Gentoo Archives: gentoo-announce

From: Thomas Deutschmann <whissi@g.o>
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 202012-05 ] Chromium, Google Chrome: Multiple vulnerabilities
Date: Mon, 07 Dec 2020 00:41:39
Message-Id: eace0daa-0e93-3679-cd70-7b722b9767c0@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 202012-05
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: Chromium, Google Chrome: Multiple vulnerabilities
9 Date: December 07, 2020
10 Bugs: #755227, #758368
11 ID: 202012-05
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been found in Chromium and Google Chrome,
19 the worst of which could result in the arbitrary execution of code.
20
21 Background
22 ==========
23
24 Chromium is an open-source browser project that aims to build a safer,
25 faster, and more stable way for all users to experience the web.
26
27 Google Chrome is one fast, simple, and secure browser for all your
28 devices.
29
30 Affected packages
31 =================
32
33 -------------------------------------------------------------------
34 Package / Vulnerable / Unaffected
35 -------------------------------------------------------------------
36 1 www-client/chromium < 87.0.4280.88 >= 87.0.4280.88
37 2 www-client/google-chrome
38 < 87.0.4280.88 >= 87.0.4280.88
39 -------------------------------------------------------------------
40 2 affected packages
41
42 Description
43 ===========
44
45 Multiple vulnerabilities have been discovered in Chromium and Google
46 Chrome. Please review the CVE identifiers referenced below for details.
47
48 Impact
49 ======
50
51 Please review the referenced CVE identifiers for details.
52
53 Workaround
54 ==========
55
56 There is no known workaround at this time.
57
58 Resolution
59 ==========
60
61 All Chromium users should upgrade to the latest version:
62
63 # emerge --sync
64 # emerge --ask --oneshot -v ">=www-client/chromium-87.0.4280.88"
65
66 All Google Chrome users should upgrade to the latest version:
67
68 # emerge --sync
69 # emerge --ask --oneshot -v ">=www-client/google-chrome-87.0.4280.88"
70
71 References
72 ==========
73
74 [ 1 ] CVE-2020-16014
75 https://nvd.nist.gov/vuln/detail/CVE-2020-16014
76 [ 2 ] CVE-2020-16015
77 https://nvd.nist.gov/vuln/detail/CVE-2020-16015
78 [ 3 ] CVE-2020-16018
79 https://nvd.nist.gov/vuln/detail/CVE-2020-16018
80 [ 4 ] CVE-2020-16019
81 https://nvd.nist.gov/vuln/detail/CVE-2020-16019
82 [ 5 ] CVE-2020-16020
83 https://nvd.nist.gov/vuln/detail/CVE-2020-16020
84 [ 6 ] CVE-2020-16021
85 https://nvd.nist.gov/vuln/detail/CVE-2020-16021
86 [ 7 ] CVE-2020-16022
87 https://nvd.nist.gov/vuln/detail/CVE-2020-16022
88 [ 8 ] CVE-2020-16023
89 https://nvd.nist.gov/vuln/detail/CVE-2020-16023
90 [ 9 ] CVE-2020-16024
91 https://nvd.nist.gov/vuln/detail/CVE-2020-16024
92 [ 10 ] CVE-2020-16025
93 https://nvd.nist.gov/vuln/detail/CVE-2020-16025
94 [ 11 ] CVE-2020-16026
95 https://nvd.nist.gov/vuln/detail/CVE-2020-16026
96 [ 12 ] CVE-2020-16027
97 https://nvd.nist.gov/vuln/detail/CVE-2020-16027
98 [ 13 ] CVE-2020-16028
99 https://nvd.nist.gov/vuln/detail/CVE-2020-16028
100 [ 14 ] CVE-2020-16029
101 https://nvd.nist.gov/vuln/detail/CVE-2020-16029
102 [ 15 ] CVE-2020-16030
103 https://nvd.nist.gov/vuln/detail/CVE-2020-16030
104 [ 16 ] CVE-2020-16031
105 https://nvd.nist.gov/vuln/detail/CVE-2020-16031
106 [ 17 ] CVE-2020-16032
107 https://nvd.nist.gov/vuln/detail/CVE-2020-16032
108 [ 18 ] CVE-2020-16033
109 https://nvd.nist.gov/vuln/detail/CVE-2020-16033
110 [ 19 ] CVE-2020-16034
111 https://nvd.nist.gov/vuln/detail/CVE-2020-16034
112 [ 20 ] CVE-2020-16036
113 https://nvd.nist.gov/vuln/detail/CVE-2020-16036
114 [ 21 ] CVE-2020-16037
115 https://nvd.nist.gov/vuln/detail/CVE-2020-16037
116 [ 22 ] CVE-2020-16038
117 https://nvd.nist.gov/vuln/detail/CVE-2020-16038
118 [ 23 ] CVE-2020-16039
119 https://nvd.nist.gov/vuln/detail/CVE-2020-16039
120 [ 24 ] CVE-2020-16040
121 https://nvd.nist.gov/vuln/detail/CVE-2020-16040
122 [ 25 ] CVE-2020-16041
123 https://nvd.nist.gov/vuln/detail/CVE-2020-16041
124 [ 26 ] CVE-2020-16042
125 https://nvd.nist.gov/vuln/detail/CVE-2020-16042
126
127 Availability
128 ============
129
130 This GLSA and any updates to it are available for viewing at
131 the Gentoo Security Website:
132
133 https://security.gentoo.org/glsa/202012-05
134
135 Concerns?
136 =========
137
138 Security is a primary focus of Gentoo Linux and ensuring the
139 confidentiality and security of our users' machines is of utmost
140 importance to us. Any security concerns should be addressed to
141 security@g.o or alternatively, you may file a bug at
142 https://bugs.gentoo.org.
143
144 License
145 =======
146
147 Copyright 2020 Gentoo Foundation, Inc; referenced text
148 belongs to its owner(s).
149
150 The contents of this document are licensed under the
151 Creative Commons - Attribution / Share Alike license.
152
153 https://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
OpenPGP_signature.asc application/pgp-signature