ALT-BU-2022-3689-1
Branch p10 update bulletin.
Package perl-Gear-Remotes updated to version 0.030-alt1 for branch p10 in task 293318.
Closed bugs
Undefined subroutine &RPM::Devscripts::Versort::myvercmp
Closed bugs
отвалилось rpmquery --lastchange
Closed vulnerabilities
BDU:2022-01029
Уязвимость компонента входа в систему Sign-In браузера Google Chrome, позволяющая нарушителю выполнить произвольный код
BDU:2022-01185
Уязвимость компонента SwiftShader браузера Google Chrome, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
BDU:2022-01186
Уязвимость реализации функции автозаполнения Autofill браузера Google Chrome, позволяющая нарушителю раскрыть защищаемую информацию
BDU:2022-01187
Уязвимость реализации функции автозаполнения Autofill браузера Google Chrome, позволяющая нарушителю оказать воздействие на целостность защищаемой информации
BDU:2022-01198
Уязвимость компонента File Manager API браузера Google Chrome, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
BDU:2022-01233
Уязвимость элемента управления «Bookmarks» («Закладки») браузеров Google Chrome и Microsoft Edge, позволяющая нарушителю выполнить произвольный код
BDU:2022-01235
Уязвимость реализации функции автозаполнения Autofill браузеров Microsoft Edge и Google Chrome, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
BDU:2022-01287
Уязвимость интерфейса File API браузера Google Chrome, позволяющая нарушителю обойти ограничения безопасности
BDU:2022-01294
Уязвимость интерфейса Web Serial API браузера Google Chrome, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2022-01300
Уязвимость обработчика JavaScript-сценариев V8 браузера Microsoft Edge и Google Chrome, позволяющая нарушителю выполнить произвольный код
BDU:2022-01308
Уязвимость интерфейса для поддержки потоковых аудио и видео данных Media streams API браузеров Google Chrome и Microsoft Edge, позволяющая нарушителю выполнить произвольный код в целевой системе
BDU:2022-01310
Уязвимость компонента Compositing браузеров браузеров Microsoft Edge и Google Chrome, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
BDU:2022-01311
Уязвимость реализации компонента WebShare браузера Google Chrome, позволяющая нарушителю раскрыть защищаемую информацию
BDU:2022-01333
Уязвимость механизма отображения веб-страниц Blink браузера Google Chrome, позволяющая нарушителю раскрыть защищаемую информацию
BDU:2022-01359
Уязвимость функции Navigation браузера Google Chrome, позволяющая нарушителю подделать содержимое адресной строки
BDU:2022-01361
Уязвимость функции захват экрана (Screen Capture) браузера Google Chrome, позволяющая нарушителю выполнить произвольный код
BDU:2022-01362
Уязвимость набора инструментов для веб-разработки DevTools браузера Google Chrome, позволяющая нарушителю выйти из изолированной программной среды
BDU:2022-01380
Уязвимость компонента Storage браузера Google Chrome, позволяющая нарушителю выполнить произвольный код
BDU:2022-01560
Уязвимость механизма отображения веб-страниц Blink браузера Google Chrome, позволяющая нарушителю раскрыть защищаемую информацию
BDU:2022-01561
Уязвимость менеджера паролей браузера Google Chrome, позволяющая нарушителю раскрыть защищаемую информацию
BDU:2022-01563
Уязвимость пользовательского интерфейса браузера Google Chrome, позволяющая нарушителю проводить спуфинг-атаки
BDU:2022-01708
Уязвимость обработчика PDF-содержимого браузера Google Chrome, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
BDU:2022-01709
Уязвимость функции Navigation браузера Google Chrome, позволяющая нарушителю раскрыть защищаемую информацию
BDU:2022-01710
Уязвимость библиотеки ANGLE браузера Google Chrome, позволяющая нарушителю выполнить произвольный код
Modified: 2024-11-21
CVE-2022-0096
Use after free in Storage in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://crbug.com/1275020
- https://crbug.com/1275020
- FEDORA-2022-d1a15f9cdb
- FEDORA-2022-d1a15f9cdb
- FEDORA-2022-49b52819a4
- FEDORA-2022-49b52819a4
- FEDORA-2022-57923346cf
- FEDORA-2022-57923346cf
Modified: 2024-11-21
CVE-2022-0097
Inappropriate implementation in DevTools in Google Chrome prior to 97.0.4692.71 allowed an attacker who convinced a user to install a malicious extension to to potentially allow extension to escape the sandbox via a crafted HTML page.
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://crbug.com/1117173
- https://crbug.com/1117173
- FEDORA-2022-d1a15f9cdb
- FEDORA-2022-d1a15f9cdb
- FEDORA-2022-49b52819a4
- FEDORA-2022-49b52819a4
- FEDORA-2022-57923346cf
- FEDORA-2022-57923346cf
Modified: 2024-11-21
CVE-2022-0098
Use after free in Screen Capture in Google Chrome on Chrome OS prior to 97.0.4692.71 allowed an attacker who convinced a user to perform specific user gestures to potentially exploit heap corruption via specific user gestures.
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://crbug.com/1273609
- https://crbug.com/1273609
- FEDORA-2022-d1a15f9cdb
- FEDORA-2022-d1a15f9cdb
- FEDORA-2022-49b52819a4
- FEDORA-2022-49b52819a4
- FEDORA-2022-57923346cf
- FEDORA-2022-57923346cf
Modified: 2024-11-21
CVE-2022-0099
Use after free in Sign-in in Google Chrome prior to 97.0.4692.71 allowed a remote attacker who convinced a user to perform specific user gestures to potentially exploit heap corruption via specific user gesture.
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://crbug.com/1245629
- https://crbug.com/1245629
- FEDORA-2022-d1a15f9cdb
- FEDORA-2022-d1a15f9cdb
- FEDORA-2022-49b52819a4
- FEDORA-2022-49b52819a4
- FEDORA-2022-57923346cf
- FEDORA-2022-57923346cf
Modified: 2024-11-21
CVE-2022-0100
Heap buffer overflow in Media streams API in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://crbug.com/1238209
- https://crbug.com/1238209
- FEDORA-2022-d1a15f9cdb
- FEDORA-2022-d1a15f9cdb
- FEDORA-2022-49b52819a4
- FEDORA-2022-49b52819a4
- FEDORA-2022-57923346cf
- FEDORA-2022-57923346cf
Modified: 2024-11-21
CVE-2022-0101
Heap buffer overflow in Bookmarks in Google Chrome prior to 97.0.4692.71 allowed a remote attacker who convinced a user to perform specific user gesture to potentially exploit heap corruption via specific user gesture.
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://crbug.com/1249426
- https://crbug.com/1249426
- FEDORA-2022-d1a15f9cdb
- FEDORA-2022-d1a15f9cdb
- FEDORA-2022-49b52819a4
- FEDORA-2022-49b52819a4
- FEDORA-2022-57923346cf
- FEDORA-2022-57923346cf
Modified: 2024-11-21
CVE-2022-0102
Type confusion in V8 in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://crbug.com/1260129
- https://crbug.com/1260129
- FEDORA-2022-d1a15f9cdb
- FEDORA-2022-d1a15f9cdb
- FEDORA-2022-49b52819a4
- FEDORA-2022-49b52819a4
- FEDORA-2022-57923346cf
- FEDORA-2022-57923346cf
Modified: 2024-11-21
CVE-2022-0103
Use after free in SwiftShader in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://crbug.com/1272266
- https://crbug.com/1272266
- FEDORA-2022-d1a15f9cdb
- FEDORA-2022-d1a15f9cdb
- FEDORA-2022-49b52819a4
- FEDORA-2022-49b52819a4
- FEDORA-2022-57923346cf
- FEDORA-2022-57923346cf
Modified: 2024-11-21
CVE-2022-0104
Heap buffer overflow in ANGLE in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://crbug.com/1273661
- https://crbug.com/1273661
- FEDORA-2022-d1a15f9cdb
- FEDORA-2022-d1a15f9cdb
- FEDORA-2022-49b52819a4
- FEDORA-2022-49b52819a4
- FEDORA-2022-57923346cf
- FEDORA-2022-57923346cf
Modified: 2024-11-21
CVE-2022-0105
Use after free in PDF Accessibility in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://crbug.com/1274376
- https://crbug.com/1274376
- FEDORA-2022-d1a15f9cdb
- FEDORA-2022-d1a15f9cdb
- FEDORA-2022-49b52819a4
- FEDORA-2022-49b52819a4
- FEDORA-2022-57923346cf
- FEDORA-2022-57923346cf
Modified: 2024-11-21
CVE-2022-0106
Use after free in Autofill in Google Chrome prior to 97.0.4692.71 allowed a remote attacker who convinced a user to perform specific user gesture to potentially exploit heap corruption via a crafted HTML page.
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://crbug.com/1278960
- https://crbug.com/1278960
- FEDORA-2022-d1a15f9cdb
- FEDORA-2022-d1a15f9cdb
- FEDORA-2022-49b52819a4
- FEDORA-2022-49b52819a4
- FEDORA-2022-57923346cf
- FEDORA-2022-57923346cf
Modified: 2024-11-21
CVE-2022-0107
Use after free in File Manager API in Google Chrome on Chrome OS prior to 97.0.4692.71 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://crbug.com/1248438
- https://crbug.com/1248438
- FEDORA-2022-d1a15f9cdb
- FEDORA-2022-d1a15f9cdb
- FEDORA-2022-49b52819a4
- FEDORA-2022-49b52819a4
- FEDORA-2022-57923346cf
- FEDORA-2022-57923346cf
Modified: 2024-11-21
CVE-2022-0108
Inappropriate implementation in Navigation in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- [oss-security] 20230421 WebKitGTK and WPE WebKit Security Advisory WSA-2023-0003
- [oss-security] 20230421 WebKitGTK and WPE WebKit Security Advisory WSA-2023-0003
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://crbug.com/1248444
- https://crbug.com/1248444
- [debian-lts-announce] 20230512 [SECURITY] [DLA 3419-1] webkit2gtk security update
- [debian-lts-announce] 20230512 [SECURITY] [DLA 3419-1] webkit2gtk security update
- FEDORA-2023-a4bbf02a57
- FEDORA-2023-a4bbf02a57
- FEDORA-2022-d1a15f9cdb
- FEDORA-2022-d1a15f9cdb
- FEDORA-2023-5b61346bbe
- FEDORA-2023-5b61346bbe
- FEDORA-2023-8900b35c6f
- FEDORA-2023-8900b35c6f
- FEDORA-2022-49b52819a4
- FEDORA-2022-49b52819a4
- FEDORA-2022-57923346cf
- FEDORA-2022-57923346cf
- DSA-5396
- DSA-5396
- DSA-5397
- DSA-5397
Modified: 2024-11-21
CVE-2022-0109
Inappropriate implementation in Autofill in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to obtain potentially sensitive information via a crafted HTML page.
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://crbug.com/1261689
- https://crbug.com/1261689
- FEDORA-2022-d1a15f9cdb
- FEDORA-2022-d1a15f9cdb
- FEDORA-2022-49b52819a4
- FEDORA-2022-49b52819a4
- FEDORA-2022-57923346cf
- FEDORA-2022-57923346cf
Modified: 2024-11-21
CVE-2022-0110
Incorrect security UI in Autofill in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://crbug.com/1237310
- https://crbug.com/1237310
- FEDORA-2022-d1a15f9cdb
- FEDORA-2022-d1a15f9cdb
- FEDORA-2022-49b52819a4
- FEDORA-2022-49b52819a4
- FEDORA-2022-57923346cf
- FEDORA-2022-57923346cf
Modified: 2024-11-21
CVE-2022-0111
Inappropriate implementation in Navigation in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to incorrectly set origin via a crafted HTML page.
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://crbug.com/1241188
- https://crbug.com/1241188
- FEDORA-2022-d1a15f9cdb
- FEDORA-2022-d1a15f9cdb
- FEDORA-2022-49b52819a4
- FEDORA-2022-49b52819a4
- FEDORA-2022-57923346cf
- FEDORA-2022-57923346cf
Modified: 2024-11-21
CVE-2022-0112
Incorrect security UI in Browser UI in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to display missing URL or incorrect URL via a crafted URL.
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://crbug.com/1255713
- https://crbug.com/1255713
- FEDORA-2022-d1a15f9cdb
- FEDORA-2022-d1a15f9cdb
- FEDORA-2022-49b52819a4
- FEDORA-2022-49b52819a4
- FEDORA-2022-57923346cf
- FEDORA-2022-57923346cf
Modified: 2024-11-21
CVE-2022-0113
Inappropriate implementation in Blink in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://crbug.com/1039885
- https://crbug.com/1039885
- FEDORA-2022-d1a15f9cdb
- FEDORA-2022-d1a15f9cdb
- FEDORA-2022-49b52819a4
- FEDORA-2022-49b52819a4
- FEDORA-2022-57923346cf
- FEDORA-2022-57923346cf
Modified: 2024-11-21
CVE-2022-0114
Out of bounds memory access in Blink Serial API in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page and virtual serial port driver.
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://crbug.com/1267627
- https://crbug.com/1267627
- FEDORA-2022-d1a15f9cdb
- FEDORA-2022-d1a15f9cdb
- FEDORA-2022-49b52819a4
- FEDORA-2022-49b52819a4
- FEDORA-2022-57923346cf
- FEDORA-2022-57923346cf
Modified: 2024-11-21
CVE-2022-0115
Uninitialized use in File API in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://crbug.com/1268903
- https://crbug.com/1268903
- FEDORA-2022-d1a15f9cdb
- FEDORA-2022-d1a15f9cdb
- FEDORA-2022-49b52819a4
- FEDORA-2022-49b52819a4
- FEDORA-2022-57923346cf
- FEDORA-2022-57923346cf
Modified: 2024-11-21
CVE-2022-0116
Inappropriate implementation in Compositing in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://crbug.com/1272250
- https://crbug.com/1272250
- FEDORA-2022-d1a15f9cdb
- FEDORA-2022-d1a15f9cdb
- FEDORA-2022-49b52819a4
- FEDORA-2022-49b52819a4
- FEDORA-2022-57923346cf
- FEDORA-2022-57923346cf
Modified: 2024-11-21
CVE-2022-0117
Policy bypass in Blink in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://crbug.com/1115847
- https://crbug.com/1115847
- FEDORA-2022-d1a15f9cdb
- FEDORA-2022-d1a15f9cdb
- FEDORA-2022-49b52819a4
- FEDORA-2022-49b52819a4
- FEDORA-2022-57923346cf
- FEDORA-2022-57923346cf
Modified: 2024-11-21
CVE-2022-0118
Inappropriate implementation in WebShare in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially hide the contents of the Omnibox (URL bar) via a crafted HTML page.
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://crbug.com/1238631
- https://crbug.com/1238631
- FEDORA-2022-d1a15f9cdb
- FEDORA-2022-d1a15f9cdb
- FEDORA-2022-49b52819a4
- FEDORA-2022-49b52819a4
- FEDORA-2022-57923346cf
- FEDORA-2022-57923346cf
Modified: 2024-11-21
CVE-2022-0120
Inappropriate implementation in Passwords in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially leak cross-origin data via a malicious website.
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
- https://crbug.com/1262953
- https://crbug.com/1262953
- FEDORA-2022-d1a15f9cdb
- FEDORA-2022-d1a15f9cdb
- FEDORA-2022-49b52819a4
- FEDORA-2022-49b52819a4
- FEDORA-2022-57923346cf
- FEDORA-2022-57923346cf