{"schema_version":"1.7.3","id":"openSUSE-SU-2020:1705-1","published":"2020-10-22T05:51:33Z","modified":"2026-02-04T03:17:33.069356Z","related":["CVE-2020-15967","CVE-2020-15968","CVE-2020-15969","CVE-2020-15970","CVE-2020-15971","CVE-2020-15972","CVE-2020-15973","CVE-2020-15974","CVE-2020-15975","CVE-2020-15976","CVE-2020-15977","CVE-2020-15978","CVE-2020-15979","CVE-2020-15980","CVE-2020-15981","CVE-2020-15982","CVE-2020-15983","CVE-2020-15984","CVE-2020-15985","CVE-2020-15986","CVE-2020-15987","CVE-2020-15988","CVE-2020-15989","CVE-2020-15990","CVE-2020-15991","CVE-2020-15992","CVE-2020-6557"],"upstream":["CVE-2020-15967","CVE-2020-15968","CVE-2020-15969","CVE-2020-15970","CVE-2020-15971","CVE-2020-15972","CVE-2020-15973","CVE-2020-15974","CVE-2020-15975","CVE-2020-15976","CVE-2020-15977","CVE-2020-15978","CVE-2020-15979","CVE-2020-15980","CVE-2020-15981","CVE-2020-15982","CVE-2020-15983","CVE-2020-15984","CVE-2020-15985","CVE-2020-15986","CVE-2020-15987","CVE-2020-15988","CVE-2020-15989","CVE-2020-15990","CVE-2020-15991","CVE-2020-15992","CVE-2020-6557"],"summary":"Security update for chromium","details":"This update for chromium fixes the following issues:\n\n-chromium was updated to 86.0.4240.75 (boo#1177408):\n   - CVE-2020-15967: Fixed Use after free in payments.\n   - CVE-2020-15968: Fixed Use after free in Blink.\n   - CVE-2020-15969: Fixed Use after free in WebRTC. \n   - CVE-2020-15970: Fixed Use after free in NFC.\n   - CVE-2020-15971: Fixed Use after free in printing. \n   - CVE-2020-15972: Fixed Use after free in audio. \n   - CVE-2020-15990: Fixed Use after free in autofill. \n   - CVE-2020-15991: Fixed Use after free in password manager.\n   - CVE-2020-15973: Fixed Insufficient policy enforcement in extensions.\n   - CVE-2020-15974: Fixed Integer overflow in Blink. \n   - CVE-2020-15975: Fixed Integer overflow in SwiftShader. \n   - CVE-2020-15976: Fixed Use after free in WebXR. \n   - CVE-2020-6557: Fixed Inappropriate implementation in networking. \n   - CVE-2020-15977: Fixed Insufficient data validation in dialogs.\n   - CVE-2020-15978: Fixed Insufficient data validation in navigation.\n   - CVE-2020-15979: Fixed Inappropriate implementation in V8.\n   - CVE-2020-15980: Fixed Insufficient policy enforcement in Intents.\n   - CVE-2020-15981: Fixed Out of bounds read in audio. \n   - CVE-2020-15982: Fixed Side-channel information leakage in cache. \n   - CVE-2020-15983: Fixed Insufficient data validation in webUI.\n   - CVE-2020-15984: Fixed Insufficient policy enforcement in Omnibox. \n   - CVE-2020-15985: Fixed Inappropriate implementation in Blink. \n   - CVE-2020-15986: Fixed Integer overflow in media. \n   - CVE-2020-15987: Fixed Use after free in WebRTC. \n   - CVE-2020-15992: Fixed Insufficient policy enforcement in networking. \n   - CVE-2020-15988: Fixed Insufficient policy enforcement in downloads.\n   - CVE-2020-15989: Fixed Uninitialized Use in PDFium. \n\n","affected":[{"package":{"name":"chromium","ecosystem":"openSUSE:Leap 15.1","purl":"pkg:rpm/opensuse/chromium&distro=openSUSE%20Leap%2015.1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"86.0.4240.75-lp152.2.39.1"}]}],"ecosystem_specific":{"binaries":[{"chromedriver":"86.0.4240.75-lp152.2.39.1","chromium":"86.0.4240.75-lp152.2.39.1","gn":"0.1807-lp152.2.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2020:1705-1.json"}},{"package":{"name":"gn","ecosystem":"openSUSE:Leap 15.1","purl":"pkg:rpm/opensuse/gn&distro=openSUSE%20Leap%2015.1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.1807-lp152.2.3.1"}]}],"ecosystem_specific":{"binaries":[{"chromedriver":"86.0.4240.75-lp152.2.39.1","chromium":"86.0.4240.75-lp152.2.39.1","gn":"0.1807-lp152.2.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2020:1705-1.json"}},{"package":{"name":"chromium","ecosystem":"openSUSE:Leap 15.2","purl":"pkg:rpm/opensuse/chromium&distro=openSUSE%20Leap%2015.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"86.0.4240.75-lp152.2.39.1"}]}],"ecosystem_specific":{"binaries":[{"chromedriver":"86.0.4240.75-lp152.2.39.1","chromium":"86.0.4240.75-lp152.2.39.1","gn":"0.1807-lp152.2.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2020:1705-1.json"}},{"package":{"name":"gn","ecosystem":"openSUSE:Leap 15.2","purl":"pkg:rpm/opensuse/gn&distro=openSUSE%20Leap%2015.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.1807-lp152.2.3.1"}]}],"ecosystem_specific":{"binaries":[{"chromedriver":"86.0.4240.75-lp152.2.39.1","chromium":"86.0.4240.75-lp152.2.39.1","gn":"0.1807-lp152.2.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2020:1705-1.json"}}],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/RSRYM5HZR7DJFCM4PTV3322SCZDBNVEX/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1177408"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15967"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15968"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15969"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15970"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15971"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15972"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15973"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15974"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15975"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15976"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15977"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15978"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15979"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15980"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15981"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15982"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15983"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15984"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15985"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15986"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15987"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15988"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15989"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15990"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15991"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15992"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6557"}]}