Debian Security Advisory

DSA-3564-1 chromium-browser -- security update

Date Reported:
02 May 2016
Affected Packages:
chromium-browser
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2016-1660, CVE-2016-1661, CVE-2016-1662, CVE-2016-1663, CVE-2016-1664, CVE-2016-1665, CVE-2016-1666.
More information:

Several vulnerabilities have been discovered in the chromium web browser.

  • CVE-2016-1660

    Atte Kettunen discovered an out-of-bounds write issue.

  • CVE-2016-1661

    Wadih Matar discovered a memory corruption issue.

  • CVE-2016-1662

    Rob Wu discovered a use-after-free issue related to extensions.

  • CVE-2016-1663

    A use-after-free issue was discovered in Blink's bindings to V8.

  • CVE-2016-1664

    Wadih Matar discovered a way to spoof URLs.

  • CVE-2016-1665

    gksgudtjr456 discovered an information leak in the v8 javascript library.

  • CVE-2016-1666

    The chrome development team found and fixed various issues during internal auditing.

For the stable distribution (jessie), these problems have been fixed in version 50.0.2661.94-1~deb8u1.

For the testing distribution (stretch), these problems will be fixed soon.

For the unstable distribution (sid), these problems have been fixed in version 50.0.2661.94-1.

We recommend that you upgrade your chromium-browser packages.