Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.851374
Kategorie:SuSE Local Security Checks
Titel:openSUSE: Security Advisory for Chromium (openSUSE-SU-2016:1918-1)
Zusammenfassung:The remote host is missing an update for the 'Chromium'; package(s) announced via the referenced advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'Chromium'
package(s) announced via the referenced advisory.

Vulnerability Insight:
Chromium was updated to 52.0.2743.82 to fix the following security issues
(boo#989901):

- CVE-2016-1706: Sandbox escape in PPAPI

- CVE-2016-1707: URL spoofing on iOS

- CVE-2016-1708: Use-after-free in Extensions

- CVE-2016-1709: Heap-buffer-overflow in sfntly

- CVE-2016-1710: Same-origin bypass in Blink

- CVE-2016-1711: Same-origin bypass in Blink

- CVE-2016-5127: Use-after-free in Blink

- CVE-2016-5128: Same-origin bypass in V8

- CVE-2016-5129: Memory corruption in V8

- CVE-2016-5130: URL spoofing

- CVE-2016-5131: Use-after-free in libxml

- CVE-2016-5132: Limited same-origin bypass in Service Workers

- CVE-2016-5133: Origin confusion in proxy authentication

- CVE-2016-5134: URL leakage via PAC script

- CVE-2016-5135: Content-Security-Policy bypass

- CVE-2016-5136: Use after free in extensions

- CVE-2016-5137: History sniffing with HSTS and CSP

- CVE-2016-1705: Various fixes from internal audits, fuzzing and other
initiatives

Affected Software/OS:
Chromium on openSUSE 13.1

Solution:
Please install the updated package(s).

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2016-1705
BugTraq ID: 92053
http://www.securityfocus.com/bid/92053
Debian Security Information: DSA-3637 (Google Search)
http://www.debian.org/security/2016/dsa-3637
RedHat Security Advisories: RHSA-2016:1485
http://rhn.redhat.com/errata/RHSA-2016-1485.html
http://www.securitytracker.com/id/1036428
SuSE Security Announcement: openSUSE-SU-2016:1865 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00020.html
SuSE Security Announcement: openSUSE-SU-2016:1868 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00021.html
SuSE Security Announcement: openSUSE-SU-2016:1869 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00022.html
SuSE Security Announcement: openSUSE-SU-2016:1918 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00028.html
http://www.ubuntu.com/usn/USN-3041-1
Common Vulnerability Exposure (CVE) ID: CVE-2016-1706
Common Vulnerability Exposure (CVE) ID: CVE-2016-1707
Common Vulnerability Exposure (CVE) ID: CVE-2016-1708
Common Vulnerability Exposure (CVE) ID: CVE-2016-1709
Common Vulnerability Exposure (CVE) ID: CVE-2016-1710
Common Vulnerability Exposure (CVE) ID: CVE-2016-1711
Common Vulnerability Exposure (CVE) ID: CVE-2016-5127
https://security.gentoo.org/glsa/201610-09
Common Vulnerability Exposure (CVE) ID: CVE-2016-5128
Common Vulnerability Exposure (CVE) ID: CVE-2016-5129
http://www.securitytracker.com/id/1038201
Common Vulnerability Exposure (CVE) ID: CVE-2016-5130
Common Vulnerability Exposure (CVE) ID: CVE-2016-5131
http://lists.apple.com/archives/security-announce/2016/Sep/msg00006.html
http://lists.apple.com/archives/security-announce/2016/Sep/msg00008.html
http://lists.apple.com/archives/security-announce/2016/Sep/msg00010.html
http://lists.apple.com/archives/security-announce/2016/Sep/msg00011.html
https://security.gentoo.org/glsa/201701-37
http://www.securitytracker.com/id/1038623
Common Vulnerability Exposure (CVE) ID: CVE-2016-5132
Common Vulnerability Exposure (CVE) ID: CVE-2016-5133
Common Vulnerability Exposure (CVE) ID: CVE-2016-5134
CERT/CC vulnerability note: VU#877625
https://www.kb.cert.org/vuls/id/877625
Common Vulnerability Exposure (CVE) ID: CVE-2016-5135
Common Vulnerability Exposure (CVE) ID: CVE-2016-5136
Common Vulnerability Exposure (CVE) ID: CVE-2016-5137
CopyrightCopyright (C) 2016 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.