Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 330003 - <www-client/chromium-5.0.375.125: Multiple vulnerabilities (CVE-2010-{2898,2899,2900,2901,2902,2903})
Summary: <www-client/chromium-5.0.375.125: Multiple vulnerabilities (CVE-2010-{2898,28...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://googlechromereleases.blogspot....
Whiteboard: B2? [glsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2010-07-26 23:28 UTC by Paweł Hajdan, Jr. (RETIRED)
Modified: 2012-09-10 23:30 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Paweł Hajdan, Jr. (RETIRED) gentoo-dev 2010-07-26 23:28:02 UTC
See the release notes at http://googlechromereleases.blogspot.com/2010/07/stable-channel-update_26.html

Some details:

Aside from the listed security bugs fixed in Chromium, we have also deployed workarounds for two critical vulnerabilities where the root cause lies in external components. Credit and $1337 to Marc Schoenefeld for enabling us to work around a Windows kernel bug [48283]. Credit and $1337 to Simon Berry-Byrne for enabling us to work around a glibc bug [48733].
[$500] [42736] Medium Memory contents disclosure in layout code. Credit to Michail Nikolaev.
[$500] [43813] High Issue with large canvases. Credit to sp3x of SecurityReason.com.
[$500] [47866] High Memory corruption in rendering code. Credit to Jose A. Vazquez.
[$500] [48284] High Memory corruption in SVG handling. Credit to Aki Helin of OUSPG.
[48597] Low Avoid hostname truncation and incorrect eliding. Credit to Google Chrome Security Team (Inferno).

You can read more about the severity ratings at
http://sites.google.com/a/chromium.org/dev/developers/severity-guidelines . I
suggest to rate it B2 on the Gentoo scale.

Security, this bug sort of obsoletes bug #326717 (you now have 3 www-client/chromium bugs in the queue). Arches, please stabilize. A compile test and basic smoke test is sufficient. The 375 branch gets only the most important bugfixes.
Comment 1 Christian Faulhammer (RETIRED) gentoo-dev 2010-07-27 13:44:44 UTC
stable x86
Comment 2 Markos Chandras (RETIRED) gentoo-dev 2010-07-29 15:14:59 UTC
amd64 done
Comment 3 Paweł Hajdan, Jr. (RETIRED) gentoo-dev 2010-09-17 01:05:17 UTC
Chromium Herd has nothing to do here. The vulnerable versions are no longer in the tree.
Comment 4 Tobias Heinlein (RETIRED) gentoo-dev 2010-12-18 00:06:13 UTC
GLSA 201012-01, thanks everyone.
Comment 5 GLSAMaker/CVETool Bot gentoo-dev 2012-09-10 23:30:57 UTC
CVE-2010-2903 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2903):
  Google Chrome before 5.0.375.125 performs unexpected truncation and improper
  eliding of hostnames, which has unspecified impact and remote attack
  vectors.

CVE-2010-2902 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2902):
  The SVG implementation in Google Chrome before 5.0.375.125 allows remote
  attackers to cause a denial of service (memory corruption) or possibly have
  unspecified other impact via unknown vectors.

CVE-2010-2901 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2901):
  The rendering implementation in Google Chrome before 5.0.375.125 allows
  remote attackers to cause a denial of service (memory corruption) or
  possibly have unspecified other impact via unknown vectors.

CVE-2010-2900 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2900):
  Google Chrome before 5.0.375.125 does not properly handle a large canvas,
  which has unspecified impact and remote attack vectors.

CVE-2010-2899 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2899):
  Unspecified vulnerability in the layout implementation in Google Chrome
  before 5.0.375.125 allows remote attackers to obtain sensitive information
  from process memory via unknown vectors.

CVE-2010-2898 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2898):
  Google Chrome before 5.0.375.125 does not properly mitigate an unspecified
  flaw in the GNU C Library, which has unknown impact and attack vectors.