MGASA-2014-0107
Dashboard / Vulnerabilities / MGASA-2014-0107
MGASA-2014-0107
Summary: Updated chromium-browser-stable packages address multiple vulnerabilities
Details: Use-after-free related to web contents (CVE-2013-6653). Bad cast in SVG (CVE-2013-6654). Use-after-free in layout (CVE-2013-6655). Information leaks in XSS auditor (CVE-2013-6656, CVE-2013-6657). Use-after-free in layout (CVE-2013-6658). Issue with certificates validation in TLS handshake (CVE-2013-6659). Information leak in drag and drop (CVE-2013-6660). Various fixes from internal audits, fuzzing and other initiatives. Of these, seven are fixes for issues that could have allowed for sandbox escapes from compromised renderers (CVE-2013-6661).
References: https://advisories.mageia.org/MGASA-2014-0107.html, http://googlechromereleases.blogspot.com/2014/02/stable-channel-update_20.html, https://bugs.mageia.org/show_bug.cgi?id=12885
Affected packages
Package
Name: chromium-browser-stable
Purl: pkg:rpm/mageia/chromium-browser-stable?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
