This bug was fixed in the package chromium-browser - 37.0.2062.94-0ubuntu0.12.04.1~pkg909
--------------- chromium-browser (37.0.2062.94-0ubuntu0.12.04.1~pkg909) precise-security; urgency=medium * Release to stage chromium-browser (37.0.2062.94-0ubuntu1) UNRELEASED; urgency=low * Upstream release 37.0.2062.94. - CVE-2014-3165: Use-after-free in Blink websockets. - CVE-2014-3176, CVE-2014-3177: A combination of bugs in V8, IPC, sync, and extensions that can lead to remote code execution outside of the sandbox. - CVE-2014-3168: Use-after-free in SVG. - CVE-2014-3169: Use-after-free in DOM. - CVE-2014-3170: Extension permission dialog spoofing. - CVE-2014-3171: Use-after-free in bindings. - CVE-2014-3172: Issue related to extension debugging. - CVE-2014-3173: Uninitialized memory read in WebGL. - CVE-2014-3174: Uninitialized memory read in Web Audio. - CVE-2014-3175: Various fixes from internal audits, fuzzing and other initiatives. - CVE-2014-3176, CVE-2014-3177: Interaction of extensions, IPC, the sync API, and Google V8 to execute arbitrary code. * Fix a shell bug in the binary-wrapper that prevented USER flags from working properly. * debian/control: Suggests chromiumflashplugin . * debian/apport: Significant cleanup. * debian/rules: Disable SSE instructions on x86 to avoid SIGILL on some CPUs. (LP: #1353185) * debian/checkout-orig-source.mk: Don't include src/ prefix in orig tarball. * debian/patches/*: refresh line numbers. * debian/patches/search-credit.patch, debian/patches/additional-search-engines.patch: Track source files moved. * debian/patches/ffmpeg-gyp-config.patch, debian/patches/fix-gyp-space-in-object-filename-exception.patch, debian/patches/gyp-icu-m32-test: Disabled. No longer needs fixing. * debian/control: build-dep on openssl. * debian/patches/disable-sse2: Don't require SSE/SSE2 CPU features on x86. (LP: #1353185) * debian/rules: Use built-in PDF support. (LP: #513745, #1009902) chromium-browser (36.0.1985.143-0ubuntu1) precise-security; urgency=low * Upstream release 36.0.1985.143: - CVE-2014-3165: Use-after-free in web sockets. - CVE-2014-3166: Information disclosure in SPDY. - CVE-2014-3167: Various fixes from internal audits, fuzzing and other initiatives. * debian/rules: Avoid some unnecessary warning of invalid mv. * debian/rules: Don't use tcmalloc on i386. * debian/control: Don't have (unused) shlibs-depends on -dbg packages and non-binary packages. * debian/chromium-browser-codecs-ffmpeg-extra.dirs, debian/chromium-browser-codecs-ffmpeg.dirs: Removed. Unused. * debian/chromium-browser.lintian-overrides, debian/chromium-codecs-ffmpeg-extra-dbg.lintian-overrides, debian/chromium-codecs-ffmpeg-extra.lintian-overrides, debian/chromium-codecs-ffmpeg.lintian-overrides, debian/source/lintian-overrides: Add lintian overrides. -- Chad MILLER <chad.mil...@canonical.com> Sun, 31 Aug 2014 17:27:11 -0400 ** Changed in: chromium-browser (Ubuntu) Status: Incomplete => Fix Released ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2014-3165 ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2014-3166 ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2014-3167 ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2014-3168 ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2014-3169 ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2014-3170 ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2014-3171 ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2014-3172 ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2014-3173 ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2014-3174 ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2014-3175 ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2014-3176 ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2014-3177 -- You received this bug notification because you are a member of Desktop Packages, which is subscribed to chromium-browser in Ubuntu. https://bugs.launchpad.net/bugs/1353185 Title: Chromium 36 upgrade will not execute Status in “chromium-browser” package in Ubuntu: Fix Released Bug description: Chromium will no longer start after version 36 upgrade. Previous version worked ok. Execution from command line reports "Illegal instruction (core dumped)". Nothing displayed on screen. lshw reports: description: Tower Computer version: System Version width: 32 bits capabilities: smbios-2.3 dmi-2.3 configuration: boot=normal chassis=tower *-core description: Motherboard product: A7V8X vendor: ASUSTeK Computer INC. *-firmware description: BIOS vendor: Award Software, Inc. physical id: 0 version: ASUS A7V8X ACPI BIOS Revision 1010 *-cpu description: CPU product: AMD Athlon(TM) XP 2400+ vendor: Hynix Semiconductor (Hyundai Electronics) *-memory description: System Memory slot: System board or motherboard size: 1GiB ProblemType: Bug DistroRelease: Ubuntu 12.04 Package: chromium-browser 36.0.1985.125-0ubuntu1.12.04.0~pkg897 ProcVersionSignature: Ubuntu 3.2.0-67.101-generic 3.2.60 Uname: Linux 3.2.0-67-generic i686 NonfreeKernelModules: nvidia ApportVersion: 2.0.1-0ubuntu17.6 Architecture: i386 Date: Tue Aug 5 19:35:30 2014 Desktop-Session: DESKTOP_SESSION = ubuntu-2d XDG_CONFIG_DIRS = /etc/xdg/xdg-ubuntu-2d:/etc/xdg XDG_DATA_DIRS = /usr/share/ubuntu-2d:/usr/share/gnome:/usr/local/share/:/usr/share/ DmesgChromium: [ 28.356536] type=1400 audit(1407283433.748:15): apparmor="STATUS" operation="profile_load" name="/usr/lib/lightdm/lightdm/lightdm-guest-session-wrapper//chromium_browser" pid=853 comm="apparmor_parser" Env: MOZ_PLUGIN_PATH = None LD_LIBRARY_PATH = None InstallationMedia: Ubuntu 11.04 "Natty Narwhal" - Release i386 (20110427.1) MarkForUpload: True ProcEnviron: TERM=xterm PATH=(custom, no user) LANG=en_US.UTF-8 SHELL=/bin/bash SourcePackage: chromium-browser UpgradeStatus: Upgraded to precise on 2012-09-15 (689 days ago) chromium-default: CHROMIUM_FLAGS="" modified.conffile..etc.default.chromium.browser: [deleted] To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/chromium-browser/+bug/1353185/+subscriptions -- Mailing list: https://launchpad.net/~desktop-packages Post to : desktop-packages@lists.launchpad.net Unsubscribe : https://launchpad.net/~desktop-packages More help : https://help.launchpad.net/ListHelp