Upstream information

CVE-2021-37979 at MITRE

Description

heap buffer overflow in WebRTC in Google Chrome prior to 94.0.4606.81 allowed a remote attacker who convinced a user to browse to a malicious website to potentially exploit heap corruption via a crafted HTML page.

SUSE information

Overall state of this security issue: Does not affect SUSE products

This issue is currently rated as having moderate severity.

SUSE Bugzilla entry: 1191463 [RESOLVED / FIXED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
openSUSE Leap 15.2
  • chromedriver >= 94.0.4606.81-lp152.2.132.1
  • chromium >= 94.0.4606.81-lp152.2.132.1
Patchnames:
openSUSE-2021-1350
openSUSE Leap 15.2 NonFree
  • opera >= 80.0.4170.63-lp152.2.73.1
Patchnames:
openSUSE-2021-1433
openSUSE Tumbleweed
  • chromedriver >= 94.0.4606.81-1.1
  • chromium >= 94.0.4606.81-1.1
  • libQt5Pdf5 >= 5.15.7-1.1
  • libQt5PdfWidgets5 >= 5.15.7-1.1
  • libqt5-qtpdf-devel >= 5.15.7-1.1
  • libqt5-qtpdf-examples >= 5.15.7-1.1
  • libqt5-qtpdf-imports >= 5.15.7-1.1
  • libqt5-qtpdf-private-headers-devel >= 5.15.7-1.1
  • libqt5-qtwebengine >= 5.15.7-1.1
  • libqt5-qtwebengine-devel >= 5.15.7-1.1
  • libqt5-qtwebengine-examples >= 5.15.7-1.1
  • libqt5-qtwebengine-private-headers-devel >= 5.15.7-1.1
Patchnames:
openSUSE Tumbleweed GA chromedriver-94.0.4606.81-1.1
openSUSE Tumbleweed GA libQt5Pdf5-5.15.7-1.1