ArchLinux: 201906-4: chromium: multiple issues
Summary
- CVE-2019-5828 (arbitrary code execution)
A use-after-free vulnerability has been found in the ServiceWorker
component of the chromium browser before 75.0.3770.80.
- CVE-2019-5829 (arbitrary code execution)
A use-after-free vulnerability has been found in the Download Manager
component of the chromium browser before 75.0.3770.80.
- CVE-2019-5830 (access restriction bypass)
An incorrectly credentialed requests vulnerability has been found in
the CORS component of the chromium browser before 75.0.3770.80.
- CVE-2019-5831 (incorrect calculation)
An incorrect map processing vulnerability has been found in the V8
component of the chromium browser before 75.0.3770.80.
- CVE-2019-5832 (access restriction bypass)
An incorrect CORS handling vulnerability has been found in the XHR
component of the chromium browser before 75.0.3770.80.
- CVE-2019-5833 (content spoofing)
An inconsistent security UI placement vulnerability has been found in
the chromium browser before 75.0.3770.80.
- CVE-2019-5835 (information disclosure)
An out-of-bounds read vulnerability has been found in the Swiftshader
component of the chromium browser before 75.0.3770.80.
- CVE-2019-5836 (arbitrary code execution)
A heap-based buffer overflow vulnerability has been found in the Angle
component of the chromium browser before 75.0.3770.80.
- CVE-2019-5837 (information disclosure)
A cross-origin resources size disclosure vulnerability has been found
in the Appcache component of the chromium browser before 75.0.3770.80.
- CVE-2019-5838 (access restriction bypass)
An overly permissive tab access vulnerability has been found in the
Extensions component of the chromium browser before 75.0.3770.80.
- CVE-2019-5839 (access restriction bypass)
An incorrect handling of certain code points vulnerability has been
found in the Blink component of the chromium browser before
75.0.3770.80.
- CVE-2019-5840 (access restriction bypass)
A popup blocker bypass vulnerability has been found in the chromium
browser before 75.0.3770.80.
Resolution
Upgrade to 75.0.3770.80-1.
# pacman -Syu "chromium>=75.0.3770.80-1"
The problems have been fixed upstream in version 75.0.3770.80.
References
https://chromereleases.googleblog.com/2019/06/stable-channel-update-for-desktop.html https://security.archlinux.org/CVE-2019-5828 https://security.archlinux.org/CVE-2019-5829 https://security.archlinux.org/CVE-2019-5830 https://security.archlinux.org/CVE-2019-5831 https://security.archlinux.org/CVE-2019-5832 https://security.archlinux.org/CVE-2019-5833 https://security.archlinux.org/CVE-2019-5835 https://security.archlinux.org/CVE-2019-5836 https://security.archlinux.org/CVE-2019-5837 https://security.archlinux.org/CVE-2019-5838 https://security.archlinux.org/CVE-2019-5839 https://security.archlinux.org/CVE-2019-5840
Workaround
None.