ArchLinux: 201908-1: chromium: multiple issues
Summary
- CVE-2019-5850 (arbitrary code execution)
A use-after-free issue has been found in the offline page fetcher
component of Chromium before 76.0.3809.87.
- CVE-2019-5851 (arbitrary code execution)
A use-after-poison issue has been found in the offline audio context
component of Chromium before 76.0.3809.87.
- CVE-2019-5852 (denial of service)
An object leak issue has been found in the utility functions of
Chromium before 76.0.3809.87.
- CVE-2019-5853 (arbitrary code execution)
A memory corruption issue has been found in the regexp length checks of
Chromium before 76.0.3809.87.
- CVE-2019-5854 (arbitrary code execution)
An integer overflow issue has been found in the text rendering of the
PDFium component of Chromium before 76.0.3809.87.
- CVE-2019-5855 (arbitrary code execution)
An integer overflow issue has been found in the text rendering of the
PDFium component of Chromium before 76.0.3809.87.
- CVE-2019-5856 (access restriction bypass)
An insufficient checks on filesystem: URI permissions issue has been
found in Chromium before 76.0.3809.87.
- CVE-2019-5857 (denial of service)
An issue has been found in Chromium before 76.0.3809.87 where the
comparison of -0 and null yields a crash.
- CVE-2019-5858 (insufficient validation)
An insufficient filtering of Open URL service parameters issue has been
found in Chromium before 76.0.3809.87.
- CVE-2019-5859 (access restriction bypass)
An issue has been found in Chromium before 76.0.3809.87, where res:
URIs can load alternative browsers.
- CVE-2019-5860 (arbitrary code execution)
A use-after-free issue has been found in the PDFium component of
Chromium before 76.0.3809.87.
- CVE-2019-5861 (content spoofing)
An issue has been found in Chromium before 76.0.3809.87, where click
location was incorrectly checked.
- CVE-2019-5862 (access restriction bypass)
An issue with AppCache not being robust to compromised renderers has
been found in Chromium before 76.0.3809.87.
- CVE-2019-5864 (access restriction bypass)
An insufficient port filtering in CORS for extensions issue has been
found in Chromium before 76.0.3809.87.
- CVE-2019-5865 (access restriction bypass)
A site isolation bypass from a compromised renderer has been found in
Chromium before 76.0.3809.87.
Resolution
Upgrade to 76.0.3809.87-1.
# pacman -Syu "chromium>=76.0.3809.87-1"
The problems have been fixed upstream in version 76.0.3809.87.
References
https://chromereleases.googleblog.com/2019/07/stable-channel-update-for-desktop_30.html https://security.archlinux.org/CVE-2019-5850 https://security.archlinux.org/CVE-2019-5851 https://security.archlinux.org/CVE-2019-5852 https://security.archlinux.org/CVE-2019-5853 https://security.archlinux.org/CVE-2019-5854 https://security.archlinux.org/CVE-2019-5855 https://security.archlinux.org/CVE-2019-5856 https://security.archlinux.org/CVE-2019-5857 https://security.archlinux.org/CVE-2019-5858 https://security.archlinux.org/CVE-2019-5859 https://security.archlinux.org/CVE-2019-5860 https://security.archlinux.org/CVE-2019-5861 https://security.archlinux.org/CVE-2019-5862 https://security.archlinux.org/CVE-2019-5864 https://security.archlinux.org/CVE-2019-5865
Workaround
None.