{"id":"openSUSE-SU-2018:1175-1","summary":"Security update for Chromium","details":"This update for Chromium to version 66.0.3359.181 fixes the following issues:\n\n- CVE-2018-6118: Use after free in Media Cache (bsc#1091288)\n- CVE-2018-6085: Use after free in Disk Cache\n- CVE-2018-6086: Use after free in Disk Cache\n- CVE-2018-6087: Use after free in WebAssembly\n- CVE-2018-6088: Use after free in PDFium\n- CVE-2018-6089: Same origin policy bypass in Service Worker\n- CVE-2018-6090: Heap buffer overflow in Skia\n- CVE-2018-6091: Incorrect handling of plug-ins by Service Worker\n- CVE-2018-6092: Integer overflow in WebAssembly\n- CVE-2018-6093: Same origin bypass in Service Worker\n- CVE-2018-6094: Exploit hardening regression in Oilpan\n- CVE-2018-6095: Lack of meaningful user interaction requirement before file upload\n- CVE-2018-6096: Fullscreen UI spoof\n- CVE-2018-6097: Fullscreen UI spoof\n- CVE-2018-6098: URL spoof in Omnibox\n- CVE-2018-6099: CORS bypass in ServiceWorker\n- CVE-2018-6100: URL spoof in Omnibox\n- CVE-2018-6101: Insufficient protection of remote debugging prototol in DevTools \n- CVE-2018-6102: URL spoof in Omnibox\n- CVE-2018-6103: UI spoof in Permissions\n- CVE-2018-6104: URL spoof in Omnibox\n- CVE-2018-6105: URL spoof in Omnibox\n- CVE-2018-6106: Incorrect handling of promises in V8\n- CVE-2018-6107: URL spoof in Omnibox\n- CVE-2018-6108: URL spoof in Omnibox\n- CVE-2018-6109: Incorrect handling of files by FileAPI\n- CVE-2018-6110: Incorrect handling of plaintext files via file:// \n- CVE-2018-6111: Heap-use-after-free in DevTools\n- CVE-2018-6112: Incorrect URL handling in DevTools\n- CVE-2018-6113: URL spoof in Navigation\n- CVE-2018-6114: CSP bypass\n- CVE-2018-6115: SmartScreen bypass in downloads\n- CVE-2018-6116: Incorrect low memory handling in WebAssembly\n- CVE-2018-6117: Confusing autofill settings\n- CVE-2017-11215: Use after free in Flash\n- CVE-2017-11225: Use after free in Flash\n- CVE-2018-6060: Use after free in Blink\n- CVE-2018-6061: Race condition in V8\n- CVE-2018-6062: Heap buffer overflow in Skia\n- CVE-2018-6057: Incorrect permissions on shared memory\n- CVE-2018-6063: Incorrect permissions on shared memory\n- CVE-2018-6064: Type confusion in V8\n- CVE-2018-6065: Integer overflow in V8\n- CVE-2018-6066: Same Origin Bypass via canvas\n- CVE-2018-6067: Buffer overflow in Skia\n- CVE-2018-6068: Object lifecycle issues in Chrome Custom Tab\n- CVE-2018-6069: Stack buffer overflow in Skia\n- CVE-2018-6070: CSP bypass through extensions\n- CVE-2018-6071: Heap bufffer overflow in Skia\n- CVE-2018-6072: Integer overflow in PDFium\n- CVE-2018-6073: Heap bufffer overflow in WebGL\n- CVE-2018-6074: Mark-of-the-Web bypass\n- CVE-2018-6075: Overly permissive cross origin downloads\n- CVE-2018-6076: Incorrect handling of URL fragment identifiers in Blink\n- CVE-2018-6077: Timing attack using SVG filters\n- CVE-2018-6078: URL Spoof in OmniBox\n- CVE-2018-6079: Information disclosure via texture data in WebGL\n- CVE-2018-6080: Information disclosure in IPC call\n- CVE-2018-6081: XSS in interstitials\n- CVE-2018-6082: Circumvention of port blocking\n- CVE-2018-6083: Incorrect processing of AppManifests\n- CVE-2018-6121: Privilege Escalation in extensions\n- CVE-2018-6122: Type confusion in V8\n- CVE-2018-6120: Heap buffer overflow in PDFium    \n- bsc#1086124: Various fixes from internal audits, fuzzing and other initiatives\n\nThis update also supports mitigation against the Spectre vulnerabilities:\n\n'Strict site isolation' is disabled for most users and can be turned on via:\nchrome://flags/#enable-site-per-process\n\nThis feature is undergoing a small percentage trial. Out out of the trial is possible via:\nchrome://flags/#site-isolation-trial-opt-out\n\n    \nThe following tracked packaging bug were fixed:\n\n- Chromium could not be installed from SUSE PackageHub 12 without having the SDK enabled (bsc#1070421)\n- Chromium could not be installed when libminizip1 was not available (bsc#1093031)\n","modified":"2026-02-04T04:28:52.540012Z","published":"2018-05-27T11:26:33Z","related":["CVE-2017-11215","CVE-2017-11225","CVE-2018-6057","CVE-2018-6060","CVE-2018-6061","CVE-2018-6062","CVE-2018-6063","CVE-2018-6064","CVE-2018-6065","CVE-2018-6066","CVE-2018-6067","CVE-2018-6068","CVE-2018-6069","CVE-2018-6070","CVE-2018-6071","CVE-2018-6072","CVE-2018-6073","CVE-2018-6074","CVE-2018-6075","CVE-2018-6076","CVE-2018-6077","CVE-2018-6078","CVE-2018-6079","CVE-2018-6080","CVE-2018-6081","CVE-2018-6082","CVE-2018-6083","CVE-2018-6085","CVE-2018-6086","CVE-2018-6087","CVE-2018-6088","CVE-2018-6089","CVE-2018-6090","CVE-2018-6091","CVE-2018-6092","CVE-2018-6093","CVE-2018-6094","CVE-2018-6095","CVE-2018-6096","CVE-2018-6097","CVE-2018-6098","CVE-2018-6099","CVE-2018-6100","CVE-2018-6101","CVE-2018-6102","CVE-2018-6103","CVE-2018-6104","CVE-2018-6105","CVE-2018-6106","CVE-2018-6107","CVE-2018-6108","CVE-2018-6109","CVE-2018-6110","CVE-2018-6111","CVE-2018-6112","CVE-2018-6113","CVE-2018-6114","CVE-2018-6115","CVE-2018-6116","CVE-2018-6117","CVE-2018-6118","CVE-2018-6120","CVE-2018-6121","CVE-2018-6122"],"upstream":["CVE-2017-11215","CVE-2017-11225","CVE-2018-6057","CVE-2018-6060","CVE-2018-6061","CVE-2018-6062","CVE-2018-6063","CVE-2018-6064","CVE-2018-6065","CVE-2018-6066","CVE-2018-6067","CVE-2018-6068","CVE-2018-6069","CVE-2018-6070","CVE-2018-6071","CVE-2018-6072","CVE-2018-6073","CVE-2018-6074","CVE-2018-6075","CVE-2018-6076","CVE-2018-6077","CVE-2018-6078","CVE-2018-6079","CVE-2018-6080","CVE-2018-6081","CVE-2018-6082","CVE-2018-6083","CVE-2018-6085","CVE-2018-6086","CVE-2018-6087","CVE-2018-6088","CVE-2018-6089","CVE-2018-6090","CVE-2018-6091","CVE-2018-6092","CVE-2018-6093","CVE-2018-6094","CVE-2018-6095","CVE-2018-6096","CVE-2018-6097","CVE-2018-6098","CVE-2018-6099","CVE-2018-6100","CVE-2018-6101","CVE-2018-6102","CVE-2018-6103","CVE-2018-6104","CVE-2018-6105","CVE-2018-6106","CVE-2018-6107","CVE-2018-6108","CVE-2018-6109","CVE-2018-6110","CVE-2018-6111","CVE-2018-6112","CVE-2018-6113","CVE-2018-6114","CVE-2018-6115","CVE-2018-6116","CVE-2018-6117","CVE-2018-6118","CVE-2018-6120","CVE-2018-6121","CVE-2018-6122"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IDH7ZAFKSWX2J7H7ULZFAVM7KUQXQHZZ/#IDH7ZAFKSWX2J7H7ULZFAVM7KUQXQHZZ"},{"type":"REPORT","url":"https://bugzilla.suse.com/1084296"},{"type":"REPORT","url":"https://bugzilla.suse.com/1086124"},{"type":"REPORT","url":"https://bugzilla.suse.com/1090000"},{"type":"REPORT","url":"https://bugzilla.suse.com/1091288"},{"type":"REPORT","url":"https://bugzilla.suse.com/1092272"},{"type":"REPORT","url":"https://bugzilla.suse.com/1092923"},{"type":"REPORT","url":"https://bugzilla.suse.com/1093031"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-11215"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-11225"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6057"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6060"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6061"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6062"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6063"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6064"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6065"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6066"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6067"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6068"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6069"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6070"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6071"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6072"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6073"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6074"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6075"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6076"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6077"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6078"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6079"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6080"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6081"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6082"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6083"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6085"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6086"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6087"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6088"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6089"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6090"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6091"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6092"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6093"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6094"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6095"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6096"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6097"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6098"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6099"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6100"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6101"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6102"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6103"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6104"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6105"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6106"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6107"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6108"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6109"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6110"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6111"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6112"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6113"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6114"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6115"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6116"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6117"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6118"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6120"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6121"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6122"}],"affected":[{"package":{"name":"chromium","ecosystem":"SUSE:Package Hub 12 SP2","purl":"pkg:rpm/suse/chromium&distro=SUSE%20Package%20Hub%2012%20SP2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"66.0.3359.181-55.1"}]}],"ecosystem_specific":{"binaries":[{"chromedriver":"66.0.3359.181-55.1","chromium":"66.0.3359.181-55.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2018:1175-1.json"}}],"schema_version":"1.7.3"}