|
|
Log in / Subscribe / Register

chromium: multiple vulnerabilities

Package(s):chromium CVE #(s):CVE-2016-1630 CVE-2016-1631 CVE-2016-1632 CVE-2016-1633 CVE-2016-1634 CVE-2016-1635 CVE-2016-1636 CVE-2016-1637 CVE-2016-1638 CVE-2016-1639 CVE-2016-1640 CVE-2016-1641 CVE-2016-1642
Created:March 4, 2016 Updated:March 9, 2016
Description:

From the Arch Linux advisory:

CVE-2016-1630: Same-origin bypass in Blink. Credit to Mariusz Mlynski.

CVE-2016-1631: Same-origin bypass in Pepper Plugin. Credit to Mariusz Mlynski.

CVE-2016-1632: Bad cast in Extensions.

CVE-2016-1633, CVE-2016-1634: Use-after-free in Blink. Credit to cloudfuzzer.

CVE-2016-1635: Use-after-free in Blink. Credit to Rob Wu.

CVE-2016-1636: SRI Validation Bypass. Credit to Ryan Lester and Bryant Zadegan.

CVE-2016-1637: Information Leak in Skia. Credit to Keve Nagy.

CVE-2016-1638: WebAPI Bypass. Credit to Rob Wu.

CVE-2016-1639: Use-after-free in WebRTC. Credit to Khalil Zhani.

CVE-2016-1640: Origin confusion in Extensions UI. Credit to Luan Herrera.

CVE-2016-1641: Use-after-free in Favicon. Credit to Atte Kettunen of OUSPG.

CVE-2016-1642: Various fixes from internal audits, fuzzing and other initiatives.

Alerts:
Mageia MGASA-2016-0127 chromium-browser-stable 2016-03-31
openSUSE openSUSE-SU-2016:0729-1 Chromium 2016-03-11
Gentoo 201603-09 chromium 2016-03-12
openSUSE openSUSE-SU-2016:0684-1 Chromium 2016-03-08
SUSE SUSE-SU-2016:0665-1 Chromium 2016-03-06
openSUSE openSUSE-SU-2016:0664-1 Chromium 2016-03-06
Debian DSA-3507-1 chromium-browser 2016-03-05
Red Hat RHSA-2016:0359-01 chromium-browser 2016-03-07
Arch Linux ASA-201603-1 chromium 2016-03-03

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds