Gentoo Archives: gentoo-announce

From: Alex Legler <a3li@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 201111-01 ] Chromium, V8: Multiple vulnerabilities
Date: Tue, 01 Nov 2011 10:07:50
Message-Id: 201111011101.53010.a3li@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 201111-01
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: High
8 Title: Chromium, V8: Multiple vulnerabilities
9 Date: November 01, 2011
10 Bugs: #351525, #353626, #354121, #356933, #357963, #358581,
11 #360399, #363629, #365125, #366335, #367013, #368649,
12 #370481, #373451, #373469, #377475, #377629, #380311,
13 #380897, #381713, #383251, #385649, #388461
14 ID: 201111-01
15
16 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
17
18 Synopsis
19 ========
20
21 Multiple vulnerabilities have been reported in Chromium and V8, some of
22 which may allow execution of arbitrary code and local root privilege
23 escalation.
24
25 Background
26 ==========
27
28 Chromium is an open-source web browser project. V8 is Google's open
29 source JavaScript engine.
30
31 Affected packages
32 =================
33
34 -------------------------------------------------------------------
35 Package / Vulnerable / Unaffected
36 -------------------------------------------------------------------
37 1 www-client/chromium < 15.0.874.102 >= 15.0.874.102
38 2 dev-lang/v8 < 3.5.10.22 >= 3.5.10.22
39 -------------------------------------------------------------------
40 2 affected packages
41 -------------------------------------------------------------------
42
43 Description
44 ===========
45
46 Multiple vulnerabilities have been discovered in Chromium and V8.
47 Please review the CVE identifiers and release notes referenced below
48 for details.
49
50 Impact
51 ======
52
53 A local attacker could gain root privileges (CVE-2011-1444, fixed in
54 chromium-11.0.696.57).
55
56 A context-dependent attacker could entice a user to open a specially
57 crafted web site or JavaScript program using Chromium or V8, possibly
58 resulting in the execution of arbitrary code with the privileges of the
59 process, or a Denial of Service condition. The attacker also could
60 obtain cookies and other sensitive information, conduct
61 man-in-the-middle attacks, perform address bar spoofing, bypass the
62 same origin policy, perform Cross-Site Scripting attacks, or bypass
63 pop-up blocks.
64
65 Workaround
66 ==========
67
68 There is no known workaround at this time.
69
70 Resolution
71 ==========
72
73 All Chromium users should upgrade to the latest version:
74
75 # emerge --sync
76 # emerge --ask --oneshot -v ">=www-client/chromium-15.0.874.102"
77
78 All V8 users should upgrade to the latest version:
79
80 # emerge --sync
81 # emerge --ask --oneshot --verbose ">=dev-lang/v8-3.5.10.22"
82
83 References
84 ==========
85
86 [ 1 ] CVE-2011-2345
87 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2345
88 [ 2 ] CVE-2011-2346
89 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2346
90 [ 3 ] CVE-2011-2347
91 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2347
92 [ 4 ] CVE-2011-2348
93 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2348
94 [ 5 ] CVE-2011-2349
95 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2349
96 [ 6 ] CVE-2011-2350
97 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2350
98 [ 7 ] CVE-2011-2351
99 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2351
100 [ 8 ] CVE-2011-2834
101 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2834
102 [ 9 ] CVE-2011-2835
103 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2835
104 [ 10 ] CVE-2011-2837
105 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2837
106 [ 11 ] CVE-2011-2838
107 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2838
108 [ 12 ] CVE-2011-2839
109 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2839
110 [ 13 ] CVE-2011-2840
111 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2840
112 [ 14 ] CVE-2011-2841
113 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2841
114 [ 15 ] CVE-2011-2843
115 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2843
116 [ 16 ] CVE-2011-2844
117 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2844
118 [ 17 ] CVE-2011-2845
119 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2845
120 [ 18 ] CVE-2011-2846
121 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2846
122 [ 19 ] CVE-2011-2847
123 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2847
124 [ 20 ] CVE-2011-2848
125 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2848
126 [ 21 ] CVE-2011-2849
127 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2849
128 [ 22 ] CVE-2011-2850
129 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2850
130 [ 23 ] CVE-2011-2851
131 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2851
132 [ 24 ] CVE-2011-2852
133 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2852
134 [ 25 ] CVE-2011-2853
135 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2853
136 [ 26 ] CVE-2011-2854
137 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2854
138 [ 27 ] CVE-2011-2855
139 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2855
140 [ 28 ] CVE-2011-2856
141 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2856
142 [ 29 ] CVE-2011-2857
143 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2857
144 [ 30 ] CVE-2011-2858
145 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2858
146 [ 31 ] CVE-2011-2859
147 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2859
148 [ 32 ] CVE-2011-2860
149 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2860
150 [ 33 ] CVE-2011-2861
151 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2861
152 [ 34 ] CVE-2011-2862
153 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2862
154 [ 35 ] CVE-2011-2864
155 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2864
156 [ 36 ] CVE-2011-2874
157 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2874
158 [ 37 ] CVE-2011-3234
159 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3234
160 [ 38 ] CVE-2011-3873
161 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3873
162 [ 39 ] CVE-2011-3875
163 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3875
164 [ 40 ] CVE-2011-3876
165 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3876
166 [ 41 ] CVE-2011-3877
167 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3877
168 [ 42 ] CVE-2011-3878
169 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3878
170 [ 43 ] CVE-2011-3879
171 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3879
172 [ 44 ] CVE-2011-3880
173 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3880
174 [ 45 ] CVE-2011-3881
175 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3881
176 [ 46 ] CVE-2011-3882
177 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3882
178 [ 47 ] CVE-2011-3883
179 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3883
180 [ 48 ] CVE-2011-3884
181 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3884
182 [ 49 ] CVE-2011-3885
183 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3885
184 [ 50 ] CVE-2011-3886
185 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3886
186 [ 51 ] CVE-2011-3887
187 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3887
188 [ 52 ] CVE-2011-3888
189 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3888
190 [ 53 ] CVE-2011-3889
191 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3889
192 [ 54 ] CVE-2011-3890
193 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3890
194 [ 55 ] CVE-2011-3891
195 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3891
196 [ 56 ] Release Notes 10.0.648.127
197 http://googlechromereleases.blogspot.com/2011/03/chrome-stable-release.html
198 [ 57 ] Release Notes 10.0.648.133
199 http://googlechromereleases.blogspot.com/2011/03/stable-and-beta-channel-updates.html
200 [ 58 ] Release Notes 10.0.648.205
201 http://googlechromereleases.blogspot.com/2011/04/stable-channel-update.html
202 [ 59 ] Release Notes 11.0.696.57
203 http://googlechromereleases.blogspot.com/2011/04/chrome-stable-update.html
204 [ 60 ] Release Notes 11.0.696.65
205 http://googlechromereleases.blogspot.com/2011/05/beta-and-stable-channel-update.html
206 [ 61 ] Release Notes 11.0.696.68
207 http://googlechromereleases.blogspot.com/2011/05/stable-channel-update.html
208 [ 62 ] Release Notes 11.0.696.71
209 http://googlechromereleases.blogspot.com/2011/05/stable-channel-update_24.html
210 [ 63 ] Release Notes 12.0.742.112
211 http://googlechromereleases.blogspot.com/2011/06/stable-channel-update_28.html
212 [ 64 ] Release Notes 12.0.742.91
213 http://googlechromereleases.blogspot.com/2011/06/chrome-stable-release.html
214 [ 65 ] Release Notes 13.0.782.107
215 http://googlechromereleases.blogspot.com/2011/08/stable-channel-update.html
216 [ 66 ] Release Notes 13.0.782.215
217 http://googlechromereleases.blogspot.com/2011/08/stable-channel-update_22.html
218 [ 67 ] Release Notes 13.0.782.220
219 http://googlechromereleases.blogspot.com/2011/09/stable-channel-update.html
220 [ 68 ] Release Notes 14.0.835.163
221 http://googlechromereleases.blogspot.com/2011/09/stable-channel-update_16.html
222 [ 69 ] Release Notes 14.0.835.202
223 http://googlechromereleases.blogspot.com/2011/10/stable-channel-update.html
224 [ 70 ] Release Notes 15.0.874.102
225 http://googlechromereleases.blogspot.com/2011/10/chrome-stable-release.html
226 [ 71 ] Release Notes 8.0.552.237
227 http://googlechromereleases.blogspot.com/2011/01/chrome-stable-release.html
228 [ 72 ] Release Notes 9.0.597.107
229 http://googlechromereleases.blogspot.com/2011/02/stable-channel-update_28.html
230 [ 73 ] Release Notes 9.0.597.84
231 http://googlechromereleases.blogspot.com/2011/02/stable-channel-update.html
232 [ 74 ] Release Notes 9.0.597.94
233 http://googlechromereleases.blogspot.com/2011/02/stable-channel-update_08.html
234
235 Availability
236 ============
237
238 This GLSA and any updates to it are available for viewing at
239 the Gentoo Security Website:
240
241 http://security.gentoo.org/glsa/glsa-201111-01.xml
242
243 Concerns?
244 =========
245
246 Security is a primary focus of Gentoo Linux and ensuring the
247 confidentiality and security of our users' machines is of utmost
248 importance to us. Any security concerns should be addressed to
249 security@g.o or alternatively, you may file a bug at
250 https://bugs.gentoo.org.
251
252 License
253 =======
254
255 Copyright 2011 Gentoo Foundation, Inc; referenced text
256 belongs to its owner(s).
257
258 The contents of this document are licensed under the
259 Creative Commons - Attribution / Share Alike license.
260
261 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature