Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 377475 - <www-client/chromium-13.0.782.107: multiple vulnerabilities (CVE-2011-{2358,2359,2360,2361,2782,2783,2784,2785,2786,2787,2788,2789,2790,2792,2793,2794,2795,2796,2797,2798,2799,2800,2801,2802,2803,2805,2818,2819})
Summary: <www-client/chromium-13.0.782.107: multiple vulnerabilities (CVE-2011-{2358,2...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B2 [glsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2011-08-02 21:36 UTC by Paweł Hajdan, Jr. (RETIRED)
Modified: 2012-09-11 00:39 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Paweł Hajdan, Jr. (RETIRED) gentoo-dev 2011-08-02 21:36:12 UTC
Release notes: http://googlechromereleases.blogspot.com/2011/08/stable-channel-update.html

Gentoo is _not_ affected by CVE-2011-2804 (we don't ship the internal PDF plugin)

I have to check the status of CVE-2011-2791, we're using system ICU.
Comment 1 Paweł Hajdan, Jr. (RETIRED) gentoo-dev 2011-08-02 21:38:08 UTC
Arches, please stabilize =www-client/chromium-13.0.782.107

Notable changes from latest stable:
 - added support for LINGUAS
Comment 2 Agostino Sarubbo gentoo-dev 2011-08-02 23:54:27 UTC
works as usual on amd64.
Comment 3 Markos Chandras (RETIRED) gentoo-dev 2011-08-04 14:51:41 UTC
amd64 done. Thanks Agostino
Comment 4 Markus Meier gentoo-dev 2011-08-07 15:20:07 UTC
x86 stable, all arches done.
Comment 5 Tim Sammut (RETIRED) gentoo-dev 2011-08-17 15:42:53 UTC
Thanks, folks. Added to existing GLSA request.
Comment 6 GLSAMaker/CVETool Bot gentoo-dev 2011-11-01 10:02:47 UTC
This issue was resolved and addressed in
 GLSA 201111-01 at http://security.gentoo.org/glsa/glsa-201111-01.xml
by GLSA coordinator Alex Legler (a3li).
Comment 7 GLSAMaker/CVETool Bot gentoo-dev 2011-11-01 10:03:50 UTC
This issue was resolved and addressed in
 GLSA 201111-01 at http://security.gentoo.org/glsa/glsa-201111-01.xml
by GLSA coordinator Alex Legler (a3li).
Comment 8 GLSAMaker/CVETool Bot gentoo-dev 2012-09-11 00:39:25 UTC
CVE-2011-2819 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2819):
  Google Chrome before 13.0.782.107 allows remote attackers to bypass the Same
  Origin Policy via vectors related to handling of the base URI.

CVE-2011-2818 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2818):
  Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows
  remote attackers to cause a denial of service or possibly have unspecified
  other impact via vectors related to display box rendering.

CVE-2011-2805 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2805):
  Google Chrome before 13.0.782.107 allows remote attackers to bypass the Same
  Origin Policy and conduct script injection attacks via unspecified vectors.

CVE-2011-2803 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2803):
  Google Chrome before 13.0.782.107 does not properly handle Skia paths, which
  allows remote attackers to cause a denial of service (out-of-bounds read)
  via unspecified vectors.

CVE-2011-2802 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2802):
  Google V8, as used in Google Chrome before 13.0.782.107, does not properly
  perform const lookups, which allows remote attackers to cause a denial of
  service (application crash) or possibly have unspecified other impact via a
  crafted web site.

CVE-2011-2801 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2801):
  Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows
  remote attackers to cause a denial of service or possibly have unspecified
  other impact via vectors related to the frame loader.

CVE-2011-2800 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2800):
  Google Chrome before 13.0.782.107 allows remote attackers to obtain
  potentially sensitive information about client-side redirect targets via a
  crafted web site.

CVE-2011-2799 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2799):
  Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows
  remote attackers to cause a denial of service or possibly have unspecified
  other impact via vectors related to HTML range handling.

CVE-2011-2798 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2798):
  Google Chrome before 13.0.782.107 does not properly restrict access to
  internal schemes, which allows remote attackers to have an unspecified
  impact via a crafted web site.

CVE-2011-2797 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2797):
  Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows
  remote attackers to cause a denial of service or possibly have unspecified
  other impact via vectors related to resource caching.

CVE-2011-2796 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2796):
  Use-after-free vulnerability in Skia, as used in Google Chrome before
  13.0.782.107, allows remote attackers to cause a denial of service or
  possibly have unspecified other impact via unknown vectors.

CVE-2011-2795 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2795):
  Google Chrome before 13.0.782.107 does not prevent calls to functions in
  other frames, which allows remote attackers to bypass intended access
  restrictions via a crafted web site, related to a "cross-frame function
  leak."

CVE-2011-2794 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2794):
  Google Chrome before 13.0.782.107 does not properly perform text iteration,
  which allows remote attackers to cause a denial of service (out-of-bounds
  read) via unspecified vectors.

CVE-2011-2793 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2793):
  Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows
  remote attackers to cause a denial of service or possibly have unspecified
  other impact via vectors related to media selectors.

CVE-2011-2792 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2792):
  Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows
  remote attackers to cause a denial of service or possibly have unspecified
  other impact via vectors related to float removal.

CVE-2011-2790 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2790):
  Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows
  remote attackers to cause a denial of service or possibly have unspecified
  other impact via vectors involving floating styles.

CVE-2011-2789 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2789):
  Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows
  remote attackers to cause a denial of service or possibly have unspecified
  other impact via vectors related to instantiation of the Pepper plug-in.

CVE-2011-2788 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2788):
  Buffer overflow in the inspector serialization functionality in Google
  Chrome before 13.0.782.107 allows user-assisted remote attackers to have an
  unspecified impact via unknown vectors.

CVE-2011-2787 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2787):
  Google Chrome before 13.0.782.107 does not properly address re-entrancy
  issues associated with the GPU lock, which allows remote attackers to cause
  a denial of service (application crash) via unspecified vectors.

CVE-2011-2786 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2786):
  Google Chrome before 13.0.782.107 does not ensure that the speech-input
  bubble is shown on the product's screen, which might make it easier for
  remote attackers to make audio recordings via a crafted web page containing
  an INPUT element.

CVE-2011-2785 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2785):
  The extensions implementation in Google Chrome before 13.0.782.107 does not
  properly validate the URL for the home page, which allows remote attackers
  to have an unspecified impact via a crafted extension.

CVE-2011-2784 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2784):
  Google Chrome before 13.0.782.107 allows remote attackers to obtain
  sensitive information via a request for the GL program log, which reveals a
  local path in an unspecified log entry.

CVE-2011-2783 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2783):
  Google Chrome before 13.0.782.107 does not ensure that developer-mode NPAPI
  extension installations are confirmed by a browser dialog, which makes it
  easier for remote attackers to modify the product's functionality via a
  Trojan horse extension.

CVE-2011-2782 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2782):
  The drag-and-drop implementation in Google Chrome before 13.0.782.107 on
  Linux does not properly enforce permissions for files, which allows
  user-assisted remote attackers to bypass intended access restrictions via
  unspecified vectors.

CVE-2011-2361 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2361):
  The Basic Authentication dialog implementation in Google Chrome before
  13.0.782.107 does not properly handle strings, which might make it easier
  for remote attackers to capture credentials via a crafted web site.

CVE-2011-2360 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2360):
  Google Chrome before 13.0.782.107 does not ensure that the user is prompted
  before download of a dangerous file, which makes it easier for remote
  attackers to bypass intended content restrictions via a crafted web site.

CVE-2011-2359 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2359):
  Google Chrome before 13.0.782.107 does not properly track line boxes during
  rendering, which allows remote attackers to cause a denial of service or
  possibly have unspecified other impact via unknown vectors that lead to a
  "stale pointer."

CVE-2011-2358 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2358):
  Google Chrome before 13.0.782.107 does not ensure that extension
  installations are confirmed by a browser dialog, which makes it easier for
  remote attackers to modify the product's functionality via a Trojan horse
  extension.