Update Chromium to >= 36.0.1985.125 (including security fixes)

Bug #1331375 reported by Alexander Buchner
286
This bug affects 7 people
Affects Status Importance Assigned to Milestone
chromium-browser (Ubuntu)
Fix Released
Undecided
Chad Miller

Bug Description

Updating fixes security bugs, see the linked CVEs

information type: Private Security → Public Security
Changed in chromium-browser (Ubuntu):
status: New → Confirmed
assignee: nobody → Chad Miller (cmiller)
Revision history for this message
Florian W. (florian-will) wrote :

Are there any issues preventing chromium from being updated to a version without known security vulnerabilities? Even debian has v35 in stable-security since June 15, and Arch Linux (unsurprisingly) since June 11, and the vulnerabilites are public since June 10.

Since most other distributions (ignoring Fedora, which probably handles chromium in the sanest way…) have switched to v35 two weeks ago, the problems with the new version can't be that bad I guess. At least better than browsing with 4 CVEs. Or is this repeated chromium update delay due to a lack of manpower? In that case, is there any reason not to use and contribute to the debian packaging work directly?

Revision history for this message
f00fbug (topolm5678) wrote :

Another possibility is that Chromium get not updated is that with release 35 NPAPI got removed and therfore the Adobe flash plugin do not work anymore and users have to pull in chromium-pepper-flash. However I agree do put users at security risk due to browser vulnerabilities which are already fixed in newer releases is a problem.

Revision history for this message
pcworld (pcworld) wrote :

@f00fbug:
No, this change has already taken place with Chromium 34.

Revision history for this message
f00fbug (topolm5678) wrote :

@pcworld: thanks and yes I think that's the reason why no update occured yet (maybe only speculation)

Revision history for this message
pcworld (pcworld) wrote :

@f00fbug:
No, this is *not* the reason, since Ubuntu 13.10 and 14.04 both ship Chromium 34 currently: http://packages.ubuntu.com/search?keywords=chromium-browser

Revision history for this message
Saikrishna Arcot (saiarcot895) wrote :

@f00fbug: In fact, the switch to Aura was made early with version 34 (the default Chrome(ium) made the switch in version 35 to avoid the bugs in 34), therefore removing support for NPAPI plugins.

Revision history for this message
Saikrishna Arcot (saiarcot895) wrote :

I believe version 35 will be landing in the next week or so.

Revision history for this message
Florian W. (florian-will) wrote :

FYI, stable Chromium 36.0.1985.125 is now out for Linux, containing 26 security fixes for two more CVEs.

summary: - Update Chromium to >= 35.0.1916.153 (including security fixes)
+ Update Chromium to >= 36.0.1985.125 (including security fixes)
Revision history for this message
Alexander Buchner (alexander-buchner) wrote :

@Saikrishna Arcot
What makes you believe that there will be an update?

pcworld (pcworld)
Changed in chromium-browser (Ubuntu):
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.