Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Debian: DSA-2724-1 Severe: Chromium Multiple Remote Issues

debian
Calendar Grey July 18, 2013
Debian Logo
Various vulnerabilities resolved in chromium-browser. Update advisable for improved safety on Debian platforms.
Several vulnerabilities have been discovered in the Chromium web browser

Summary

Several vulnerabilities have been discovered in the Chromium web browser.

CVE-2013-2853

The HTTPS implementation does not ensure that headers are terminated
by \r\n\r\n (carriage return, newline, carriage return, newline).

CVE-2013-2867

Chrome does not properly prevent pop-under windows.

CVE-2013-2868

common/extensions/sync_helper.cc proceeds with sync operations for
NPAPI extensions without checking for a certain plugin permission
setting.

CVE-2013-2869

Denial of service (out-of-bounds read) via a crafted JPEG2000
image.

CVE-2013-2870

Use-after-free vulnerability in network sockets.

CVE-2013-2871

Use-after-free vulnerability in input handling.

CVE-2013-2873

Use-after-free vulnerability in resource loading.

CVE-2013-2875

Out-of-bounds read in SVG file handling.

CVE-2013-2876

Chrome does not properly enforce restrictions on the capture of
screenshots by extensions, which could lead to information
disclosure from previous page visits.

CVE-2013-2877

...

Read the Full Advisory

Package: chromium-browser
CVE ID: CVE-2013-2853 CVE-2013-2867 CVE-2013-2868 CVE-2013-2869

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here