Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 698398 (CVE-2019-13699, CVE-2019-13700, CVE-2019-13701, CVE-2019-13703, CVE-2019-13704, CVE-2019-13705, CVE-2019-13706, CVE-2019-13707, CVE-2019-13708, CVE-2019-13709, CVE-2019-13710, CVE-2019-13711, CVE-2019-13713, CVE-2019-13714, CVE-2019-13715, CVE-2019-13716, CVE-2019-13717, CVE-2019-13718, CVE-2019-13719)

Summary: <www-client/chromium-78.0.3904.70: multiple vulnerabilities
Product: Gentoo Security Reporter: Stephan Hartmann (RETIRED) <sultan>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: normal CC: chromium
Priority: Normal Flags: stable-bot: sanity-check+
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://chromereleases.googleblog.com/2019/10/stable-channel-update-for-desktop_22.html
See Also: https://github.com/gentoo/gentoo/pull/13465
Whiteboard: A2 [glsa+ cve]
Package list:
www-client/chromium-78.0.3904.70
Runtime testing required: ---

Description Stephan Hartmann (RETIRED) gentoo-dev 2019-10-23 16:21:07 UTC
See ${URL}

Reproducible: Always
Comment 1 Larry the Git Cow gentoo-dev 2019-10-25 03:07:02 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=401cccecb8de91c2b1e27ac202544e03bea13e2a

commit 401cccecb8de91c2b1e27ac202544e03bea13e2a
Author:     Stephan Hartmann <stha09@googlemail.com>
AuthorDate: 2019-10-24 13:40:28 +0000
Commit:     Mike Gilbert <floppym@gentoo.org>
CommitDate: 2019-10-25 03:06:40 +0000

    www-client/chromium: stable channel bump to 78.0.3904.70
    
    Bug: https://bugs.gentoo.org/698398
    Package-Manager: Portage-2.3.76, Repoman-2.3.16
    Signed-off-by: Stephan Hartmann <stha09@googlemail.com>
    Signed-off-by: Mike Gilbert <floppym@gentoo.org>

 www-client/chromium/Manifest                                            | 2 +-
 .../{chromium-78.0.3904.63.ebuild => chromium-78.0.3904.70.ebuild}      | 0
 2 files changed, 1 insertion(+), 1 deletion(-)
Comment 2 Thomas Deutschmann (RETIRED) gentoo-dev 2019-10-26 19:41:06 UTC
Added to an existing GLSA request.
Comment 3 Thomas Deutschmann (RETIRED) gentoo-dev 2019-10-26 19:50:04 UTC
Removing inapplicable CVEs:

CVE-2019-13702: Affecting installer, not us.

CVE-2019-15903: Affectx bundled expat but we are using dev-libs/expat.
Comment 4 Agostino Sarubbo gentoo-dev 2019-10-27 12:00:12 UTC
amd64 stable.

Maintainer(s), please cleanup.
Comment 5 Larry the Git Cow gentoo-dev 2019-10-27 14:40:07 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=f39b48f3c96f1881eea8ba2bd5b3c0e19e091c4a

commit f39b48f3c96f1881eea8ba2bd5b3c0e19e091c4a
Author:     Stephan Hartmann <stephan.hartmann@tu-dresden.de>
AuthorDate: 2019-10-27 12:29:32 +0000
Commit:     Mike Gilbert <floppym@gentoo.org>
CommitDate: 2019-10-27 14:39:36 +0000

    www-client/chromium: security cleanup
    
    Bug: https://bugs.gentoo.org/698398
    Closes: https://github.com/gentoo/gentoo/pull/13465
    Package-Manager: Portage-2.3.76, Repoman-2.3.16
    Signed-off-by: Stephan Hartmann <stha09@googlemail.com>
    Signed-off-by: Mike Gilbert <floppym@gentoo.org>

 www-client/chromium/Manifest                       |   1 -
 www-client/chromium/chromium-77.0.3865.120.ebuild  | 733 ---------------------
 .../chromium/files/chromium-77-blink-include.patch |  28 -
 .../chromium/files/chromium-77-fix-gn-gen.patch    |  11 -
 .../chromium/files/chromium-77-gcc-abstract.patch  |  61 --
 .../chromium/files/chromium-77-gcc-alignas.patch   |  72 --
 .../chromium/files/chromium-77-gcc-include.patch   |  26 -
 .../chromium/files/chromium-77-no-cups.patch       |  42 --
 .../chromium/files/chromium-77-std-string.patch    | 130 ----
 .../chromium/files/chromium-77-system-hb.patch     |  13 -
 .../chromium/files/chromium-unbundle-zlib.patch    |  25 -
 11 files changed, 1142 deletions(-)
Comment 6 GLSAMaker/CVETool Bot gentoo-dev 2019-11-25 00:15:13 UTC
This issue was resolved and addressed in
 GLSA 201911-06 at https://security.gentoo.org/glsa/201911-06
by GLSA coordinator Aaron Bauman (b-man).