And 27.0.1453.110: http://googlechromereleases.blogspot.com/2013/06
/stable-channel-update.html

CVE-2013-2854: Bad handle passed to renderer. 
CVE-2013-2855: Memory corruption in dev tools API. 
CVE-2013-2856: Use-after-free in input handling. 
CVE-2013-2857: Use-after-free in image handling. 
CVE-2013-2858: Use-after-free in HTML5 Audio. 
CVE-2013-2859: Cross-origin namespace pollution. 
CVE-2013-2860: Use-after-free with workers accessing database APIs. 
CVE-2013-2861: Use-after-free with SVG. 
CVE-2013-2862: Memory corruption in Skia GPU handling. 
CVE-2013-2863: Memory corruption in SSL socket handling. 
CVE-2013-2864: Bad free in PDF viewer. 
CVE-2013-2865: Various fixes from internal audits, fuzzing and other 
initiatives.

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2013-2854

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2013-2855

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2013-2856

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2013-2857

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2013-2858

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2013-2859

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2013-2860

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2013-2861

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2013-2862

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2013-2863

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2013-2864

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2013-2865

** Summary changed:

- Please update to 27.0.1453.93
+ Please update to 27.0.1453.110

-- 
You received this bug notification because you are a member of Desktop
Packages, which is subscribed to chromium-browser in Ubuntu.
https://bugs.launchpad.net/bugs/1183086

Title:
  Please update to 27.0.1453.110

Status in “chromium-browser” package in Ubuntu:
  Confirmed

Bug description:
  And again a new stable release with lots of security fixes:
  http://googlechromereleases.blogspot.de/2013/05/stable-channel-
  release.html

  Here are the CVEs:

  CVE-2013-2837: Use-after-free in SVG.
  CVE-2013-2838: Out-of-bounds read in v8.
  CVE-2013-2839: Bad cast in clipboard handling.
  CVE-2013-2840: Use-after-free in media loader.
  CVE-2013-2841: Use-after-free in Pepper resource handling.
  CVE-2013-2842: Use-after-free in widget handling.
  CVE-2013-2843: Use-after-free in speech handling.
  CVE-2013-2844: Use-after-free in style resolution.
  CVE-2013-2845: Memory safety issues in Web Audio.
  CVE-2013-2846: Use-after-free in media loader.
  CVE-2013-2847: Use-after-free race condition with workers.
  CVE-2013-2848: Possible data extraction with XSS Auditor.
  CVE-2013-2849: Possible XSS with drag+drop or copy+paste.

  Please update and keep current. Thanks.

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/chromium-browser/+bug/1183086/+subscriptions

-- 
Mailing list: https://launchpad.net/~desktop-packages
Post to     : desktop-packages@lists.launchpad.net
Unsubscribe : https://launchpad.net/~desktop-packages
More help   : https://help.launchpad.net/ListHelp

Reply via email to