Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -1 articles for you...
89

Fedora 40: FEDORA-2024-f1117faa03 High: chromium type confusion issues

update to 130.0.6723.69 * High CVE-2024-10229: Inappropriate implementation in Extensions * High CVE-2024-10230: Type Confusion in V8 * High CVE-2024-10231: Type Confusion in V8. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-f1117faa03 2024-10-28 03:52:20.506444 -------------------------------------------------------------------------------- Name : chromium Product : Fedora 40 Version : 130.0.6723.69 Release : 1.fc40 URL : http://www.chromium.org/Home Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: update to 130.0.6723.69 * High CVE-2024-10229: Inappropriate implementation in Extensions * High CVE-2024-10230: Type Confusion in V8 * High CVE-2024-10231: Type Confusion in V8 -------------------------------------------------------------------------------- ChangeLog: * Sat Oct 26 2024 Than Ngo - 130.0.6723.69-1 - update to 130.0.6723.69 * High CVE-2024-10229: Inappropriate implementation in Extensions * High CVE-2024-10230: Type Confusion in V8 * High CVE-2024-10231: Type Confusion in V8 * Mon Oct 21 2024 Than Ngo - 130.0.6723.58-2 - Add missing pthread stack size for ppc64 (openpower-patches) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2319007 - CVE-2024-9955 chromium: Use after free in WebAuthentication [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2319007 [ 2 ] Bug #2319008 - CVE-2024-9955 chromium: Use after free in WebAuthentication [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2319008 [ 3 ] Bug #2319009 - CVE-2024-9954 chromium: Use after free in AI [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2319009 [ 4 ]Bug #2319010 - CVE-2024-9954 chromium: Use after free in AI [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2319010 [ 5 ] Bug #2319011 - CVE-2024-9966 chromium: Inappropriate implementation in Navigations [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2319011 [ 6 ] Bug #2319012 - CVE-2024-9966 chromium: Inappropriate implementation in Navigations [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2319012 [ 7 ] Bug #2319013 - CVE-2024-9958 chromium: Inappropriate implementation in PictureInPicture [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2319013 [ 8 ] Bug #2319014 - CVE-2024-9958 chromium: Inappropriate implementation in PictureInPicture [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2319014 [ 9 ] Bug #2321525 - CVE-2024-10231 chromium: Type Confusion in V8 [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2321525 [ 10 ] Bug #2321526 - CVE-2024-10231 chromium: Type Confusion in V8 [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2321526 [ 11 ] Bug #2321527 - CVE-2024-10229 chromium: Inappropriate implementation in Extensions [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2321527 [ 12 ] Bug #2321528 - CVE-2024-10229 chromium: Inappropriate implementation in Extensions [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2321528 [ 13 ] Bug #2321529 - CVE-2024-10230 chromium: Type Confusion in V8 [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2321529 [ 14 ] Bug #2321530 - CVE-2024-10230 chromium: Type Confusion in V8 [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2321530 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-f1117faa03' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Keep informed about security patches for Fedora Chromium version 130.0.6723.69 related to vulnerabilities marked as CVE-2024-10232, 33, and 34.. chromium updates, security notifications, Fedora advisory. . LinuxSecurity.com Team

Calendar 2 Oct 28, 2024 Fedora
89

Fedora 40: 2024-b5dd623284 High: Chromium Type Confusion Issue

update to 125.0.6422.112 High CVE-2024-5274: Type Confusion in V8. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-b5dd623284 2024-05-29 03:35:14.764026 -------------------------------------------------------------------------------- Name : chromium Product : Fedora 40 Version : 125.0.6422.112 Release : 2.fc40 URL : http://www.chromium.org/Home Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: update to 125.0.6422.112 High CVE-2024-5274: Type Confusion in V8 -------------------------------------------------------------------------------- ChangeLog: * Tue May 28 2024 Than Ngo - 125.0.6422.112-2 - Workaround for build error on pp64le * Sun May 26 2024 Than Ngo - 125.0.6422.112-1 - update to 125.0.6422.112 * High CVE-2024-5274: Type Confusion in V8 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2283083 - CVE-2024-5274 chromium: chromium-browser: Type Confusion in V8 [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2283083 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-b5dd623284' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Tackling the Critical Type Mismatch Issue in V8 via Chromium Patch 125.0.6422.112 on Fedora.. Fedora Update, Chromium Security, Type Confusion. . LinuxSecurity.com Team

Calendar 2 May 29, 2024 Fedora
91

Gentoo: GLSA-202210-16 High Severity Remote Code Execution in Chromium

Multiple vulnerabilities have been found in Chromium and its derivatives, the worst of which could result in remote code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202210-16 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: Chromium, Google Chrome, Microsoft Edge: Multiple Vulnerabilities Date: October 31, 2022 Bugs: #873817, #874855, #876855, #873217 ID: 202210-16 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in Chromium and its derivatives, the worst of which could result in remote code execution. Background ========= Chromium is an open-source browser project that aims to build a safer, faster, and more stable way for all users to experience the web. Google Chrome is one fast, simple, and secure browser for all your devices. Microsoft Edge is a browser that combines a minimal design with sophisticated technology to make the web faster, safer, and easier. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-client/chromium < 106.0.5249.119 > = 106.0.5249.119 2 www-client/chromium-bin < 106.0.5249.119 > = 106.0.5249.119 3 www-client/google-chrome < 106.0.5249.119 > = 106.0.5249.119 4 www-client/microsoft-edge < 106.0.1370.37 > = 106.0.1370.37 Description ========== Multiple vulnerabilities have been discovered in Chromium, Google Chrome, and Microsoft Edge. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVEidentifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All Chromium users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =www-client/chromium-106.0.5249.119" All Chromium binary users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =www-client/chromium-bin-106.0.5249.119" All Google Chrome users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =www-client/google-chrome-106.0.5249.119" All Microsoft Edge users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =www-client/microsoft-edge-106.0.1370.37" References ========= [ 1 ] CVE-2022-3201 https://nvd.nist.gov/vuln/detail/CVE-2022-3201 [ 2 ] CVE-2022-3304 https://nvd.nist.gov/vuln/detail/CVE-2022-3304 [ 3 ] CVE-2022-3305 https://nvd.nist.gov/vuln/detail/CVE-2022-3305 [ 4 ] CVE-2022-3306 https://nvd.nist.gov/vuln/detail/CVE-2022-3306 [ 5 ] CVE-2022-3307 https://nvd.nist.gov/vuln/detail/CVE-2022-3307 [ 6 ] CVE-2022-3308 https://nvd.nist.gov/vuln/detail/CVE-2022-3308 [ 7 ] CVE-2022-3309 https://nvd.nist.gov/vuln/detail/CVE-2022-3309 [ 8 ] CVE-2022-3310 https://nvd.nist.gov/vuln/detail/CVE-2022-3310 [ 9 ] CVE-2022-3311 https://nvd.nist.gov/vuln/detail/CVE-2022-3311 [ 10 ] CVE-2022-3312 https://nvd.nist.gov/vuln/detail/CVE-2022-3312 [ 11 ] CVE-2022-3313 https://nvd.nist.gov/vuln/detail/CVE-2022-3313 [ 12 ] CVE-2022-3314 https://nvd.nist.gov/vuln/detail/CVE-2022-3314 [ 13 ] CVE-2022-3315 https://nvd.nist.gov/vuln/detail/CVE-2022-3315 [ 14 ] CVE-2022-3316 https://nvd.nist.gov/vuln/detail/CVE-2022-3316 [ 15 ] CVE-2022-3317 https://nvd.nist.gov/vuln/detail/CVE-2022-3317 [ 16 ] CVE-2022-3318 https://nvd.nist.gov/vuln/detail/CVE-2022-3318 [ 17 ] CVE-2022-3370 https://nvd.nist.gov/vuln/detail/CVE-2022-3370 [ 18 ]CVE-2022-3373 https://nvd.nist.gov/vuln/detail/CVE-2022-3373 [ 19 ] CVE-2022-3445 https://nvd.nist.gov/vuln/detail/CVE-2022-3445 [ 20 ] CVE-2022-3446 https://nvd.nist.gov/vuln/detail/CVE-2022-3446 [ 21 ] CVE-2022-3447 https://nvd.nist.gov/vuln/detail/CVE-2022-3447 [ 22 ] CVE-2022-3448 https://nvd.nist.gov/vuln/detail/CVE-2022-3448 [ 23 ] CVE-2022-3449 https://nvd.nist.gov/vuln/detail/CVE-2022-3449 [ 24 ] CVE-2022-3450 https://nvd.nist.gov/vuln/detail/CVE-2022-3450 [ 25 ] CVE-2022-41035 https://nvd.nist.gov/vuln/detail/CVE-2022-41035 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202210-16 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2022 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Gentoo has issued a critical alert about vulnerabilities in Chromium and its derivatives. Users should review and apply the recommended patches immediately. Gentoo Security Advisory, Chromium Update, High Severity Security. . LinuxSecurity.com Team

Calendar 2 Oct 30, 2022 Gentoo
198

Arch Linux: 202107-30 High: Chromium Code Execution Issues

The package chromium before version 91.0.4472.164-1 is vulnerable to arbitrary code execution. . Arch Linux Security Advisory ASA-202107-30 ========================================= Severity: High Date : 2021-07-16 CVE-ID : CVE-2021-30541 CVE-2021-30559 CVE-2021-30560 CVE-2021-30561 CVE-2021-30562 CVE-2021-30563 CVE-2021-30564 Package : chromium Type : arbitrary code execution Remote : Yes Link : https://security.archlinux.org/AVG-2166 Summary ====== The package chromium before version 91.0.4472.164-1 is vulnerable to arbitrary code execution. Resolution ========= Upgrade to 91.0.4472.164-1. # pacman -Syu "chromium> =91.0.4472.164-1" The problems have been fixed upstream in version 91.0.4472.164. Workaround ========= None. Description ========== - CVE-2021-30541 (arbitrary code execution) A use after free security issue has been found in the V8 component of the Chromium browser engine before version 91.0.4472.164. - CVE-2021-30559 (arbitrary code execution) An out of bounds write security issue has been found in the ANGLE component of the Chromium browser engine before version 91.0.4472.164. - CVE-2021-30560 (arbitrary code execution) A use after free security issue has been found in the Blink XSLT component of the Chromium browser engine before version 91.0.4472.164. - CVE-2021-30561 (arbitrary code execution) A type confusion security issue has been found in the V8 component of the Chromium browser engine before version 91.0.4472.164. - CVE-2021-30562 (arbitrary code execution) A use after free security issue has been found in the WebSerial component of the Chromium browser engine before version 91.0.4472.164. - CVE-2021-30563 (arbitrary code execution) A type confusion security issue has been found in the V8 component of the Chromium browser engine before version 91.0.4472.164. Google is aware of reports that an exploit for CVE-2021-30563 exists in the wild. - CVE-2021-30564 (arbitrary code execution) A heap buffer overflow security issue has been found in theWebXR component of the Chromium browser engine before version 91.0.4472.164. Impact ===== A remote attacker could execute arbitrary code through a crafted web page. Google is aware that an exploit for one of the security issues exists in the wild. References ========= https://chromereleases.googleblog.com/2021/07/stable-channel-update-for-desktop.html https://security.archlinux.org/CVE-2021-30541 https://security.archlinux.org/CVE-2021-30559 https://security.archlinux.org/CVE-2021-30560 https://security.archlinux.org/CVE-2021-30561 https://security.archlinux.org/CVE-2021-30562 https://security.archlinux.org/CVE-2021-30563 https://security.archlinux.org/CVE-2021-30564 . Update chromium package to version 91.0.4472.164-1 to address critical vulnerabilities linked to arbitrary code execution on Arch Linux.. Arch Linux advisory, Chrome update, security patch for Chromium. . LinuxSecurity.com Team

Calendar 2 Jul 16, 2021 ArchLinux
202

openSUSE: 2021:0047-1 Critical: Chromium Use After Free Issue

An update that fixes 13 vulnerabilities is now available. . openSUSE Security Update: Security update for chromium ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:0047-1 Rating: important References: #1180645 Cross-References: CVE-2020-15995 CVE-2020-16043 CVE-2021-21106 CVE-2021-21107 CVE-2021-21108 CVE-2021-21109 CVE-2021-21110 CVE-2021-21111 CVE-2021-21112 CVE-2021-21113 CVE-2021-21114 CVE-2021-21115 CVE-2021-21116 Affected Products: openSUSE Backports SLE-15-SP1 ______________________________________________________________________________ An update that fixes 13 vulnerabilities is now available. Description: This update for chromium fixes the following issues: - Update to 87.0.4280.141 (boo#1180645) - CVE-2021-21106: Use after free in autofill - CVE-2021-21107: Use after free in drag and drop - CVE-2021-21108: Use after free in media - CVE-2021-21109: Use after free in payments - CVE-2021-21110: Use after free in safe browsing - CVE-2021-21111: Insufficient policy enforcement in WebUI - CVE-2021-21112: Use after free in Blink - CVE-2021-21113: Heap buffer overflow in Skia - CVE-2020-16043: Insufficient data validation in networking - CVE-2021-21114: Use after free in audio - CVE-2020-15995: Out of bounds write in V8 - CVE-2021-21115: Use after free in safe browsing - CVE-2021-21116: Heap buffer overflow in audio - Use main URLs instead of redirects in master preferences This update was imported from the openSUSE:Leap:15.1:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP1: zypper in -t patchopenSUSE-2021-47=1 Package List: - openSUSE Backports SLE-15-SP1 (aarch64 x86_64): chromedriver-87.0.4280.141-bp151.3.150.1 chromium-87.0.4280.141-bp151.3.150.1 References: https://www.suse.com/security/cve/CVE-2020-15995.html https://www.suse.com/security/cve/CVE-2020-16043.html https://www.suse.com/security/cve/CVE-2021-21106.html https://www.suse.com/security/cve/CVE-2021-21107.html https://www.suse.com/security/cve/CVE-2021-21108.html https://www.suse.com/security/cve/CVE-2021-21109.html https://www.suse.com/security/cve/CVE-2021-21110.html https://www.suse.com/security/cve/CVE-2021-21111.html https://www.suse.com/security/cve/CVE-2021-21112.html https://www.suse.com/security/cve/CVE-2021-21113.html https://www.suse.com/security/cve/CVE-2021-21114.html https://www.suse.com/security/cve/CVE-2021-21115.html https://www.suse.com/security/cve/CVE-2021-21116.html https://bugzilla.suse.com/1180645 . Addressing 13 chromium vulnerabilities with essential updates for openSUSE users to bolster security measures and optimize functionality.. openSUSE Backports SLE-15-SP1, Chromedriver Update, Chrome Security Patch. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jan 11, 2021 Important OpenSUSE
202

openSUSE: 2020:1181-1 Low Severity: chromium Backports Fixes

An update that fixes 6 vulnerabilities is now available.. openSUSE Security Update: Security update of chromium ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:1181-1 Rating: low References: #1174582 Cross-References: CVE-2020-6532 CVE-2020-6537 CVE-2020-6538 CVE-2020-6539 CVE-2020-6540 CVE-2020-6541 Affected Products: openSUSE Backports SLE-15-SP2 ______________________________________________________________________________ An update that fixes 6 vulnerabilities is now available. Description: Chromium was updated to 84.0.4147.105 (boo#1174582): * CVE-2020-6537: Type Confusion in V8 * CVE-2020-6538: Inappropriate implementation in WebView * CVE-2020-6532: Use after free in SCTP * CVE-2020-6539: Use after free in CSS * CVE-2020-6540: Heap buffer overflow in Skia * CVE-2020-6541: Use after free in WebUSB This update was imported from the openSUSE:Leap:15.2:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP2: zypper in -t patch openSUSE-2020-1181=1 Package List: - openSUSE Backports SLE-15-SP2 (aarch64 x86_64): chromedriver-84.0.4147.105-bp152.2.10.1 chromium-84.0.4147.105-bp152.2.10.1 References: https://www.suse.com/security/cve/CVE-2020-6532.html https://www.suse.com/security/cve/CVE-2020-6537.html https://www.suse.com/security/cve/CVE-2020-6538.html https://www.suse.com/security/cve/CVE-2020-6539.html https://www.suse.com/security/cve/CVE-2020-6540.html https://www.suse.com/security/cve/CVE-2020-6541.html https://bugzilla.suse.com/1174582 -- . Critical openSUSE patch resolves 6 minor vulnerabilities in chromium to enhance user security andimprove functionality.. openSUSE Security Update, Chromium Version, Patch Instructions. . Severity: Low. LinuxSecurity.com Team

Calendar 2 Sep 18, 2020 Low OpenSUSE
87

Debian Buster: DSA-4714-3 Moderate: Chromium Service Worker Flaw

The previous update for chromium released as DSA 4714-2 contained a flaw in the service worker implementation. This problem causes the browser to crash when a connection error occurs. Updated chromium packages are now available that correct this issue. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4714-3 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Michael Gilbert July 13, 2020 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : chromium Debian Bug : 963548 The previous update for chromium released as DSA 4714-2 contained a flaw in the service worker implementation. This problem causes the browser to crash when a connection error occurs. Updated chromium packages are now available that correct this issue. For the stable distribution (buster), this problem has been fixed in version 83.0.4103.116-1~deb10u3. We recommend that you upgrade your chromium packages. For the detailed security status of chromium please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/chromium Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Newly released chromium updates address service worker issues leading to system crashes on Debian Buster.. Debian Chromium Update, Service Worker Issue, Security Fixes. . LinuxSecurity.com Team

Calendar 2 Jul 13, 2020 Debian
91

Gentoo: GLSA-201804-22 Normal: Multiple Issues in Chromium Chrome

Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could result in the execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201804-22 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Chromium, Google Chrome: Multiple vulnerabilities Date: April 24, 2018 Bugs: #653696 ID: 201804-22 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could result in the execution of arbitrary code. Background ========= Chromium is an open-source browser project that aims to build a safer, faster, and more stable way for all users to experience the web. Google Chrome is one fast, simple, and secure browser for all your devices. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-client/chromium < 66.0.3359.117 > = 66.0.3359.117 2 www-client/google-chrome < 66.0.3359.117 > = 66.0.3359.117 ------------------------------------------------------------------- 2 affected packages Description ========== Multiple vulnerabilities have been discovered in Chromium and Google Chrome. Please review the referenced CVE identifiers and Google Chrome Releases for details. Impact ===== A remote attacker could possibly execute arbitrary code with the privileges of the process, cause a Denial of Service condition, bypass content security controls, or conduct URLspoofing. Workaround ========= There is no known workaround at this time. Resolution ========= All Chromium users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v "> =www-client/chromium-66.0.3359.117" All Google Chrome users should upgrade to the latest version: # emerge --sync # emerge -a --oneshot -v "> =www-client/google-chrome-66.0.3359.117" References ========= [ 1 ] CVE-2018-6085 https://nvd.nist.gov/vuln/detail/CVE-2018-6085 [ 2 ] CVE-2018-6086 https://nvd.nist.gov/vuln/detail/CVE-2018-6086 [ 3 ] CVE-2018-6087 https://nvd.nist.gov/vuln/detail/CVE-2018-6087 [ 4 ] CVE-2018-6088 https://nvd.nist.gov/vuln/detail/CVE-2018-6088 [ 5 ] CVE-2018-6089 https://nvd.nist.gov/vuln/detail/CVE-2018-6089 [ 6 ] CVE-2018-6090 https://nvd.nist.gov/vuln/detail/CVE-2018-6090 [ 7 ] CVE-2018-6091 https://nvd.nist.gov/vuln/detail/CVE-2018-6091 [ 8 ] CVE-2018-6092 https://nvd.nist.gov/vuln/detail/CVE-2018-6092 [ 9 ] CVE-2018-6093 https://nvd.nist.gov/vuln/detail/CVE-2018-6093 [ 10 ] CVE-2018-6094 https://nvd.nist.gov/vuln/detail/CVE-2018-6094 [ 11 ] CVE-2018-6095 https://nvd.nist.gov/vuln/detail/CVE-2018-6095 [ 12 ] CVE-2018-6096 https://nvd.nist.gov/vuln/detail/CVE-2018-6096 [ 13 ] CVE-2018-6097 https://nvd.nist.gov/vuln/detail/CVE-2018-6097 [ 14 ] CVE-2018-6098 https://nvd.nist.gov/vuln/detail/CVE-2018-6098 [ 15 ] CVE-2018-6099 https://nvd.nist.gov/vuln/detail/CVE-2018-6099 [ 16 ] CVE-2018-6100 https://nvd.nist.gov/vuln/detail/CVE-2018-6100 [ 17 ] CVE-2018-6101 https://nvd.nist.gov/vuln/detail/CVE-2018-6101 [ 18 ] CVE-2018-6102 https://nvd.nist.gov/vuln/detail/CVE-2018-6102 [ 19 ] CVE-2018-6103 https://nvd.nist.gov/vuln/detail/CVE-2018-6103 [ 20 ] CVE-2018-6104 https://nvd.nist.gov/vuln/detail/CVE-2018-6104 [ 21 ] CVE-2018-6105 https://nvd.nist.gov/vuln/detail/CVE-2018-6105 [ 22 ] CVE-2018-6106 https://nvd.nist.gov/vuln/detail/CVE-2018-6106 [ 23 ] CVE-2018-6107 https://nvd.nist.gov/vuln/detail/CVE-2018-6107 [ 24 ] CVE-2018-6108 https://nvd.nist.gov/vuln/detail/CVE-2018-6108 [ 25 ] CVE-2018-6109 https://nvd.nist.gov/vuln/detail/CVE-2018-6109 [ 26 ] CVE-2018-6110 https://nvd.nist.gov/vuln/detail/CVE-2018-6110 [ 27 ] CVE-2018-6111 https://nvd.nist.gov/vuln/detail/CVE-2018-6111 [ 28 ] CVE-2018-6112 https://nvd.nist.gov/vuln/detail/CVE-2018-6112 [ 29 ] CVE-2018-6113 https://nvd.nist.gov/vuln/detail/CVE-2018-6113 [ 30 ] CVE-2018-6114 https://nvd.nist.gov/vuln/detail/CVE-2018-6114 [ 31 ] CVE-2018-6115 https://nvd.nist.gov/vuln/detail/CVE-2018-6115 [ 32 ] CVE-2018-6116 https://nvd.nist.gov/vuln/detail/CVE-2018-6116 [ 33 ] CVE-2018-6117 https://nvd.nist.gov/vuln/detail/CVE-2018-6117 [ 34 ] Google Chrome Release 20180417 https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201804-22 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2018 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Enhance Chromium and Google Chrome to address several security flaws that could facilitate code execution or lead to service interruptions.. Gentoo Advisory, Chromium Updates, Google Chrome Security, Code Execution Risks, Browser Vulnerabilities. . LinuxSecurity.com Team

Calendar 2 Apr 24, 2018 Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here