RHEL 6 : chromium-browser (RHSA-2019:0309)

Medium Nessus Plugin ID 122112

New! Vulnerability Priority Rating (VPR)

Tenable calculates a dynamic VPR for every vulnerability. VPR combines vulnerability information with threat intelligence and machine learning algorithms to predict which vulnerabilities are most likely to be exploited in attacks. Read more about what VPR is and how it's different from CVSS.

VPR Score: 7.3

Synopsis

The remote Red Hat host is missing one or more security updates.

Description

An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary.

Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Chromium is an open source web browser, powered by WebKit (Blink).

This update upgrades Chromium to version 72.0.3626.81.

Security Fix(es) :

* chromium-browser: Inappropriate implementation in QUIC Networking (CVE-2019-5754)

* chromium-browser: Inappropriate implementation in V8 (CVE-2019-5755)

* chromium-browser: Use after free in PDFium (CVE-2019-5756)

* chromium-browser: Type Confusion in SVG (CVE-2019-5757)

* chromium-browser: Use after free in Blink (CVE-2019-5758)

* chromium-browser: Use after free in HTML select elements (CVE-2019-5759)

* chromium-browser: Use after free in WebRTC (CVE-2019-5760)

* chromium-browser: Use after free in SwiftShader (CVE-2019-5761)

* chromium-browser: Use after free in PDFium (CVE-2019-5762)

* chromium-browser: Insufficient validation of untrusted input in V8 (CVE-2019-5763)

* chromium-browser: Use after free in WebRTC (CVE-2019-5764)

* chromium-browser: Insufficient policy enforcement in the browser (CVE-2019-5765)

* chromium-browser: Inappropriate implementation in V8 (CVE-2019-5782)

* chromium-browser: Insufficient policy enforcement in Canvas (CVE-2019-5766)

* chromium-browser: Incorrect security UI in WebAPKs (CVE-2019-5767)

* chromium-browser: Insufficient policy enforcement in DevTools (CVE-2019-5768)

* chromium-browser: Insufficient validation of untrusted input in Blink (CVE-2019-5769)

* chromium-browser: Heap buffer overflow in WebGL (CVE-2019-5770)

* chromium-browser: Heap buffer overflow in SwiftShader (CVE-2019-5771)

* chromium-browser: Use after free in PDFium (CVE-2019-5772)

* chromium-browser: Insufficient data validation in IndexedDB (CVE-2019-5773)

* chromium-browser: Insufficient validation of untrusted input in SafeBrowsing (CVE-2019-5774)

* chromium-browser: Insufficient policy enforcement in Omnibox (CVE-2019-5775)

* chromium-browser: Insufficient policy enforcement in Omnibox (CVE-2019-5776)

* chromium-browser: Insufficient policy enforcement in Omnibox (CVE-2019-5777)

* chromium-browser: Insufficient policy enforcement in Extensions (CVE-2019-5778)

* chromium-browser: Insufficient policy enforcement in ServiceWorker (CVE-2019-5779)

* chromium-browser: Insufficient policy enforcement (CVE-2019-5780)

* chromium-browser: Insufficient policy enforcement in Omnibox (CVE-2019-5781)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

Update the affected chromium-browser and / or chromium-browser-debuginfo packages.

See Also

https://access.redhat.com/errata/RHSA-2019:0309

https://access.redhat.com/security/cve/cve-2019-5754

https://access.redhat.com/security/cve/cve-2019-5755

https://access.redhat.com/security/cve/cve-2019-5756

https://access.redhat.com/security/cve/cve-2019-5757

https://access.redhat.com/security/cve/cve-2019-5758

https://access.redhat.com/security/cve/cve-2019-5759

https://access.redhat.com/security/cve/cve-2019-5760

https://access.redhat.com/security/cve/cve-2019-5761

https://access.redhat.com/security/cve/cve-2019-5762

https://access.redhat.com/security/cve/cve-2019-5763

https://access.redhat.com/security/cve/cve-2019-5764

https://access.redhat.com/security/cve/cve-2019-5765

https://access.redhat.com/security/cve/cve-2019-5766

https://access.redhat.com/security/cve/cve-2019-5767

https://access.redhat.com/security/cve/cve-2019-5768

https://access.redhat.com/security/cve/cve-2019-5769

https://access.redhat.com/security/cve/cve-2019-5770

https://access.redhat.com/security/cve/cve-2019-5771

https://access.redhat.com/security/cve/cve-2019-5772

https://access.redhat.com/security/cve/cve-2019-5773

https://access.redhat.com/security/cve/cve-2019-5774

https://access.redhat.com/security/cve/cve-2019-5775

https://access.redhat.com/security/cve/cve-2019-5776

https://access.redhat.com/security/cve/cve-2019-5777

https://access.redhat.com/security/cve/cve-2019-5778

https://access.redhat.com/security/cve/cve-2019-5779

https://access.redhat.com/security/cve/cve-2019-5780

https://access.redhat.com/security/cve/cve-2019-5781

https://access.redhat.com/security/cve/cve-2019-5782

Plugin Details

Severity: Medium

ID: 122112

File Name: redhat-RHSA-2019-0309.nasl

Version: 1.7

Type: local

Agent: unix

Published: 2019/02/12

Updated: 2020/05/29

Dependencies: 12634

Risk Information

Risk Factor: Medium

VPR Score: 7.3

CVSS Score Source: CVE-2019-5782

CVSS v2.0

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:U/RL:OF/RC:C

CVSS v3.0

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:redhat:enterprise_linux:chromium-browser, p-cpe:/a:redhat:enterprise_linux:chromium-browser-debuginfo, cpe:/o:redhat:enterprise_linux:6

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Exploit Ease: No known exploits are available

Patch Publication Date: 2019/02/11

Vulnerability Publication Date: 2019/02/19

Reference Information

CVE: CVE-2019-5754, CVE-2019-5755, CVE-2019-5756, CVE-2019-5757, CVE-2019-5758, CVE-2019-5759, CVE-2019-5760, CVE-2019-5761, CVE-2019-5762, CVE-2019-5763, CVE-2019-5764, CVE-2019-5765, CVE-2019-5766, CVE-2019-5767, CVE-2019-5768, CVE-2019-5769, CVE-2019-5770, CVE-2019-5771, CVE-2019-5772, CVE-2019-5773, CVE-2019-5774, CVE-2019-5775, CVE-2019-5776, CVE-2019-5777, CVE-2019-5778, CVE-2019-5779, CVE-2019-5780, CVE-2019-5781, CVE-2019-5782

RHSA: 2019:0309