Debian Security Advisory DSA 3660-1 (chromium-browser - security update)

Information

Severity

Severity

High

Family

Family

Debian Local Security Checks

CVSSv2 Base

CVSSv2 Base

7.5

CVSSv2 Vector

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

Solution Type

Solution Type

Vendor Patch

Created

Created

5 years ago

Modified

Modified

6 months ago

Summary

Several vulnerabilities have been discovered in the chromium web browser. CVE-2016-5147 A cross-site scripting issue was discovered. CVE-2016-5148 Another cross-site scripting issue was discovered. CVE-2016-5149 Max Justicz discovered a script injection issue in extension handling. CVE-2016-5150 A use-after-free issue was discovered in Blink/Webkit. CVE-2016-5151 A use-after-free issue was discovered in the pdfium library. CVE-2016-5152 GiWan Go discovered a heap overflow issue in the pdfium library. CVE-2016-5153 Atte Kettunen discovered a use-after-destruction issue. CVE-2016-5154 A heap overflow issue was discovered in the pdfium library. CVE-2016-5155 An address bar spoofing issue was discovered. CVE-2016-5156 jinmo123 discovered a use-after-free issue. CVE-2016-5157 A heap overflow issue was discovered in the pdfium library. CVE-2016-5158 GiWan Go discovered a heap overflow issue in the pdfium library. CVE-2016-5159 GiWan Go discovered another heap overflow issue in the pdfium library. CVE-2016-5160 l33terally discovered an extensions resource bypass. CVE-2016-5161 A type confusion issue was discovered. CVE-2016-5162 Nicolas Golubovic discovered an extensions resource bypass. CVE-2016-5163 Rafay Baloch discovered an address bar spoofing issue. CVE-2016-5164 A cross-site scripting issue was discovered in the developer tools. CVE-2016-5165 Gregory Panakkal discovered a script injection issue in the developer tools. CVE-2016-5166 Gregory Panakkal discovered an issue with the Save Page As feature. CVE-2016-5167 The chrome development team found and fixed various issues during internal auditing.

Affected Software

Affected Software

chromium-browser on Debian Linux

Detection Method

Detection Method

This check tests the installed software version using the apt package manager.

Solution

Solution

For the stable distribution (jessie), these problems have been fixed in version 53.0.2785.89-1~deb8u1. For the testing distribution (stretch), these problems will be fixed soon. For the unstable distribution (sid), these problems have been fixed in version 53.0.2785.89-1. We recommend that you upgrade your chromium-browser packages.

Free Vulnerability Scanner

Mageni can help you to scan, assess and manage your vulnerabilities.

Processing. Please wait...

We care about the protection of your data. Read our Privacy Policy.