Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 360399

Summary: <www-client/chromium-10.0.648.204: multiple vulnerabilities (CVE-2011-{1291,1292,1293,1294,1295,1296})
Product: Gentoo Security Reporter: Paweł Hajdan, Jr. (RETIRED) <phajdan.jr>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: normal CC: chromium
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: http://googlechromereleases.blogspot.com/2011/03/stable-channel-update.html
Whiteboard: B2 [glsa]
Package list:
Runtime testing required: ---

Description Paweł Hajdan, Jr. (RETIRED) gentoo-dev 2011-03-25 09:53:54 UTC
Release notes: http://googlechromereleases.blogspot.com/2011/03/stable-channel-update.html

Synopsis:

A vulnerability has been reported in Chromium, that may
allow user-assisted execution of arbitrary code.

Impact:

A remote attacker could entice a user to visit a specially-crafted web page or perform a set of UI actions that would trigger one of the vulnerabilities, leading to execution of arbitrary code, or a Denial of Service.
Comment 1 Paweł Hajdan, Jr. (RETIRED) gentoo-dev 2011-03-25 09:54:51 UTC
Arches, please stabilize =www-client/chromium-10.0.648.204
Comment 2 Agostino Sarubbo gentoo-dev 2011-03-25 10:54:49 UTC
amd64 ok


( anyway if you want check, there are some part that compiling without respecting user cflags )
Comment 3 Christoph Mende (RETIRED) gentoo-dev 2011-03-25 10:57:12 UTC
amd64 done, thanks Agostino
Comment 4 Christian Faulhammer (RETIRED) gentoo-dev 2011-03-26 09:32:03 UTC
x86 stable, last arch, whiteboard updated
Comment 5 Tim Sammut (RETIRED) gentoo-dev 2011-03-26 14:55:51 UTC
Thanks, folks. Added to existing GLSA request.
Comment 6 Stefan Behte (RETIRED) gentoo-dev Security 2011-03-29 19:47:14 UTC
@fauli: please never set a whiteboard of "[glsa]", we set it after having filed a glsa only. By setting it yourself, security might think that this bug was already handled or could at least get confused. ;)
Comment 7 GLSAMaker/CVETool Bot gentoo-dev 2011-11-01 10:01:57 UTC
This issue was resolved and addressed in
 GLSA 201111-01 at http://security.gentoo.org/glsa/glsa-201111-01.xml
by GLSA coordinator Alex Legler (a3li).
Comment 8 GLSAMaker/CVETool Bot gentoo-dev 2011-11-01 10:03:04 UTC
This issue was resolved and addressed in
 GLSA 201111-01 at http://security.gentoo.org/glsa/glsa-201111-01.xml
by GLSA coordinator Alex Legler (a3li).
Comment 9 GLSAMaker/CVETool Bot gentoo-dev 2012-09-11 00:27:39 UTC
CVE-2011-1296 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1296):
  Google Chrome before 10.0.648.204 does not properly handle SVG text, which
  allows remote attackers to cause a denial of service or possibly have
  unspecified other impact via unknown vectors that lead to a "stale pointer."

CVE-2011-1295 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1295):
  WebKit, as used in Google Chrome before 10.0.648.204 and Apple Safari before
  5.0.6, does not properly handle node parentage, which allows remote
  attackers to cause a denial of service (DOM tree corruption), conduct
  cross-site scripting (XSS) attacks, or possibly have unspecified other
  impact via unknown vectors.

CVE-2011-1294 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1294):
  Google Chrome before 10.0.648.204 does not properly handle Cascading Style
  Sheets (CSS) token sequences, which allows remote attackers to cause a
  denial of service or possibly have unspecified other impact via unknown
  vectors that lead to a "stale pointer."

CVE-2011-1293 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1293):
  Use-after-free vulnerability in the HTMLCollection implementation in Google
  Chrome before 10.0.648.204 allows remote attackers to cause a denial of
  service or possibly have unspecified other impact via unknown vectors.

CVE-2011-1292 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1292):
  Use-after-free vulnerability in the frame-loader implementation in Google
  Chrome before 10.0.648.204 allows remote attackers to cause a denial of
  service or possibly have unspecified other impact via unknown vectors.

CVE-2011-1291 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1291):
  Google Chrome before 10.0.648.204 does not properly handle base strings,
  which allows remote attackers to cause a denial of service or possibly have
  unspecified other impact via unknown vectors, related to a "buffer error."