Gentoo Archives: gentoo-announce

From: Tim Sammut <underling@g.o>
To: gentoo-announce@g.o
Subject: [gentoo-announce] [ GLSA 201203-24 ] Chromium, V8: Multiple vulnerabilities
Date: Fri, 30 Mar 2012 22:46:47
Message-Id: 4F7635B3.90401@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 201203-24
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: Chromium, V8: Multiple vulnerabilities
9 Date: March 30, 2012
10 Bugs: #410045
11 ID: 201203-24
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been reported in Chromium and V8, some of
19 which may allow execution of arbitrary code.
20
21 Background
22 ==========
23
24 Chromium is an open source web browser project. V8 is Google's open
25 source JavaScript engine. SPDY is an experimental networking protocol.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 www-client/chromium < 18.0.1025.142 >= 18.0.1025.142
34 2 dev-lang/v8 < 3.8.9.16 >= 3.8.9.16
35 -------------------------------------------------------------------
36 2 affected packages
37
38 Description
39 ===========
40
41 Multiple vulnerabilities have been discovered in Chromium and V8.
42 Please review the CVE identifiers and release notes referenced below
43 for details.
44
45 Impact
46 ======
47
48 A context-dependent attacker could entice a user to open a specially
49 crafted web site or JavaScript program using Chromium or V8, possibly
50 resulting in the execution of arbitrary code with the privileges of the
51 process, or a Denial of Service condition.
52
53 The attacker could also entice a user to open a specially crafted web
54 site using Chromium, possibly resulting in cross-site scripting (XSS),
55 or an unspecified SPDY certificate checking error.
56
57 Workaround
58 ==========
59
60 There is no known workaround at this time.
61
62 Resolution
63 ==========
64
65 All Chromium users should upgrade to the latest version:
66
67 # emerge --sync
68 # emerge --ask --oneshot -v ">=www-client/chromium-18.0.1025.142"
69
70 All V8 users should upgrade to the latest version:
71
72 # emerge --sync
73 # emerge --ask --oneshot --verbose ">=dev-lang/v8-3.8.9.16"
74
75 References
76 ==========
77
78 [ 1 ] CVE-2011-3057
79 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3057
80 [ 2 ] CVE-2011-3058
81 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3058
82 [ 3 ] CVE-2011-3059
83 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3059
84 [ 4 ] CVE-2011-3060
85 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3060
86 [ 5 ] CVE-2011-3061
87 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3061
88 [ 6 ] CVE-2011-3062
89 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3062
90 [ 7 ] CVE-2011-3063
91 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3063
92 [ 8 ] CVE-2011-3064
93 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3064
94 [ 9 ] CVE-2011-3065
95 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3065
96 [ 10 ] Release Notes 18.0.1025.142
97
98 http://googlechromereleases.blogspot.com/2012/03/stable-channel-release-and-beta-channel.html
99
100 Availability
101 ============
102
103 This GLSA and any updates to it are available for viewing at
104 the Gentoo Security Website:
105
106 http://security.gentoo.org/glsa/glsa-201203-24.xml
107
108 Concerns?
109 =========
110
111 Security is a primary focus of Gentoo Linux and ensuring the
112 confidentiality and security of our users' machines is of utmost
113 importance to us. Any security concerns should be addressed to
114 security@g.o or alternatively, you may file a bug at
115 https://bugs.gentoo.org.
116
117 License
118 =======
119
120 Copyright 2012 Gentoo Foundation, Inc; referenced text
121 belongs to its owner(s).
122
123 The contents of this document are licensed under the
124 Creative Commons - Attribution / Share Alike license.
125
126 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature