The package vivaldi before version 3.5.2115.87-1 is vulnerable to multiple issues including access restriction bypass, arbitrary code execution and insufficient validation. . Arch Linux Security Advisory ASA-202101-20 ========================================= Severity: High Date : 2021-01-12 CVE-ID : CVE-2020-15995 CVE-2020-16043 CVE-2021-21106 CVE-2021-21107 CVE-2021-21108 CVE-2021-21109 CVE-2021-21110 CVE-2021-21111 CVE-2021-21112 CVE-2021-21113 CVE-2021-21114 CVE-2021-21115 CVE-2021-21116 Package : vivaldi Type : multiple issues Remote : Yes Link : https://security.archlinux.org/AVG-1424 Summary ====== The package vivaldi before version 3.5.2115.87-1 is vulnerable to multiple issues including access restriction bypass, arbitrary code execution and insufficient validation. Resolution ========= Upgrade to 3.5.2115.87-1. # pacman -Syu "vivaldi> =3.5.2115.87-1" The problems have been fixed upstream in version 3.5.2115.87. Workaround ========= None. Description ========== - CVE-2020-15995 (arbitrary code execution) An out of bounds write security issue has been found in the V8 component of the Chromium browser before version 87.0.4280.141. - CVE-2020-16043 (insufficient validation) An insufficient data validation security issue has been found in the networking component of the Chromium browser before version 87.0.4280.141. - CVE-2021-21106 (arbitrary code execution) A use after free security issue has been found in the autofill component of the Chromium browser before version 87.0.4280.141. - CVE-2021-21107 (arbitrary code execution) A use after free security issue has been found in the drag and drop component of the Chromium browser before version 87.0.4280.141. - CVE-2021-21108 (arbitrary code execution) A use after free security issue has been found in the media component of the Chromium browser before version 87.0.4280.141. - CVE-2021-21109 (arbitrary code execution) A use after free security issue has been found in the payments component of theChromium browser before version 87.0.4280.141. - CVE-2021-21110 (arbitrary code execution) A use after free security issue has been found in the safe browsing component of the Chromium browser before version 87.0.4280.141. - CVE-2021-21111 (access restriction bypass) An insufficient policy enforcement security issue has been found in the WebUI component of the Chromium browser before version 87.0.4280.141. - CVE-2021-21112 (arbitrary code execution) A use after free security issue has been found in the Blink component of the Chromium browser before version 87.0.4280.141. - CVE-2021-21113 (arbitrary code execution) A heap buffer overflow security issue has been found in the Skia component of the Chromium browser before version 87.0.4280.141. - CVE-2021-21114 (arbitrary code execution) A use after free security issue has been found in the audio component of the Chromium browser before version 87.0.4280.141. - CVE-2021-21115 (arbitrary code execution) A use after free security issue has been found in the safe browsing component of the Chromium browser before version 87.0.4280.141. - CVE-2021-21116 (arbitrary code execution) A heap buffer overflow security issue has been found in the audio component of the Chromium browser before version 87.0.4280.141. Impact ===== A remote attacker might be able to bypass security restrictions and execute arbitrarycode. References ========= https://vivaldi.com/blog/desktop/minor-update-for-vivaldi-desktop-browser-3-5/ https://chromereleases.googleblog.com/2021/01/stable-channel-update-for-desktop.html https://security.archlinux.org/CVE-2020-15995 https://security.archlinux.org/CVE-2020-16043 https://security.archlinux.org/CVE-2021-21106 https://security.archlinux.org/CVE-2021-21107 https://security.archlinux.org/CVE-2021-21108 https://security.archlinux.org/CVE-2021-21109 https://security.archlinux.org/CVE-2021-21110 https://security.archlinux.org/CVE-2021-21111 https://security.archlinux.org/CVE-2021-21112 https://security.archlinux.org/CVE-2021-21113 https://security.archlinux.org/CVE-2021-21114 https://security.archlinux.org/CVE-2021-21115 https://security.archlinux.org/CVE-2021-21116 . Enhance the Vivaldi browser on Arch Linux to address critical vulnerabilities involving access limitations and potential execution of arbitrary code.. ArchLinux, Vivaldi Security, Code Execution Risks. . LinuxSecurity.com Team
The package linux-lts before version 4.4.44-1 is vulnerable to privilege escalation. . Arch Linux Security Advisory ASA-201701-35 ========================================= Severity: Medium Date : 2017-01-27 CVE-ID : CVE-2017-2583 Package : linux-lts Type : privilege escalation Remote : No Link : https://security.archlinux.org/AVG-150 Summary ====== The package linux-lts before version 4.4.44-1 is vulnerable to privilege escalation. Resolution ========= Upgrade to 4.4.44-1. # pacman -Syu "linux-lts> =4.4.44-1" The problem has been fixed upstream in version 4.4.44. Workaround ========= None. Description ========== The Linux kernel > 3.6-rc1, when built with Kernel-based Virtual Machine (CONFIG_KVM) support, is vulnerable to an incorrect segment selector (SS) value error. It could occur loading values into SS register in long mode. A user/process inside a guest host could use this flaw to crash the guest, resulting in denial of service, or potentially escalate their privileges inside the guest system on an AMD processor. Impact ===== A local attacker in a guest host is able to crash the system or escalate privileges inside the guest on an AMD processor. References ========= https://seclists.org/oss-sec/2017/q1/137 https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/ https://security.archlinux.org/CVE-2017-2583 . The Linux-lts earlier than version 4.4.44-1 on Arch Linux possesses a risk for privilege escalation. An update is essential.. Arch Linux, Privilege Escalation, Linux-LTS Advisory. . Severity: Medium. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.