Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 491128 - <www-client/chromium-31.0.1650.48 multiple vulnerabilities (CVE-2013-{2931,6621,6622,6623,6624,6625,6626,6627,6628,6629,6630,6631})
Summary: <www-client/chromium-31.0.1650.48 multiple vulnerabilities (CVE-2013-{2931,66...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal major (vote)
Assignee: Gentoo Security
URL: http://googlechromereleases.blogspot....
Whiteboard: A2 [glsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2013-11-12 23:04 UTC by Mike Gilbert
Modified: 2014-03-05 11:23 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Mike Gilbert gentoo-dev 2013-11-12 23:04:06 UTC
Release notes in URL.
Comment 1 Mike Gilbert gentoo-dev 2013-11-12 23:05:46 UTC
Please stabilize on amd64 and x86.

=www-client/chromium-31.0.1650.48
Comment 2 Yury German Gentoo Infrastructure gentoo-dev 2013-11-13 07:16:03 UTC
Adding amd64 to arches list (not added originally)
Comment 3 Agostino Sarubbo gentoo-dev 2013-11-13 07:47:19 UTC
x86 stable
Comment 4 Agostino Sarubbo gentoo-dev 2013-11-13 07:48:08 UTC
amd64 stable.

Maintainer(s), please cleanup.
Security, please add it to the existing request, or file a new one.
Comment 5 Agostino Sarubbo gentoo-dev 2013-11-13 07:50:51 UTC
(In reply to Yury German from comment #2)
> Adding amd64 to arches list (not added originally)

You don't need to do that for chromium bugs. Check the stable liaison instead:
http://www.gentoo.org/proj/en/desktop/chromium/#doc_chap3
Comment 6 GLSAMaker/CVETool Bot gentoo-dev 2013-11-19 04:16:44 UTC
CVE-2013-6628 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-6628):
  net/socket/ssl_client_socket_nss.cc in the TLS implementation in Google
  Chrome before 31.0.1650.48 does not ensure that a server's X.509 certificate
  is the same during renegotiation as it was before renegotiation, which might
  allow remote web servers to interfere with trust relationships by
  renegotiating a session.

CVE-2013-6627 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-6627):
  net/http/http_stream_parser.cc in Google Chrome before 31.0.1650.48 does not
  properly process HTTP Informational (aka 1xx) status codes, which allows
  remote web servers to cause a denial of service (out-of-bounds read) via a
  crafted response.

CVE-2013-6626 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-6626):
  The WebContentsImpl::AttachInterstitialPage function in
  content/browser/web_contents/web_contents_impl.cc in Google Chrome before
  31.0.1650.48 does not cancel JavaScript dialogs upon generating an
  interstitial warning, which allows remote attackers to spoof the address bar
  via a crafted web site.

CVE-2013-6625 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-6625):
  Use-after-free vulnerability in core/dom/ContainerNode.cpp in Blink, as used
  in Google Chrome before 31.0.1650.48, allows remote attackers to cause a
  denial of service or possibly have unspecified other impact by leveraging
  improper handling of DOM range objects in circumstances that require child
  node removal after a (1) mutation or (2) blur event.

CVE-2013-6624 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-6624):
  Use-after-free vulnerability in Google Chrome before 31.0.1650.48 allows
  remote attackers to cause a denial of service or possibly have unspecified
  other impact via vectors involving the string values of id attributes.

CVE-2013-6623 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-6623):
  The SVG implementation in Blink, as used in Google Chrome before
  31.0.1650.48, allows remote attackers to cause a denial of service
  (out-of-bounds read) by leveraging the use of tree order, rather than
  transitive dependency order, for layout.

CVE-2013-6622 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-6622):
  Use-after-free vulnerability in the HTMLMediaElement::didMoveToNewDocument
  function in core/html/HTMLMediaElement.cpp in Blink, as used in Google
  Chrome before 31.0.1650.48, allows remote attackers to cause a denial of
  service or possibly have unspecified other impact via vectors involving the
  movement of a media element between documents.

CVE-2013-6621 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-6621):
  Use-after-free vulnerability in Google Chrome before 31.0.1650.48 allows
  remote attackers to cause a denial of service or possibly have unspecified
  other impact via vectors related to the x-webkit-speech attribute in a text
  INPUT element.

CVE-2013-2931 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-2931):
  Multiple unspecified vulnerabilities in Google Chrome before 31.0.1650.48
  allow attackers to execute arbitrary code or possibly have other impact via
  unknown vectors.
Comment 7 Yury German Gentoo Infrastructure gentoo-dev 2013-11-19 05:08:17 UTC
Thank you for all for cleanup.

GLSA Request Filed
Comment 8 GLSAMaker/CVETool Bot gentoo-dev 2013-12-09 05:57:11 UTC
CVE-2013-6631 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-6631):
  Use-after-free vulnerability in the Channel::SendRTCPPacket function in
  voice_engine/channel.cc in libjingle in WebRTC, as used in Google Chrome
  before 31.0.1650.48 and other products, allows remote attackers to cause a
  denial of service (heap memory corruption) or possibly have unspecified
  other impact via vectors that trigger the absence of certain statistics
  initialization, leading to the skipping of a required
  DeRegisterExternalTransport call.

CVE-2013-6630 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-6630):
  The get_dht function in jdmarker.c in libjpeg-turbo through 1.3.0, as used
  in Google Chrome before 31.0.1650.48 and other products, does not set all
  elements of a certain Huffman value array during the reading of segments
  that follow Define Huffman Table (DHT) JPEG markers, which allows remote
  attackers to obtain sensitive information from uninitialized memory
  locations via a crafted JPEG image.

CVE-2013-6629 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-6629):
  The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo
  through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript,
  and other products, does not check for certain duplications of component
  data during the reading of segments that follow Start Of Scan (SOS) JPEG
  markers, which allows remote attackers to obtain sensitive information from
  uninitialized memory locations via a crafted JPEG image.
Comment 9 GLSAMaker/CVETool Bot gentoo-dev 2014-03-05 11:23:27 UTC
This issue was resolved and addressed in
 GLSA 201403-01 at http://security.gentoo.org/glsa/glsa-201403-01.xml
by GLSA coordinator Mikle Kolyada (Zlogene).