Gentoo Archives: gentoo-announce

From: Aaron Bauman <bman@g.o>
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 201903-23 ] Chromium: Multiple vulnerabilities
Date: Thu, 28 Mar 2019 02:55:44
Message-Id: 20190328022301.GH14496@monkey
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 201903-23
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: High
8 Title: Chromium: Multiple vulnerabilities
9 Date: March 28, 2019
10 Bugs: #671550, #677066, #679530, #680242
11 ID: 201903-23
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been found in Chromium, the worst of
19 which could result in the remote execution of code.
20
21 Background
22 ==========
23
24 Chromium is an open-source browser project that aims to build a safer,
25 faster, and more stable way for all users to experience the web.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 www-client/chromium < 73.0.3683.75 >= 73.0.3683.75
34
35 Description
36 ===========
37
38 Multiple vulnerabilities have been discovered in Chromium and Google
39 Chrome. Please review the referenced CVE identifiers and Google Chrome
40 Releases for details.
41
42 Impact
43 ======
44
45 Please review the referenced CVE identifiers and Google Chrome Releases
46 for details.
47
48 Workaround
49 ==========
50
51 There is no known workaround at this time.
52
53 Resolution
54 ==========
55
56 All Chromium users should upgrade to the latest version:
57
58 # emerge --sync
59 # emerge --ask --oneshot -v ">=www-client/chromium-73.0.3683.75"
60
61 References
62 ==========
63
64 [ 1 ] CVE-2018-17479
65 https://nvd.nist.gov/vuln/detail/CVE-2018-17479
66 [ 2 ] CVE-2019-5786
67 https://nvd.nist.gov/vuln/detail/CVE-2019-5786
68 [ 3 ] CVE-2019-5786
69 https://nvd.nist.gov/vuln/detail/CVE-2019-5786
70 [ 4 ] CVE-2019-5787
71 https://nvd.nist.gov/vuln/detail/CVE-2019-5787
72 [ 5 ] CVE-2019-5788
73 https://nvd.nist.gov/vuln/detail/CVE-2019-5788
74 [ 6 ] CVE-2019-5789
75 https://nvd.nist.gov/vuln/detail/CVE-2019-5789
76 [ 7 ] CVE-2019-5790
77 https://nvd.nist.gov/vuln/detail/CVE-2019-5790
78 [ 8 ] CVE-2019-5791
79 https://nvd.nist.gov/vuln/detail/CVE-2019-5791
80 [ 9 ] CVE-2019-5792
81 https://nvd.nist.gov/vuln/detail/CVE-2019-5792
82 [ 10 ] CVE-2019-5793
83 https://nvd.nist.gov/vuln/detail/CVE-2019-5793
84 [ 11 ] CVE-2019-5794
85 https://nvd.nist.gov/vuln/detail/CVE-2019-5794
86 [ 12 ] CVE-2019-5795
87 https://nvd.nist.gov/vuln/detail/CVE-2019-5795
88 [ 13 ] CVE-2019-5796
89 https://nvd.nist.gov/vuln/detail/CVE-2019-5796
90 [ 14 ] CVE-2019-5797
91 https://nvd.nist.gov/vuln/detail/CVE-2019-5797
92 [ 15 ] CVE-2019-5798
93 https://nvd.nist.gov/vuln/detail/CVE-2019-5798
94 [ 16 ] CVE-2019-5799
95 https://nvd.nist.gov/vuln/detail/CVE-2019-5799
96 [ 17 ] CVE-2019-5800
97 https://nvd.nist.gov/vuln/detail/CVE-2019-5800
98 [ 18 ] CVE-2019-5801
99 https://nvd.nist.gov/vuln/detail/CVE-2019-5801
100 [ 19 ] CVE-2019-5802
101 https://nvd.nist.gov/vuln/detail/CVE-2019-5802
102 [ 20 ] CVE-2019-5803
103 https://nvd.nist.gov/vuln/detail/CVE-2019-5803
104 [ 21 ] CVE-2019-5804
105 https://nvd.nist.gov/vuln/detail/CVE-2019-5804
106
107 Availability
108 ============
109
110 This GLSA and any updates to it are available for viewing at
111 the Gentoo Security Website:
112
113 https://security.gentoo.org/glsa/201903-23
114
115 Concerns?
116 =========
117
118 Security is a primary focus of Gentoo Linux and ensuring the
119 confidentiality and security of our users' machines is of utmost
120 importance to us. Any security concerns should be addressed to
121 security@g.o or alternatively, you may file a bug at
122 https://bugs.gentoo.org.
123
124 License
125 =======
126
127 Copyright 2019 Gentoo Foundation, Inc; referenced text
128 belongs to its owner(s).
129
130 The contents of this document are licensed under the
131 Creative Commons - Attribution / Share Alike license.
132
133 https://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature