{"id":"openSUSE-SU-2020:0389-1","summary":"Security update for chromium","details":"This update for chromium to version 80.0.3987.149 fixes the following issues:\n\nChromium was update to 80.0.3987.149 (bsc#1167090):\n\n- CVE-2020-6422: Fixed a use after free in WebGL. \n- CVE-2020-6424: Fixed a use after free in media. \n- CVE-2020-6425: Fixed an insufficient policy enforcement in extensions. \n- CVE-2020-6426: Fixed an inappropriate implementation in V8. \n- CVE-2020-6427: Fixed a use after free in audio. \n- CVE-2020-6428: Fixed a use after free in audio. \n- CVE-2020-6429: Fixed a use after free in audio. \n- CVE-2019-20503: Fixed an out of bounds read in usersctplib.\n- CVE-2020-6449: Fixed a use after free in audio. \n\nThis update was imported from the openSUSE:Leap:15.1:Update update project.","modified":"2026-02-04T04:31:22.579456Z","published":"2020-03-27T05:20:53Z","related":["CVE-2019-20503","CVE-2020-6422","CVE-2020-6424","CVE-2020-6425","CVE-2020-6426","CVE-2020-6427","CVE-2020-6428","CVE-2020-6429","CVE-2020-6449"],"upstream":["CVE-2019-20503","CVE-2020-6422","CVE-2020-6424","CVE-2020-6425","CVE-2020-6426","CVE-2020-6427","CVE-2020-6428","CVE-2020-6429","CVE-2020-6449"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/WW3SNSMEGRDYQ4Y6PCVLKAPOLTCQF2FP/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1167090"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-20503"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6422"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6424"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6425"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6426"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6427"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6428"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6429"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6449"}],"affected":[{"package":{"name":"chromium","ecosystem":"SUSE:Package Hub 15 SP1","purl":"pkg:rpm/suse/chromium&distro=SUSE%20Package%20Hub%2015%20SP1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"80.0.3987.149-bp151.3.63.3"}]}],"ecosystem_specific":{"binaries":[{"chromedriver":"80.0.3987.149-bp151.3.63.3","chromium":"80.0.3987.149-bp151.3.63.3"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2020:0389-1.json"}}],"schema_version":"1.7.3"}