{"id":"openSUSE-SU-2020:0832-1","summary":"Security update for chromium","details":"This update for chromium fixes the following issues:\n\nChromium was updated to 83.0.4103.97 (boo#1171910,bsc#1172496):\n\n* CVE-2020-6463: Use after free in ANGLE (boo#1170107 boo#1171975).\n* CVE-2020-6465: Use after free in reader mode. Reported by Woojin Oh(@pwn_expoit) of STEALIEN on 2020-04-21\n* CVE-2020-6466: Use after free in media. Reported by Zhe Jin from cdsrc of Qihoo 360 on 2020-04-26\n* CVE-2020-6467: Use after free in WebRTC. Reported by ZhanJia Song on 2020-04-06\n* CVE-2020-6468: Type Confusion in V8. Reported by Chris Salls and Jake Corina of Seaside Security, Chani Jindal of Shellphish on 2020-04-30\n* CVE-2020-6469: Insufficient policy enforcement in developer tools. Reported by David Erceg on 2020-04-02\n* CVE-2020-6470: Insufficient validation of untrusted input in clipboard. Reported by Michał Bentkowski of Securitum on 2020-03-30\n* CVE-2020-6471: Insufficient policy enforcement in developer tools. Reported by David Erceg on 2020-03-08\n* CVE-2020-6472: Insufficient policy enforcement in developer tools. Reported by David Erceg on 2020-03-25\n* CVE-2020-6473: Insufficient policy enforcement in Blink. Reported by Soroush Karami and Panagiotis Ilia on 2020-02-06\n* CVE-2020-6474: Use after free in Blink. Reported by Zhe Jin from cdsrc of Qihoo 360 on 2020-03-07\n* CVE-2020-6475: Incorrect security UI in full screen. Reported by Khalil Zhani on 2019-10-31\n* CVE-2020-6476: Insufficient policy enforcement in tab strip. Reported by Alexandre Le Borgne on 2019-12-18\n* CVE-2020-6477: Inappropriate implementation in installer. Reported by RACK911 Labs on 2019-03-26\n* CVE-2020-6478: Inappropriate implementation in full screen. Reported by Khalil Zhani on 2019-12-24\n* CVE-2020-6479: Inappropriate implementation in sharing. Reported by Zhong Zhaochen of andsecurity.cn on 2020-01-14\n* CVE-2020-6480: Insufficient policy enforcement in enterprise. Reported by Marvin Witt on 2020-02-21\n* CVE-2020-6481: Insufficient policy enforcement in URL formatting. Reported by Rayyan Bijoora on 2020-04-07\n* CVE-2020-6482: Insufficient policy enforcement in developer tools. Reported by Abdulrahman Alqabandi (@qab) on 2017-12-17\n* CVE-2020-6483: Insufficient policy enforcement in payments. Reported by Jun Kokatsu, Microsoft Browser Vulnerability Research on 2019-05-23\n* CVE-2020-6484: Insufficient data validation in ChromeDriver. Reported by Artem Zinenko on 2020-01-26\n* CVE-2020-6485: Insufficient data validation in media router. Reported by Sergei Glazunov of Google Project Zero on 2020-01-30\n* CVE-2020-6486: Insufficient policy enforcement in navigations. Reported by David Erceg on 2020-02-24\n* CVE-2020-6487: Insufficient policy enforcement in downloads. Reported by Jun Kokatsu (@shhnjk) on 2015-10-06\n* CVE-2020-6488: Insufficient policy enforcement in downloads. Reported by David Erceg on 2020-01-21\n* CVE-2020-6489: Inappropriate implementation in developer tools. Reported by @lovasoa (Ophir LOJKINE) on 2020-02-10\n* CVE-2020-6490: Insufficient data validation in loader. Reported by Twitter on 2019-12-19\n* CVE-2020-6491: Incorrect security UI in site information. Reported by Sultan Haikal M.A on 2020-02-07\n* CVE-2020-6493: Use after free in WebAuthentication.\n* CVE-2020-6494: Incorrect security UI in payments.\n* CVE-2020-6495: Insufficient policy enforcement in developer tools.\n* CVE-2020-6496: Use after free in payments.\n\n\nThis update was imported from the openSUSE:Leap:15.1:Update update project.","modified":"2026-02-04T02:57:22.054537Z","published":"2020-06-18T16:17:43Z","related":["CVE-2020-6463","CVE-2020-6465","CVE-2020-6466","CVE-2020-6467","CVE-2020-6468","CVE-2020-6469","CVE-2020-6470","CVE-2020-6471","CVE-2020-6472","CVE-2020-6473","CVE-2020-6474","CVE-2020-6475","CVE-2020-6476","CVE-2020-6477","CVE-2020-6478","CVE-2020-6479","CVE-2020-6480","CVE-2020-6481","CVE-2020-6482","CVE-2020-6483","CVE-2020-6484","CVE-2020-6485","CVE-2020-6486","CVE-2020-6487","CVE-2020-6488","CVE-2020-6489","CVE-2020-6490","CVE-2020-6491","CVE-2020-6493","CVE-2020-6494","CVE-2020-6495","CVE-2020-6496"],"upstream":["CVE-2020-6463","CVE-2020-6465","CVE-2020-6466","CVE-2020-6467","CVE-2020-6468","CVE-2020-6469","CVE-2020-6470","CVE-2020-6471","CVE-2020-6472","CVE-2020-6473","CVE-2020-6474","CVE-2020-6475","CVE-2020-6476","CVE-2020-6477","CVE-2020-6478","CVE-2020-6479","CVE-2020-6480","CVE-2020-6481","CVE-2020-6482","CVE-2020-6483","CVE-2020-6484","CVE-2020-6485","CVE-2020-6486","CVE-2020-6487","CVE-2020-6488","CVE-2020-6489","CVE-2020-6490","CVE-2020-6491","CVE-2020-6493","CVE-2020-6494","CVE-2020-6495","CVE-2020-6496"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/LHJICQXQ63XG4HH3O4IEPJYNQJNP2NVV/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1170107"},{"type":"REPORT","url":"https://bugzilla.suse.com/1171910"},{"type":"REPORT","url":"https://bugzilla.suse.com/1171975"},{"type":"REPORT","url":"https://bugzilla.suse.com/1172496"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6463"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6465"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6466"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6467"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6468"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6469"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6470"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6471"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6472"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6473"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6474"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6475"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6476"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6477"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6478"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6479"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6480"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6481"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6482"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6483"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6484"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6485"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6486"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6487"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6488"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6489"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6490"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6491"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6493"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6494"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6495"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6496"}],"affected":[{"package":{"name":"chromium","ecosystem":"SUSE:Package Hub 15 SP1","purl":"pkg:rpm/suse/chromium&distro=SUSE%20Package%20Hub%2015%20SP1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"83.0.4103.97-bp151.3.85.1"}]}],"ecosystem_specific":{"binaries":[{"chromedriver":"83.0.4103.97-bp151.3.85.1","chromium":"83.0.4103.97-bp151.3.85.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2020:0832-1.json"}}],"schema_version":"1.7.3"}