Upstream has released version 45.0.2454.101 on September 24: http://googlechromereleases.blogspot.com/2015/09/stable-channel-update_24.html This fixes two new security issues. This is the current version in the stable channel: http://googlechromereleases.blogspot.com/search/label/Stable%20updates Reproducible: Steps to Reproduce:
Bugfix updates since the last security update: http://googlechromereleases.blogspot.com/2015/09/stable-channel-update_15.html http://googlechromereleases.blogspot.com/2015/09/stable-channel-refresh.html
RedHat has issued an advisory for this today (September 29): https://rhn.redhat.com/errata/RHSA-2015-1841.html
Checked into SVN. Will push later when the build system is usable.
Updated packages building now for Mageia 5 and Cauldron. Advisory: ======================== Updated chromium-browser-stable packages fix security vulnerabilities: Two flaws were found in the processing of malformed web content. A web page containing malicious content could cause Chromium to bypass cross origin restrictions, and access or modify data from an unrelated web site (CVE-2015-1303, CVE-2015-1304). References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1303 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1304 http://googlechromereleases.blogspot.com/2015/09/stable-channel-refresh.html http://googlechromereleases.blogspot.com/2015/09/stable-channel-update_15.html http://googlechromereleases.blogspot.com/2015/09/stable-channel-update_24.html https://rhn.redhat.com/errata/RHSA-2015-1841.html ======================== Updated packages in core/updates_testing: ======================== chromium-browser-45.0.2454.101-1.mga5 chromium-browser-stable-45.0.2454.101-1.mga5 from chromium-browser-45.0.2454.101-1.mga5.src.rpm
Assignee: cjw => qa-bugs
Advisory uploaded.
Whiteboard: (none) => advisory
Testing complete mga5 32 Ensured chromium-browser-stable was required by chromium-browser. Tested with general browsing.
Whiteboard: advisory => has_procedure advisory mga5-32-ok
Tested mga5-64. Jetstream test for JavaScript, acid3 general use, general browsing. All OK Validating. Ready to push to updates.
Whiteboard: has_procedure advisory mga5-32-ok => has_procedure advisory mga5-32-ok mga5-64-okKeywords: (none) => validated_updateCC: (none) => wrw105, sysadmin-bugs
An update for this issue has been pushed to Mageia Updates repository. http://advisories.mageia.org/MGASA-2015-0389.html
Status: NEW => RESOLVEDResolution: (none) => FIXED