ArchLinux: 201910-7: chromium: multiple issues
Summary
- CVE-2019-13693 (arbitrary code execution)
A use-after-free vulnerability has been found in the IndexedDB
component of the chromium browser before 77.0.3865.120.
- CVE-2019-13694 (arbitrary code execution)
A use-after-free vulnerability has been found in the WebRTC component
of the chromium browser before 77.0.3865.120.
- CVE-2019-13695 (arbitrary code execution)
A use-after-free vulnerability has been found in the audio component of
the chromium browser before 77.0.3865.120.
- CVE-2019-13696 (arbitrary code execution)
A use-after-free vulnerability has been found in the V8 component of
the chromium browser before 77.0.3865.120.
- CVE-2019-13697 (information disclosure)
A cross-origin size leak vulnerability has been found in the chromium
browser before 77.0.3865.120.
Resolution
Upgrade to 77.0.3865.120-1.
# pacman -Syu "chromium>=77.0.3865.120-1"
The problems have been fixed upstream in version 77.0.3865.120.
References
https://chromereleases.googleblog.com/2019/10/stable-channel-update-for-desktop.html https://security.archlinux.org/CVE-2019-13693 https://security.archlinux.org/CVE-2019-13694 https://security.archlinux.org/CVE-2019-13695 https://security.archlinux.org/CVE-2019-13696 https://security.archlinux.org/CVE-2019-13697
Workaround
None.