The package chromium before version 93.0.4577.82-1 is vulnerable to arbitrary code execution. . Arch Linux Security Advisory ASA-202109-6 ======================================== Severity: High Date : 2021-09-14 CVE-ID : CVE-2021-30625 CVE-2021-30626 CVE-2021-30627 CVE-2021-30628 CVE-2021-30629 CVE-2021-30630 CVE-2021-30631 CVE-2021-30632 CVE-2021-30633 Package : chromium Type : arbitrary code execution Remote : Yes Link : https://security.archlinux.org/AVG-2379 Summary ====== The package chromium before version 93.0.4577.82-1 is vulnerable to arbitrary code execution. Resolution ========= Upgrade to 93.0.4577.82-1. # pacman -Syu "chromium> =93.0.4577.82-1" The problems have been fixed upstream in version 93.0.4577.82. Workaround ========= None. Description ========== - CVE-2021-30625 (arbitrary code execution) A use after free security issue has been found in the Selection API component of the Chromium browser engine before version 93.0.4577.82. - CVE-2021-30626 (arbitrary code execution) An out of bounds memory access security issue has been found in the ANGLE component of the Chromium browser engine before version 93.0.4577.82. - CVE-2021-30627 (arbitrary code execution) A type confusion security issue has been found in the Blink layout component of the Chromium browser engine before version 93.0.4577.82. - CVE-2021-30628 (arbitrary code execution) A stack buffer overflow security issue has been found in the ANGLE component of the Chromium browser engine before version 93.0.4577.82. - CVE-2021-30629 (arbitrary code execution) A use after free security issue has been found in the Permissions component of the Chromium browser engine before version 93.0.4577.82. - CVE-2021-30630 (arbitrary code execution) An inappropriate implementation security issue has been found in the Blink component of the Chromium browser engine before version 93.0.4577.82. - CVE-2021-30631 (arbitrary code execution) A type confusion security issue has been found in the Blinklayout component of the Chromium browser engine before version 93.0.4577.82. - CVE-2021-30632 (arbitrary code execution) An out of bounds write security issue has been found in the V8 component of the Chromium browser engine before version 93.0.4577.82. Google is aware that exploits for this issue exist in the wild. - CVE-2021-30633 (arbitrary code execution) A use after free security issue has been found in the Indexed DB API component of the Chromium browser engine before version 93.0.4577.82. Google is aware that exploits for this issue exist in the wild. Impact ===== A remote attacker could execute arbitrary code through crafted web content. References ========= https://chromereleases.googleblog.com/2021/09/stable-channel-update-for-desktop.html https://security.archlinux.org/CVE-2021-30625 https://security.archlinux.org/CVE-2021-30626 https://security.archlinux.org/CVE-2021-30627 https://security.archlinux.org/CVE-2021-30628 https://security.archlinux.org/CVE-2021-30629 https://security.archlinux.org/CVE-2021-30630 https://security.archlinux.org/CVE-2021-30631 https://security.archlinux.org/CVE-2021-30632 https://security.archlinux.org/CVE-2021-30633 . The latest Fedora Security Bulletin FSA-202109-8 has issued a critical alert regarding a vulnerability in the nginx web server that could allow remote execution. Update immediately.. chromium security issues, remote code execution risks, Arch Linux advisory, package vulnerability solutions. . LinuxSecurity.com Team
On case-insensitive file systems with support for symbolic links, if Git is configured globally to apply delay-capable clean/smudge filters (such as Git LFS), Git could be fooled into running remote code during a clone (CVE-2021-21300). . MGASA-2021-0137 - Updated git packages fix a security vulnerability Publication date: 14 Mar 2021 URL: https://advisories.mageia.org/MGASA-2021-0137.html Type: security Affected Mageia releases: 7, 8 CVE: CVE-2021-21300 On case-insensitive file systems with support for symbolic links, if Git is configured globally to apply delay-capable clean/smudge filters (such as Git LFS), Git could be fooled into running remote code during a clone (CVE-2021-21300). References: - https://bugs.mageia.org/show_bug.cgi?id=28566 - https://lkml.org/lkml/2021/3/9/995 - https://www.cve.org/CVERecord?id=CVE-2021-21300 SRPMS: - 8/core/git-2.30.2-1.mga8 - 7/core/git-2.21.4-1.mga7 . Mageia 2021-0142 highlights a vulnerability in the Linux kernel that could permit unauthorized access to sensitive data on affected systems. Learn more.. Mageia Git Update, Code Execution Flaw, Git Security Fix. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.