File _patchinfo of Package patchinfo.17806
<patchinfo incident="17806">
<issue tracker="bnc" id="1207018">VUL-0: chromium: multiple security issues fixed in 109.0.5414.74</issue>
<issue tracker="cve" id="2023-0128"/>
<issue tracker="cve" id="2023-0129"/>
<issue tracker="cve" id="2023-0130"/>
<issue tracker="cve" id="2023-0131"/>
<issue tracker="cve" id="2023-0132"/>
<issue tracker="cve" id="2023-0133"/>
<issue tracker="cve" id="2023-0134"/>
<issue tracker="cve" id="2023-013e"/>
<issue tracker="cve" id="2023-0136"/>
<issue tracker="cve" id="2023-0137"/>
<issue tracker="cve" id="2023-0138"/>
<issue tracker="cve" id="2023-0139"/>
<issue tracker="cve" id="2023-0140"/>
<issue tracker="cve" id="2023-0141"/>
<category>security</category>
<rating>important</rating>
<packager>AndreasStieger</packager>
<summary>Security update for chromium</summary>
<description>This update for chromium fixes the following issues:
Update to version 109.0.5414.74 (boo#1207018):
- CVE-2023-0128: Use after free in Overview Mode
- CVE-2023-0129: Heap buffer overflow in Network Service
- CVE-2023-0130: Inappropriate implementation in Fullscreen API
- CVE-2023-0131: Inappropriate implementation in iframe Sandbox
- CVE-2023-0132: Inappropriate implementation in Permission prompts
- CVE-2023-0133: Inappropriate implementation in Permission prompts
- CVE-2023-0134: Use after free in Cart
- CVE-2023-0135: Use after free in Cart
- CVE-2023-0136: Inappropriate implementation in Fullscreen API
- CVE-2023-0137: Heap buffer overflow in Platform Apps
- CVE-2023-0138: Heap buffer overflow in libphonenumber
- CVE-2023-0139: Insufficient validation of untrusted input in Downloads
- CVE-2023-0140: Inappropriate implementation in File System API
- CVE-2023-0141: Insufficient policy enforcement in CORS
- Various fixes from internal audits, fuzzing and other initiatives
</description>
</patchinfo>