- Issued:
- 2016-08-09
- Updated:
- 2016-08-09
RHSA-2016:1580 - Security Advisory
Synopsis
Important: chromium-browser security update
Type/Severity
Security Advisory: Important
Red Hat Insights patch analysis
Identify and remediate systems affected by this advisory.
Topic
An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary.
Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Description
Chromium is an open-source web browser, powered by WebKit (Blink).
This update upgrades Chromium to version 52.0.2743.116.
Security Fix(es):
- Multiple flaws were found in the processing of malformed web content. A web page containing malicious content could cause Chromium to crash, execute arbitrary code, or disclose sensitive information when visited by the victim. (CVE-2016-5139, CVE-2016-5140, CVE-2016-5141, CVE-2016-5142, CVE-2016-5146, CVE-2016-5143, CVE-2016-5144, CVE-2016-5145)
Solution
For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258
After installing the update, Chromium must be restarted for the changes to take effect.
Affected Products
- Red Hat Enterprise Linux Server 6 x86_64
- Red Hat Enterprise Linux Server 6 i386
- Red Hat Enterprise Linux Workstation 6 x86_64
- Red Hat Enterprise Linux Workstation 6 i386
- Red Hat Enterprise Linux Desktop 6 x86_64
- Red Hat Enterprise Linux Desktop 6 i386
Fixes
- BZ - 1363980 - CVE-2016-5141 chromium-browser: Address bar spoofing
- BZ - 1363981 - CVE-2016-5142 chromium-browser: Use-after-free in Blink
- BZ - 1363982 - CVE-2016-5139 chromium-browser: Heap overflow in pdfium
- BZ - 1363983 - CVE-2016-5140 chromium-browser: Heap overflow in pdfium
- BZ - 1363984 - CVE-2016-5145 chromium-browser: Same origin bypass for images in Blink
- BZ - 1363985 - CVE-2016-5143 chromium-browser: Parameter sanitization failure in DevTools
- BZ - 1363986 - CVE-2016-5144 chromium-browser: Parameter sanitization failure in DevTools
- BZ - 1363987 - CVE-2016-5146 chromium-browser: various fixes from internal audits
CVEs
Red Hat Enterprise Linux Server 6
SRPM | |
---|---|
x86_64 | |
chromium-browser-52.0.2743.116-1.el6.x86_64.rpm | SHA-256: 5b9c5bd315eb5d97d0b5eb6d927bf56da680e481c8dc98fae0531d5fed9ddc9b |
chromium-browser-debuginfo-52.0.2743.116-1.el6.x86_64.rpm | SHA-256: b8fb6c791d6b4fc1c416701693eb501a36ac2dcb265da9f18d2eba529e6e2c8e |
i386 | |
chromium-browser-52.0.2743.116-1.el6.i686.rpm | SHA-256: 1239a50bca4c6f678ad2e050099a23ed9f2b01180017f38e81bfef690dd9467b |
chromium-browser-debuginfo-52.0.2743.116-1.el6.i686.rpm | SHA-256: 01cc7759668660d84290d47c1181802921997b355355964888f1ff188195b361 |
Red Hat Enterprise Linux Workstation 6
SRPM | |
---|---|
x86_64 | |
chromium-browser-52.0.2743.116-1.el6.x86_64.rpm | SHA-256: 5b9c5bd315eb5d97d0b5eb6d927bf56da680e481c8dc98fae0531d5fed9ddc9b |
chromium-browser-debuginfo-52.0.2743.116-1.el6.x86_64.rpm | SHA-256: b8fb6c791d6b4fc1c416701693eb501a36ac2dcb265da9f18d2eba529e6e2c8e |
i386 | |
chromium-browser-52.0.2743.116-1.el6.i686.rpm | SHA-256: 1239a50bca4c6f678ad2e050099a23ed9f2b01180017f38e81bfef690dd9467b |
chromium-browser-debuginfo-52.0.2743.116-1.el6.i686.rpm | SHA-256: 01cc7759668660d84290d47c1181802921997b355355964888f1ff188195b361 |
Red Hat Enterprise Linux Desktop 6
SRPM | |
---|---|
x86_64 | |
chromium-browser-52.0.2743.116-1.el6.x86_64.rpm | SHA-256: 5b9c5bd315eb5d97d0b5eb6d927bf56da680e481c8dc98fae0531d5fed9ddc9b |
chromium-browser-debuginfo-52.0.2743.116-1.el6.x86_64.rpm | SHA-256: b8fb6c791d6b4fc1c416701693eb501a36ac2dcb265da9f18d2eba529e6e2c8e |
i386 | |
chromium-browser-52.0.2743.116-1.el6.i686.rpm | SHA-256: 1239a50bca4c6f678ad2e050099a23ed9f2b01180017f38e81bfef690dd9467b |
chromium-browser-debuginfo-52.0.2743.116-1.el6.i686.rpm | SHA-256: 01cc7759668660d84290d47c1181802921997b355355964888f1ff188195b361 |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.