{"id":"MGASA-2016-0042","summary":"Updated chromium-browser-stable packages fix security vulnerability","details":"The LoadIC::UpdateCaches function in ic/ic.cc in Google V8, as used in\nGoogle Chrome before 48.0.2564.82, does not ensure receiver compatibility\nbefore performing a cast of an unspecified variable, which allows remote\nattackers to cause a denial of service or possibly have unknown other\nimpact via crafted JavaScript code. (CVE-2016-1612)\n\nMultiple use-after-free vulnerabilities in the formfiller implementation\nin PDFium, as used in Google Chrome before 48.0.2564.82, allow remote\nattackers to cause a denial of service or possibly have unspecified other\nimpact via a crafted PDF document, related to improper tracking of the\ndestruction of (1) IPWL_FocusHandler and (2) IPWL_Provider objects.\n(CVE-2016-1613)\n\nThe UnacceleratedImageBufferSurface class in\nWebKit/Source/platform/graphics/UnacceleratedImageBufferSurface.cpp in\nBlink, as used in Google Chrome before 48.0.2564.82, mishandles the\ninitialization mode, which allows remote attackers to obtain sensitive\ninformation from process memory via a crafted web site. (CVE-2016-1614)\n\nThe Omnibox implementation in Google Chrome before 48.0.2564.82 allows\nremote attackers to spoof a document's origin via unspecified vectors.\n(CVE-2016-1615)\n\nThe CustomButton::AcceleratorPressed function in\nui/views/controls/button/custom_button.cc in Google Chrome before\n48.0.2564.82 allows remote attackers to spoof URLs via vectors involving\nan unfocused custom button. (CVE-2016-1616)\n\nThe CSPSource::schemeMatches function in\nWebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy\n(CSP) implementation in Blink, as used in Google Chrome before\n48.0.2564.82, does not apply http policies to https URLs and does not\napply ws policies to wss URLs, which makes it easier for remote attackers\nto determine whether a specific HSTS web site has been visited by reading\na CSP report. (CVE-2016-1617)\n\nBlink, as used in Google Chrome before 48.0.2564.82, does not ensure that\na proper cryptographicallyRandomValues random number generator is used,\nwhich makes it easier for remote attackers to defeat cryptographic\nprotection mechanisms via unspecified vectors. (CVE-2016-1618)\n\nMultiple integer overflows in the (1) sycc422_to_rgb and (2)\nsycc444_to_rgb functions in fxcodec/codec/fx_codec_jpx_opj.cpp in PDFium,\nas used in Google Chrome before 48.0.2564.82, allow remote attackers to\ncause a denial of service (out-of-bounds read) or possibly have\nunspecified other impact via a crafted PDF document. (CVE-2016-1619)\n\nMultiple unspecified vulnerabilities in Google Chrome before 48.0.2564.82\nallow attackers to cause a denial of service or possibly have other impact\nvia unknown vectors. (CVE-2016-1620)\n\nThe included V8 version 4.8.271.17 fixes multiple vulnerabilities.\n","modified":"2026-04-16T06:26:14.258544307Z","published":"2016-01-29T11:02:50Z","upstream":["CVE-2016-1612","CVE-2016-1613","CVE-2016-1614","CVE-2016-1615","CVE-2016-1616","CVE-2016-1617","CVE-2016-1618","CVE-2016-1619","CVE-2016-1620"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2016-0042.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=17567"},{"type":"WEB","url":"http://googlechromereleases.blogspot.com/2016/01/stable-channel-update_20.html"},{"type":"WEB","url":"http://googlechromereleases.blogspot.com/2016/01/stable-channel-update_27.html"}],"affected":[{"package":{"name":"chromium-browser-stable","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/chromium-browser-stable?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"48.0.2564.97-1.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2016-0042.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}