Debian Security Advisory
DSA-4917-1 chromium -- security update
- Date Reported:
- 17 May 2021
- Affected Packages:
- Security database references:
- In Mitre's CVE dictionary: CVE-2021-30506, CVE-2021-30507, CVE-2021-30508, CVE-2021-30509, CVE-2021-30510, CVE-2021-30511, CVE-2021-30512, CVE-2021-30513, CVE-2021-30514, CVE-2021-30515, CVE-2021-30516, CVE-2021-30517, CVE-2021-30518, CVE-2021-30519, CVE-2021-30520.
- More information:
Several vulnerabilities have been discovered in the chromium web browser.
@retsew0x01 discovered an error in the Web App installation interface.
Alison Huffman discovered an error in the Offline mode.
Leecraso and Guang Gong discovered a buffer overflow issue in the Media Feeds implementation.
David Erceg discovered an out-of-bounds write issue in the Tab Strip implementation.
Weipeng Jiang discovered a race condition in the aura window manager.
David Erceg discovered an out-of-bounds read issue in the Tab Strip implementation.
ZhanJia Song discovered a use-after-free issue in the notifications implementation.
koocola and Wang discovered a use-after-free issue in the Autofill feature.
Rong Jian and Guang Gong discovered a use-after-free issue in the file system access API.
ZhanJia Song discovered a buffer overflow issue in the browsing history.
Jun Kokatsu discovered a buffer overflow issue in the reader mode.
asnine discovered a use-after-free issue in the Payments feature.
Khalil Zhani discovered a use-after-free issue in the Tab Strip implementation.
For the stable distribution (buster), these problems have been fixed in version 90.0.4430.212-1~deb10u1.
We recommend that you upgrade your chromium packages.
For the detailed security status of chromium please refer to its security tracker page at: https://security-tracker.debian.org/tracker/chromium