Jump to content
Compatible Support Forums
Sign in to follow this  
news

[RHSA-2016:2919-01] Important: chromium-browser security update

Recommended Posts

-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA1

 

=====================================================================

Red Hat Security Advisory

 

Synopsis: Important: chromium-browser security update

Advisory ID: RHSA-2016:2919-01

Product: Red Hat Enterprise Linux Supplementary

Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-2919.html

Issue date: 2016-12-07

CVE Names: CVE-2016-5203 CVE-2016-5204 CVE-2016-5205

CVE-2016-5206 CVE-2016-5207 CVE-2016-5208

CVE-2016-5209 CVE-2016-5210 CVE-2016-5211

CVE-2016-5212 CVE-2016-5213 CVE-2016-5214

CVE-2016-5215 CVE-2016-5216 CVE-2016-5217

CVE-2016-5218 CVE-2016-5219 CVE-2016-5220

CVE-2016-5221 CVE-2016-5222 CVE-2016-5223

CVE-2016-5224 CVE-2016-5225 CVE-2016-5226

CVE-2016-9650 CVE-2016-9651 CVE-2016-9652

=====================================================================

 

1. Summary:

 

An update for chromium-browser is now available for Red Hat Enterprise

Linux 6 Supplementary.

 

Red Hat Product Security has rated this update as having a security impact

of Important. A Common Vulnerability Scoring System (CVSS) base score,

which gives a detailed severity rating, is available for each vulnerability

from the CVE link(s) in the References section.

 

2. Relevant releases/architectures:

 

Red Hat Enterprise Linux Desktop Supplementary (v. 6) - i386, x86_64

Red Hat Enterprise Linux Server Supplementary (v. 6) - i386, x86_64

Red Hat Enterprise Linux Workstation Supplementary (v. 6) - i386, x86_64

 

3. Description:

 

Chromium is an open-source web browser, powered by WebKit (Blink).

 

This update upgrades Chromium to version 55.0.2883.75.

 

Security Fix(es):

 

* Multiple flaws were found in the processing of malformed web content. A

web page containing malicious content could cause Chromium to crash,

execute arbitrary code, or disclose sensitive information when visited by

the victim. (CVE-2016-5203, CVE-2016-5204, CVE-2016-5205, CVE-2016-5206,

CVE-2016-5207, CVE-2016-5208, CVE-2016-5209, CVE-2016-5210, CVE-2016-5211,

CVE-2016-5212, CVE-2016-5213, CVE-2016-9651, CVE-2016-9652, CVE-2016-5214,

CVE-2016-5215, CVE-2016-5216, CVE-2016-5217, CVE-2016-5218, CVE-2016-5219,

CVE-2016-5220, CVE-2016-5221, CVE-2016-5222, CVE-2016-5223, CVE-2016-5224,

CVE-2016-5225, CVE-2016-5226, CVE-2016-9650)

 

4. Solution:

 

For details on how to apply this update, which includes the changes

described in this advisory, refer to:

 

https://access.redhat.com/articles/11258

 

After installing the update, Chromium must be restarted for the changes to

take effect.

 

5. Bugs fixed (https://bugzilla.redhat.com/):

 

1400850 - CVE-2016-9651 chromium-browser: private property access in v8

1400851 - CVE-2016-5208 chromium-browser: universal xss in blink

1400852 - CVE-2016-5207 chromium-browser: universal xss in blink

1400853 - CVE-2016-5206 chromium-browser: same-origin bypass in pdfium

1400854 - CVE-2016-5205 chromium-browser: universal xss in blink

1400855 - CVE-2016-5204 chromium-browser: universal xss in blink

1400856 - CVE-2016-5209 chromium-browser: out of bounds write in blink

1400857 - CVE-2016-5203 chromium-browser: use after free in pdfium

1400859 - CVE-2016-5210 chromium-browser: out of bounds write in pdfium

1400861 - CVE-2016-5212 chromium-browser: local file disclosure in devtools

1400862 - CVE-2016-5211 chromium-browser: use after free in pdfium

1400863 - CVE-2016-5213 chromium-browser: use after free in v8

1400864 - CVE-2016-5214 chromium-browser: file download protection bypass

1400865 - CVE-2016-5216 chromium-browser: use after free in pdfium

1400866 - CVE-2016-5215 chromium-browser: use after free in webaudio

1400867 - CVE-2016-5217 chromium-browser: use of unvalidated data in pdfium

1400868 - CVE-2016-5218 chromium-browser: address spoofing in omnibox

1400869 - CVE-2016-5219 chromium-browser: use after free in v8

1400870 - CVE-2016-5221 chromium-browser: integer overflow in angle

1400871 - CVE-2016-5220 chromium-browser: local file access in pdfium

1400872 - CVE-2016-5222 chromium-browser: address spoofing in omnibox

1400873 - CVE-2016-9650 chromium-browser: csp referrer disclosure

1400875 - CVE-2016-5223 chromium-browser: integer overflow in pdfium

1400876 - CVE-2016-5226 chromium-browser: limited xss in blink

1400877 - CVE-2016-5225 chromium-browser: csp bypass in blink

1400878 - CVE-2016-5224 chromium-browser: same-origin bypass in svg

1400879 - CVE-2016-9652 chromium-browser: various fixes from internal audits

 

6. Package List:

 

Red Hat Enterprise Linux Desktop Supplementary (v. 6):

 

i386:

chromium-browser-55.0.2883.75-1.el6.i686.rpm

chromium-browser-debuginfo-55.0.2883.75-1.el6.i686.rpm

 

x86_64:

chromium-browser-55.0.2883.75-1.el6.x86_64.rpm

chromium-browser-debuginfo-55.0.2883.75-1.el6.x86_64.rpm

 

Red Hat Enterprise Linux Server Supplementary (v. 6):

 

i386:

chromium-browser-55.0.2883.75-1.el6.i686.rpm

chromium-browser-debuginfo-55.0.2883.75-1.el6.i686.rpm

 

x86_64:

chromium-browser-55.0.2883.75-1.el6.x86_64.rpm

chromium-browser-debuginfo-55.0.2883.75-1.el6.x86_64.rpm

 

Red Hat Enterprise Linux Workstation Supplementary (v. 6):

 

i386:

chromium-browser-55.0.2883.75-1.el6.i686.rpm

chromium-browser-debuginfo-55.0.2883.75-1.el6.i686.rpm

 

x86_64:

chromium-browser-55.0.2883.75-1.el6.x86_64.rpm

chromium-browser-debuginfo-55.0.2883.75-1.el6.x86_64.rpm

 

These packages are GPG signed by Red Hat for security. Our key and

details on how to verify the signature are available from

https://access.redhat.com/security/team/key/

 

7. References:

 

https://access.redhat.com/security/cve/CVE-2016-5203

https://access.redhat.com/security/cve/CVE-2016-5204

https://access.redhat.com/security/cve/CVE-2016-5205

https://access.redhat.com/security/cve/CVE-2016-5206

https://access.redhat.com/security/cve/CVE-2016-5207

https://access.redhat.com/security/cve/CVE-2016-5208

https://access.redhat.com/security/cve/CVE-2016-5209

https://access.redhat.com/security/cve/CVE-2016-5210

https://access.redhat.com/security/cve/CVE-2016-5211

https://access.redhat.com/security/cve/CVE-2016-5212

https://access.redhat.com/security/cve/CVE-2016-5213

https://access.redhat.com/security/cve/CVE-2016-5214

https://access.redhat.com/security/cve/CVE-2016-5215

https://access.redhat.com/security/cve/CVE-2016-5216

https://access.redhat.com/security/cve/CVE-2016-5217

https://access.redhat.com/security/cve/CVE-2016-5218

https://access.redhat.com/security/cve/CVE-2016-5219

https://access.redhat.com/security/cve/CVE-2016-5220

https://access.redhat.com/security/cve/CVE-2016-5221

https://access.redhat.com/security/cve/CVE-2016-5222

https://access.redhat.com/security/cve/CVE-2016-5223

https://access.redhat.com/security/cve/CVE-2016-5224

https://access.redhat.com/security/cve/CVE-2016-5225

https://access.redhat.com/security/cve/CVE-2016-5226

https://access.redhat.com/security/cve/CVE-2016-9650

https://access.redhat.com/security/cve/CVE-2016-9651

https://access.redhat.com/security/cve/CVE-2016-9652

https://access.redhat.com/security/updates/classification/#important

https://googlechromereleases.blogspot.com/2016/12/stable-channel-update-for-desktop.html

 

8. Contact:

 

The Red Hat security contact is . More contact

details at https://access.redhat.com/security/team/contact/

 

Copyright 2016 Red Hat, Inc.

-----BEGIN PGP SIGNATURE-----

Version: GnuPG v1

 

iD8DBQFYSGRcXlSAg2UNWIIRAiHmAJ9Nl7uHXgQUjZU81KybHyCCHmCi8QCgr8fs

CEnkb1YITLftO/cJ3o/KLWA=

=cu2B

-----END PGP SIGNATURE-----

 

 

--

 

Share this post


Link to post

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now
Sign in to follow this  

×