Your message dated Sun, 11 Feb 2018 04:22:13 +0000
with message-id <e1ekj9z-0000sf...@fasolo.debian.org>
and subject line Bug#884173: fixed in chromium-browser 64.0.3282.119-2
has caused the Debian Bug report #884173,
regarding Chromium 62/63 media router cast segfaults browser, possible security 
implications
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
884173: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=884173
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Package: chromium
Version: 62.0.3202.89-1~deb9u1
Severity: grave
Tags: security, buster

Although --media-router=0 is the default, Chromium now randomly crashes, but 
did not crash in release 61. Only setting media-router to "2" in the Chromium 
"Local State" file fixes the issue temporarily, but still with random crashes. 
Something is really broken in the media router or cast functionality after 
updating to chromium 62/63. Not sure why, but perhaps some maintainers or users 
have seen similar issues? This appears to have broken between the update from 
61 to 62.

>From /etc/chromium.d/default-flags:
# Disable the builtin media router (bug #833477)
export CHROMIUM_FLAGS="$CHROMIUM_FLAGS --media-router=0"

$ chromium
Received signal 11 SEGV_MAPERR 000000000010
#0 0x55aa4d3d6f56 <unknown>
#1 0x55aa4bfa3a58 <unknown>
#2 0x55aa4d3d72dc <unknown>
#3 0x7fa33249d0c0 <unknown>
#4 0x55aa4c8c85ba <unknown>
#5 0x55aa4c8c943d <unknown>
#6 0x55aa4c8c9a4d <unknown>
#7 0x55aa4c8c9bb5 <unknown>
#8 0x55aa4d43af19 <unknown>
#9 0x55aa4d3d8136 <unknown>
#10 0x55aa4d3f7318 <unknown>
#11 0x55aa4d3f7a1f <unknown>
#12 0x55aa4d3f86c6 <unknown>
#13 0x55aa4d3fa822 <unknown>
#14 0x55aa4d41fffb <unknown>
#15 0x55aa4d43fd58 <unknown>
#16 0x55aa4d43ae10 <unknown>
#17 0x7fa332493494 start_thread
#18 0x7fa326e2dabf clone
  r8: 0000000000000001  r9: 000055aa5017290c r10: 000055aa50172910 r11: 
00007fa326eaee20
 r12: 0000000000000008 r13: 00007fa2e8b1cdf0 r14: 00007fa2e8b1d000 r15: 
0000000000000000
  di: 0000000000000000  si: 00007fa2e8b1cdf0  bp: 00007fa2e8b1cf10  bx: 
0000000000000008
  dx: 0000000000000004  ax: 0000222ad12c4300  cx: 0000000000000000  sp: 
00007fa2e8b1cd90
  ip: 000055aa4c8c85ba efl: 0000000000010206 cgf: 002b000000000033 erf: 
0000000000000004
 trp: 000000000000000e msk: 0000000000000000 cr2: 0000000000000010
[end of stack trace]
Calling _exit(1). Core file will not be generated.

To get chromium to launch without crashing, use:
$ sed -i 
's/load-media-router-component-extension@./load-media-router-component-extension@2/'
 ~/.config/chromium/Local\ State

This should disable the media router extension and allow you to run chromium 
again without it immediately crashing.
Either the media router should be fixed since this is a blocking bug, or media 
router should be removed. From past experience, the media router or casting 
functionality has been semi broken or only half working for some time. It 
appears to work sometimes, but not others, or crashes during use. As it stands 
now, perhaps permanently removing the functionality is best until it is 
rigorously tested for quality and security issues. This issue may even be 
exploitable due to the segmentation fault parameters that might be controllable 
over the network to attack the media router component.

--- End Message ---
--- Begin Message ---
Source: chromium-browser
Source-Version: 64.0.3282.119-2

We believe that the bug you reported is fixed in the latest version of
chromium-browser, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 884...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Michael Gilbert <mgilb...@debian.org> (supplier of updated chromium-browser 
package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sun, 11 Feb 2018 03:00:09 +0000
Source: chromium-browser
Binary: chromium chromium-l10n chromium-shell chromium-widevine chromium-driver 
chromium-common
Architecture: source
Version: 64.0.3282.119-2
Distribution: unstable
Urgency: medium
Maintainer: Debian Chromium Maintainers 
<pkg-chromium-ma...@lists.alioth.debian.org>
Changed-By: Michael Gilbert <mgilb...@debian.org>
Description:
 chromium   - web browser
 chromium-common - web browser - common resources used by the chromium packages
 chromium-driver - web browser - WebDriver support
 chromium-l10n - web browser - language packs
 chromium-shell - web browser - minimal shell
 chromium-widevine - web browser - widevine content decryption support
Closes: 884173
Changes:
 chromium-browser (64.0.3282.119-2) unstable; urgency=medium
 .
   * Drop chromecast patch (closes: #884173).
Checksums-Sha1:
 b553f948eb0a8a768a96274f187ce69ac2b748a1 4306 
chromium-browser_64.0.3282.119-2.dsc
 ce915cde7a933d471bcbfd093ece47c47c99dcaf 137100 
chromium-browser_64.0.3282.119-2.debian.tar.xz
 e199673f3f280a5ea059b7f6dc6708f875390728 18981 
chromium-browser_64.0.3282.119-2_source.buildinfo
Checksums-Sha256:
 5181802cca082d5ebf58dcf803cbd5003ac61315d7654935687a955e0872baac 4306 
chromium-browser_64.0.3282.119-2.dsc
 c179f2bf05dc313a52765b038309f29bfadb1fe699956efa22fe1a5f3f9d8a6e 137100 
chromium-browser_64.0.3282.119-2.debian.tar.xz
 18c79a0651c3f3fb7ee3be356c5a92e5880e459b8d807f521ea66ae9a8bc2d01 18981 
chromium-browser_64.0.3282.119-2_source.buildinfo
Files:
 323087f32ed7f1501c6bf4640a8447ea 4306 web optional 
chromium-browser_64.0.3282.119-2.dsc
 1ad212236291bc03e8fa44c1d0fcc7c8 137100 web optional 
chromium-browser_64.0.3282.119-2.debian.tar.xz
 afaabac210b22a0a636aa901c70b2c38 18981 web optional 
chromium-browser_64.0.3282.119-2_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQQzBAEBCgAdFiEEluhy7ASCBulP9FUWuNayzQLW9HMFAlp/t4IACgkQuNayzQLW
9HOQCB/8DdxFaqk0WLlYtPrAB2kl0fTngCx0NH8wT2s8NjJHMIkxYx7KGkfIIZ2z
2AW96Gckf+OLhHK+bwhW8fJAkL4Rtlfo5MYkmTHjjx8653UCkVXuXgsPwKj3JrrY
a/T1cZqP0ZvNK9hvt2Gm3Jr2DhtDFwZyYR6/d8m+HoFFJoEtRt8gOhkE4rLvQyRr
lcARpHS6XMOAOa5P00lwmCiM6FSB9026dt4qc0XfqBv/5Ly2sTFCvoeWEEbHK2ce
F1wp5ciLXM61A2ChFYorF6OCBvESwXqCO17lpMN/1nvdbV/MqYWA46PUnvt/Mxbb
849jicKV9jvRAemblkjQXLOP92VEdhJmxuHZ/dXkzfNDh/C1eNOGTH54ZzqSYi9p
p3Um0qhKgFf6AWcW/gHc3SOTSszhiUINbBYpXZYxKodBeVnOw61ucWhG5V7lIU4U
R2GyFdQf6G4K2wd/fVQhu6CjapgZDJG2IKxxgJjMFUKyr2r3Q2k4Jun7Z9sSPkFU
jsmQItDOVX48RFs1iEJwbw/DNE6xAmd1Ka7wazgc14x9g58z886YYy3vk/V8Yj3X
ivdn3IhnKyCaH7jLbsGUimwowxosuBOIEVeKNBoZFX3LK6ZNySWq5kFnaRsqfv2G
jFKSkYiuCqA98gscDsL2DiGFcJMD2OuzFgfL1QhPGcbYL297ErN1WnfdALlFkU3r
LABEVP30yXf6lIyKGiC8PbaMcjidkNo+ZAFHr5dK1Ty4n9stjZ5XiCaB9NN2Advl
bZpijFoW3lxq4rbk4nBw+BnPDT8mY9Q9IC6JvCIBExve3pRt+R3cLkKtkHfzRTra
TRB2weR6j9ZUnduDJqScpSbDKtTDHMAJdKIgdfxwVLi3XH03CNM+BxEJ45+G1Oog
DW4SkrmQlVc+Xe64se4Ay3NupMBJPO+jABSH8EFNWI9sB+X9+4Z/qHI4z98ivPud
+G3xWHuUWDmD/w+G1t79MEfBkK/cYEd5zilQ3xh7cEE/dmVnS3jsUVg/gXGQcu8+
3/ECFMtCLGFAwjvNm4NJT0TSDmBjtwh7U4CdbPDgEALSL7OxGqmSYVcaMu2iiYEV
9C4iQxms0ajc6w3+y4S7jQWc+Y7WsQAap38CGRGoxarRtjozEtSbnbYB6R2buw2F
hBSUGy/oapXFS7mDSDTOhWWa0d5DtOv/5T5hGBt8o+dKHfr/mHYRpNrPFCc+sH8u
CbuOpHqRVaZT4/EaXeDb4KjU5ccmtMUeiQPtqq7wCOxtjLYqaTksy5u+uYNMqJ3N
DXqYMLQsV8WsOInq8erroxEzEW6MGZbXwytmm5EGycf96QcDYvo6G8akBibB0cIi
OxDq/F8Pk6bkIvkMHHv+GCb+1kB7eA==
=jowh
-----END PGP SIGNATURE-----

--- End Message ---

Reply via email to