- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 201203-19
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                            https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

 Severity: Normal
    Title: Chromium: Multiple vulnerabilities
     Date: March 25, 2012
     Bugs: #406975, #407465, #407755, #409251
       ID: 201203-19

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
=======
Multiple vulnerabilities have been reported in Chromium, some of which
may allow execution of arbitrary code.

Background
=========
Chromium is an open source web browser project.

Affected packages
================
    -------------------------------------------------------------------
     Package              /     Vulnerable     /            Unaffected
    -------------------------------------------------------------------
  1  www-client/chromium       < 17.0.963.83           >= 17.0.963.83

Description
==========
Multiple vulnerabilities have been discovered in Chromium. Please
review the CVE identifiers and release notes referenced below for
details.

Impact
=====
A remote attacker could entice a user to open a specially crafted web
site using Chromium, possibly resulting in the execution of arbitrary
code with the privileges of the process, a Denial of Service condition,
Universal Cross-Site Scripting, or installation of an extension without
user interaction.

A remote attacker could also entice a user to install a specially
crafted extension that would interfere with browser-issued web
requests.

Workaround
=========
There is no known workaround at this time.

Resolution
=========
All Chromium users should upgrade to the latest version:

  # emerge --sync
  # emerge --ask --oneshot -v ">=www-client/chromium-17.0.963.83"

References
=========
[  1 ] CVE-2011-3031
       http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3031
[  2 ] CVE-2011-3032
       http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3032
[  3 ] CVE-2011-3033
       http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3033
[  4 ] CVE-2011-3034
       http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3034
[  5 ] CVE-2011-3035
       http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3035
[  6 ] CVE-2011-3036
       http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3036
[  7 ] CVE-2011-3037
       http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3037
[  8 ] CVE-2011-3038
       http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3038
[  9 ] CVE-2011-3039
       http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3039
[ 10 ] CVE-2011-3040
       http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3040
[ 11 ] CVE-2011-3041
       http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3041
[ 12 ] CVE-2011-3042
       http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3042
[ 13 ] CVE-2011-3043
       http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3043
[ 14 ] CVE-2011-3044
       http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3044
[ 15 ] CVE-2011-3046
       http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3046
[ 16 ] CVE-2011-3047
       http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3047
[ 17 ] CVE-2011-3049
       http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3049
[ 18 ] CVE-2011-3050
       http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3050
[ 19 ] CVE-2011-3051
       http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3051
[ 20 ] CVE-2011-3052
       http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3052
[ 21 ] CVE-2011-3053
       http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3053
[ 22 ] CVE-2011-3054
       http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3054
[ 23 ] CVE-2011-3055
       http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3055
[ 24 ] CVE-2011-3056
       http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3056
[ 25 ] CVE-2011-3057
       http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3057
[ 26 ] Release Notes 17.0.963.65

https://chromereleases.googleblog.com/2012/03/chrome-stable-update.html
[ 27 ] Release Notes 17.0.963.78

https://chromereleases.googleblog.com/2012/03/chrome-stable-channel-update.html
[ 28 ] Release Notes 17.0.963.79

https://chromereleases.googleblog.com/2012/03/chrome-stable-update_10.html
[ 29 ] Release Notes 17.0.963.83

https://chromereleases.googleblog.com/2012/03/stable-channel-update_21.html

Availability
===========
This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

 https://security.gentoo.org/glsa/201203-19

Concerns?
========
Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
======
Copyright 2012 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

https://creativecommons.org/licenses/by-sa/2.5/

Gentoo: GLSA-201203-19: Chromium: Multiple vulnerabilities

Multiple vulnerabilities have been reported in Chromium, some of which may allow execution of arbitrary code.

Summary

Multiple vulnerabilities have been discovered in Chromium. Please review the CVE identifiers and release notes referenced below for details.

Resolution

All Chromium users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v ">=www-client/chromium-17.0.963.83"

References

[ 1 ] CVE-2011-3031 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3031 [ 2 ] CVE-2011-3032 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3032 [ 3 ] CVE-2011-3033 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3033 [ 4 ] CVE-2011-3034 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3034 [ 5 ] CVE-2011-3035 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3035 [ 6 ] CVE-2011-3036 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3036 [ 7 ] CVE-2011-3037 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3037 [ 8 ] CVE-2011-3038 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3038 [ 9 ] CVE-2011-3039 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3039 [ 10 ] CVE-2011-3040 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3040 [ 11 ] CVE-2011-3041 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3041 [ 12 ] CVE-2011-3042 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3042 [ 13 ] CVE-2011-3043 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3043 [ 14 ] CVE-2011-3044 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3044 [ 15 ] CVE-2011-3046 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3046 [ 16 ] CVE-2011-3047 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3047 [ 17 ] CVE-2011-3049 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3049 [ 18 ] CVE-2011-3050 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3050 [ 19 ] CVE-2011-3051 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3051 [ 20 ] CVE-2011-3052 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3052 [ 21 ] CVE-2011-3053 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3053 [ 22 ] CVE-2011-3054 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3054 [ 23 ] CVE-2011-3055 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3055 [ 24 ] CVE-2011-3056 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3056 [ 25 ] CVE-2011-3057 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3057 [ 26 ] Release Notes 17.0.963.65 https://chromereleases.googleblog.com/2012/03/chrome-stable-update.html [ 27 ] Release Notes 17.0.963.78
https://chromereleases.googleblog.com/2012/03/chrome-stable-channel-update.html [ 28 ] Release Notes 17.0.963.79
https://chromereleases.googleblog.com/2012/03/chrome-stable-update_10.html [ 29 ] Release Notes 17.0.963.83
https://chromereleases.googleblog.com/2012/03/stable-channel-update_21.html

Availability

This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201203-19

Concerns

Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org.

Severity
Severity: Normal
Title: Chromium: Multiple vulnerabilities
Date: March 25, 2012
Bugs: #406975, #407465, #407755, #409251
ID: 201203-19

Synopsis

Multiple vulnerabilities have been reported in Chromium, some of which may allow execution of arbitrary code.

Background

Chromium is an open source web browser project.

Affected Packages

------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-client/chromium < 17.0.963.83 >= 17.0.963.83

Impact

===== A remote attacker could entice a user to open a specially crafted web site using Chromium, possibly resulting in the execution of arbitrary code with the privileges of the process, a Denial of Service condition, Universal Cross-Site Scripting, or installation of an extension without user interaction. A remote attacker could also entice a user to install a specially crafted extension that would interfere with browser-issued web requests.

Workaround

There is no known workaround at this time.

Related News