Lucene search

K
redhatRedHatRHSA-2019:0708
HistoryApr 08, 2019 - 7:40 a.m.

(RHSA-2019:0708) Important: chromium-browser security update

2019-04-0807:40:56
access.redhat.com
57

0.331 Low

EPSS

Percentile

97.1%

Chromium is an open-source web browser, powered by WebKit (Blink).

This update upgrades Chromium to version 73.0.3683.75.

Security Fix(es):

  • chromium-browser: Use after free in Canvas (CVE-2019-5787)

  • chromium-browser: Use after free in FileAPI (CVE-2019-5788)

  • chromium-browser: Use after free in WebMIDI (CVE-2019-5789)

  • chromium-browser: Heap buffer overflow in V8 (CVE-2019-5790)

  • chromium-browser: Type confusion in V8 (CVE-2019-5791)

  • chromium-browser: Integer overflow in PDFium (CVE-2019-5792)

  • chromium-browser: Excessive permissions for private API in Extensions (CVE-2019-5793)

  • chromium-browser: Security UI spoofing (CVE-2019-5794)

  • chromium-browser: Integer overflow in PDFium (CVE-2019-5795)

  • chromium-browser: Race condition in Extensions (CVE-2019-5796)

  • chromium-browser: Race condition in DOMStorage (CVE-2019-5797)

  • chromium-browser: Out of bounds read in Skia (CVE-2019-5798)

  • chromium-browser: CSP bypass with blob URL (CVE-2019-5799)

  • chromium-browser: CSP bypass with blob URL (CVE-2019-5800)

  • chromium-browser: Security UI spoofing (CVE-2019-5802)

  • chromium-browser: CSP bypass with Javascript URLs (CVE-2019-5803)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.