Debian Security Advisory
DSA-4340-1 chromium-browser -- security update
- Date Reported:
- 18 Nov 2018
- Affected Packages:
- chromium-browser
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2018-17478.
- More information:
-
An out-of-bounds bounds memory access issue was discovered in chromium's v8 javascript library by cloudfuzzer.
This update also fixes two problems introduced by the previous security upload. Support for arm64 has been restored and gconf-service is no longer a package dependency.
For the stable distribution (stretch), this problem has been fixed in version 70.0.3538.102-1~deb9u1.
We recommend that you upgrade your chromium-browser packages.
For the detailed security status of chromium-browser please refer to its security tracker page at: https://security-tracker.debian.org/tracker/chromium-browser