Bug 939077 (CVE-2015-1271) - VUL-0: chromium: Chrome 44.0.2403.89 with various security fixes
Summary: VUL-0: chromium: Chrome 44.0.2403.89 with various security fixes
Status: RESOLVED FIXED
Alias: CVE-2015-1271
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P5 - None : Major
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/119179/
Whiteboard: CVSSv2:SUSE:CVE-2015-1283:6.8:(AV:N/...
Keywords:
Depends on:
Blocks:
 
Reported: 2015-07-22 11:02 UTC by Johannes Segitz
Modified: 2020-06-08 11:06 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Johannes Segitz 2015-07-22 11:02:07 UTC
http://googlechromereleases.blogspot.de/2015/07/stable-channel-update_21.html

Security issues fixed:
CVE-2015-1271: Heap-buffer-overflow in pdfium. Credit to cloudfuzzer.
CVE-2015-1273: Heap-buffer-overflow in pdfium. Credit to makosoft.
CVE-2015-1274: Settings allowed executable files to run immediately after download. Credit to  andrewm.bpi.
CVE-2015-1275: UXSS in Chrome for Android. Credit to WangTao(neobyte) of Baidu X-Team.
CVE-2015-1276: Use-after-free in IndexedDB. Credit to Collin Payne.
CVE-2015-1279: Heap-buffer-overflow in pdfium. Credit to mlafon.
CVE-2015-1280: Memory corruption in skia. Credit to cloudfuzzer.
CVE-2015-1281: CSP bypass. Credit to Masato Kinugawa.
CVE-2015-1282: Use-after-free in pdfium. Credit to Chamal de Silva.
CVE-2015-1283: Heap-buffer-overflow in expat. Credit to sidhpurwala.huzaifa.
CVE-2015-1284: Use-after-free in blink. Credit to Atte Kettunen of OUSPG.
CVE-2015-1286: UXSS in blink. Credit to anonymous.
CVE-2015-1287: SOP bypass with CSS. Credit to filedescriptor.
CVE-2015-1270: Uninitialized memory read in ICU. Credit to Atte Kettunen of OUSPG.
CVE-2015-1272: Use-after-free related to unexpected GPU process termination. Credit to Chamal de Silva.
CVE-2015-1277: Use-after-free in accessibility. Credit to SkyLined.
CVE-2015-1278: URL spoofing using pdf files. Credit to Chamal de Silva.
CVE-2015-1285: Information leak in XSS auditor. Credit to gazheyes.
CVE-2015-1288: Spell checking dictionaries fetched over HTTP. Credit to mike@michaelruddy.com.
CVE-2015-1289: Various fixes from internal audits, fuzzing and other initiatives.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1245436
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-1271
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1271
Comment 1 Bernhard Wiedemann 2015-07-22 14:00:39 UTC
This is an autogenerated message for OBS integration:
This bug (939077) was mentioned in
https://build.opensuse.org/request/show/317946 13.2 / chromium
https://build.opensuse.org/request/show/317947 13.1 / chromium
Comment 2 Andreas Stieger 2015-07-22 14:25:23 UTC
Update is running, including SLE 12 backport
Comment 3 Johannes Segitz 2015-07-23 07:48:22 UTC
Also fixed in 44.0.2403.89:

CVE-2015-5605: The regular-expression implementation in Google V8, as used in Google Chrome before 44.0.2403.89, mishandles interrupts, which allows remote attackers to cause a denial of service (application crash) via crafted JavaScript code, as demonstrated by an error in garbage collection during allocation of a stack-overflow exception message.
Comment 4 Andreas Stieger 2015-07-26 18:19:28 UTC
releasing
Comment 5 Swamp Workflow Management 2015-07-26 19:07:45 UTC
openSUSE-SU-2015:1287-1: An update that fixes 21 vulnerabilities is now available.

Category: security (important)
Bug References: 939077
CVE References: CVE-2015-1270,CVE-2015-1271,CVE-2015-1272,CVE-2015-1273,CVE-2015-1274,CVE-2015-1275,CVE-2015-1276,CVE-2015-1277,CVE-2015-1278,CVE-2015-1279,CVE-2015-1280,CVE-2015-1281,CVE-2015-1282,CVE-2015-1283,CVE-2015-1284,CVE-2015-1285,CVE-2015-1286,CVE-2015-1287,CVE-2015-1288,CVE-2015-1289,CVE-2015-5605
Sources used:
openSUSE 13.2 (src):    chromium-44.0.2403.89-38.1
openSUSE 13.1 (src):    chromium-44.0.2403.89-93.1