Bug 19493

Summary: chromium-browser-stable new security issues fixed in 53.0.2785.143
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: QA Team <qa-bugs>
Status: RESOLVED FIXED QA Contact: Sec team <security>
Severity: critical    
Priority: Normal CC: cjw, davidwhodgins, sysadmin-bugs, wrw105
Version: 5Keywords: validated_update
Target Milestone: ---   
Hardware: All   
OS: Linux   
URL: http://lwn.net/Vulnerabilities/702474/
Whiteboard: has_procedure mga5-64-ok advisory
Source RPM: chromium-browser-stable-53.0.2785.113-1.mga5.src.rpm CVE:
Status comment:

Description David Walser 2016-09-30 11:34:43 CEST
Upstream has released version 53.0.2785.143 on September 29:
https://googlechromereleases.blogspot.com/2016/09/stable-channel-update-for-desktop_29.html

This fixes several new security issues.

This is the current version in the stable channel:
http://googlechromereleases.blogspot.com/search/label/Stable%20updates

There was also a bugfix release since our last update:
https://googlechromereleases.blogspot.com/2016/09/stable-channel-update-for-desktop_14.html
Comment 1 Christiaan Welvaart 2016-10-03 07:44:05 CEST
Updated packages are available for testing:

MGA5
SRPM:
chromium-browser-stable-53.0.2785.143-1.mga5.src.rpm
RPMS:
chromium-browser-stable-53.0.2785.143-1.mga5.i586.rpm
chromium-browser-53.0.2785.143-1.mga5.i586.rpm
chromium-browser-stable-53.0.2785.143-1.mga5.x86_64.rpm
chromium-browser-53.0.2785.143-1.mga5.x86_64.rpm



Advisory:



Chromium-browser-stable 53.0.2785.143 provides fixes for security issues: a use-after-free bug in V8 (CVE-2016-5177) and various problems found in upstream's internal audits, fuzzing, and other initiatives (CVE-2016-5178).


References:
https://googlechromereleases.blogspot.com/2016/09/stable-channel-update-for-desktop_29.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5177
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5178

CC: (none) => cjw
Assignee: cjw => qa-bugs

Comment 2 Bill Wilkinson 2016-10-03 18:34:46 CEST
Tested mga5-64:

Jetstream, Acid3, general browsing, youtube video, all OK.

CC: (none) => wrw105
Whiteboard: (none) => has_procedure mga5-64-ok

Dave Hodgins 2016-10-04 13:29:58 CEST

Keywords: (none) => validated_update
Whiteboard: has_procedure mga5-64-ok => has_procedure mga5-64-ok advisory
CC: (none) => davidwhodgins, sysadmin-bugs

David Walser 2016-10-04 13:51:37 CEST

URL: (none) => http://lwn.net/Vulnerabilities/702474/

Comment 3 Mageia Robot 2016-10-04 14:21:46 CEST
An update for this issue has been pushed to the Mageia Updates repository.

http://advisories.mageia.org/MGASA-2016-0335.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED