Alerts This Week
Warning Icon 1 914
Alerts This Week
Warning Icon 1 914

Fedora 31: FEDORA-2020-aea86f913e Moderate: Chromium Browser Update

fedora
Calendar Grey October 2, 2020
Dist Fedora Esm H88
Version 85.0.4183.121 of Chromium for Fedora 31 resolves vulnerabilities and improves connectivity with this release.
Update to 85.0.4183.121

Summary

Chromium is an open-source web browser, powered by WebKit (Blink).

Update to 85.0.4183.121. Why? Because security, that's why. It fixes these CVEs:

CVE-2020-15960 CVE-2020-15961 CVE-2020-15962 CVE-2020-15963 CVE-2020-15964

CVE-2020-15965 CVE-2020-15966 It also has a fix for an issue where

networking... uh... didn't. ---- Update Chromium to 85.0.4183.102. Fix issue

where unpackaged components prevented hardware accelerated rendering from

working. Also fixes the following security issues: CVE-2020-6573 CVE-2020-6574

CVE-2020-6575 CVE-2020-6576 CVE-2020-15959

* Mon Sep 21 2020 Tom Callaway - 85.0.4183.121-1

- update to 85.0.4183.121

- apply upstream fix for networking issue with CookieMonster

* Tue Sep 8 2020 Tom Callaway - 85.0.4183.102-1

- update to 85.0.4183.102

- install ANGLE so files (libEGL.so, libGLESv2.so)

[ 1 ] Bug #1877090 - CVE-2020-6573 chromium-browser: Use after free in video

https://bugzilla.redhat.com/show_bug.cgi?id=1877090

[ 2 ] Bug #1877091 - CVE-2020-6574 chromium-browser: Insufficient policy enforcement in installer

https://bugzilla.redhat.com/show_bug.cgi?id=1877091

[ 3 ] Bug #1877093 - CVE-2020-6575 chromium-browser: Race in Mojo

https://bugzilla.redhat.com/show_bug.cgi?id=1877093

[ 4 ] Bug #1877094 - CVE-2020-6576 chromium-browser: Use after free in offscreen canvas

https://bugzilla.redhat.com/show_bug.cgi?id=1877094

[ 5 ] Bug #1877095 - CVE-2020-15959 chromium-browser: Insufficient policy enforcement in networking

https://bugzilla.redhat.com/show_bug.cgi?id=1877095

[ 6 ] Bug #1881593 - CVE-2020-15960 chromium-browser: Out of bounds read in storage

https://bugzilla.redhat.com/show_bug.cgi?id=1881593

[ 7 ] Bug #1881595 - CVE-2020-15961 chromium-browser: Insufficient policy enforcement in extensions

https://bugzilla.redhat.com/show_bug.cgi?id=1881595

[ 8 ] Bug #1881596 - CVE-2020-15962 chromium-browser: Insufficient policy enforcement in serial

https://bugzilla.redhat.com/show_bug.cgi?id=1881596

[ 9 ] Bug #1881597 - CVE-2020-15963 chromium-browser: Insufficient policy enforcement in extensions

https://bugzilla.redhat.com/show_bug.cgi?id=1881597

[ 10 ] Bug #1881598 - CVE-2020-15965 chromium-browser: Out of bounds write in V8

https://bugzilla.redhat.com/show_bug.cgi?id=1881598

[ 11 ] Bug #1881599 - CVE-2020-15966 chromium-browser: Insufficient policy enforcement in extensions

https://bugzilla.redhat.com/show_bug.cgi?id=1881599

[ 12 ] Bug #1881600 - CVE-2020-15964 chromium-browser: Insufficient data validation in media

https://bugzilla.redhat.com/show_bug.cgi?id=1881600

su -c 'dnf upgrade --advisory FEDORA-2020-aea86f913e' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
important
Lowest
Low
Medium
High
Critical

Product: Fedora 31
Version: 85.0.4183.121
Release: 1.fc31
Summary: A WebKit (Blink) powered web browser

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here