*** This bug is a security vulnerability ***

Public security bug reported:

The current chromium-browser version in 12.04 is outdated 
(http://packages.ubuntu.com/precise/chromium-browser is at version 18 when 
current version is 23).
That were most probably security vulnerabilities that where fixed between these 
2 versions, which Ubuntu chromium-browser users are still vulnerable to.
The Quantal package is at version 22: 
http://packages.ubuntu.com/quantal/chromium-browser 

I see that the firefox package keeps the same version betweeen Precise and 
Quantal, since running an outdated browser version has security implications.
The same logic should be applied to chromium-browser.

Futhermore; there is a (formerly) "official" PPA at 
https://launchpad.net/~chromium-daily/+archive/ppa that used to maintain the 
latest version of each channel. This PPA is no longer maintained and according 
to the Chromium team's support IRC channel, it won't be maintained in the near 
future.
I believe it is best to delete this PPA, to avoid users thinking that their 
browsers are up-to-date when they are not.

** Affects: chromium-browser (Ubuntu)
     Importance: Undecided
         Status: New

** Also affects: chromium-browser
   Importance: Undecided
       Status: New

** No longer affects: nautilus (Ubuntu)

** Project changed: chromium-browser => chromium-browser (Ubuntu)

** Information type changed from Private Security to Public Security

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1081518

Title:
  Chromium-browser package is outdated and poses a security risk

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/chromium-browser/+bug/1081518/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to