Update to 17.0.963.83
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
chromium-browser (Ubuntu) |
Fix Released
|
Medium
|
Micah Gersten | ||
Lucid |
Fix Released
|
Medium
|
Micah Gersten | ||
Maverick |
Fix Released
|
Medium
|
Micah Gersten | ||
Natty |
Fix Released
|
Medium
|
Micah Gersten | ||
Oneiric |
Fix Released
|
Medium
|
Micah Gersten | ||
Precise |
Fix Released
|
Medium
|
Micah Gersten |
Bug Description
[113902] High CVE-2011-3050: Use-after-free with first-letter handling. Credit to miaubiz.
[116162] High CVE-2011-3045: libpng integer issue from upstream. Credit to Glenn Randers-Pehrson of the libpng project.
[116461] High CVE-2011-3051: Use-after-free in CSS cross-fade handling. Credit to Arthur Gerkis.
[116637] High CVE-2011-3052: Memory corruption in WebGL canvas handling. Credit to Ben Vanik of Google.
[116746] High CVE-2011-3053: Use-after-free in block splitting. Credit to miaubiz.
[117418] Low CVE-2011-3054: Apply additional isolations to webui privileges. Credit to Sergey Glazunov.
[117736] Low CVE-2011-3055: Prompt in the browser native UI for unpacked extension installation. Credit to PinkiePie.
[117550] High CVE-2011-3056: Cross-origin violation with “magic iframe”. Credit to Sergey Glazunov.
[117794] Medium CVE-2011-3057: Invalid read in v8. Credit to Christian Holler.
Related branches
CVE References
visibility: | private → public |
Changed in chromium-browser (Ubuntu Lucid): | |
status: | New → In Progress |
Changed in chromium-browser (Ubuntu Maverick): | |
status: | New → In Progress |
Changed in chromium-browser (Ubuntu Natty): | |
status: | New → In Progress |
Changed in chromium-browser (Ubuntu Oneiric): | |
status: | New → In Progress |
Changed in chromium-browser (Ubuntu Precise): | |
status: | New → In Progress |
Changed in chromium-browser (Ubuntu Lucid): | |
importance: | Undecided → Medium |
Changed in chromium-browser (Ubuntu Maverick): | |
importance: | Undecided → Medium |
Changed in chromium-browser (Ubuntu Natty): | |
importance: | Undecided → Medium |
Changed in chromium-browser (Ubuntu Oneiric): | |
importance: | Undecided → Medium |
Changed in chromium-browser (Ubuntu Precise): | |
importance: | Undecided → Medium |
assignee: | nobody → Micah Gersten (micahg) |
Changed in chromium-browser (Ubuntu Oneiric): | |
assignee: | nobody → Micah Gersten (micahg) |
Changed in chromium-browser (Ubuntu Lucid): | |
assignee: | nobody → Micah Gersten (micahg) |
Changed in chromium-browser (Ubuntu Natty): | |
assignee: | nobody → Micah Gersten (micahg) |
Changed in chromium-browser (Ubuntu Maverick): | |
assignee: | nobody → Micah Gersten (micahg) |
This bug was fixed in the package chromium-browser - 17.0.963. 83~r127885- 0ubuntu1
--------------- 83~r127885- 0ubuntu1) precise; urgency=low
chromium-browser (17.0.963.
* New upstream release from the Stable Channel (LP: #961831)
This release fixes the following security issues:
- [113902] High CVE-2011-3050: Use-after-free with first-letter handling.
Credit to miaubiz.
- [116162] High CVE-2011-3045: libpng integer issue from upstream. Credit
to Glenn Randers-Pehrson of the libpng project.
- [116461] High CVE-2011-3051: Use-after-free in CSS cross-fade handling.
Credit to Arthur Gerkis.
- [116637] High CVE-2011-3052: Memory corruption in WebGL canvas handling.
Credit to Ben Vanik of Google.
- [116746] High CVE-2011-3053: Use-after-free in block splitting.
Credit to miaubiz.
- [117418] Low CVE-2011-3054: Apply additional isolations to webui
privileges. Credit to Sergey Glazunov.
- [117736] Low CVE-2011-3055: Prompt in the browser native UI for unpacked
extension installation. Credit to PinkiePie.
- [117550] High CVE-2011-3056: Cross-origin violation with “magic iframe”.
Credit to Sergey Glazunov.
- [117794] Medium CVE-2011-3057: Invalid read in v8. Credit to Christian
Holler.
-- Micah Gersten <email address hidden> Wed, 21 Mar 2012 21:31:34 -0500