Пакет chromium-gnome: Информация

    Бинарный пакет: chromium-gnome
    Версия: 66.0.3359.117-alt1
    Архитектура: x86_64
    Собран:  29 апреля 2018 г. 0:31 в задании #205409
    Исходный пакет: chromium
    Категория: Сети/WWW
    Сообщить об ошибке в пакете
    Домашняя страница: http://www.chromium.org

    Лицензия: BSD-3-Clause and LGPL-2.1+
    О пакете: Update to chromium to use Gnome keyring to store passwords
    Описание: 
    By using the update-alternatives the password store for Chromium is
    changed to utilize Gnome's Keyring. Please be aware that by this change
    the old password are no longer accessible and are also not converted
    to Gnome's Keyring.

    Сопровождающий: Alexey Gladkov


    Последнее изменение


    19 апреля 2018 г. Alexey Gladkov 66.0.3359.117-alt1
    - New version (66.0.3359.117).
    - Security fixes:
      - CVE-2018-6085: Use after free in Disk Cache.
      - CVE-2018-6086: Use after free in Disk Cache.
      - CVE-2018-6087: Use after free in WebAssembly.
      - CVE-2018-6088: Use after free in PDFium.
      - CVE-2018-6089: Same origin policy bypass in Service Worker.
      - CVE-2018-6090: Heap buffer overflow in Skia.
      - CVE-2018-6091: Incorrect handling of plug-ins by Service Worker.
      - CVE-2018-6092: Integer overflow in WebAssembly.
      - CVE-2018-6093: Same origin bypass in Service Worker.
      - CVE-2018-6094: Exploit hardening regression in Oilpan.
      - CVE-2018-6095: Lack of meaningful user interaction requirement before file upload.
      - CVE-2018-6096: Fullscreen UI spoof.
      - CVE-2018-6097: Fullscreen UI spoof.
      - CVE-2018-6098: URL spoof in Omnibox.
      - CVE-2018-6099: CORS bypass in ServiceWorker.
      - CVE-2018-6100: URL spoof in Omnibox.
      - CVE-2018-6101: Insufficient protection of remote debugging prototol in DevTools .
      - CVE-2018-6102: URL spoof in Omnibox.
      - CVE-2018-6103: UI spoof in Permissions.
      - CVE-2018-6104: URL spoof in Omnibox.
      - CVE-2018-6105: URL spoof in Omnibox.
      - CVE-2018-6106: Incorrect handling of promises in V8.
      - CVE-2018-6107: URL spoof in Omnibox.
      - CVE-2018-6108: URL spoof in Omnibox.
      - CVE-2018-6109: Incorrect handling of files by FileAPI.
      - CVE-2018-6110: Incorrect handling of plaintext files via file:// .
      - CVE-2018-6111: Heap-use-after-free in DevTools.
      - CVE-2018-6112: Incorrect URL handling in DevTools.
      - CVE-2018-6113: URL spoof in Navigation.
      - CVE-2018-6114: CSP bypass.
      - CVE-2018-6115: SmartScreen bypass in downloads.
      - CVE-2018-6116: Incorrect low memory handling in WebAssembly.
      - CVE-2018-6117: Confusing autofill settings.
      - CVE-2018-6084: Incorrect use of Distributed Objects in Google Software Updater on MacOS.
    30 марта 2018 г. Alexey Gladkov 65.0.3325.181-alt1
    - New version (65.0.3325.181).
    7 марта 2018 г. Alexey Gladkov 65.0.3325.146-alt1
    - New version (65.0.3325.146).
    - Use clang.
    - Security fixes:
      - CVE-2018-6058: Use after free in Flash.
      - CVE-2018-6059: Use after free in Flash.
      - CVE-2018-6060: Use after free in Blink.
      - CVE-2018-6061: Race condition in V8.
      - CVE-2018-6062: Heap buffer overflow in Skia.
      - CVE-2018-6057: Incorrect permissions on shared memory.
      - CVE-2018-6063: Incorrect permissions on shared memory.
      - CVE-2018-6064: Type confusion in V8.
      - CVE-2018-6065: Integer overflow in V8.
      - CVE-2018-6066: Same Origin Bypass via canvas.
      - CVE-2018-6067: Buffer overflow in Skia.
      - CVE-2018-6068: Object lifecycle issues in Chrome Custom Tab.
      - CVE-2018-6069: Stack buffer overflow in Skia.
      - CVE-2018-6070: CSP bypass through extensions.
      - CVE-2018-6071: Heap bufffer overflow in Skia.
      - CVE-2018-6072: Integer overflow in PDFium.
      - CVE-2018-6073: Heap bufffer overflow in WebGL.
      - CVE-2018-6074: Mark-of-the-Web bypass.
      - CVE-2018-6075: Overly permissive cross origin downloads.
      - CVE-2018-6076: Incorrect handling of URL fragment identifiers in Blink.
      - CVE-2018-6077: Timing attack using SVG filters.
      - CVE-2018-6078: URL Spoof in OmniBox.
      - CVE-2018-6079: Information disclosure via texture data in WebGL.
      - CVE-2018-6080: Information disclosure in IPC call.
      - CVE-2018-6081: XSS in interstitials.
      - CVE-2018-6082: Circumvention of port blocking.
      - CVE-2018-6083: Incorrect processing of AppManifests.