Opened 8 years ago

Closed 8 years ago

Last modified 7 years ago

#8400 closed enhancement (fixed)

chromium-53.0.2785.143 (CVE-2016-5177 CVE-2016-5178)

Reported by: Douglas R. Reno Owned by: Douglas R. Reno
Priority: high Milestone: 8.0
Component: BOOK Version: SVN
Severity: normal Keywords:
Cc:

Description

An Arch Security Advisory came out for two vulnerabilities in Chrome.

Upon discussing it with DJ, since I need to build it tonight anyway, I offered to create a patch for it.

https://lists.archlinux.org/pipermail/arch-security/2016-October/000729.html

Severity: Critical
Date    : 2016-10-03
CVE-ID  : CVE-2016-5177 CVE-2016-5178
Package : chromium
Type    : arbitrary code execution
Remote  : Yes

Impact
======

A remote attacker could be able to execute arbitrary code.

Description
===========

- CVE-2016-5177 (arbitrary code execution)

Use after free in V8.

- CVE-2016-5178 (arbitrary code execution)

Various fixes from internal audits, fuzzing and other initiatives.

Change History (3)

comment:1 by Douglas R. Reno, 8 years ago

Owner: changed from blfs-book@… to Douglas R. Reno
Status: newassigned
Summary: Generate Chromium security patch (CVE-2016-5177 CVE-2016-5178)chromium-53.0.2785.143 (CVE-2016-5177 CVE-2016-5178)

DJ found a new version - will just update, not generate a security patch.

comment:2 by Douglas R. Reno, 8 years ago

Resolution: fixed
Status: assignedclosed

Fixed at r17856

comment:3 by bdubbs@…, 7 years ago

Milestone: 7.118.0

Milestone renamed

Note: See TracTickets for help on using tickets.