Upstream information

CVE-2021-37995 at MITRE

Description

Inappropriate implementation in WebApp Installer in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially overlay and spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

SUSE information

Overall state of this security issue: Revisit

This issue is currently rated as having moderate severity.

SUSE Bugzilla entry: 1191844 [RESOLVED / FIXED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Package Hub for SUSE Linux Enterprise 15 SP3
  • chromedriver >= 95.0.4638.54-bp153.2.37.1
  • chromium >= 95.0.4638.54-bp153.2.37.1
Patchnames:
openSUSE-2021-1392
openSUSE Leap 15.2
  • chromedriver >= 95.0.4638.54-lp152.2.135.1
  • chromium >= 95.0.4638.54-lp152.2.135.1
Patchnames:
openSUSE-2021-1396
openSUSE Leap 15.2 NonFree
  • opera >= 81.0.4196.31-lp152.2.76.1
Patchnames:
openSUSE-2021-1488
openSUSE Leap 15.3
  • chromedriver >= 95.0.4638.54-bp153.2.37.1
  • chromium >= 95.0.4638.54-bp153.2.37.1
Patchnames:
openSUSE-2021-1392
openSUSE Tumbleweed
  • chromedriver >= 95.0.4638.54-1.1
  • chromium >= 95.0.4638.54-1.1
Patchnames:
openSUSE Tumbleweed GA chromedriver-95.0.4638.54-1.1