Bug 977830 - (CVE-2016-1664) VUL-0: chromium: multiple vulnerabilities fixed in 50.0.2661.94
(CVE-2016-1664)
VUL-0: chromium: multiple vulnerabilities fixed in 50.0.2661.94
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other openSUSE 42.1
: P3 - Medium : Major
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/168430/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2016-04-29 11:29 UTC by Andreas Stieger
Modified: 2016-06-30 14:14 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Stieger 2016-04-29 11:29:05 UTC
http://googlechromereleases.blogspot.de/2016/04/stable-channel-update_28.html

Fixed in 50.0.2661.94

https://crbug.com/574802 High CVE-2016-1660: Out-of-bounds write in Blink. Credit to Atte Kettunen of OUSPG.
https://crbug.com/601629 High CVE-2016-1661: Memory corruption in cross-process frames. Credit to Wadih Matar.
https://crbug.com/603732 High CVE-2016-1662: Use-after-free in extensions. Credit to Rob Wu.
https://crbug.com/603987 High CVE-2016-1663: Use-after-free in Blink’s V8 bindings. Credit to anonymous.
https://crbug.com/597322 Medium CVE-2016-1664: Address bar spoofing. Credit to Wadih Matar.
https://crbug.com/606181 Medium CVE-2016-1665: Information leak in V8. Credit to gksgudtjr456.
https://crbug.com/607652 CVE-2016-1666: Various fixes from internal audits, fuzzing and other initiatives.
Comment 1 Andreas Stieger 2016-04-29 15:57:59 UTC
https://build.opensuse.org/request/show/392651
Comment 2 Swamp Workflow Management 2016-04-29 22:00:11 UTC
bugbot adjusting priority
Comment 3 Andreas Stieger 2016-05-03 07:49:27 UTC
tittiatcode or Normand, can you action the request below? 4 days. 
https://build.opensuse.org/request/show/392651
We have a security maintenance update ready to go out.
Comment 4 Andreas Stieger 2016-05-03 18:24:35 UTC
release
Comment 5 Swamp Workflow Management 2016-05-03 22:07:53 UTC
openSUSE-SU-2016:1207-1: An update that fixes 7 vulnerabilities is now available.

Category: security (important)
Bug References: 977830
CVE References: CVE-2016-1660,CVE-2016-1661,CVE-2016-1662,CVE-2016-1663,CVE-2016-1664,CVE-2016-1665,CVE-2016-1666
Sources used:
SUSE Package Hub for SUSE Linux Enterprise 12 (src):    chromium-50.0.2661.94-71.1
Comment 6 Swamp Workflow Management 2016-05-03 22:08:07 UTC
openSUSE-SU-2016:1208-1: An update that fixes 7 vulnerabilities is now available.

Category: security (important)
Bug References: 977830
CVE References: CVE-2016-1660,CVE-2016-1661,CVE-2016-1662,CVE-2016-1663,CVE-2016-1664,CVE-2016-1665,CVE-2016-1666
Sources used:
openSUSE Leap 42.1 (src):    chromium-50.0.2661.94-45.1
Comment 7 Swamp Workflow Management 2016-05-03 22:08:18 UTC
openSUSE-SU-2016:1209-1: An update that fixes 7 vulnerabilities is now available.

Category: security (important)
Bug References: 977830
CVE References: CVE-2016-1660,CVE-2016-1661,CVE-2016-1662,CVE-2016-1663,CVE-2016-1664,CVE-2016-1665,CVE-2016-1666
Sources used:
openSUSE 13.2 (src):    chromium-50.0.2661.94-97.1
Comment 8 Swamp Workflow Management 2016-06-22 13:16:28 UTC
openSUSE-SU-2016:1655-1: An update that fixes 12 vulnerabilities is now available.

Category: security (important)
Bug References: 977830,979859,985397
CVE References: CVE-2016-1660,CVE-2016-1661,CVE-2016-1662,CVE-2016-1663,CVE-2016-1664,CVE-2016-1665,CVE-2016-1666,CVE-2016-1667,CVE-2016-1668,CVE-2016-1669,CVE-2016-1670,CVE-2016-1704
Sources used:
openSUSE 13.1 (src):    chromium-51.0.2704.103-147.1