{"id":"openSUSE-SU-2020:1715-1","summary":"Security update for chromium","details":"This update for chromium fixes the following issues:\n\n-chromium was updated to 86.0.4240.75 (boo#1177408):\n   - CVE-2020-15967: Fixed Use after free in payments.\n   - CVE-2020-15968: Fixed Use after free in Blink.\n   - CVE-2020-15969: Fixed Use after free in WebRTC. \n   - CVE-2020-15970: Fixed Use after free in NFC.\n   - CVE-2020-15971: Fixed Use after free in printing. \n   - CVE-2020-15972: Fixed Use after free in audio. \n   - CVE-2020-15990: Fixed Use after free in autofill. \n   - CVE-2020-15991: Fixed Use after free in password manager.\n   - CVE-2020-15973: Fixed Insufficient policy enforcement in extensions.\n   - CVE-2020-15974: Fixed Integer overflow in Blink. \n   - CVE-2020-15975: Fixed Integer overflow in SwiftShader. \n   - CVE-2020-15976: Fixed Use after free in WebXR. \n   - CVE-2020-6557: Fixed Inappropriate implementation in networking. \n   - CVE-2020-15977: Fixed Insufficient data validation in dialogs.\n   - CVE-2020-15978: Fixed Insufficient data validation in navigation.\n   - CVE-2020-15979: Fixed Inappropriate implementation in V8.\n   - CVE-2020-15980: Fixed Insufficient policy enforcement in Intents.\n   - CVE-2020-15981: Fixed Out of bounds read in audio. \n   - CVE-2020-15982: Fixed Side-channel information leakage in cache. \n   - CVE-2020-15983: Fixed Insufficient data validation in webUI.\n   - CVE-2020-15984: Fixed Insufficient policy enforcement in Omnibox. \n   - CVE-2020-15985: Fixed Inappropriate implementation in Blink. \n   - CVE-2020-15986: Fixed Integer overflow in media. \n   - CVE-2020-15987: Fixed Use after free in WebRTC. \n   - CVE-2020-15992: Fixed Insufficient policy enforcement in networking. \n   - CVE-2020-15988: Fixed Insufficient policy enforcement in downloads.\n   - CVE-2020-15989: Fixed Uninitialized Use in PDFium. \n\n\nThis update was imported from the openSUSE:Leap:15.1:Update update project.","modified":"2026-03-11T07:32:42.608670Z","published":"2020-10-23T12:21:50Z","related":["CVE-2020-15967","CVE-2020-15968","CVE-2020-15969","CVE-2020-15970","CVE-2020-15971","CVE-2020-15972","CVE-2020-15973","CVE-2020-15974","CVE-2020-15975","CVE-2020-15976","CVE-2020-15977","CVE-2020-15978","CVE-2020-15979","CVE-2020-15980","CVE-2020-15981","CVE-2020-15982","CVE-2020-15983","CVE-2020-15984","CVE-2020-15985","CVE-2020-15986","CVE-2020-15987","CVE-2020-15988","CVE-2020-15989","CVE-2020-15990","CVE-2020-15991","CVE-2020-15992","CVE-2020-6557"],"upstream":["CVE-2020-15967","CVE-2020-15968","CVE-2020-15969","CVE-2020-15970","CVE-2020-15971","CVE-2020-15972","CVE-2020-15973","CVE-2020-15974","CVE-2020-15975","CVE-2020-15976","CVE-2020-15977","CVE-2020-15978","CVE-2020-15979","CVE-2020-15980","CVE-2020-15981","CVE-2020-15982","CVE-2020-15983","CVE-2020-15984","CVE-2020-15985","CVE-2020-15986","CVE-2020-15987","CVE-2020-15988","CVE-2020-15989","CVE-2020-15990","CVE-2020-15991","CVE-2020-15992","CVE-2020-6557"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/7SPENP4DSO2RHCGDP36WTNMPXQSGB2TO/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1177408"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15967"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15968"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15969"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15970"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15971"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15972"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15973"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15974"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15975"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15976"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15977"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15978"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15979"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15980"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15981"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15982"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15983"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15984"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15985"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15986"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15987"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15988"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15989"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15990"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15991"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15992"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6557"}],"affected":[{"package":{"name":"chromium","ecosystem":"SUSE:Package Hub 15 SP1","purl":"pkg:rpm/suse/chromium&distro=SUSE%20Package%20Hub%2015%20SP1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"86.0.4240.75-bp151.3.113.1"}]}],"ecosystem_specific":{"binaries":[{"chromedriver":"86.0.4240.75-bp151.3.113.1","chromium":"86.0.4240.75-bp151.3.113.1","gn":"0.1807-bp151.3.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2020:1715-1.json"}},{"package":{"name":"gn","ecosystem":"SUSE:Package Hub 15 SP1","purl":"pkg:rpm/suse/gn&distro=SUSE%20Package%20Hub%2015%20SP1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.1807-bp151.3.6.1"}]}],"ecosystem_specific":{"binaries":[{"chromedriver":"86.0.4240.75-bp151.3.113.1","chromium":"86.0.4240.75-bp151.3.113.1","gn":"0.1807-bp151.3.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2020:1715-1.json"}}],"schema_version":"1.7.5"}