ArchLinux: 202002-11: chromium: multiple issues
Summary
- CVE-2020-6407 (information disclosure)
An out-of-bounds memory access vulnerability has been found in the
streams component of chromium before 80.0.3987.122.
- CVE-2020-6418 (arbitrary code execution)
A type confusion vulnerability has been found in the V8 component of
chromium before 80.0.3987.122.
Resolution
Upgrade to 80.0.3987.122-1.
# pacman -Syu "chromium>=80.0.3987.122-1"
The problems have been fixed upstream in version 80.0.3987.122.
References
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop_24.html https://security.archlinux.org/CVE-2020-6407 https://security.archlinux.org/CVE-2020-6418
Workaround
None.