Debian Security Advisory
DSA-4906-1 chromium -- security update
- Date Reported:
- 27 Apr 2021
- Affected Packages:
- chromium
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2021-21201, CVE-2021-21202, CVE-2021-21203, CVE-2021-21204, CVE-2021-21205, CVE-2021-21207, CVE-2021-21208, CVE-2021-21209, CVE-2021-21210, CVE-2021-21211, CVE-2021-21212, CVE-2021-21213, CVE-2021-21214, CVE-2021-21215, CVE-2021-21216, CVE-2021-21217, CVE-2021-21218, CVE-2021-21219, CVE-2021-21221, CVE-2021-21222, CVE-2021-21223, CVE-2021-21224, CVE-2021-21225, CVE-2021-21226.
- More information:
-
Several vulnerabilities have been discovered in the chromium web browser.
- CVE-2021-21201
Gengming Liu and Jianyu Chen discovered a use-after-free issue.
- CVE-2021-21202
David Erceg discovered a use-after-free issue in extensions.
- CVE-2021-21203
asnine discovered a use-after-free issue in Blink/Webkit.
- CVE-2021-21204
Tsai-Simek, Jeanette Ulloa, and Emily Voigtlander discovered a use-after-free issue in Blink/Webkit.
- CVE-2021-21205
Alison Huffman discovered a policy enforcement error.
- CVE-2021-21207
koocola and Nan Wang discovered a use-after-free in the indexed database.
- CVE-2021-21208
Ahmed Elsobky discovered a data validation error in the QR code scanner.
- CVE-2021-21209
Tom Van Goethem discovered an implementation error in the Storage API.
- CVE-2021-21210
@bananabr discovered an error in the networking implementation.
- CVE-2021-21211
Akash Labade discovered an error in the navigation implementation.
- CVE-2021-21212
Hugo Hue and Sze Yui Chau discovered an error in the network configuration user interface.
- CVE-2021-21213
raven discovered a use-after-free issue in the WebMIDI implementation.
- CVE-2021-21214
A use-after-free issue was discovered in the networking implementation.
- CVE-2021-21215
Abdulrahman Alqabandi discovered an error in the Autofill feature.
- CVE-2021-21216
Abdulrahman Alqabandi discovered an error in the Autofill feature.
- CVE-2021-21217
Zhou Aiting discovered use of uninitialized memory in the pdfium library.
- CVE-2021-21218
Zhou Aiting discovered use of uninitialized memory in the pdfium library.
- CVE-2021-21219
Zhou Aiting discovered use of uninitialized memory in the pdfium library.
- CVE-2021-21221
Guang Gong discovered insufficient validation of untrusted input.
- CVE-2021-21222
Guang Gong discovered a buffer overflow issue in the v8 javascript library.
- CVE-2021-21223
Guang Gong discovered an integer overflow issue.
- CVE-2021-21224
Jose Martinez discovered a type error in the v8 javascript library.
- CVE-2021-21225
Brendon Tiszka discovered an out-of-bounds memory access issue in the v8 javascript library.
- CVE-2021-21226
Brendon Tiszka discovered a use-after-free issue in the networking implementation.
For the stable distribution (buster), these problems have been fixed in version 90.0.4430.85-1~deb10u1.
We recommend that you upgrade your chromium packages.
For the detailed security status of chromium please refer to its security tracker page at: https://security-tracker.debian.org/tracker/chromium
- CVE-2021-21201