Gentoo Archives: gentoo-announce

From: Thomas Deutschmann <whissi@g.o>
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 202104-08 ] Chromium, Google Chrome: Multiple vulnerabilities
Date: Sat, 01 May 2021 00:12:43
Message-Id: feac809b-8a5d-3863-9917-0edf53e65866@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 202104-08
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: Chromium, Google Chrome: Multiple vulnerabilities
9 Date: April 30, 2021
10 Bugs: #768459, #768831, #771012, #774015, #776181, #779493,
11 #782802, #782970, #784554, #785889
12 ID: 202104-08
13
14 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
15
16 Synopsis
17 ========
18
19 Multiple vulnerabilities have been found in Chromium and Google Chrome,
20 the worst of which could result in the arbitrary execution of code.
21
22 Background
23 ==========
24
25 Chromium is an open-source browser project that aims to build a safer,
26 faster, and more stable way for all users to experience the web.
27
28 Google Chrome is one fast, simple, and secure browser for all your
29 devices.
30
31 Affected packages
32 =================
33
34 -------------------------------------------------------------------
35 Package / Vulnerable / Unaffected
36 -------------------------------------------------------------------
37 1 www-client/chromium < 90.0.4430.93 >= 90.0.4430.93
38 2 www-client/google-chrome
39 < 90.0.4430.93 >= 90.0.4430.93
40 -------------------------------------------------------------------
41 2 affected packages
42
43 Description
44 ===========
45
46 Multiple vulnerabilities have been discovered in Chromium and Google
47 Chrome. Please review the CVE identifiers referenced below for details.
48
49 Impact
50 ======
51
52 Please review the referenced CVE identifiers for details.
53
54 Workaround
55 ==========
56
57 There is no known workaround at this time.
58
59 Resolution
60 ==========
61
62 All Chromium users should upgrade to the latest version:
63
64 # emerge --sync
65 # emerge --ask --oneshot -v ">=www-client/chromium-90.0.4430.93"
66
67 All Google Chrome users should upgrade to the latest version:
68
69 # emerge --sync
70 # emerge --ask --oneshot -v ">=www-client/google-chrome-90.0.4430.93"
71
72 References
73 ==========
74
75 [ 1 ] CVE-2021-21142
76 https://nvd.nist.gov/vuln/detail/CVE-2021-21142
77 [ 2 ] CVE-2021-21143
78 https://nvd.nist.gov/vuln/detail/CVE-2021-21143
79 [ 3 ] CVE-2021-21144
80 https://nvd.nist.gov/vuln/detail/CVE-2021-21144
81 [ 4 ] CVE-2021-21145
82 https://nvd.nist.gov/vuln/detail/CVE-2021-21145
83 [ 5 ] CVE-2021-21146
84 https://nvd.nist.gov/vuln/detail/CVE-2021-21146
85 [ 6 ] CVE-2021-21147
86 https://nvd.nist.gov/vuln/detail/CVE-2021-21147
87 [ 7 ] CVE-2021-21148
88 https://nvd.nist.gov/vuln/detail/CVE-2021-21148
89 [ 8 ] CVE-2021-21149
90 https://nvd.nist.gov/vuln/detail/CVE-2021-21149
91 [ 9 ] CVE-2021-21150
92 https://nvd.nist.gov/vuln/detail/CVE-2021-21150
93 [ 10 ] CVE-2021-21151
94 https://nvd.nist.gov/vuln/detail/CVE-2021-21151
95 [ 11 ] CVE-2021-21152
96 https://nvd.nist.gov/vuln/detail/CVE-2021-21152
97 [ 12 ] CVE-2021-21153
98 https://nvd.nist.gov/vuln/detail/CVE-2021-21153
99 [ 13 ] CVE-2021-21154
100 https://nvd.nist.gov/vuln/detail/CVE-2021-21154
101 [ 14 ] CVE-2021-21155
102 https://nvd.nist.gov/vuln/detail/CVE-2021-21155
103 [ 15 ] CVE-2021-21156
104 https://nvd.nist.gov/vuln/detail/CVE-2021-21156
105 [ 16 ] CVE-2021-21157
106 https://nvd.nist.gov/vuln/detail/CVE-2021-21157
107 [ 17 ] CVE-2021-21159
108 https://nvd.nist.gov/vuln/detail/CVE-2021-21159
109 [ 18 ] CVE-2021-21160
110 https://nvd.nist.gov/vuln/detail/CVE-2021-21160
111 [ 19 ] CVE-2021-21161
112 https://nvd.nist.gov/vuln/detail/CVE-2021-21161
113 [ 20 ] CVE-2021-21162
114 https://nvd.nist.gov/vuln/detail/CVE-2021-21162
115 [ 21 ] CVE-2021-21163
116 https://nvd.nist.gov/vuln/detail/CVE-2021-21163
117 [ 22 ] CVE-2021-21165
118 https://nvd.nist.gov/vuln/detail/CVE-2021-21165
119 [ 23 ] CVE-2021-21166
120 https://nvd.nist.gov/vuln/detail/CVE-2021-21166
121 [ 24 ] CVE-2021-21167
122 https://nvd.nist.gov/vuln/detail/CVE-2021-21167
123 [ 25 ] CVE-2021-21168
124 https://nvd.nist.gov/vuln/detail/CVE-2021-21168
125 [ 26 ] CVE-2021-21169
126 https://nvd.nist.gov/vuln/detail/CVE-2021-21169
127 [ 27 ] CVE-2021-21170
128 https://nvd.nist.gov/vuln/detail/CVE-2021-21170
129 [ 28 ] CVE-2021-21171
130 https://nvd.nist.gov/vuln/detail/CVE-2021-21171
131 [ 29 ] CVE-2021-21172
132 https://nvd.nist.gov/vuln/detail/CVE-2021-21172
133 [ 30 ] CVE-2021-21173
134 https://nvd.nist.gov/vuln/detail/CVE-2021-21173
135 [ 31 ] CVE-2021-21174
136 https://nvd.nist.gov/vuln/detail/CVE-2021-21174
137 [ 32 ] CVE-2021-21175
138 https://nvd.nist.gov/vuln/detail/CVE-2021-21175
139 [ 33 ] CVE-2021-21176
140 https://nvd.nist.gov/vuln/detail/CVE-2021-21176
141 [ 34 ] CVE-2021-21177
142 https://nvd.nist.gov/vuln/detail/CVE-2021-21177
143 [ 35 ] CVE-2021-21178
144 https://nvd.nist.gov/vuln/detail/CVE-2021-21178
145 [ 36 ] CVE-2021-21179
146 https://nvd.nist.gov/vuln/detail/CVE-2021-21179
147 [ 37 ] CVE-2021-21180
148 https://nvd.nist.gov/vuln/detail/CVE-2021-21180
149 [ 38 ] CVE-2021-21181
150 https://nvd.nist.gov/vuln/detail/CVE-2021-21181
151 [ 39 ] CVE-2021-21182
152 https://nvd.nist.gov/vuln/detail/CVE-2021-21182
153 [ 40 ] CVE-2021-21183
154 https://nvd.nist.gov/vuln/detail/CVE-2021-21183
155 [ 41 ] CVE-2021-21184
156 https://nvd.nist.gov/vuln/detail/CVE-2021-21184
157 [ 42 ] CVE-2021-21185
158 https://nvd.nist.gov/vuln/detail/CVE-2021-21185
159 [ 43 ] CVE-2021-21186
160 https://nvd.nist.gov/vuln/detail/CVE-2021-21186
161 [ 44 ] CVE-2021-21187
162 https://nvd.nist.gov/vuln/detail/CVE-2021-21187
163 [ 45 ] CVE-2021-21188
164 https://nvd.nist.gov/vuln/detail/CVE-2021-21188
165 [ 46 ] CVE-2021-21189
166 https://nvd.nist.gov/vuln/detail/CVE-2021-21189
167 [ 47 ] CVE-2021-2119
168 https://nvd.nist.gov/vuln/detail/CVE-2021-2119
169 [ 48 ] CVE-2021-21191
170 https://nvd.nist.gov/vuln/detail/CVE-2021-21191
171 [ 49 ] CVE-2021-21192
172 https://nvd.nist.gov/vuln/detail/CVE-2021-21192
173 [ 50 ] CVE-2021-21193
174 https://nvd.nist.gov/vuln/detail/CVE-2021-21193
175 [ 51 ] CVE-2021-21194
176 https://nvd.nist.gov/vuln/detail/CVE-2021-21194
177 [ 52 ] CVE-2021-21195
178 https://nvd.nist.gov/vuln/detail/CVE-2021-21195
179 [ 53 ] CVE-2021-21196
180 https://nvd.nist.gov/vuln/detail/CVE-2021-21196
181 [ 54 ] CVE-2021-21197
182 https://nvd.nist.gov/vuln/detail/CVE-2021-21197
183 [ 55 ] CVE-2021-21198
184 https://nvd.nist.gov/vuln/detail/CVE-2021-21198
185 [ 56 ] CVE-2021-21199
186 https://nvd.nist.gov/vuln/detail/CVE-2021-21199
187 [ 57 ] CVE-2021-21201
188 https://nvd.nist.gov/vuln/detail/CVE-2021-21201
189 [ 58 ] CVE-2021-21202
190 https://nvd.nist.gov/vuln/detail/CVE-2021-21202
191 [ 59 ] CVE-2021-21203
192 https://nvd.nist.gov/vuln/detail/CVE-2021-21203
193 [ 60 ] CVE-2021-21204
194 https://nvd.nist.gov/vuln/detail/CVE-2021-21204
195 [ 61 ] CVE-2021-21205
196 https://nvd.nist.gov/vuln/detail/CVE-2021-21205
197 [ 62 ] CVE-2021-21206
198 https://nvd.nist.gov/vuln/detail/CVE-2021-21206
199 [ 63 ] CVE-2021-21207
200 https://nvd.nist.gov/vuln/detail/CVE-2021-21207
201 [ 64 ] CVE-2021-21208
202 https://nvd.nist.gov/vuln/detail/CVE-2021-21208
203 [ 65 ] CVE-2021-21209
204 https://nvd.nist.gov/vuln/detail/CVE-2021-21209
205 [ 66 ] CVE-2021-21210
206 https://nvd.nist.gov/vuln/detail/CVE-2021-21210
207 [ 67 ] CVE-2021-21211
208 https://nvd.nist.gov/vuln/detail/CVE-2021-21211
209 [ 68 ] CVE-2021-21212
210 https://nvd.nist.gov/vuln/detail/CVE-2021-21212
211 [ 69 ] CVE-2021-21213
212 https://nvd.nist.gov/vuln/detail/CVE-2021-21213
213 [ 70 ] CVE-2021-21214
214 https://nvd.nist.gov/vuln/detail/CVE-2021-21214
215 [ 71 ] CVE-2021-21215
216 https://nvd.nist.gov/vuln/detail/CVE-2021-21215
217 [ 72 ] CVE-2021-21216
218 https://nvd.nist.gov/vuln/detail/CVE-2021-21216
219 [ 73 ] CVE-2021-21217
220 https://nvd.nist.gov/vuln/detail/CVE-2021-21217
221 [ 74 ] CVE-2021-21218
222 https://nvd.nist.gov/vuln/detail/CVE-2021-21218
223 [ 75 ] CVE-2021-21219
224 https://nvd.nist.gov/vuln/detail/CVE-2021-21219
225 [ 76 ] CVE-2021-21220
226 https://nvd.nist.gov/vuln/detail/CVE-2021-21220
227 [ 77 ] CVE-2021-21221
228 https://nvd.nist.gov/vuln/detail/CVE-2021-21221
229 [ 78 ] CVE-2021-21222
230 https://nvd.nist.gov/vuln/detail/CVE-2021-21222
231 [ 79 ] CVE-2021-21223
232 https://nvd.nist.gov/vuln/detail/CVE-2021-21223
233 [ 80 ] CVE-2021-21224
234 https://nvd.nist.gov/vuln/detail/CVE-2021-21224
235 [ 81 ] CVE-2021-21225
236 https://nvd.nist.gov/vuln/detail/CVE-2021-21225
237 [ 82 ] CVE-2021-21226
238 https://nvd.nist.gov/vuln/detail/CVE-2021-21226
239 [ 83 ] CVE-2021-21227
240 https://nvd.nist.gov/vuln/detail/CVE-2021-21227
241 [ 84 ] CVE-2021-21228
242 https://nvd.nist.gov/vuln/detail/CVE-2021-21228
243 [ 85 ] CVE-2021-21229
244 https://nvd.nist.gov/vuln/detail/CVE-2021-21229
245 [ 86 ] CVE-2021-21230
246 https://nvd.nist.gov/vuln/detail/CVE-2021-21230
247 [ 87 ] CVE-2021-21231
248 https://nvd.nist.gov/vuln/detail/CVE-2021-21231
249 [ 88 ] CVE-2021-21232
250 https://nvd.nist.gov/vuln/detail/CVE-2021-21232
251 [ 89 ] CVE-2021-21233
252 https://nvd.nist.gov/vuln/detail/CVE-2021-21233
253
254 Availability
255 ============
256
257 This GLSA and any updates to it are available for viewing at
258 the Gentoo Security Website:
259
260 https://security.gentoo.org/glsa/202104-08
261
262 Concerns?
263 =========
264
265 Security is a primary focus of Gentoo Linux and ensuring the
266 confidentiality and security of our users' machines is of utmost
267 importance to us. Any security concerns should be addressed to
268 security@g.o or alternatively, you may file a bug at
269 https://bugs.gentoo.org.
270
271 License
272 =======
273
274 Copyright 2021 Gentoo Foundation, Inc; referenced text
275 belongs to its owner(s).
276
277 The contents of this document are licensed under the
278 Creative Commons - Attribution / Share Alike license.
279
280 https://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
OpenPGP_signature.asc application/pgp-signature