File _patchinfo of Package patchinfo.17806

<patchinfo incident="17806">
  <issue tracker="bnc" id="1207018">VUL-0: chromium: multiple security issues fixed in 109.0.5414.74</issue>
  <issue tracker="cve" id="2023-0128"/>
  <issue tracker="cve" id="2023-0129"/>
  <issue tracker="cve" id="2023-0130"/>
  <issue tracker="cve" id="2023-0131"/>
  <issue tracker="cve" id="2023-0132"/>
  <issue tracker="cve" id="2023-0133"/>
  <issue tracker="cve" id="2023-0134"/>
  <issue tracker="cve" id="2023-013e"/>
  <issue tracker="cve" id="2023-0136"/>
  <issue tracker="cve" id="2023-0137"/>
  <issue tracker="cve" id="2023-0138"/>
  <issue tracker="cve" id="2023-0139"/>
  <issue tracker="cve" id="2023-0140"/>
  <issue tracker="cve" id="2023-0141"/>
  <category>security</category>
  <rating>important</rating>
  <packager>AndreasStieger</packager>
  <summary>Security update for chromium</summary>
  <description>This update for chromium fixes the following issues:

Update to version 109.0.5414.74 (boo#1207018):

- CVE-2023-0128: Use after free in Overview Mode
- CVE-2023-0129: Heap buffer overflow in Network Service
- CVE-2023-0130: Inappropriate implementation in Fullscreen API
- CVE-2023-0131: Inappropriate implementation in iframe Sandbox
- CVE-2023-0132: Inappropriate implementation in Permission prompts
- CVE-2023-0133: Inappropriate implementation in Permission prompts
- CVE-2023-0134: Use after free in Cart
- CVE-2023-0135: Use after free in Cart
- CVE-2023-0136: Inappropriate implementation in Fullscreen API
- CVE-2023-0137: Heap buffer overflow in Platform Apps
- CVE-2023-0138: Heap buffer overflow in libphonenumber
- CVE-2023-0139: Insufficient validation of untrusted input in Downloads
- CVE-2023-0140: Inappropriate implementation in File System API
- CVE-2023-0141: Insufficient policy enforcement in CORS
- Various fixes from internal audits, fuzzing and other initiatives
</description>
</patchinfo>
openSUSE Build Service is sponsored by