• [SECURITY] [DSA 3507-1] chromium-browser security update

    From Michael Gilbert@1:229/2 to All on Sat Mar 5 22:30:02 2016
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-3507-1 [email protected] https://www.debian.org/security/ Michael Gilbert
    March 05, 2016 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : chromium-browser
    CVE ID : CVE-2015-8126 CVE-2016-1630 CVE-2016-1631 CVE-2016-1632
    CVE-2016-1633 CVE-2016-1634 CVE-2016-1635 CVE-2016-1636
    CVE-2016-1637 CVE-2016-1638 CVE-2016-1639 CVE-2016-1640
    CVE-2016-1641 CVE-2016-1642

    Several vulnerabilities have been discovered in the chromium web browser.

    CVE-2015-8126

    Joerg Bornemann discovered multiple buffer overflow issues in the
    libpng library.

    CVE-2016-1630

    Mariusz Mlynski discovered a way to bypass the Same Origin Policy
    in Blink/Webkit.

    CVE-2016-1631

    Mariusz Mlynski discovered a way to bypass the Same Origin Policy
    in the Pepper Plugin API.

    CVE-2016-1632

    A bad cast was discovered.

    CVE-2016-1633

    cloudfuzzer discovered a use-after-free issue in Blink/Webkit.

    CVE-2016-1634

    cloudfuzzer discovered a use-after-free issue in Blink/Webkit.

    CVE-2016-1635

    Rob Wu discovered a use-after-free issue in Blink/Webkit.

    CVE-2016-1636

    A way to bypass SubResource Integrity validation was discovered.

    CVE-2016-1637

    Keve Nagy discovered an information leak in the skia library.

    CVE-2016-1638

    Rob Wu discovered a WebAPI bypass issue.

    CVE-2016-1639

    Khalil Zhani discovered a use-after-free issue in the WebRTC
    implementation.

    CVE-2016-1640

    Luan Herrera discovered an issue with the Extensions user interface.

    CVE-2016-1641

    Atte Kettunen discovered a use-after-free issue in the handling of
    favorite icons.

    CVE-2016-1642

    The chrome 49 development team found and fixed various issues
    during internal auditing. Also multiple issues were fixed in
    the v8 javascript library, version 4.9.385.26.

    For the stable distribution (jessie), these problems have been fixed in
    version 49.0.2623.75-1~deb8u1.

    For the testing distribution (stretch), these problems will be fixed soon.

    For the unstable distribution (sid), these problems have been fixed in
    version 49.0.2623.75-1.

    We recommend that you upgrade your chromium-browser packages.

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1

    iQQcBAEBCgAGBQJW202dAAoJELjWss0C1vRz9jwgAL0TiUnwvdutW66wNE/T+jYW W6yyrzLOJkoocT1wpp0opB75noRxqx6KDrGOcKByyK7vrM2y/amsId6NyvD8mRm5 RTfEa/4d00Y61W7xDXeyvOazTyCW3+LCZK6Lg1XYvXleYdun4vNWIxsEcBdqezD6 0oLrwHv+TuWCqdQxB3ZccXBVOOP8RVZIcq/BCAL6pP9VqwtR+jR4aYLsQ8RPn8M+ wR+QO6Ab+Dzja/+l3NE4+q1Oy9uyfr49Afhfvc2bGlTiUgCPMZiACEZVoH4CzQi6 Da1cB5vckoQhqixf/+HSp8ohQ6jOTemDfwpbXnyqKtpdoeCfbuOwGipZHFb/mxCb APCWZwcfVIvNzCZr4Vq33VpWHS53AE5yMiWTKqOqQsSNfvEwP1QB+8ixDFqgIxlf BbfuzyfeBkh6ylGpd4Lvsav6BK66pRvNr+liFbqyacm4z98oN0K+Soyi1FxJTBDA ipb28crv+LkNSX4yX3aFptPedLaYyqtR25MYKtjw4Ro6Q0aw0jdQfABzol9vyJiM /SaS4rSJ1zGV7e2nk9nYrDPDzsL9nzar92/qvRIVSXJJ0gGIvG5En8iPg6OLOZPz rLyECn30QtT35bKfy5+/VXc6rArb2IEcR4irKMSp3zon8WkX5amVPE05RKDzPX8p 16Kh1lmHRk0ng3FJtHtbZHe/T3W8FwPUWUhr47Rl2vlqFDlZM8zAgZ0DOlbzmwQJ 2Wjuy9dycoKqQIhE2opgKQf1+Q6rJHEB7FGz3oG6VOic7vCvf3lms3kBH4brOGwV xukXWds7xYQA54ItqzSnUzkgJfxBxVrm1++CLM70R6HNkDtdUrHwKLjzWqlwzTfd S0VpePjPVpEHqnT4mEs9bP8hqPno3upzwm0+rDTLocAECtAH+2y+B3UnYxIvSMcW oeSqjEuJKrKGcuhvUp/grnG/f1J2o+d0/10nkDV+XjHDzsH69qTT/Szs4cCS1r+L 1Ig/p0FwXSUMyO4V+nKv6SBG053OGWJWK24EuSIMcae5ZwPAZzni0dl1K1lEo8jf Z/tRBJNci0nvKKSHj5NURt9go87zrDB6oDCnk1hHYKCNIH2m9pKBvA8B6hC+KxVu gBjDEDEkdqyWTJqdQBN37729LMTh35N7p3qL/ddObTvzmuywsbEyufOCdV+TbgXy OYYbIumES6M3wryst/SzU/xUHZHT6FT1BLx39Sjyhq8UEnErQ5hPeMhUsFlj8gEI MIm3FbPIVfYuU0W+yl5gaLxLMELWwcdqyzSkZD0WyWXXoAUsC1iVIh1y8/uQlJxf v2eW0faGXHuifgjGOV2vqBMA9rkAmP6uNrgVbcdsgUqWxcatEduTXOAZy68zocI=
    =TLjN
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)