Gentoo Archives: gentoo-announce

From: Mikle Kolyada <zlogene@g.o>
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 201503-12 ] Chromium: Multiple vulnerabilities
Date: Sun, 22 Mar 2015 22:12:04
Message-Id: 550F3D46.5080201@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 201503-12
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: Chromium: Multiple vulnerabilities
9 Date: March 22, 2015
10 Bugs: #542090
11 ID: 201503-12
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been found in Chromium, the worst of
19 which can allow remote attackers to cause Denial of Service or bypass
20 security restrictions.
21
22 Background
23 ==========
24
25 Chromium is an open-source web browser project.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 www-client/chromium < 41.0.2272.76 >= 41.0.2272.76
34
35 Description
36 ===========
37
38 Multiple vulnerabilities have been discovered in Chromium. Please
39 review the CVE identifiers referenced below for details.
40
41 Impact
42 ======
43
44 A remote attacker may be able to cause a Denial of Service condition,
45 bypass security restrictions, or have other unspecified impact.
46
47 Workaround
48 ==========
49
50 There is no known workaround at this time.
51
52 Resolution
53 ==========
54
55 All Chromium users should upgrade to the latest version:
56
57 # emerge --sync
58 # emerge --ask --oneshot -v ">=www-client/chromium-41.0.2272.76"
59
60 References
61 ==========
62
63 [ 1 ] CVE-2015-1213
64 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-1213
65 [ 2 ] CVE-2015-1214
66 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-1214
67 [ 3 ] CVE-2015-1215
68 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-1215
69 [ 4 ] CVE-2015-1216
70 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-1216
71 [ 5 ] CVE-2015-1217
72 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-1217
73 [ 6 ] CVE-2015-1218
74 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-1218
75 [ 7 ] CVE-2015-1219
76 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-1219
77 [ 8 ] CVE-2015-1220
78 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-1220
79 [ 9 ] CVE-2015-1221
80 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-1221
81 [ 10 ] CVE-2015-1222
82 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-1222
83 [ 11 ] CVE-2015-1223
84 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-1223
85 [ 12 ] CVE-2015-1224
86 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-1224
87 [ 13 ] CVE-2015-1225
88 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-1225
89 [ 14 ] CVE-2015-1226
90 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-1226
91 [ 15 ] CVE-2015-1227
92 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-1227
93 [ 16 ] CVE-2015-1228
94 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-1228
95 [ 17 ] CVE-2015-1229
96 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-1229
97 [ 18 ] CVE-2015-1230
98 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-1230
99 [ 19 ] CVE-2015-1231
100 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-1231
101 [ 20 ] CVE-2015-1232
102 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-1232
103
104 Availability
105 ============
106
107 This GLSA and any updates to it are available for viewing at
108 the Gentoo Security Website:
109
110 https://security.gentoo.org/glsa/201503-12
111
112 Concerns?
113 =========
114
115 Security is a primary focus of Gentoo Linux and ensuring the
116 confidentiality and security of our users' machines is of utmost
117 importance to us. Any security concerns should be addressed to
118 security@g.o or alternatively, you may file a bug at
119 https://bugs.gentoo.org.
120
121 License
122 =======
123
124 Copyright 2015 Gentoo Foundation, Inc; referenced text
125 belongs to its owner(s).
126
127 The contents of this document are licensed under the
128 Creative Commons - Attribution / Share Alike license.
129
130 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature