Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 755227 (CVE-2020-16014, CVE-2020-16015, CVE-2020-16018, CVE-2020-16019, CVE-2020-16020, CVE-2020-16021, CVE-2020-16022, CVE-2020-16023, CVE-2020-16024, CVE-2020-16025, CVE-2020-16026, CVE-2020-16027, CVE-2020-16028, CVE-2020-16029, CVE-2020-16030, CVE-2020-16031, CVE-2020-16032, CVE-2020-16033, CVE-2020-16034, CVE-2020-16036) - <www-client/chromium-87.0.4280.66 <www-client/google-chrome-87.0.4280.66: Multiple vulnerabilities (CVE-2020-{16018,16019,16020,16021,16022,16015,16014,16023,16024,16025,16026,16027,16028,16029,16030,16031,16032,16033,16034,16012,16036})
Summary: <www-client/chromium-87.0.4280.66 <www-client/google-chrome-87.0.4280.66: Mul...
Status: RESOLVED FIXED
Alias: CVE-2020-16014, CVE-2020-16015, CVE-2020-16018, CVE-2020-16019, CVE-2020-16020, CVE-2020-16021, CVE-2020-16022, CVE-2020-16023, CVE-2020-16024, CVE-2020-16025, CVE-2020-16026, CVE-2020-16027, CVE-2020-16028, CVE-2020-16029, CVE-2020-16030, CVE-2020-16031, CVE-2020-16032, CVE-2020-16033, CVE-2020-16034, CVE-2020-16036
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal major (vote)
Assignee: Gentoo Security
URL: https://chromereleases.googleblog.com...
Whiteboard: A2 [glsa+ cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2020-11-18 08:22 UTC by Stephan Hartmann (RETIRED)
Modified: 2021-02-26 13:40 UTC (History)
1 user (show)

See Also:
Package list:
www-client/chromium-87.0.4280.66 amd64 arm64 dev-libs/re2-0.2020.11.01
Runtime testing required: ---
nattka: sanity-check-


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stephan Hartmann (RETIRED) gentoo-dev 2020-11-18 08:22:20 UTC
See ${URL}.

www-client/google-chrome bumped already. Checking chromium atm.

Not added CVE-2020-16035 (cros) and CVE-2019-8075 (flash), because those look unrelated.

Can't add CVE-2020-16012 to alias (already taken by firefox in bug #755170).
Comment 1 Larry the Git Cow gentoo-dev 2020-11-18 11:01:56 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=a2d36e1cb2596a11cf03cb92b44a52d1e07f2c0a

commit a2d36e1cb2596a11cf03cb92b44a52d1e07f2c0a
Author:     Stephan Hartmann <sultan@gentoo.org>
AuthorDate: 2020-11-18 10:58:11 +0000
Commit:     Stephan Hartmann <sultan@gentoo.org>
CommitDate: 2020-11-18 11:01:50 +0000

    www-client/chromium: stable channel bump to 87.0.4280.66
    
    Bug: https://bugs.gentoo.org/755227
    Package-Manager: Portage-3.0.9, Repoman-3.0.2
    Signed-off-by: Stephan Hartmann <sultan@gentoo.org>

 www-client/chromium/Manifest                                            | 2 +-
 .../{chromium-87.0.4280.63.ebuild => chromium-87.0.4280.66.ebuild}      | 0
 2 files changed, 1 insertion(+), 1 deletion(-)
Comment 2 Thomas Deutschmann (RETIRED) gentoo-dev 2020-11-18 23:42:46 UTC
x86 stable
Comment 3 Agostino Sarubbo gentoo-dev 2020-11-19 11:16:58 UTC
amd64 stable
Comment 4 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-11-22 03:24:51 UTC
arm done
Comment 5 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-11-22 03:25:25 UTC
arm64 done

all arches done
Comment 6 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-11-22 03:32:41 UTC
Please cleanup, thanks!
Comment 7 Larry the Git Cow gentoo-dev 2020-11-22 08:18:48 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=102e93f384ad8fcf9fbcc729641de6a4a09cb73a

commit 102e93f384ad8fcf9fbcc729641de6a4a09cb73a
Author:     Stephan Hartmann <sultan@gentoo.org>
AuthorDate: 2020-11-22 08:17:59 +0000
Commit:     Stephan Hartmann <sultan@gentoo.org>
CommitDate: 2020-11-22 08:17:59 +0000

    www-client/chromium: security cleanup
    
    Bug: https://bugs.gentoo.org/755227
    Package-Manager: Portage-3.0.9, Repoman-3.0.2
    Signed-off-by: Stephan Hartmann <sultan@gentoo.org>

 www-client/chromium/Manifest                       |   2 -
 www-client/chromium/chromium-86.0.4240.198.ebuild  | 893 ---------------------
 .../chromium/files/chromium-87-xproto-crash.patch  |  38 -
 www-client/chromium/files/chromium-launcher-r5.sh  |  56 --
 www-client/chromium/metadata.xml                   |   3 -
 5 files changed, 992 deletions(-)
Comment 8 NATTkA bot gentoo-dev 2020-12-04 13:32:55 UTC
Unable to check for sanity:

> no match for package: www-client/chromium-87.0.4280.66
Comment 9 GLSAMaker/CVETool Bot gentoo-dev 2020-12-07 00:38:18 UTC
This issue was resolved and addressed in
 GLSA 202012-05 at https://security.gentoo.org/glsa/202012-05
by GLSA coordinator Thomas Deutschmann (whissi).