Gentoo Archives: gentoo-announce

From: John Helmert III <ajak@g.o>
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 202107-06 ] Chromium, Google Chrome: Multiple vulnerabilities
Date: Tue, 06 Jul 2021 08:31:57
Message-Id: YOPPIThR2YGV2P/i@sol.nexus.lan
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 202107-06
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: High
8 Title: Chromium, Google Chrome: Multiple vulnerabilities
9 Date: July 06, 2021
10 Bugs: #789420, #792084, #795204, #796338, #796521
11 ID: 202107-06
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabillities have been found in Chromium and Google
19 Chrome, the worst of which could allow remote attackers to execute
20 arbitrary code.
21
22 Background
23 ==========
24
25 Chromium is an open-source browser project that aims to build a safer,
26 faster, and more stable way for all users to experience the web.
27
28 Google Chrome is one fast, simple, and secure browser for all your
29 devices.
30
31 Affected packages
32 =================
33
34 -------------------------------------------------------------------
35 Package / Vulnerable / Unaffected
36 -------------------------------------------------------------------
37 1 www-client/google-chrome
38 < 91.0.4472.114 >= 91.0.4472.114
39 2 www-client/chromium < 91.0.4472.114 >= 91.0.4472.114
40 -------------------------------------------------------------------
41 2 affected packages
42
43 Description
44 ===========
45
46 Multiple vulnerabilities have been discovered in Chromium and Google
47 Chrome. Please review the CVE identifiers referenced below for details.
48
49 Impact
50 ======
51
52 A remote attacker could execute arbitrary code, escalate privileges,
53 obtain sensitive information, spoof a URL or cause a Denial of Service
54 condition.
55
56 Workaround
57 ==========
58
59 There is no known workaround at this time.
60
61 Resolution
62 ==========
63
64 All Google Chrome users should upgrade to the latest version:
65
66 # emerge --sync
67 # emerge -a --oneshot -v ">=www-client/google-chrome-91.0.4472.114"
68
69 All Chromium users should upgrade to the latest version:
70
71 # emerge --sync
72 # emerge --ask --oneshot -v ">=www-client/chromium-91.0.4472.114"
73
74 References
75 ==========
76
77 [ 1 ] CVE-2021-30506
78 https://nvd.nist.gov/vuln/detail/CVE-2021-30506
79 [ 2 ] CVE-2021-30507
80 https://nvd.nist.gov/vuln/detail/CVE-2021-30507
81 [ 3 ] CVE-2021-30508
82 https://nvd.nist.gov/vuln/detail/CVE-2021-30508
83 [ 4 ] CVE-2021-30509
84 https://nvd.nist.gov/vuln/detail/CVE-2021-30509
85 [ 5 ] CVE-2021-30510
86 https://nvd.nist.gov/vuln/detail/CVE-2021-30510
87 [ 6 ] CVE-2021-30511
88 https://nvd.nist.gov/vuln/detail/CVE-2021-30511
89 [ 7 ] CVE-2021-30512
90 https://nvd.nist.gov/vuln/detail/CVE-2021-30512
91 [ 8 ] CVE-2021-30513
92 https://nvd.nist.gov/vuln/detail/CVE-2021-30513
93 [ 9 ] CVE-2021-30514
94 https://nvd.nist.gov/vuln/detail/CVE-2021-30514
95 [ 10 ] CVE-2021-30515
96 https://nvd.nist.gov/vuln/detail/CVE-2021-30515
97 [ 11 ] CVE-2021-30516
98 https://nvd.nist.gov/vuln/detail/CVE-2021-30516
99 [ 12 ] CVE-2021-30517
100 https://nvd.nist.gov/vuln/detail/CVE-2021-30517
101 [ 13 ] CVE-2021-30518
102 https://nvd.nist.gov/vuln/detail/CVE-2021-30518
103 [ 14 ] CVE-2021-30519
104 https://nvd.nist.gov/vuln/detail/CVE-2021-30519
105 [ 15 ] CVE-2021-30520
106 https://nvd.nist.gov/vuln/detail/CVE-2021-30520
107 [ 16 ] CVE-2021-30521
108 https://nvd.nist.gov/vuln/detail/CVE-2021-30521
109 [ 17 ] CVE-2021-30522
110 https://nvd.nist.gov/vuln/detail/CVE-2021-30522
111 [ 18 ] CVE-2021-30523
112 https://nvd.nist.gov/vuln/detail/CVE-2021-30523
113 [ 19 ] CVE-2021-30524
114 https://nvd.nist.gov/vuln/detail/CVE-2021-30524
115 [ 20 ] CVE-2021-30525
116 https://nvd.nist.gov/vuln/detail/CVE-2021-30525
117 [ 21 ] CVE-2021-30526
118 https://nvd.nist.gov/vuln/detail/CVE-2021-30526
119 [ 22 ] CVE-2021-30527
120 https://nvd.nist.gov/vuln/detail/CVE-2021-30527
121 [ 23 ] CVE-2021-30528
122 https://nvd.nist.gov/vuln/detail/CVE-2021-30528
123 [ 24 ] CVE-2021-30530
124 https://nvd.nist.gov/vuln/detail/CVE-2021-30530
125 [ 25 ] CVE-2021-30531
126 https://nvd.nist.gov/vuln/detail/CVE-2021-30531
127 [ 26 ] CVE-2021-30532
128 https://nvd.nist.gov/vuln/detail/CVE-2021-30532
129 [ 27 ] CVE-2021-30533
130 https://nvd.nist.gov/vuln/detail/CVE-2021-30533
131 [ 28 ] CVE-2021-30534
132 https://nvd.nist.gov/vuln/detail/CVE-2021-30534
133 [ 29 ] CVE-2021-30536
134 https://nvd.nist.gov/vuln/detail/CVE-2021-30536
135 [ 30 ] CVE-2021-30537
136 https://nvd.nist.gov/vuln/detail/CVE-2021-30537
137 [ 31 ] CVE-2021-30538
138 https://nvd.nist.gov/vuln/detail/CVE-2021-30538
139 [ 32 ] CVE-2021-30539
140 https://nvd.nist.gov/vuln/detail/CVE-2021-30539
141 [ 33 ] CVE-2021-30540
142 https://nvd.nist.gov/vuln/detail/CVE-2021-30540
143 [ 34 ] CVE-2021-30544
144 https://nvd.nist.gov/vuln/detail/CVE-2021-30544
145 [ 35 ] CVE-2021-30545
146 https://nvd.nist.gov/vuln/detail/CVE-2021-30545
147 [ 36 ] CVE-2021-30546
148 https://nvd.nist.gov/vuln/detail/CVE-2021-30546
149 [ 37 ] CVE-2021-30548
150 https://nvd.nist.gov/vuln/detail/CVE-2021-30548
151 [ 38 ] CVE-2021-30549
152 https://nvd.nist.gov/vuln/detail/CVE-2021-30549
153 [ 39 ] CVE-2021-30550
154 https://nvd.nist.gov/vuln/detail/CVE-2021-30550
155 [ 40 ] CVE-2021-30551
156 https://nvd.nist.gov/vuln/detail/CVE-2021-30551
157 [ 41 ] CVE-2021-30552
158 https://nvd.nist.gov/vuln/detail/CVE-2021-30552
159 [ 42 ] CVE-2021-30553
160 https://nvd.nist.gov/vuln/detail/CVE-2021-30553
161 [ 43 ] CVE-2021-30554
162 https://nvd.nist.gov/vuln/detail/CVE-2021-30554
163 [ 44 ] CVE-2021-30555
164 https://nvd.nist.gov/vuln/detail/CVE-2021-30555
165 [ 45 ] CVE-2021-30556
166 https://nvd.nist.gov/vuln/detail/CVE-2021-30556
167 [ 46 ] CVE-2021-30557
168 https://nvd.nist.gov/vuln/detail/CVE-2021-30557
169
170 Availability
171 ============
172
173 This GLSA and any updates to it are available for viewing at
174 the Gentoo Security Website:
175
176 https://security.gentoo.org/glsa/202107-06
177
178 Concerns?
179 =========
180
181 Security is a primary focus of Gentoo Linux and ensuring the
182 confidentiality and security of our users' machines is of utmost
183 importance to us. Any security concerns should be addressed to
184 security@g.o or alternatively, you may file a bug at
185 https://bugs.gentoo.org.
186
187 License
188 =======
189
190 Copyright 2021 Gentoo Foundation, Inc; referenced text
191 belongs to its owner(s).
192
193 The contents of this document are licensed under the
194 Creative Commons - Attribution / Share Alike license.
195
196 https://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature