ArchLinux: 202004-1: chromium: arbitrary code execution
Summary
- CVE-2020-6450 (arbitrary code execution)
A use-after-free vulnerability has been found in the WebAudio component
of the chromium browser before 80.0.3987.162.
- CVE-2020-6451 (arbitrary code execution)
A use-after-free vulnerability has been found in the WebAudio component
of the chromium browser before 80.0.3987.162.
- CVE-2020-6452 (arbitrary code execution)
A head-based buffer overflow vulnerability has been found in the Media
component of the chromium browser before 80.0.3987.162.
Resolution
Upgrade to 80.0.3987.162-1.
# pacman -Syu "chromium>=80.0.3987.162-1"
The problems have been fixed upstream in version 80.0.3987.162.
References
https://chromereleases.googleblog.com/2020/03/stable-channel-update-for-desktop_31.html https://security.archlinux.org/CVE-2020-6450 https://security.archlinux.org/CVE-2020-6451 https://security.archlinux.org/CVE-2020-6452
Workaround
None.