New upstream release 16.0.912.77
Bug #923602 reported by
Micah Gersten
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
chromium-browser (Ubuntu) |
Fix Released
|
Medium
|
Micah Gersten | ||
Lucid |
Fix Released
|
Medium
|
Micah Gersten | ||
Maverick |
Fix Released
|
Medium
|
Micah Gersten | ||
Natty |
Fix Released
|
Medium
|
Micah Gersten | ||
Oneiric |
Fix Released
|
Medium
|
Micah Gersten | ||
Precise |
Fix Released
|
Medium
|
Micah Gersten |
Bug Description
[106484] High CVE-2011-3924: Use-after-free in DOM selections. Credit to Arthur Gerkis.
[107182] Critical CVE-2011-3925: Use-after-free in Safe Browsing navigation. Credit to Chamal de Silva.
[108461] High CVE-2011-3928: Use-after-free in DOM handling. Credit to wushi of team509 reported through ZDI (ZDI-CAN-1415).
[108605] High CVE-2011-3927: Uninitialized value in Skia. Credit to miaubiz.
[109556] High CVE-2011-3926: Heap-buffer-
Related branches
CVE References
- 2011-2845
- 2011-3875
- 2011-3876
- 2011-3877
- 2011-3878
- 2011-3879
- 2011-3880
- 2011-3881
- 2011-3882
- 2011-3883
- 2011-3884
- 2011-3885
- 2011-3886
- 2011-3887
- 2011-3888
- 2011-3889
- 2011-3890
- 2011-3891
- 2011-3892
- 2011-3893
- 2011-3894
- 2011-3895
- 2011-3896
- 2011-3897
- 2011-3900
- 2011-3903
- 2011-3904
- 2011-3905
- 2011-3906
- 2011-3907
- 2011-3908
- 2011-3909
- 2011-3910
- 2011-3911
- 2011-3912
- 2011-3913
- 2011-3914
- 2011-3915
- 2011-3916
- 2011-3917
- 2011-3919
- 2011-3921
- 2011-3922
- 2011-3924
- 2011-3925
- 2011-3926
- 2011-3927
- 2011-3928
visibility: | private → public |
Changed in chromium-browser (Ubuntu Lucid): | |
assignee: | nobody → Micah Gersten (micahg) |
Changed in chromium-browser (Ubuntu Maverick): | |
assignee: | nobody → Micah Gersten (micahg) |
Changed in chromium-browser (Ubuntu Natty): | |
assignee: | nobody → Micah Gersten (micahg) |
Changed in chromium-browser (Ubuntu Oneiric): | |
assignee: | nobody → Micah Gersten (micahg) |
importance: | Undecided → High |
Changed in chromium-browser (Ubuntu Natty): | |
importance: | Undecided → High |
Changed in chromium-browser (Ubuntu Maverick): | |
importance: | Undecided → High |
Changed in chromium-browser (Ubuntu Lucid): | |
importance: | Undecided → High |
Changed in chromium-browser (Ubuntu Precise): | |
importance: | High → Medium |
Changed in chromium-browser (Ubuntu Oneiric): | |
importance: | High → Medium |
Changed in chromium-browser (Ubuntu Natty): | |
importance: | High → Medium |
Changed in chromium-browser (Ubuntu Maverick): | |
importance: | High → Medium |
Changed in chromium-browser (Ubuntu Lucid): | |
importance: | High → Medium |
Changed in chromium-browser (Ubuntu Oneiric): | |
status: | New → In Progress |
Changed in chromium-browser (Ubuntu Natty): | |
status: | New → In Progress |
Changed in chromium-browser (Ubuntu Maverick): | |
status: | New → In Progress |
Changed in chromium-browser (Ubuntu Lucid): | |
status: | New → In Progress |
Changed in chromium-browser (Ubuntu Natty): | |
status: | In Progress → Fix Committed |
Changed in chromium-browser (Ubuntu Oneiric): | |
status: | In Progress → Fix Committed |
To post a comment you must log in.
This bug was fixed in the package chromium-browser - 16.0.912. 77~r118311- 0ubuntu1
--------------- 77~r118311- 0ubuntu1) precise; urgency=low
chromium-browser (16.0.912.
* New upstream release from the Stable Channel (LP: #923602, #897389) overflow in tree builder.
(LP: #914648, #889711)
This release fixes the following security issues:
- [106484] High CVE-2011-3924: Use-after-free in DOM selections. Credit to
Arthur Gerkis.
- [107182] Critical CVE-2011-3925: Use-after-free in Safe Browsing
navigation. Credit to Chamal de Silva.
- [108461] High CVE-2011-3928: Use-after-free in DOM handling. Credit to
wushi of team509 reported through ZDI (ZDI-CAN-1415).
- [108605] High CVE-2011-3927: Uninitialized value in Skia. Credit to
miaubiz.
- [109556] High CVE-2011-3926: Heap-buffer-
Credit to Arthur Gerkis.
This upload also includes the following security fixes from 16.0.912.75: overflow in libxml. Credit to overflow in glyph handling.
- [106672] High CVE-2011-3921: Use-after-free in animation frames. Credit to
Boris Zbarsky of Mozilla.
- [107128] High CVE-2011-3919: Heap-buffer-
Jüri Aedla.
- [108006] High CVE-2011-3922: Stack-buffer-
Credit to Google Chrome Security Team (Cris Neckar).
This upload also includes the following security fixes from 16.0.912.63: overflow in FileWatcher.
- [81753] Medium CVE-2011-3903: Out-of-bounds read in regex matching. Credit
to David Holloway of the Chromium development community.
- [95465] Low CVE-2011-3905: Out-of-bounds reads in libxml. Credit to Google
Chrome Security Team (Inferno).
- [98809] Medium CVE-2011-3906: Out-of-bounds read in PDF parser. Credit to
Aki Helin of OUSPG.
- [99016] High CVE-2011-3907: URL bar spoofing with view-source. Credit to
Luka Treiber of ACROS Security.
- [100863] Low CVE-2011-3908: Out-of-bounds read in SVG parsing. Credit to
Aki Helin of OUSPG.
- [101010] Medium CVE-2011-3909: [64-bit only] Memory corruption in CSS
property array. Credit to Google Chrome Security Team (scarybeasts) and
Chu.
- [101494] Medium CVE-2011-3910: Out-of-bounds read in YUV video frame
handling. Credit to Google Chrome Security Team (Cris Neckar).
- [101779] Medium CVE-2011-3911: Out-of-bounds read in PDF. Credit to Google
Chrome Security Team (scarybeasts) and Robert Swiecki of the Google
Security Team.
- [102359] High CVE-2011-3912: Use-after-free in SVG filters. Credit to
Arthur Gerkis.
- [103921] High CVE-2011-3913: Use-after-free in Range handling. Credit to
Arthur Gerkis.
- [104011] High CVE-2011-3914: Out-of-bounds write in v8 i18n handling.
Credit to Sławomir Błażek.
- [104529] High CVE-2011-3915: Buffer overflow in PDF font handling. Credit
to Atte Kettunen of OUSPG.
- [104959] Medium CVE-2011-3916: Out-of-bounds reads in PDF cross
references. Credit to Atte Kettunen of OUSPG.
- [105162] Medium CVE-2011-3917: Stack-buffer-
Credit to Google Chrome Security Team (Marty Barbella).
This upload also includes the following fixes from 15.0.874.121:
- fix...