|
|
Log in / Subscribe / Register

Arch Linux alert ASA-201911-7 (electron)

From:  Remi Gacogne <rgacogne@archlinux.org>
To:  arch-security@archlinux.org
Subject:  [ASA-201911-7] electron: arbitrary code execution
Date:  Mon, 4 Nov 2019 20:36:06 +0100
Message-ID:  <fa96d8ed-a0aa-e648-0d2e-2dd00e93b23b@archlinux.org>

Arch Linux Security Advisory ASA-201911-7 ========================================= Severity: Critical Date : 2019-11-04 CVE-ID : CVE-2019-13720 Package : electron Type : arbitrary code execution Remote : Yes Link : https://security.archlinux.org/AVG-1061 Summary ======= The package electron before version 7.0.1-1 is vulnerable to arbitrary code execution. Resolution ========== Upgrade to 7.0.1-1. # pacman -Syu "electron>=7.0.1-1" The problem has been fixed upstream in version 7.0.1. Workaround ========== None. Description =========== A use-after-free vulnerability has been found in the audio component of the chromium browser before 78.0.3904.87. Google is aware of reports that an exploit for this vulnerability exists in the wild. Impact ====== A remote attacker can execute arbitrary code on the affected host. References ========== https://github.com/electron/electron/commit/25b3ee29cf9a8... https://chromereleases.googleblog.com/2019/10/stable-chan... https://crbug.com/1019226 https://security.archlinux.org/CVE-2019-13720


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds