RedHat: RHSA-2018-3004:01 Important: chromium-browser security update
Summary
Chromium is an open-source web browser, powered by WebKit (Blink).
This update upgrades Chromium to version 70.0.3538.67.
Security Fix(es):
* chromium-browser: Sandbox escape in AppCache (CVE-2018-17462)
* chromium-browser: Remote code execution in V8 (CVE-2018-17463)
* chromium-browser: URL spoof in Omnibox (CVE-2018-17464)
* chromium-browser: Use after free in V8 (CVE-2018-17465)
* chromium-browser: Memory corruption in Angle (CVE-2018-17466)
* lcms2: Integer overflow in AllocateDataSet() in cmscgats.c leading to
heap-based buffer overflow (CVE-2018-16435)
* chromium-browser: URL spoof in Omnibox (CVE-2018-17467)
* chromium-browser: Cross-origin URL disclosure in Blink (CVE-2018-17468)
* chromium-browser: Heap buffer overflow in PDFium (CVE-2018-17469)
* chromium-browser: Memory corruption in GPU Internals (CVE-2018-17470)
* chromium-browser: Security UI occlusion in full screen mode
(CVE-2018-17471)
* chromium-browser: URL spoof in Omnibox (CVE-2018-17473)
* chromium-browser: Use after free in Blink (CVE-2018-17474)
* chromium-browser: Lack of limits on update() in ServiceWorker
(CVE-2018-5179)
* chromium-browser: URL spoof in Omnibox (CVE-2018-17475)
* chromium-browser: Security UI occlusion in full screen mode
(CVE-2018-17476)
* chromium-browser: UI spoof in Extensions (CVE-2018-17477)
For more details about the security issue(s), including the impact, a CVSS
score, and other related information, refer to the CVE page(s) listed in
the References section.
Summary
Solution
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
After installing the update, Chromium must be restarted for the changes to
take effect.
References
https://access.redhat.com/security/cve/CVE-2018-5179 https://access.redhat.com/security/cve/CVE-2018-16435 https://access.redhat.com/security/cve/CVE-2018-17462 https://access.redhat.com/security/cve/CVE-2018-17463 https://access.redhat.com/security/cve/CVE-2018-17464 https://access.redhat.com/security/cve/CVE-2018-17465 https://access.redhat.com/security/cve/CVE-2018-17466 https://access.redhat.com/security/cve/CVE-2018-17467 https://access.redhat.com/security/cve/CVE-2018-17468 https://access.redhat.com/security/cve/CVE-2018-17469 https://access.redhat.com/security/cve/CVE-2018-17470 https://access.redhat.com/security/cve/CVE-2018-17471 https://access.redhat.com/security/cve/CVE-2018-17473 https://access.redhat.com/security/cve/CVE-2018-17474 https://access.redhat.com/security/cve/CVE-2018-17475 https://access.redhat.com/security/cve/CVE-2018-17476 https://access.redhat.com/security/cve/CVE-2018-17477 https://access.redhat.com/security/updates/classification/#important
Package List
Red Hat Enterprise Linux Desktop Supplementary (v. 6):
i386:
chromium-browser-70.0.3538.67-1.el6_10.i686.rpm
chromium-browser-debuginfo-70.0.3538.67-1.el6_10.i686.rpm
x86_64:
chromium-browser-70.0.3538.67-1.el6_10.x86_64.rpm
chromium-browser-debuginfo-70.0.3538.67-1.el6_10.x86_64.rpm
Red Hat Enterprise Linux Server Supplementary (v. 6):
i386:
chromium-browser-70.0.3538.67-1.el6_10.i686.rpm
chromium-browser-debuginfo-70.0.3538.67-1.el6_10.i686.rpm
x86_64:
chromium-browser-70.0.3538.67-1.el6_10.x86_64.rpm
chromium-browser-debuginfo-70.0.3538.67-1.el6_10.x86_64.rpm
Red Hat Enterprise Linux Workstation Supplementary (v. 6):
i386:
chromium-browser-70.0.3538.67-1.el6_10.i686.rpm
chromium-browser-debuginfo-70.0.3538.67-1.el6_10.i686.rpm
x86_64:
chromium-browser-70.0.3538.67-1.el6_10.x86_64.rpm
chromium-browser-debuginfo-70.0.3538.67-1.el6_10.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
Topic
An update for chromium-browser is now available for Red Hat EnterpriseLinux 6 Supplementary.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.
Topic
Relevant Releases Architectures
Red Hat Enterprise Linux Desktop Supplementary (v. 6) - i386, x86_64
Red Hat Enterprise Linux Server Supplementary (v. 6) - i386, x86_64
Red Hat Enterprise Linux Workstation Supplementary (v. 6) - i386, x86_64
Bugs Fixed
1628969 - CVE-2018-16435 lcms2: Integer overflow in AllocateDataSet() in cmscgats.c leading to heap-based buffer overflow
1640098 - CVE-2018-17462 chromium-browser: Sandbox escape in AppCache
1640099 - CVE-2018-17463 chromium-browser: Remote code execution in V8
1640100 - CVE-2018-17464 chromium-browser: URL spoof in Omnibox
1640101 - CVE-2018-17465 chromium-browser: Use after free in V8
1640102 - CVE-2018-17466 chromium-browser: Memory corruption in Angle
1640103 - CVE-2018-17467 chromium-browser: URL spoof in Omnibox
1640104 - CVE-2018-17468 chromium-browser: Cross-origin URL disclosure in Blink
1640105 - CVE-2018-17469 chromium-browser: Heap buffer overflow in PDFium
1640106 - CVE-2018-17470 chromium-browser: Memory corruption in GPU Internals
1640107 - CVE-2018-17471 chromium-browser: Security UI occlusion in full screen mode
1640110 - CVE-2018-17473 chromium-browser: URL spoof in Omnibox
1640111 - CVE-2018-17474 chromium-browser: Use after free in Blink
1640112 - CVE-2018-17475 chromium-browser: URL spoof in Omnibox
1640113 - CVE-2018-17476 chromium-browser: Security UI occlusion in full screen mode
1640114 - CVE-2018-5179 chromium-browser: Lack of limits on update() in ServiceWorker
1640115 - CVE-2018-17477 chromium-browser: UI spoof in Extensions