MGASA-2015-0265
Dashboard / Vulnerabilities / MGASA-2015-0265
MGASA-2015-0265
Summary: Updated chromium-browser package fixes security vulnerability
Details: A scheme validation error in WebUI (CVE-2015-1266). Two cross-origin bypass issues in Blink (CVE-2015-1267, CVE-2015-1268). A normalization error in the HSTS/HPKP preload list (CVE-2015-1269). This update also disables the automatic, silent downloading and installation of "external components" like the hotword extension.
References: https://advisories.mageia.org/MGASA-2015-0265.html, https://bugs.mageia.org/show_bug.cgi?id=16190, http://googlechromereleases.blogspot.com/2015/06/chrome-stable-update.html, https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=786909
Affected packages
Package
Name: chromium-browser-stable
Purl: pkg:rpm/mageia/chromium-browser-stable?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
