Bug 19493 - chromium-browser-stable new security issues fixed in 53.0.2785.143
Summary: chromium-browser-stable new security issues fixed in 53.0.2785.143
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 5
Hardware: All Linux
Priority: Normal critical
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL: http://lwn.net/Vulnerabilities/702474/
Whiteboard: has_procedure mga5-64-ok advisory
Keywords: validated_update
Depends on:
Blocks:
 
Reported: 2016-09-30 11:34 CEST by David Walser
Modified: 2016-10-04 14:21 CEST (History)
4 users (show)

See Also:
Source RPM: chromium-browser-stable-53.0.2785.113-1.mga5.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2016-09-30 11:34:43 CEST
Upstream has released version 53.0.2785.143 on September 29:
https://googlechromereleases.blogspot.com/2016/09/stable-channel-update-for-desktop_29.html

This fixes several new security issues.

This is the current version in the stable channel:
http://googlechromereleases.blogspot.com/search/label/Stable%20updates

There was also a bugfix release since our last update:
https://googlechromereleases.blogspot.com/2016/09/stable-channel-update-for-desktop_14.html
Comment 1 Christiaan Welvaart 2016-10-03 07:44:05 CEST
Updated packages are available for testing:

MGA5
SRPM:
chromium-browser-stable-53.0.2785.143-1.mga5.src.rpm
RPMS:
chromium-browser-stable-53.0.2785.143-1.mga5.i586.rpm
chromium-browser-53.0.2785.143-1.mga5.i586.rpm
chromium-browser-stable-53.0.2785.143-1.mga5.x86_64.rpm
chromium-browser-53.0.2785.143-1.mga5.x86_64.rpm



Advisory:



Chromium-browser-stable 53.0.2785.143 provides fixes for security issues: a use-after-free bug in V8 (CVE-2016-5177) and various problems found in upstream's internal audits, fuzzing, and other initiatives (CVE-2016-5178).


References:
https://googlechromereleases.blogspot.com/2016/09/stable-channel-update-for-desktop_29.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5177
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5178

CC: (none) => cjw
Assignee: cjw => qa-bugs

Comment 2 Bill Wilkinson 2016-10-03 18:34:46 CEST
Tested mga5-64:

Jetstream, Acid3, general browsing, youtube video, all OK.

CC: (none) => wrw105
Whiteboard: (none) => has_procedure mga5-64-ok

Dave Hodgins 2016-10-04 13:29:58 CEST

Keywords: (none) => validated_update
Whiteboard: has_procedure mga5-64-ok => has_procedure mga5-64-ok advisory
CC: (none) => davidwhodgins, sysadmin-bugs

David Walser 2016-10-04 13:51:37 CEST

URL: (none) => http://lwn.net/Vulnerabilities/702474/

Comment 3 Mageia Robot 2016-10-04 14:21:46 CEST
An update for this issue has been pushed to the Mageia Updates repository.

http://advisories.mageia.org/MGASA-2016-0335.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.