Gentoo Archives: gentoo-announce

From: Tim Sammut <underling@g.o>
To: gentoo-announce@g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 201111-05 ] Chromium, V8: Multiple vulnerabilities
Date: Sat, 19 Nov 2011 16:49:32
Message-Id: 4EC7DCC2.40706@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 201111-05
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: Chromium, V8: Multiple vulnerabilities
9 Date: November 19, 2011
10 Bugs: #390113, #390779
11 ID: 201111-05
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been reported in Chromium and V8, some of
19 which may allow execution of arbitrary code.
20
21 Background
22 ==========
23
24 Chromium is an open-source web browser project. V8 is Google's open
25 source JavaScript engine.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 www-client/chromium < 15.0.874.121 >= 15.0.874.121
34 2 dev-lang/v8 < 3.5.10.24 >= 3.5.10.24
35 -------------------------------------------------------------------
36 2 affected packages
37 -------------------------------------------------------------------
38
39 Description
40 ===========
41
42 Multiple vulnerabilities have been discovered in Chromium and V8.
43 Please review the CVE identifiers and release notes referenced below
44 for details.
45
46 Impact
47 ======
48
49 A context-dependent attacker could entice a user to open a specially
50 crafted web site or JavaScript program using Chromium or V8, possibly
51 resulting in the execution of arbitrary code with the privileges of the
52 process, or a Denial of Service condition. The attacker also could
53 cause a Java applet to run without user confirmation.
54
55 Workaround
56 ==========
57
58 There is no known workaround at this time.
59
60 Resolution
61 ==========
62
63 All Chromium users should upgrade to the latest version:
64
65 # emerge --sync
66 # emerge --ask --oneshot -v ">=www-client/chromium-15.0.874.121"
67
68 All V8 users should upgrade to the latest version:
69
70 # emerge --sync
71 # emerge --ask --oneshot --verbose ">=dev-lang/v8-3.5.10.24"
72
73 References
74 ==========
75
76 [ 1 ] CVE-2011-3892
77 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3892
78 [ 2 ] CVE-2011-3893
79 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3893
80 [ 3 ] CVE-2011-3894
81 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3894
82 [ 4 ] CVE-2011-3895
83 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3895
84 [ 5 ] CVE-2011-3896
85 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3896
86 [ 6 ] CVE-2011-3897
87 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3897
88 [ 7 ] CVE-2011-3898
89 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3898
90 [ 8 ] CVE-2011-3900
91 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3900
92 [ 9 ] Release Notes 15.0.874.120
93
94 http://googlechromereleases.blogspot.com/2011/11/stable-channel-update.html
95 [ 10 ] Release Notes 15.0.874.121
96
97 http://googlechromereleases.blogspot.com/2011/11/stable-channel-update_16.html
98
99 Availability
100 ============
101
102 This GLSA and any updates to it are available for viewing at
103 the Gentoo Security Website:
104
105 http://security.gentoo.org/glsa/glsa-201111-05.xml
106
107 Concerns?
108 =========
109
110 Security is a primary focus of Gentoo Linux and ensuring the
111 confidentiality and security of our users' machines is of utmost
112 importance to us. Any security concerns should be addressed to
113 security@g.o or alternatively, you may file a bug at
114 https://bugs.gentoo.org.
115
116 License
117 =======
118
119 Copyright 2011 Gentoo Foundation, Inc; referenced text
120 belongs to its owner(s).
121
122 The contents of this document are licensed under the
123 Creative Commons - Attribution / Share Alike license.
124
125 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature