Gentoo Archives: gentoo-announce

From: Tim Sammut <underling@g.o>
To: gentoo-announce@g.o
Subject: [gentoo-announce] [ GLSA 201205-04 ] Chromium, V8: Multiple vulnerabilities
Date: Sun, 27 May 2012 23:15:47
Message-Id: 4FC2B456.8090308@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 201205-04
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: Chromium, V8: Multiple vulnerabilities
9 Date: May 27, 2012
10 Bugs: #417321
11 ID: 201205-04
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been reported in Chromium and V8, some of
19 which may allow execution of arbitrary code.
20
21 Background
22 ==========
23
24 Chromium is an open source web browser project. V8 is Google’s open
25 source JavaScript engine.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 www-client/chromium < 19.0.1084.52 >= 19.0.1084.52
34 2 dev-lang/v8 < 3.9.24.28 >= 3.9.24.28
35 -------------------------------------------------------------------
36 2 affected packages
37
38 Description
39 ===========
40
41 Multiple vulnerabilities have been discovered in Chromium and V8.
42 Please review the CVE identifiers and release notes referenced below
43 for details.
44
45 Impact
46 ======
47
48 A context-dependent attacker could entice a user to open a specially
49 crafted web site or JavaScript program using Chromium or V8, possibly
50 resulting in the execution of arbitrary code with the privileges of the
51 process, or a Denial of Service condition.
52
53 Workaround
54 ==========
55
56 There is no known workaround at this time.
57
58 Resolution
59 ==========
60
61 All Chromium users should upgrade to the latest version:
62
63 # emerge --sync
64 # emerge --ask --oneshot -v ">=www-client/chromium-19.0.1084.52"
65
66 All V8 users should upgrade to the latest version:
67
68 # emerge --sync
69 # emerge --ask --oneshot --verbose ">=dev-lang/v8-3.9.24.28"
70
71 References
72 ==========
73
74 [ 1 ] CVE-2011-3103
75 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3103
76 [ 2 ] CVE-2011-3104
77 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3104
78 [ 3 ] CVE-2011-3105
79 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3105
80 [ 4 ] CVE-2011-3106
81 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3106
82 [ 5 ] CVE-2011-3107
83 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3107
84 [ 6 ] CVE-2011-3108
85 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3108
86 [ 7 ] CVE-2011-3109
87 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3109
88 [ 8 ] CVE-2011-3111
89 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3111
90 [ 9 ] CVE-2011-3115
91 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3115
92 [ 10 ] Release Notes 19.0.1084.52
93
94 http://googlechromereleases.blogspot.com/2012/05/stable-channel-update_23.html
95
96 Availability
97 ============
98
99 This GLSA and any updates to it are available for viewing at
100 the Gentoo Security Website:
101
102 http://security.gentoo.org/glsa/glsa-201205-04.xml
103
104 Concerns?
105 =========
106
107 Security is a primary focus of Gentoo Linux and ensuring the
108 confidentiality and security of our users' machines is of utmost
109 importance to us. Any security concerns should be addressed to
110 security@g.o or alternatively, you may file a bug at
111 https://bugs.gentoo.org.
112
113 License
114 =======
115
116 Copyright 2012 Gentoo Foundation, Inc; referenced text
117 belongs to its owner(s).
118
119 The contents of this document are licensed under the
120 Creative Commons - Attribution / Share Alike license.
121
122 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature