ArchLinux: 201904-12: chromium: multiple issues
Summary
- CVE-2019-5805 (arbitrary code execution)
A use-after-free vulnerability has been found in the PDFium component
of the chromium browser before 74.0.3729.108.
- CVE-2019-5806 (arbitrary code execution)
An integer overflow vulnerability has been found in the Andle component
of the chromium browser before 74.0.3729.108.
- CVE-2019-5807 (arbitrary code execution)
A memory corruption vulnerability has been found in the V8 component of
the chromium browser before 74.0.3729.108.
- CVE-2019-5808 (arbitrary code execution)
A use-after-free vulnerability has been found in the Blink component of
the chromium browser before 74.0.3729.108.
- CVE-2019-5809 (arbitrary code execution)
A use-after-free vulnerability has been found in the Blink component of
the chromium browser before 74.0.3729.108.
- CVE-2019-5810 (information disclosure)
A user information disclosure vulnerability has been found in the
Autofill component of the chromium browser before 74.0.3729.108.
- CVE-2019-5811 (access restriction bypass)
A CORS bypass vulnerability has been found in the Blink component of
the chromium browser before 74.0.3729.108.
- CVE-2019-5813 (information disclosure)
An out-of-bounds read vulnerability has been found in the V8 component
of the chromium browser before 74.0.3729.108.
- CVE-2019-5814 (access restriction bypass)
A CORS bypass vulnerability has been found in the Blink component of
the chromium browser before 74.0.3729.108.
- CVE-2019-5815 (arbitrary code execution)
A heap-based buffer overflow vulnerability has been found in the Blink
component of the chromium browser before 74.0.3729.108.
- CVE-2019-5818 (information disclosure)
An uninitialized value vulnerability has been found in the media reader
component of the chromium browser before 74.0.3729.108.
- CVE-2019-5819 (insufficient validation)
An incorrect escaping vulnerability has been found in the developer
tools component of the chromium browser before 74.0.3729.108.
- CVE-2019-5820 (arbitrary code execution)
An integer overflow vulnerability has been found in the PDFium
component of the chromium browser before 74.0.3729.108.
- CVE-2019-5821 (arbitrary code execution)
An integer overflow vulnerability has been found in the PDFium
component of the chromium browser before 74.0.3729.108.
- CVE-2019-5822 (access restriction bypass)
A CORS bypass vulnerability has been found in the download manager
component of the chromium browser before 74.0.3729.108.
- CVE-2019-5823 (access restriction bypass)
A forced navigation from service worker vulnerability has been found in
the chromium browser before 74.0.3729.108.
Resolution
Upgrade to 74.0.3729.108-1.
# pacman -Syu "chromium>=74.0.3729.108-1"
The problems have been fixed upstream in version 74.0.3729.108.
References
https://chromereleases.googleblog.com/2019/04/stable-channel-update-for-desktop_23.html https://bugs.chromium.org/p/chromium/issues/detail https://bugs.chromium.org/p/chromium/issues/detail https://bugs.chromium.org/p/chromium/issues/detail https://bugs.chromium.org/p/chromium/issues/detail https://bugs.chromium.org/p/chromium/issues/detail https://bugs.chromium.org/p/chromium/issues/detail https://bugs.chromium.org/p/chromium/issues/detail https://bugs.chromium.org/p/chromium/issues/detail https://bugs.chromium.org/p/chromium/issues/detail https://bugs.chromium.org/p/chromium/issues/detail https://bugs.chromium.org/p/chromium/issues/detail https://bugs.chromium.org/p/chromium/issues/detail https://bugs.chromium.org/p/chromium/issues/detail https://bugs.chromium.org/p/chromium/issues/detail https://bugs.chromium.org/p/chromium/issues/detail https://security.archlinux.org/CVE-2019-5805 https://security.archlinux.org/CVE-2019-5806 https://security.archlinux.org/CVE-2019-5807 https://security.archlinux.org/CVE-2019-5808 https://security.archlinux.org/CVE-2019-5809 https://security.archlinux.org/CVE-2019-5810 https://security.archlinux.org/CVE-2019-5811 https://security.archlinux.org/CVE-2019-5813 https://security.archlinux.org/CVE-2019-5814 https://security.archlinux.org/CVE-2019-5815 https://security.archlinux.org/CVE-2019-5818 https://security.archlinux.org/CVE-2019-5819 https://security.archlinux.org/CVE-2019-5820 https://security.archlinux.org/CVE-2019-5821 https://security.archlinux.org/CVE-2019-5822 https://security.archlinux.org/CVE-2019-5823
Workaround
None.