[Nix-dev] Chromium: Unpatched CVEs or Missing Features?

Shea Levy shea at shealevy.com
Mon Nov 7 03:29:17 CET 2016


Yeah, please merge this immediately.

Graham Christensen <graham at grahamc.com> writes:

>> can you give a sense of the severity of the CVEs in question?
>
> From one LWN summary[0], it looks pretty serious:
>
> Multiple flaws were found in the processing of malformed web content. A
> web page containing malicious content could cause Chromium to crash,
> execute arbitrary code, or disclose sensitive information when visited
> by the victim.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 800 bytes
Desc: not available
URL: <http://lists.science.uu.nl/pipermail/nix-dev/attachments/20161106/588b3bbb/attachment.sig>


More information about the nix-dev mailing list