Debian Security Advisory
DSA-3667-1 chromium-browser -- security update
- Date Reported:
- 15 Sep 2016
- Affected Packages:
- Security database references:
- In Mitre's CVE dictionary: CVE-2016-5170, CVE-2016-5171, CVE-2016-5172, CVE-2016-5173, CVE-2016-5174, CVE-2016-5175, CVE-2016-7395.
- More information:
Several vulnerabilities have been discovered in the chromium web browser.
A use-after-free issue was discovered in Blink/Webkit.
Another use-after-free issue was discovered in Blink/Webkit.
A resource bypass issue was discovered in extensions.
Andrey Kovalev discoved a way to bypass the popup blocker.
The chrome development team found and fixed various issues during internal auditing.
An uninitialized memory read issue was discovered in the skia library.
For the stable distribution (jessie), these problems have been fixed in version 53.0.2785.113-1~deb8u1.
For the testing distribution (stretch), these problems will be fixed soon.
For the unstable distribution (sid), these problems have been fixed in version 53.0.2785.113-1.
We recommend that you upgrade your chromium-browser packages.