I'm aware of the third party PPA workaround, but:
a) I'm not really sure it can be trusted (I don't know Alex Shkop, sorry)
b) I'm certain most people install Chromium from Canonical's repositories 
rather than PPA (Official or non-official). These people browse the Web with 
browsers that have known security vulnerabilities.

I believe the best way would be to treat chromium-browser updates as
security updates (which they are), and push them to LTS releases, just
like FireFox.

-- 
You received this bug notification because you are a member of Desktop
Packages, which is subscribed to chromium-browser in Ubuntu.
https://bugs.launchpad.net/bugs/1081518

Title:
  Chromium-browser package is outdated and poses a security risk

Status in “chromium-browser” package in Ubuntu:
  New

Bug description:
  The current chromium-browser version in 12.04 is outdated 
(http://packages.ubuntu.com/precise/chromium-browser is at version 18 when 
current version is 23).
  That were most probably security vulnerabilities that where fixed between 
these 2 versions, which Ubuntu chromium-browser users are still vulnerable to.
  The Quantal package is at version 22: 
http://packages.ubuntu.com/quantal/chromium-browser 

  I see that the firefox package keeps the same version betweeen Precise and 
Quantal, since running an outdated browser version has security implications.
  The same logic should be applied to chromium-browser.

  Futhermore; there is a (formerly) "official" PPA at 
https://launchpad.net/~chromium-daily/+archive/ppa that used to maintain the 
latest version of each channel. This PPA is no longer maintained and according 
to the Chromium team's support IRC channel, it won't be maintained in the near 
future.
  I believe it is best to delete this PPA, to avoid users thinking that their 
browsers are up-to-date when they are not.

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/chromium-browser/+bug/1081518/+subscriptions

-- 
Mailing list: https://launchpad.net/~desktop-packages
Post to     : desktop-packages@lists.launchpad.net
Unsubscribe : https://launchpad.net/~desktop-packages
More help   : https://help.launchpad.net/ListHelp

Reply via email to