Lucene search

K
archlinuxArch LinuxASA-201603-1
HistoryMar 03, 2016 - 12:00 a.m.

chromium: multiple issues

2016-03-0300:00:00
Arch Linux
lists.archlinux.org
24

EPSS

0.021

Percentile

89.3%

  • CVE-2015-8126:

Buffer overflow vulnerabilities in functions png_get_PLTE/png_set_PLTE,
allowing remote attackers to cause DoS to application or have
unspecified other impact. These functions failed to check for an
out-of-range palette when reading or writing PNG files with a bit_depth
less than 8. Some applications might read the bit depth from the IHDR
chunk and allocate memory for a 2^N entry palette, while libpng can
return a palette with up to 256 entries even when the bit depth is less
than 8.

  • CVE-2016-1630:

Same-origin bypass in Blink. Credit to Mariusz Mlynski.

  • CVE-2016-1631:

Same-origin bypass in Pepper Plugin. Credit to Mariusz Mlynski.

  • CVE-2016-1632:

Bad cast in Extensions.

  • CVE-2016-1633, CVE-2016-1634:

Use-after-free in Blink. Credit to cloudfuzzer.

  • CVE-2016-1635:

Use-after-free in Blink. Credit to Rob Wu.

  • CVE-2016-1636:

SRI Validation Bypass. Credit to Ryan Lester and Bryant Zadegan.

  • CVE-2016-1637:

Information Leak in Skia. Credit to Keve Nagy.

  • CVE-2016-1638:

WebAPI Bypass. Credit to Rob Wu.

  • CVE-2016-1639:

Use-after-free in WebRTC. Credit to Khalil Zhani.

  • CVE-2016-1640:

Origin confusion in Extensions UI. Credit to Luan Herrera.

  • CVE-2016-1641:

Use-after-free in Favicon. Credit to Atte Kettunen of OUSPG.

  • CVE-2016-1642:

Various fixes from internal audits, fuzzing and other initiatives.

OSVersionArchitecturePackageVersionFilename
anyanyanychromium< 49.0.2623.75-1UNKNOWN