Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 410045 - <www-client/chromium-18.0.1025.142, <dev-lang/v8-3.8.9.16: multiple vulnerabilities (CVE-2011-{3057,3058,3059,3060,3061,3062,3063,3064,3065})
Summary: <www-client/chromium-18.0.1025.142, <dev-lang/v8-3.8.9.16: multiple vulnerabi...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: http://googlechromereleases.blogspot....
Whiteboard: A2 [glsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2012-03-28 19:00 UTC by Paweł Hajdan, Jr. (RETIRED)
Modified: 2012-03-30 22:41 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Paweł Hajdan, Jr. (RETIRED) gentoo-dev 2012-03-28 19:00:05 UTC
Release notes: http://googlechromereleases.blogspot.com/2012/03/stable-channel-release-and-beta-channel.html
Comment 1 Paweł Hajdan, Jr. (RETIRED) gentoo-dev 2012-03-28 19:02:34 UTC
Okay guys, we're stabilizing:

=dev-lang/v8-3.8.9.16
=www-client/chromium-18.0.1025.142

The v8 update is also a security one (OOB read).
Comment 2 Paweł Hajdan, Jr. (RETIRED) gentoo-dev 2012-03-28 19:04:19 UTC
x86 stable
Comment 3 Richard Freeman gentoo-dev 2012-03-28 21:37:21 UTC
amd64 stable
Comment 4 Tim Sammut (RETIRED) gentoo-dev 2012-03-28 23:27:00 UTC
Thanks, everyone. GLSA request filed.
Comment 5 Paweł Hajdan, Jr. (RETIRED) gentoo-dev 2012-03-29 07:10:24 UTC
(In reply to comment #4)
> Thanks, everyone. GLSA request filed.

... to which I have no access. Should I file a new one? Should you somehow grant me access to the one you've filed? Are you going to write one yourself?
Comment 6 Tim Sammut (RETIRED) gentoo-dev 2012-03-29 14:23:11 UTC
(In reply to comment #5)
> (In reply to comment #4)
> > Thanks, everyone. GLSA request filed.
> 
> ... to which I have no access. Should I file a new one? Should you somehow
> grant me access to the one you've filed? Are you going to write one yourself?

Sorry about that. Please file a new request. Thanks.
Comment 7 Paweł Hajdan, Jr. (RETIRED) gentoo-dev 2012-03-30 07:43:54 UTC
(In reply to comment #6)
> Sorry about that. Please file a new request. Thanks.

Done, ID 0fe2f54aa.
Comment 8 GLSAMaker/CVETool Bot gentoo-dev 2012-03-30 22:41:20 UTC
This issue was resolved and addressed in
 GLSA 201203-24 at http://security.gentoo.org/glsa/glsa-201203-24.xml
by GLSA coordinator Tim Sammut (underling).