<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for opera</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2025:0012-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2025-01-15T12:36:20Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2025-01-15T12:36:20Z</InitialReleaseDate>
    <CurrentReleaseDate>2025-01-15T12:36:20Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for opera</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for opera fixes the following issues:

- Update to 116.0.5366.21
  * CHR-9904 Update Chromium on desktop-stable-131-5366 to
    131.0.6778.86
  * DNA-119581 Crash at views::View::ConvertPointToTarget
  * DNA-119847 Missing Opera warning color and some margins
    in Settings
  * DNA-119853 Eula dialog is wrong displayed and can not run
    installation with system scale 125%
  * DNA-119883 Dark mode: side bar player icons have
    no background
    * DNA-120054 Double icon effect in adress bar
  * DNA-120117 [Player] Crash when trying to Inspect Element
    on player's web page in panel
  * DNA-120155 Crash on opera:extensions with color-themes
    flag disabled
  * DNA-120195 Scroll in Theme Gallery view changes to dark
    color in Dark Mode
  * DNA-120211 Crash at extensions::
    TabsPrivateGetAllInWindowFunction::Run
  * DNA-120230 Start page button is blurry
  * DNA-120240 Dropdown display lacks expected overlay effect
  * DNA-120242 Translations for Opera 116
  * DNA-120317 Crash at opera::BrowserWindowImpl::
    SetBrowserUIVisible
  * DNA-120458 Crash at opera::BrowserWindowImpl::
    AddWidgetToTracked
  * DNA-120512 Promote 116.0 to stable
- Complete Opera 116 changelog at:
  https://blogs.opera.com/desktop/changelog-for-116
- The update to chromium 131.0.6778.86 fixes following issues:  
  CVE-2024-11395
  

- Update to 115.0.5322.119
  * CHR-9416 Updating Chromium on desktop-stable-* branches
  * DNA-120117 [Player] Crash when trying to Inspect Element on
    player's web page in panel
  * DNA-120211 Crash at extensions::
    TabsPrivateGetAllInWindowFunction::Run

- Update to 115.0.5322.109
  * CHR-9416 Updating Chromium on desktop-stable-* branches
  * DNA-118730 Crash at opera::content_filter::
    AdBlockerWhitelistHandler::SetSiteBlocked
  * DNA-119320 [Mac] Web view corners not rounded
  * DNA-119421 [Easy setup] Dropdown for theme editing do not
    close after opening other dropdowns
  * DNA-119519 Implement stop mechanism for video as wallpaper
  * DNA-119550 Collect common shader rendering code in
    Rich Wallpaper
  * DNA-119551 Convert Midsommar to new shader-based dynamic
    theme format
  * DNA-119552 Convert Aurora to new shader-based dynamic
    theme format
  * DNA-119553 Pass configuration data to shader-based
    dynamic themes
  * DNA-119554 Logic for pause / resume animations in rich
    wallpaper page
  * DNA-119645 Install theme from the server
  * DNA-119652 Show spinner while downloading &amp; installing theme
  * DNA-119692 'start now' button not translated in hindi
  * DNA-119783 Toggles in Dark Mode unchecked state missed
    background color
  * DNA-119811 Show download icon on hover
  * DNA-119812 Implement downloading new theme by clicking
    download button
  * DNA-119813 Implement selecting new theme by clicking tile
  * DNA-119814 Implement canceling theme download API
  * DNA-119815 Implement canceling theme download UI
  * DNA-119816 Handle error callback from download/install
  * DNA-119817 Implement ability to see themes being downloaded
    when opening themes gallery
  * DNA-119834 Sometimes onboarding is blank and useless
  * DNA-119835 Crash at opera::VibesServiceImpl::OnVibeInstalled
  * DNA-119846 Animated wallpapers doesn't work in Classic theme
  * DNA-119848 Add tests for addonsPrivate.cancelInstallation and
    isThemeInstallationPending
  * DNA-119863 Create a configuration for preinstalled theme
  * DNA-119924 Relaunch button resets the toggle instead of
    relaunching browser
  * DNA-119979 Crash at opera::VibesDataReaderImpl::
    LoadDefaultColorsForVibe
  * DNA-119983 DevTools reverts to Light Mode after restart
  * DNA-120018 Context menus not opening for some internal pages
  * DNA-120020 The light mode icon on the mixer page is nearly
    invisible
  * DNA-120210 Crash at base::internal::flat_tree::contains

- Update to 115.0.5322.77
  * CHR-9896 Update Chromium on desktop-stable-130-5322 to
    130.0.6723.137
  * DNA-119410 Crash at opera::WebPanelView::ClosePanel
  * DNA-119466 Unable to open easy setup page when color-theme
    flag is disabled
  * DNA-119955 [My Flow] downloading a file never ends
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">openSUSE-2025-12</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/Q3PEGRWS7VSTXHREFS3ULWWCUPH6HWX2/</URL>
      <Description>E-Mail link for openSUSE-SU-2025:0012-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2024-11395/</URL>
      <Description>SUSE CVE CVE-2024-11395 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="openSUSE Leap 15.6 NonFree">
      <Branch Type="Product Name" Name="openSUSE Leap 15.6 NonFree">
        <FullProductName ProductID="openSUSE Leap 15.6 NonFree">openSUSE Leap 15.6 NonFree</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="opera-116.0.5366.21-lp156.2.26.1">
      <FullProductName ProductID="opera-116.0.5366.21-lp156.2.26.1">opera-116.0.5366.21-lp156.2.26.1</FullProductName>
    </Branch>
    <Relationship ProductReference="opera-116.0.5366.21-lp156.2.26.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6 NonFree">
      <FullProductName ProductID="openSUSE Leap 15.6 NonFree:opera-116.0.5366.21-lp156.2.26.1">opera-116.0.5366.21-lp156.2.26.1 as a component of openSUSE Leap 15.6 NonFree</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Type Confusion in V8 in Google Chrome prior to 131.0.6778.85 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)</Note>
    </Notes>
    <CVE>CVE-2024-11395</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.6 NonFree:opera-116.0.5366.21-lp156.2.26.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/Q3PEGRWS7VSTXHREFS3ULWWCUPH6HWX2/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2024-11395.html</URL>
        <Description>CVE-2024-11395</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1233534</URL>
        <Description>SUSE Bug 1233534</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
