{"schema_version":"1.7.3","id":"openSUSE-SU-2020:1021-1","published":"2020-07-20T14:27:17Z","modified":"2026-02-04T03:42:49.694372Z","related":["CVE-2020-6510","CVE-2020-6511","CVE-2020-6512","CVE-2020-6513","CVE-2020-6514","CVE-2020-6515","CVE-2020-6516","CVE-2020-6517","CVE-2020-6518","CVE-2020-6519","CVE-2020-6520","CVE-2020-6521","CVE-2020-6522","CVE-2020-6523","CVE-2020-6524","CVE-2020-6525","CVE-2020-6526","CVE-2020-6527","CVE-2020-6528","CVE-2020-6529","CVE-2020-6530","CVE-2020-6531","CVE-2020-6533","CVE-2020-6534","CVE-2020-6535","CVE-2020-6536"],"upstream":["CVE-2020-6510","CVE-2020-6511","CVE-2020-6512","CVE-2020-6513","CVE-2020-6514","CVE-2020-6515","CVE-2020-6516","CVE-2020-6517","CVE-2020-6518","CVE-2020-6519","CVE-2020-6520","CVE-2020-6521","CVE-2020-6522","CVE-2020-6523","CVE-2020-6524","CVE-2020-6525","CVE-2020-6526","CVE-2020-6527","CVE-2020-6528","CVE-2020-6529","CVE-2020-6530","CVE-2020-6531","CVE-2020-6533","CVE-2020-6534","CVE-2020-6535","CVE-2020-6536"],"summary":"Security update for chromium","details":"This update for chromium fixes the following issues:\n\n- Update to 84.0.4147.89 boo#1174189:\n  * Critical CVE-2020-6510: Heap buffer overflow in background fetch. \n  * High CVE-2020-6511: Side-channel information leakage in content security policy. \n  * High CVE-2020-6512: Type Confusion in V8. \n  * High CVE-2020-6513: Heap buffer overflow in PDFium. \n  * High CVE-2020-6514: Inappropriate implementation in WebRTC. \n  * High CVE-2020-6515: Use after free in tab strip. \n  * High CVE-2020-6516: Policy bypass in CORS. \n  * High CVE-2020-6517: Heap buffer overflow in history. \n  * Medium CVE-2020-6518: Use after free in developer tools. \n  * Medium CVE-2020-6519: Policy bypass in CSP. \n  * Medium CVE-2020-6520: Heap buffer overflow in Skia. \n  * Medium CVE-2020-6521: Side-channel information leakage in autofill.\n  * Medium CVE-2020-6522: Inappropriate implementation in external protocol handlers. \n  * Medium CVE-2020-6523: Out of bounds write in Skia. \n  * Medium CVE-2020-6524: Heap buffer overflow in WebAudio. \n  * Medium CVE-2020-6525: Heap buffer overflow in Skia. \n  * Low CVE-2020-6526: Inappropriate implementation in iframe sandbox. \n  * Low CVE-2020-6527: Insufficient policy enforcement in CSP. \n  * Low CVE-2020-6528: Incorrect security UI in basic auth. \n  * Low CVE-2020-6529: Inappropriate implementation in WebRTC. \n  * Low CVE-2020-6530: Out of bounds memory access in developer tools. \n  * Low CVE-2020-6531: Side-channel information leakage in scroll to text. \n  * Low CVE-2020-6533: Type Confusion in V8. \n  * Low CVE-2020-6534: Heap buffer overflow in WebRTC. \n  * Low CVE-2020-6535: Insufficient data validation in WebUI. \n  * Low CVE-2020-6536: Incorrect security UI in PWAs.\n- Use bundled xcb-proto as we need to generate py2 bindings\n- Try to fix non-wayland build for Leap builds\n","affected":[{"package":{"name":"chromium","ecosystem":"openSUSE:Leap 15.1","purl":"pkg:rpm/opensuse/chromium&distro=openSUSE%20Leap%2015.1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"84.0.4147.89-lp151.2.109.1"}]}],"ecosystem_specific":{"binaries":[{"chromedriver":"84.0.4147.89-lp151.2.109.1","chromium":"84.0.4147.89-lp151.2.109.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2020:1021-1.json"}}],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/Q55W7KZFLR3UGN4DZTG2DV3E64K6CNP6/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1174189"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6510"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6511"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6512"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6513"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6514"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6515"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6516"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6517"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6518"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6519"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6520"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6521"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6522"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6523"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6524"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6525"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6526"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6527"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6528"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6529"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6530"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6531"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6533"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6534"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6535"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6536"}]}