{"affected":[{"ecosystem_specific":{"binaries":[{"chromedriver":"106.0.5249.91-bp154.2.32.1","chromium":"106.0.5249.91-bp154.2.32.1"}]},"package":{"ecosystem":"SUSE:Package Hub 15 SP4","name":"chromium","purl":"pkg:rpm/suse/chromium&distro=SUSE%20Package%20Hub%2015%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"106.0.5249.91-bp154.2.32.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"chromedriver":"106.0.5249.91-bp154.2.32.1","chromium":"106.0.5249.91-bp154.2.32.1"}]},"package":{"ecosystem":"openSUSE:Leap 15.4","name":"chromium","purl":"pkg:rpm/opensuse/chromium&distro=openSUSE%20Leap%2015.4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"106.0.5249.91-bp154.2.32.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for chromium fixes the following issues:\n\nChromium 106.0.5249.91 (boo#1203808):\n\n* CVE-2022-3370: Use after free in Custom Elements\n* CVE-2022-3373: Out of bounds write in V8\n\nincludes changes from 106.0.5249.61:\n\n* CVE-2022-3304: Use after free in CSS\n* CVE-2022-3201: Insufficient validation of untrusted input in Developer Tools\n* CVE-2022-3305: Use after free in Survey\n* CVE-2022-3306: Use after free in Survey\n* CVE-2022-3307: Use after free in Media\n* CVE-2022-3308: Insufficient policy enforcement in Developer Tools\n* CVE-2022-3309: Use after free in Assistant\n* CVE-2022-3310: Insufficient policy enforcement in Custom Tabs\n* CVE-2022-3311: Use after free in Import\n* CVE-2022-3312: Insufficient validation of untrusted input in VPN\n* CVE-2022-3313: Incorrect security UI in Full Screen\n* CVE-2022-3314: Use after free in Logging\n* CVE-2022-3315: Type confusion in Blink\n* CVE-2022-3316: Insufficient validation of untrusted input in Safe Browsing\n* CVE-2022-3317: Insufficient validation of untrusted input in Intents\n* CVE-2022-3318: Use after free in ChromeOS Notifications\n","id":"openSUSE-SU-2022:10138-1","modified":"2022-10-03T10:34:33Z","published":"2022-10-03T10:34:33Z","references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YZBW4AE4VW4MIHPWQLMJEIBGACVXWAFW/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1203808"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-3201"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-3304"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-3305"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-3306"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-3307"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-3308"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-3309"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-3310"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-3311"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-3312"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-3313"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-3314"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-3315"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-3316"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-3317"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-3318"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-3370"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-3373"}],"related":["CVE-2022-3201","CVE-2022-3304","CVE-2022-3305","CVE-2022-3306","CVE-2022-3307","CVE-2022-3308","CVE-2022-3309","CVE-2022-3310","CVE-2022-3311","CVE-2022-3312","CVE-2022-3313","CVE-2022-3314","CVE-2022-3315","CVE-2022-3316","CVE-2022-3317","CVE-2022-3318","CVE-2022-3370","CVE-2022-3373"],"summary":"Security update for chromium","upstream":["CVE-2022-3201","CVE-2022-3304","CVE-2022-3305","CVE-2022-3306","CVE-2022-3307","CVE-2022-3308","CVE-2022-3309","CVE-2022-3310","CVE-2022-3311","CVE-2022-3312","CVE-2022-3313","CVE-2022-3314","CVE-2022-3315","CVE-2022-3316","CVE-2022-3317","CVE-2022-3318","CVE-2022-3370","CVE-2022-3373"]}