An update for chromium-browser is now available for Red Hat Enterprise Linux 6Supplementary.Red Hat Product Security has rated this update as having a security impact ofImportant.

A Common Vulnerability Scoring System (CVSS) base score, which givesa detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.
Chromium is an open-source web browser, powered by WebKit (Blink).This update upgrades Chromium to version 55.0.2883.75.Security Fix(es):* Multiple flaws were found in the processing of malformed web content.

A webpage containing malicious content could cause Chromium to crash, executearbitrary code, or disclose sensitive information when visited by the victim.(CVE-2016-5203, CVE-2016-5204, CVE-2016-5205, CVE-2016-5206, CVE-2016-5207,CVE-2016-5208, CVE-2016-5209, CVE-2016-5210, CVE-2016-5211, CVE-2016-5212,CVE-2016-5213, CVE-2016-9651, CVE-2016-9652, CVE-2016-5214, CVE-2016-5215,CVE-2016-5216, CVE-2016-5217, CVE-2016-5218, CVE-2016-5219, CVE-2016-5220,CVE-2016-5221, CVE-2016-5222, CVE-2016-5223, CVE-2016-5224, CVE-2016-5225,CVE-2016-5226, CVE-2016-9650)
For details on how to apply this update, which includes the changes described inthis advisory, refer to:https://access.redhat.com/articles/11258After installing the update, Chromium must be restarted for the changes to takeeffect.Red Hat Enterprise Linux Desktop Supplementary (v. 6)

IA-32:
chromium-browser-55.0.2883.75-1.el6.i686.rpm
    MD5: 6ce9553417cd7cddbceb04c63109a198SHA-256: 04d12ea75c416b07d194a728a5fb793e9b901fd4c413e63166fc6d701866ace5
chromium-browser-debuginfo-55.0.2883.75-1.el6.i686.rpm
    MD5: 793121303496d82e75eeb3a3c6c0c194SHA-256: c3ea75fa85b82d04ee7688e14d3e3ebb9a9171a7de05c6f3dc1e38650bdf21c7
 
x86_64:
chromium-browser-55.0.2883.75-1.el6.x86_64.rpm
    MD5: 08368e57b39944c03839be6ee4f5adedSHA-256: 93698d3b303edcd46228a6a833813c3a10b07119fae6783874869ff15277cf0b
chromium-browser-debuginfo-55.0.2883.75-1.el6.x86_64.rpm
    MD5: 8720e72acb79d7c1e003e60d43effaa4SHA-256: 57c4adba3beb57a2f160018045f83824cece62fb74099198fb7b3052dff19b08
 
Red Hat Enterprise Linux Server Supplementary (v. 6)

IA-32:
chromium-browser-55.0.2883.75-1.el6.i686.rpm
    MD5: 6ce9553417cd7cddbceb04c63109a198SHA-256: 04d12ea75c416b07d194a728a5fb793e9b901fd4c413e63166fc6d701866ace5
chromium-browser-debuginfo-55.0.2883.75-1.el6.i686.rpm
    MD5: 793121303496d82e75eeb3a3c6c0c194SHA-256: c3ea75fa85b82d04ee7688e14d3e3ebb9a9171a7de05c6f3dc1e38650bdf21c7
 
x86_64:
chromium-browser-55.0.2883.75-1.el6.x86_64.rpm
    MD5: 08368e57b39944c03839be6ee4f5adedSHA-256: 93698d3b303edcd46228a6a833813c3a10b07119fae6783874869ff15277cf0b
chromium-browser-debuginfo-55.0.2883.75-1.el6.x86_64.rpm
    MD5: 8720e72acb79d7c1e003e60d43effaa4SHA-256: 57c4adba3beb57a2f160018045f83824cece62fb74099198fb7b3052dff19b08
 
Red Hat Enterprise Linux Workstation Supplementary (v. 6)

IA-32:
chromium-browser-55.0.2883.75-1.el6.i686.rpm
    MD5: 6ce9553417cd7cddbceb04c63109a198SHA-256: 04d12ea75c416b07d194a728a5fb793e9b901fd4c413e63166fc6d701866ace5
chromium-browser-debuginfo-55.0.2883.75-1.el6.i686.rpm
    MD5: 793121303496d82e75eeb3a3c6c0c194SHA-256: c3ea75fa85b82d04ee7688e14d3e3ebb9a9171a7de05c6f3dc1e38650bdf21c7
 
x86_64:
chromium-browser-55.0.2883.75-1.el6.x86_64.rpm
    MD5: 08368e57b39944c03839be6ee4f5adedSHA-256: 93698d3b303edcd46228a6a833813c3a10b07119fae6783874869ff15277cf0b
chromium-browser-debuginfo-55.0.2883.75-1.el6.x86_64.rpm
    MD5: 8720e72acb79d7c1e003e60d43effaa4SHA-256: 57c4adba3beb57a2f160018045f83824cece62fb74099198fb7b3052dff19b08
 
(The unlinked packages above are only available from the Red Hat Network)

1400850 – CVE-2016-9651 chromium-browser: private property access in v81400851 – CVE-2016-5208 chromium-browser: universal xss in blink1400852 – CVE-2016-5207 chromium-browser: universal xss in blink1400853 – CVE-2016-5206 chromium-browser: same-origin bypass in pdfium1400854 – CVE-2016-5205 chromium-browser: universal xss in blink1400855 – CVE-2016-5204 chromium-browser: universal xss in blink1400856 – CVE-2016-5209 chromium-browser: out of bounds write in blink1400857 – CVE-2016-5203 chromium-browser: use after free in pdfium1400859 – CVE-2016-5210 chromium-browser: out of bounds write in pdfium1400861 – CVE-2016-5212 chromium-browser: local file disclosure in devtools1400862 – CVE-2016-5211 chromium-browser: use after free in pdfium1400863 – CVE-2016-5213 chromium-browser: use after free in v81400864 – CVE-2016-5214 chromium-browser: file download protection bypass1400865 – CVE-2016-5216 chromium-browser: use after free in pdfium1400866 – CVE-2016-5215 chromium-browser: use after free in webaudio1400867 – CVE-2016-5217 chromium-browser: use of unvalidated data in pdfium1400868 – CVE-2016-5218 chromium-browser: address spoofing in omnibox1400869 – CVE-2016-5219 chromium-browser: use after free in v81400870 – CVE-2016-5221 chromium-browser: integer overflow in angle1400871 – CVE-2016-5220 chromium-browser: local file access in pdfium1400872 – CVE-2016-5222 chromium-browser: address spoofing in omnibox1400873 – CVE-2016-9650 chromium-browser: csp referrer disclosure1400875 – CVE-2016-5223 chromium-browser: integer overflow in pdfium1400876 – CVE-2016-5226 chromium-browser: limited xss in blink1400877 – CVE-2016-5225 chromium-browser: csp bypass in blink1400878 – CVE-2016-5224 chromium-browser: same-origin bypass in svg1400879 – CVE-2016-9652 chromium-browser: various fixes from internal audits

These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:

Leave a Reply