- Issued:
- 2017-12-07
- Updated:
- 2017-12-07
RHSA-2017:3401 - Critical: chromium-browser security update
Synopsis
Critical: chromium-browser security update
Type/Severity
Security Advisory Critical
Topic
An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary.
Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Description
Chromium is an open-source web browser, powered by WebKit (Blink).
This update upgrades Chromium to version 63.0.3239.84.
Security Fix(es):
- Multiple flaws were found in the processing of malformed web content. A web page containing malicious content could cause Chromium to crash, execute arbitrary code, or disclose sensitive information when visited by the victim. (CVE-2017-15407, CVE-2017-15408, CVE-2017-15409, CVE-2017-15410, CVE-2017-15411, CVE-2017-15412, CVE-2017-15413, CVE-2017-15415, CVE-2017-15416, CVE-2017-15417, CVE-2017-15418, CVE-2017-15419, CVE-2017-15420, CVE-2017-15422, CVE-2017-15423, CVE-2017-15424, CVE-2017-15425, CVE-2017-15426, CVE-2017-15427)
Solution
For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258
After installing the update, Chromium must be restarted for the changes to take effect.
Affected Products
| Product | Version | Arch |
|---|---|---|
| Red Hat Enterprise Linux Workstation | 6 | x86_64 |
| Red Hat Enterprise Linux Workstation | 6 | i386 |
| Red Hat Enterprise Linux Server | 6 | x86_64 |
| Red Hat Enterprise Linux Server | 6 | i386 |
| Red Hat Enterprise Linux Desktop | 6 | x86_64 |
| Red Hat Enterprise Linux Desktop | 6 | i386 |
Updated Packages
- chromium-browser-63.0.3239.84-1.el6_9.x86_64.rpm
- chromium-browser-debuginfo-63.0.3239.84-1.el6_9.x86_64.rpm
- chromium-browser-63.0.3239.84-1.el6_9.i686.rpm
- chromium-browser-debuginfo-63.0.3239.84-1.el6_9.i686.rpm
Fixes
- This content is not included.BZ - 1523123
- This content is not included.BZ - 1523124
- This content is not included.BZ - 1523125
- This content is not included.BZ - 1523126
- This content is not included.BZ - 1523127
- This content is not included.BZ - 1523128
- This content is not included.BZ - 1523129
- This content is not included.BZ - 1523130
- This content is not included.BZ - 1523131
- This content is not included.BZ - 1523132
- This content is not included.BZ - 1523133
- This content is not included.BZ - 1523134
- This content is not included.BZ - 1523135
- This content is not included.BZ - 1523136
- This content is not included.BZ - 1523137
- This content is not included.BZ - 1523138
- This content is not included.BZ - 1523139
- This content is not included.BZ - 1523140
- This content is not included.BZ - 1523141
CVEs
- CVE-2017-15407
- CVE-2017-15408
- CVE-2017-15409
- CVE-2017-15410
- CVE-2017-15411
- CVE-2017-15412
- CVE-2017-15413
- CVE-2017-15415
- CVE-2017-15416
- CVE-2017-15417
- CVE-2017-15418
- CVE-2017-15419
- CVE-2017-15420
- CVE-2017-15422
- CVE-2017-15423
- CVE-2017-15424
- CVE-2017-15425
- CVE-2017-15426
- CVE-2017-15427
References
- https://access.redhat.com/security/updates/classification/#critical
- Content from chromereleases.googleblog.com is not included.Content from chromereleases.googleblog.com is not included.https://chromereleases.googleblog.com/2017/12/stable-channel-update-for-desktop.html
Additional information
- The Red Hat security contact is This content is not included.secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.
- Offline Security Data data is available for integration with other systems. See Offline Security Data API to get started.