Bug 9703

Summary: chromium-browser-stable new version 26.0.1410.65 available
Product: Mageia Reporter: David Walser <luigiwalser>
Component: RPM PackagesAssignee: QA Team <qa-bugs>
Status: RESOLVED FIXED QA Contact: Sec team <security>
Severity: normal    
Priority: Normal CC: dmorganec, sysadmin-bugs, tmb
Version: 2Keywords: validated_update
Target Milestone: ---   
Hardware: i586   
OS: Linux   
Whiteboard: has_procedure mga2-32-ok mga2-64-ok
Source RPM: chromium-browser-stable CVE:
Status comment:

Description David Walser 2013-04-11 18:08:21 CEST
Upstream has released 26.0.1410.57 to fix CVE-2013-0927:
http://googlechromereleases.blogspot.com/2013/04/chrome-os-stable-channel-update.html

Stable channel is up to 26.0.1410.65:
http://googlechromereleases.blogspot.com/search/label/Stable%20updates

Reproducible: 

Steps to Reproduce:
David Walser 2013-04-11 18:08:28 CEST

Whiteboard: (none) => MGA2TOO

Comment 1 D Morgan 2013-04-30 21:33:38 CEST
available on updates_testing and freeze push request sent.
Comment 2 David Walser 2013-05-01 03:18:40 CEST
chromium-browser-stable-26.0.1410.65-1.mga3 uploaded for Cauldron.

Version: Cauldron => 2
Whiteboard: MGA2TOO => (none)

Comment 3 David Walser 2013-05-01 03:19:33 CEST
Assigning to QA.

chromium-browser-stable-26.0.1410.65-1.mga2 uploaded to Mageia 2 updates_testing.

Advisory to come later.

CC: (none) => dmorganec
Assignee: dmorganec => qa-bugs

Comment 4 claire robinson 2013-05-01 10:02:03 CEST
Tested ok i586

Java (although not on java.com test page, it's just a grey box), flash, addons, sunspider, browsing etc

Whiteboard: (none) => has_procedure mga2-32-ok

Comment 5 claire robinson 2013-05-01 13:53:40 CEST
Testing complete mga2 64

Validating

Advisory not yet available.

SRPM: chromium-browser-stable-26.0.1410.65-1.mga2

Could sysadmin please push from core/updates_testing to core/updates when it's ready.

Thanks!

Keywords: (none) => validated_update
Whiteboard: has_procedure mga2-32-ok => has_procedure mga2-32-ok mga2-64-ok
CC: (none) => sysadmin-bugs

Comment 6 David Walser 2013-05-01 18:47:36 CEST
OK, the Chrome Stable Updates blog is confusing.  Turns out that CVE was actually in Chrome OS in Pango, and not in the Chrome Browser itself.  They seem to have both things mixed together on this blog.  There don't appear to be any security issues in the browser fixed since the last version we released, just some "stability improvements" according to the blog.  More details are in the commit logs:
http://build.chromium.org/f/chromium/perf/dashboard/ui/changelog.html?url=/branches/1410/src&range=189671:193017&mode=html
http://build.chromium.org/f/chromium/perf/dashboard/ui/changelog.html?url=/branches/1410/src&range=192696:193261&mode=html

Sorry for the confusion.

I'm not sure we really *need* to release this update for Mageia 2, but if we do the advisory can simply read:

This updates Chromium browser to version 26.0.1410.65, which contains some
stability improvements.

References:
http://googlechromereleases.blogspot.com/2013/04/stable-channel-update.html
http://googlechromereleases.blogspot.com/2013/04/stable-channel-update_10.html

Component: Security => RPM Packages
Severity: critical => normal

David Walser 2013-05-01 18:48:19 CEST

Summary: chromium-browser-stable new security issue CVE-2013-0927 => chromium-browser-stable new version 26.0.1410.65 available

Comment 7 claire robinson 2013-05-01 18:55:09 CEST
Thanks David. It's built and tested, stability improvements are good :)

Advisory then
--------------
This updates Chromium browser to version 26.0.1410.65, which contains some
stability improvements.

References:
http://googlechromereleases.blogspot.com/2013/04/stable-channel-update.html
http://googlechromereleases.blogspot.com/2013/04/stable-channel-update_10.html
--------------

SRPM: chromium-browser-stable-26.0.1410.65-1.mga2

Could sysadmin please push from core/updates_testing to core/updates when it's ready.

Thanks!
Comment 8 claire robinson 2013-05-01 18:56:04 CEST
oops bad copy/paste. It is ready now.
Comment 9 Thomas Backlund 2013-05-02 19:40:04 CEST
Update pushed:
https://wiki.mageia.org/en/Support/Advisories/MGAA-2013-0017

Status: NEW => RESOLVED
CC: (none) => tmb
Resolution: (none) => FIXED