use after free in DevTools\n* CVE-2023-1217: Stack buffer overflow in Crash reporting\n* CVE-2023-1218: Use after free in WebRTC\n* CVE-2023-1219: Heap buffer overflow in Metrics\n* CVE-2023-1220: Heap buffer overflow in UMA\n* CVE-2023-1221: Insufficient policy enforcement in Extensions API\n* CVE-2023-1222: Heap buffer overflow in Web Audio API\n* CVE-2023-1223: Insufficient policy enforcement in Autofill\n* CVE-2023-1224: Insufficient policy enforcement in Web Payments API\n* CVE-2023-1225: Insufficient policy enforcement in Navigation\n* CVE-2023-1226: Insufficient policy enforcement in Web Payments API\n* CVE-2023-1227: Use after free in Core\n* CVE-2023-1228: Insufficient policy enforcement in Intents\n* CVE-2023-1229: Inappropriate implementation in Permission prompts\n* CVE-2023-1230: Inappropriate implementation in WebApp Installs\n* CVE-2023-1231: Inappropriate implementation in Autofill\n* CVE-2023-1232: Insufficient policy enforcement in Resource Timing\n* CVE-2023-1233: Insufficient policy enforcement in Resource Timing\n* CVE-2023-1234: Inappropriate implementation in Intents\n* CVE-2023-1235: Type Confusion in DevTools\n* CVE-2023-1236: Inappropriate implementation in Internals\n","affected":[{"package":{"name":"chromium","ecosystem":"SUSE:Package Hub 15 SP4","purl":"pkg:rpm/suse/chromium&distro=SUSE%20Package%20Hub%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"111.0.5563.64-bp154.2.73.1"}]}],"ecosystem_specific":{"binaries":[{"chromedriver":"111.0.5563.64-bp154.2.73.1","chromium":"111.0.5563.64-bp154.2.73.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2023:0068-1.json"}},{"package":{"name":"chromium","ecosystem":"openSUSE:Leap 15.4","purl":"pkg:rpm/opensuse/chromium&distro=openSUSE%20Leap%2015.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"111.0.5563.64-bp154.2.73.1"}]}],"ecosystem_specific":{"binaries":[{"chromedriver":"111.0.5563.64-bp154.2.73.1","chromium":"111.0.5563.64-bp154.2.73.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2023:0068-1.json"}}],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/E4USJJ6HOC5UIZQM6PHWKEVPCFAFN3DO/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1209040"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-1213"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-1214"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-1215"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-1216"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-1217"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-1218"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-1219"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-1220"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-1221"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-1222"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-1223"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-1224"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-1225"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-1226"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-1227"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-1228"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-1229"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-1230"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-1231"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-1232"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-1233"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-1234"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-1235"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-1236"}]}