Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 486742 - <www-client/chromium-30.0.1599.66 multiple vulnerabilities (CVE-2013-{2906,2907,2908,2909,2910,2911,2912,2913,2915,2916,2917,2918,2919,2920,2921,2922,2923})
Summary: <www-client/chromium-30.0.1599.66 multiple vulnerabilities (CVE-2013-{2906,29...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal major (vote)
Assignee: Gentoo Security
URL: http://googlechromereleases.blogspot....
Whiteboard: A2 [glsa]
Keywords:
Depends on: 486878
Blocks:
  Show dependency tree
 
Reported: 2013-10-02 01:57 UTC by Mike Gilbert
Modified: 2014-03-05 11:23 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Mike Gilbert gentoo-dev 2013-10-02 01:57:01 UTC
Release notes in URL.
Comment 1 Mike Gilbert gentoo-dev 2013-10-02 02:01:35 UTC
Please stabilize on amd64 and x86.

=dev-lang/v8-3.20.17.13
=www-client/chromium-30.0.1599.66
Comment 2 GLSAMaker/CVETool Bot gentoo-dev 2013-10-02 14:54:44 UTC
CVE-2013-2924 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-2924):
  Use-after-free vulnerability in International Components for Unicode (ICU),
  as used in Google Chrome before 30.0.1599.66 and other products, allows
  remote attackers to cause a denial of service or possibly have unspecified
  other impact via unknown vectors.

CVE-2013-2923 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-2923):
  Multiple unspecified vulnerabilities in Google Chrome before 30.0.1599.66
  allow attackers to cause a denial of service or possibly have other impact
  via unknown vectors.

CVE-2013-2922 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-2922):
  Use-after-free vulnerability in core/html/HTMLTemplateElement.cpp in Blink,
  as used in Google Chrome before 30.0.1599.66, allows remote attackers to
  cause a denial of service or possibly have unspecified other impact via
  crafted JavaScript code that operates on a TEMPLATE element.

CVE-2013-2921 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-2921):
  Double free vulnerability in the ResourceFetcher::didLoadResource function
  in core/fetch/ResourceFetcher.cpp in the resource loader in Blink, as used
  in Google Chrome before 30.0.1599.66, allows remote attackers to cause a
  denial of service or possibly have unspecified other impact by triggering
  certain callback processing during the reporting of a resource entry.

CVE-2013-2920 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-2920):
  The DoResolveRelativeHost function in url/url_canon_relative.cc in Google
  Chrome before 30.0.1599.66 allows remote attackers to cause a denial of
  service (out-of-bounds read) via a relative URL containing a hostname, as
  demonstrated by a protocol-relative URL beginning with a //www.google.com/
  substring.

CVE-2013-2919 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-2919):
  Google V8, as used in Google Chrome before 30.0.1599.66, allows remote
  attackers to cause a denial of service (memory corruption) or possibly have
  unspecified other impact via unknown vectors.

CVE-2013-2918 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-2918):
  Use-after-free vulnerability in the RenderBlock::collapseAnonymousBlockChild
  function in core/rendering/RenderBlock.cpp in the DOM implementation in
  Blink, as used in Google Chrome before 30.0.1599.66, allows remote attackers
  to cause a denial of service or possibly have unspecified other impact by
  leveraging incorrect handling of parent-child relationships for anonymous
  blocks.

CVE-2013-2917 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-2917):
  The ReverbConvolverStage::ReverbConvolverStage function in
  core/platform/audio/ReverbConvolverStage.cpp in the Web Audio implementation
  in Blink, as used in Google Chrome before 30.0.1599.66, allows remote
  attackers to cause a denial of service (out-of-bounds read) via vectors
  related to the impulseResponse array.

CVE-2013-2916 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-2916):
  Blink, as used in Google Chrome before 30.0.1599.66, allows remote attackers
  to spoof the address bar via vectors involving a response with a 204 (aka No
  Content) status code, in conjunction with a delay in notifying the user of
  an attempted spoof.

CVE-2013-2915 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-2915):
  Google Chrome before 30.0.1599.66 preserves pending NavigationEntry objects
  in certain invalid circumstances, which allows remote attackers to spoof the
  address bar via a URL with a malformed scheme, as demonstrated by a
  nonexistent:12121 URL.

CVE-2013-2914 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-2914):
  Use-after-free vulnerability in the color-chooser dialog in Google Chrome
  before 30.0.1599.66 on Windows allows remote attackers to cause a denial of
  service or possibly have unspecified other impact via vectors related to
  color_chooser_dialog.cc and color_chooser_win.cc in browser/ui/views/.

CVE-2013-2913 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-2913):
  Use-after-free vulnerability in the XMLDocumentParser::append function in
  core/xml/parser/XMLDocumentParser.cpp in Blink, as used in Google Chrome
  before 30.0.1599.66, allows remote attackers to cause a denial of service or
  possibly have unspecified other impact via vectors involving an XML
  document.

CVE-2013-2912 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-2912):
  Use-after-free vulnerability in the PepperInProcessRouter::SendToHost
  function in content/renderer/pepper/pepper_in_process_router.cc in the
  Pepper Plug-in API (PPAPI) in Google Chrome before 30.0.1599.66 allows
  remote attackers to cause a denial of service or possibly have unspecified
  other impact via vectors involving a resource-destruction message.

CVE-2013-2911 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-2911):
  Use-after-free vulnerability in the XSLStyleSheet::compileStyleSheet
  function in core/xml/XSLStyleSheetLibxslt.cpp in Blink, as used in Google
  Chrome before 30.0.1599.66, allows remote attackers to cause a denial of
  service or possibly have unspecified other impact by leveraging improper
  handling of post-failure recompilation in unspecified libxslt versions.

CVE-2013-2910 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-2910):
  Use-after-free vulnerability in
  modules/webaudio/AudioScheduledSourceNode.cpp in the Web Audio
  implementation in Blink, as used in Google Chrome before 30.0.1599.66,
  allows remote attackers to cause a denial of service or possibly have
  unspecified other impact via unknown vectors.

CVE-2013-2909 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-2909):
  Use-after-free vulnerability in Blink, as used in Google Chrome before
  30.0.1599.66, allows remote attackers to cause a denial of service or
  possibly have unspecified other impact via vectors related to inline-block
  rendering for bidirectional Unicode text in an element isolated from its
  siblings.

CVE-2013-2908 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-2908):
  Google Chrome before 30.0.1599.66 uses incorrect function calls to determine
  the values of NavigationEntry objects, which allows remote attackers to
  spoof the address bar via vectors involving a response with a 204 (aka No
  Content) status code.

CVE-2013-2907 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-2907):
  The Window.prototype object implementation in Google Chrome before
  30.0.1599.66 allows remote attackers to cause a denial of service
  (out-of-bounds read) via unspecified vectors.

CVE-2013-2906 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-2906):
  Multiple race conditions in the Web Audio implementation in Blink, as used
  in Google Chrome before 30.0.1599.66, allow remote attackers to cause a
  denial of service or possibly have unspecified other impact via vectors
  related to threading in core/html/HTMLMediaElement.cpp,
  core/platform/audio/AudioDSPKernelProcessor.cpp,
  core/platform/audio/HRTFElevation.cpp, and
  modules/webaudio/ConvolverNode.cpp.
Comment 3 Agostino Sarubbo gentoo-dev 2013-10-03 17:33:07 UTC
amd64 and x86 stable, it works for me
Comment 4 Sergey Popov gentoo-dev 2013-10-04 06:36:06 UTC
Thansk for your work. GLSA request filed
Comment 5 Sean Amoss (RETIRED) gentoo-dev Security 2013-10-04 10:55:50 UTC
CVE-2013-2914 is for Windows.
CVE-2013-2924 is for ICU.
Comment 6 GLSAMaker/CVETool Bot gentoo-dev 2014-03-05 11:23:24 UTC
This issue was resolved and addressed in
 GLSA 201403-01 at http://security.gentoo.org/glsa/glsa-201403-01.xml
by GLSA coordinator Mikle Kolyada (Zlogene).