ArchLinux: 201908-6: chromium: arbitrary code execution
Summary
- CVE-2019-5867 (arbitrary code execution)
An out-of-bounds read has been found in the V8 component of the
chromium browser before 76.0.3809.100.
- CVE-2019-5868 (arbitrary code execution)
A use-after-free issue has been found in PDFium's ExecuteFieldAction,
in the chromium browser before 76.0.3809.100.
Resolution
Upgrade to 76.0.3809.100-1.
# pacman -Syu "chromium>=76.0.3809.100-1"
The problems have been fixed upstream in version 76.0.3809.100.
References
https://chromereleases.googleblog.com/2019/08/stable-channel-update-for-desktop.html https://security.archlinux.org/CVE-2019-5867 https://security.archlinux.org/CVE-2019-5868
Workaround
None.