chromium: multiple vulnerabilities
| Package(s): | chromium-browser | CVE #(s): | CVE-2016-1651 CVE-2016-1652 CVE-2016-1653 CVE-2016-1654 CVE-2016-1655 CVE-2016-1657 CVE-2016-1658 CVE-2016-1659 CVE-2016-1656 | ||||||||||||||||||||||||||||||||||||||||
| Created: | April 15, 2016 | Updated: | April 25, 2016 | ||||||||||||||||||||||||||||||||||||||||
| Description: | From the Debian advisory:
CVE-2016-1651: An out-of-bounds read issue was discovered in the pdfium library. CVE-2016-1652: A cross-site scripting issue was discovered in extension bindings. CVE-2016-1653: Choongwoo Han discovered an out-of-bounds write issue in the v8 javascript library. CVE-2016-1654: Atte Kettunen discovered an uninitialized memory read condition. CVE-2016-1655: Rob Wu discovered a use-after-free issue related to extensions. CVE-2016-1657: Luan Herrera discovered a way to spoof URLs. CVE-2016-1658: Antonio Sanso discovered an information leak related to extensions. CVE-2016-1659: The chrome development team found and fixed various issues during internal auditing. Added CVE-2016-1656 from Red Hat advisory: android downloaded file path restriction bypass | ||||||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||||||
