{"id":"openSUSE-SU-2017:2491-1","summary":"Security update for chromium","details":"This update for chromium to version 61.0.3163.79 fixes several issues.\n\nThese security issues were fixed:\n\n- CVE-2017-5111: Use after free in PDFium (boo#1057364).\n- CVE-2017-5112: Heap buffer overflow in WebGL (boo#1057364).\n- CVE-2017-5113: Heap buffer overflow in Skia (boo#1057364).\n- CVE-2017-5114: Memory lifecycle issue in PDFium (boo#1057364).\n- CVE-2017-5115: Type confusion in V8 (boo#1057364).\n- CVE-2017-5116: Type confusion in V8 (boo#1057364).\n- CVE-2017-5117: Use of uninitialized value in Skia (boo#1057364).\n- CVE-2017-5118: Bypass of Content Security Policy in Blink (boo#1057364).\n- CVE-2017-5119: Use of uninitialized value in Skia (boo#1057364).\n- CVE-2017-5120: Potential HTTPS downgrade during redirect navigation (boo#1057364).\n","modified":"2026-02-04T04:22:17.562810Z","published":"2017-09-15T05:01:20Z","related":["CVE-2017-5111","CVE-2017-5112","CVE-2017-5113","CVE-2017-5114","CVE-2017-5115","CVE-2017-5116","CVE-2017-5117","CVE-2017-5118","CVE-2017-5119","CVE-2017-5120"],"upstream":["CVE-2017-5111","CVE-2017-5112","CVE-2017-5113","CVE-2017-5114","CVE-2017-5115","CVE-2017-5116","CVE-2017-5117","CVE-2017-5118","CVE-2017-5119","CVE-2017-5120"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CDWPUMSRWJRK7J7W6UQFDY22B2GKD3AO/#CDWPUMSRWJRK7J7W6UQFDY22B2GKD3AO"},{"type":"REPORT","url":"https://bugzilla.suse.com/1057364"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-5111"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-5112"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-5113"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-5114"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-5115"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-5116"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-5117"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-5118"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-5119"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-5120"}],"affected":[{"package":{"name":"chromium","ecosystem":"SUSE:Package Hub 12 SP2","purl":"pkg:rpm/suse/chromium&distro=SUSE%20Package%20Hub%2012%20SP2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"61.0.3163.79-29.1"}]}],"ecosystem_specific":{"binaries":[{"chromedriver":"61.0.3163.79-29.1","chromium":"61.0.3163.79-29.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2017:2491-1.json"}}],"schema_version":"1.7.3"}