chromium: multiple vulnerabilities
| Package(s): | chromium | CVE #(s): | CVE-2016-1630 CVE-2016-1631 CVE-2016-1632 CVE-2016-1633 CVE-2016-1634 CVE-2016-1635 CVE-2016-1636 CVE-2016-1637 CVE-2016-1638 CVE-2016-1639 CVE-2016-1640 CVE-2016-1641 CVE-2016-1642 | ||||||||||||||||||||||||||||||||||||
| Created: | March 4, 2016 | Updated: | March 9, 2016 | ||||||||||||||||||||||||||||||||||||
| Description: | From the Arch Linux advisory: CVE-2016-1630: Same-origin bypass in Blink. Credit to Mariusz Mlynski. CVE-2016-1631: Same-origin bypass in Pepper Plugin. Credit to Mariusz Mlynski. CVE-2016-1632: Bad cast in Extensions. CVE-2016-1633, CVE-2016-1634: Use-after-free in Blink. Credit to cloudfuzzer. CVE-2016-1635: Use-after-free in Blink. Credit to Rob Wu. CVE-2016-1636: SRI Validation Bypass. Credit to Ryan Lester and Bryant Zadegan. CVE-2016-1637: Information Leak in Skia. Credit to Keve Nagy. CVE-2016-1638: WebAPI Bypass. Credit to Rob Wu. CVE-2016-1639: Use-after-free in WebRTC. Credit to Khalil Zhani. CVE-2016-1640: Origin confusion in Extensions UI. Credit to Luan Herrera. CVE-2016-1641: Use-after-free in Favicon. Credit to Atte Kettunen of OUSPG. CVE-2016-1642: Various fixes from internal audits, fuzzing and other initiatives. | ||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||
