Bug 26603 - chromium-browser-stable new security issue fixed in 81.0.4044.138
Summary: chromium-browser-stable new security issue fixed in 81.0.4044.138
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal critical
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: mga7-64-ok
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2020-05-08 02:02 CEST by David Walser
Modified: 2020-05-10 10:56 CEST (History)
4 users (show)

See Also:
Source RPM: chromium-browser-stable-81.0.4044.129-1.mga7.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2020-05-08 02:02:37 CEST
Upstream has released version 81.0.4044.138 on May 5:
https://chromereleases.googleblog.com/2020/05/stable-channel-update-for-desktop.html

This is the current version in the stable channel:
http://googlechromereleases.blogspot.com/search/label/Stable%20updates

It fixes two new security issues.
Comment 1 Christiaan Welvaart 2020-05-09 14:02:33 CEST
Updated packages are available for testing:

MGA7
SRPM:
chromium-browser-stable-81.0.4044.138-1.mga7.src.rpm
RPMS:
chromium-browser-81.0.4044.138-1.mga7.i586.rpm
chromium-browser-stable-81.0.4044.138-1.mga7.i586.rpm
chromium-browser-81.0.4044.138-1.mga7.x86_64.rpm
chromium-browser-stable-81.0.4044.138-1.mga7.x86_64.rpm



Advisory:



Chromium-browser 81.0.4044.138 fixes security issues:

Multiple flaws were found in the way Chromium 81.0.4044.129 processes various types of web content, where loading a web page containing malicious content could cause Chromium to crash, execute arbitrary code, or disclose sensitive information. (CVE-2020-6464, CVE-2020-6831)


References:
https://chromereleases.googleblog.com/2020/05/stable-channel-update-for-desktop.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-6464
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-6831

CC: (none) => cjw
Assignee: cjw => qa-bugs

Comment 2 Bill Wilkinson 2020-05-09 18:12:28 CEST
Tested mga7-64
general browsing, youtube video, jetstream, all OK

CC: (none) => wrw105
Whiteboard: (none) => mga7-64-ok

Thomas Backlund 2020-05-10 10:21:17 CEST

CC: (none) => tmb, sysadmin-bugs
Keywords: (none) => advisory, validated_update

Comment 3 Mageia Robot 2020-05-10 10:56:46 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2020-0210.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.