Debian Security Advisory

DSA-4340-1 chromium-browser -- security update

Date Reported:
18 Nov 2018
Affected Packages:
chromium-browser
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2018-17478.
More information:

An out-of-bounds bounds memory access issue was discovered in chromium's v8 javascript library by cloudfuzzer.

This update also fixes two problems introduced by the previous security upload. Support for arm64 has been restored and gconf-service is no longer a package dependency.

For the stable distribution (stretch), this problem has been fixed in version 70.0.3538.102-1~deb9u1.

We recommend that you upgrade your chromium-browser packages.

For the detailed security status of chromium-browser please refer to its security tracker page at: https://security-tracker.debian.org/tracker/chromium-browser