ArchLinux: 202001-5: chromium: multiple issues
Summary
- CVE-2020-6378 (arbitrary code execution)
A use-after-free vulnerability has been found in the speech recognizer
component of the chromium browser before 79.0.3945.130.
- CVE-2020-6379 (arbitrary code execution)
A use-after-free vulnerability has been found in the speech recognizer
component of the chromium browser before 79.0.3945.130.
- CVE-2020-6380 (insufficient validation)
An extension message verification error has been found in the chromium
browser before 79.0.3945.130.
Resolution
Upgrade to 79.0.3945.130-1.
# pacman -Syu "chromium>=79.0.3945.130-1"
The problems have been fixed upstream in version 79.0.3945.130.
References
https://chromereleases.googleblog.com/2020/01/stable-channel-update-for-desktop_16.html https://security.archlinux.org/CVE-2020-6378 https://security.archlinux.org/CVE-2020-6379 https://security.archlinux.org/CVE-2020-6380
Workaround
None.