MGASA-2014-0037
Dashboard / Vulnerabilities / MGASA-2014-0037
MGASA-2014-0037
Summary: Updated chromium-browser-stable package fixes multiple vulnerabilities
Details: Use-after-free related to forms (CVE-2013-6641). Unprompted sync with an attackers Google account (CVE-2013-6643). Various fixes from internal audits, fuzzing and other initiatives (CVE-2013-6644). Use-after-free related to speech input elements (CVE-2013-6645). Use-after-free in web workers (CVE-2013-6646). Use-after-free in SVG images (CVE-2013-6649). Memory corruption in v8 before version 3.22.24.16 (CVE-2013-6650).
References: https://advisories.mageia.org/MGASA-2014-0037.html, http://googlechromereleases.blogspot.com/2014/01/stable-channel-update.html, http://googlechromereleases.blogspot.com/2014/01/stable-channel-update_27.html, https://bugs.mageia.org/show_bug.cgi?id=12314
Affected packages
Package
Name: chromium-browser-stable
Purl: pkg:rpm/mageia/chromium-browser-stable?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
