Executive Summary
Summary | |
---|---|
Title | chromium-browser security update |
Informations | |||
---|---|---|---|
Name | RHSA-2016:0525 | First vendor Publication | 2016-03-30 |
Vendor | RedHat | Last vendor Modification | 2016-03-30 |
Severity (Vendor) | N/A | Revision | 01 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 9.3 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Problem Description: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Supplementary (v. 6) - i386, x86_64 3. Description: Chromium is an open-source web browser, powered by WebKit (Blink). This update upgrades Chromium to version 49.0.2623.108. Security Fix(es): Several flaws were found in the processing of malformed web content. A web page containing malicious content could cause Chromium to crash, execute arbitrary code, or disclose sensitive information when visited by the victim. (CVE-2016-1646, CVE-2016-1647, CVE-2016-1648, CVE-2016-1649, CVE-2016-1650) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1321811 - CVE-2016-1646 chromium-browser: out-of-bounds read in V8 1321812 - CVE-2016-1647 chromium-browser: use-after-free in Navigation 1321814 - CVE-2016-1648 chromium-browser: use-after-free in Extensions 1321815 - CVE-2016-1649 chromium-browser: buffer overflow in libANGLE 1321816 - CVE-2016-1650 chromium-browser: various fixes from internal audits |
Original Source
Url : https://rhn.redhat.com/errata/RHSA-2016-0525.html |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
50 % | CWE-125 | Out-of-bounds Read |
50 % | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
CPE : Common Platform Enumeration
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2016-05-17 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201605-02.nasl - Type : ACT_GATHER_INFO |
2016-05-02 | Name : The remote Ubuntu host is missing a security-related patch. File : ubuntu_USN-2955-1.nasl - Type : ACT_GATHER_INFO |
2016-04-18 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2016-459.nasl - Type : ACT_GATHER_INFO |
2016-04-01 | Name : The remote FreeBSD host is missing one or more security-related updates. File : freebsd_pkg_8be8ca39ae704422bf1ad8fae6911c5e.nasl - Type : ACT_GATHER_INFO |
2016-04-01 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2016-418.nasl - Type : ACT_GATHER_INFO |
2016-04-01 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2016-0525.nasl - Type : ACT_GATHER_INFO |
2016-03-28 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-3531.nasl - Type : ACT_GATHER_INFO |
2016-03-25 | Name : The remote Windows host contains a web browser that is affected by multiple v... File : google_chrome_49_0_2623_108.nasl - Type : ACT_GATHER_INFO |
2016-03-25 | Name : The remote Mac OS X host contains a web browser that is affected by multiple ... File : macosx_google_chrome_49_0_2623_108.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2016-12-03 09:26:45 |
|
2016-04-02 13:26:25 |
|
2016-03-30 13:23:30 |
|