Gentoo Archives: gentoo-announce

From: Tim Sammut <underling@g.o>
To: gentoo-announce@g.o
Subject: [gentoo-announce] [ GLSA 201204-03 ] Chromium: Multiple vulnerabilities
Date: Tue, 10 Apr 2012 22:14:08
Message-Id: 4F84AF16.8080106@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 201204-03
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: Chromium: Multiple vulnerabilities
9 Date: April 10, 2012
10 Bugs: #410963
11 ID: 201204-03
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been reported in Chromium, some of which
19 may allow execution of arbitrary code.
20
21 Background
22 ==========
23
24 Chromium is an open source web browser project.
25
26 Affected packages
27 =================
28
29 -------------------------------------------------------------------
30 Package / Vulnerable / Unaffected
31 -------------------------------------------------------------------
32 1 www-client/chromium < 18.0.1025.151 >= 18.0.1025.151
33
34 Description
35 ===========
36
37 Multiple vulnerabilities have been discovered in Chromium. Please
38 review the CVE identifiers and release notes referenced below for
39 details.
40
41 Impact
42 ======
43
44 A remote attacker could entice a user to open a specially crafted web
45 site using Chromium, possibly resulting in the execution of arbitrary
46 code with the privileges of the process, a Denial of Service condition,
47 or bypass of the same origin policy.
48
49 Workaround
50 ==========
51
52 There is no known workaround at this time.
53
54 Resolution
55 ==========
56
57 All Chromium users should upgrade to the latest version:
58
59 # emerge --sync
60 # emerge --ask --oneshot -v ">=www-client/chromium-18.0.1025.151"
61
62 References
63 ==========
64
65 [ 1 ] CVE-2011-3066
66 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3066
67 [ 2 ] CVE-2011-3067
68 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3067
69 [ 3 ] CVE-2011-3068
70 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3068
71 [ 4 ] CVE-2011-3069
72 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3069
73 [ 5 ] CVE-2011-3070
74 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3070
75 [ 6 ] CVE-2011-3071
76 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3071
77 [ 7 ] CVE-2011-3072
78 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3072
79 [ 8 ] CVE-2011-3073
80 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3073
81 [ 9 ] CVE-2011-3074
82 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3074
83 [ 10 ] CVE-2011-3075
84 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3075
85 [ 11 ] CVE-2011-3076
86 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3076
87 [ 12 ] CVE-2011-3077
88 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3077
89 [ 13 ] Release Notes 18.0.1025.151
90
91 http://googlechromereleases.blogspot.com/2012/04/stable-and-beta-channel-updates.html
92
93 Availability
94 ============
95
96 This GLSA and any updates to it are available for viewing at
97 the Gentoo Security Website:
98
99 http://security.gentoo.org/glsa/glsa-201204-03.xml
100
101 Concerns?
102 =========
103
104 Security is a primary focus of Gentoo Linux and ensuring the
105 confidentiality and security of our users' machines is of utmost
106 importance to us. Any security concerns should be addressed to
107 security@g.o or alternatively, you may file a bug at
108 https://bugs.gentoo.org.
109
110 License
111 =======
112
113 Copyright 2012 Gentoo Foundation, Inc; referenced text
114 belongs to its owner(s).
115
116 The contents of this document are licensed under the
117 Creative Commons - Attribution / Share Alike license.
118
119 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature