Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 388461

Summary: <www-client/{chromium-15.0.874.102,google-chrome-15.0.874.102_p106587}, <dev-lang/v8-3.5.10.22: multiple vulnerabilities (CVE-2011-{2845,3875,3876,3877,3878,3879,3880,3881,3882,3883,3884,3885,3886,3887,3888,3889,3890,3891})
Product: Gentoo Security Reporter: Paweł Hajdan, Jr. (RETIRED) <phajdan.jr>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: normal CC: chromium
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: http://googlechromereleases.blogspot.com/2011/10/chrome-stable-release.html
Whiteboard: B2 [glsa]
Package list:
Runtime testing required: ---

Description Paweł Hajdan, Jr. (RETIRED) gentoo-dev 2011-10-25 16:29:43 UTC
Release notes: http://googlechromereleases.blogspot.com/2011/10/chrome-stable-release.html
Comment 1 Paweł Hajdan, Jr. (RETIRED) gentoo-dev 2011-10-25 16:32:26 UTC
Okay so we need to:

handle google-chrome (Mike/floppym, could you do that?)

And then please test (and stabilize) the following:

=www-client/chromium-15.0.874.102
=dev-lang/v8-3.5.10.22

I can stabilize based on AT/HT report, just need an independent confirmation that it's not broken.
Comment 2 Mike Gilbert gentoo-dev 2011-10-25 16:47:09 UTC
I have bumped google-chrome, but per previous discussion with the amd64 team we are NOT stabilizing it due to the likelihood of the upstream distfile becoming un-fetchable.

Please do not stable it on x86 either; better to be consistent.
Comment 3 Agostino Sarubbo gentoo-dev 2011-10-25 20:49:57 UTC
Both ok for me on amd64, please mark stable.
Comment 4 Mike Gilbert gentoo-dev 2011-10-25 21:49:36 UTC
amd64 done.
Comment 5 GLSAMaker/CVETool Bot gentoo-dev 2011-10-26 03:42:37 UTC
CVE-2011-3891 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3891):
  Google Chrome before 15.0.874.102 does not properly restrict access to
  internal Google V8 functions, which allows remote attackers to cause a
  denial of service or possibly have unspecified other impact via unknown
  vectors.

CVE-2011-3890 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3890):
  Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows
  remote attackers to cause a denial of service or possibly have unspecified
  other impact via vectors related to video source handling.

CVE-2011-3889 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3889):
  Heap-based buffer overflow in the Web Audio implementation in Google Chrome
  before 15.0.874.102 allows remote attackers to cause a denial of service or
  possibly have unspecified other impact via unknown vectors.

CVE-2011-3888 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3888):
  Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows
  user-assisted remote attackers to cause a denial of service or possibly have
  unspecified other impact via vectors related to editing operations in
  conjunction with an unknown plug-in.

CVE-2011-3887 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3887):
  Google Chrome before 15.0.874.102 does not properly handle javascript: URLs,
  which allows remote attackers to bypass intended access restrictions and
  read cookies via unspecified vectors.

CVE-2011-3886 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3886):
  Google V8, as used in Google Chrome before 15.0.874.102, allows remote
  attackers to cause a denial of service or possibly have unspecified other
  impact via crafted JavaScript code that triggers out-of-bounds write
  operations.

CVE-2011-3885 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3885):
  Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows
  remote attackers to cause a denial of service or possibly have unspecified
  other impact via vectors related to stale Cascading Style Sheets (CSS)
  token-sequence data.

CVE-2011-3884 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3884):
  Google Chrome before 15.0.874.102 does not properly address timing issues
  during DOM traversal, which allows remote attackers to cause a denial of
  service or possibly have unspecified other impact via a crafted document.

CVE-2011-3883 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3883):
  Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows
  remote attackers to cause a denial of service or possibly have unspecified
  other impact via vectors related to counters.

CVE-2011-3882 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3882):
  Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows
  remote attackers to cause a denial of service or possibly have unspecified
  other impact via vectors related to media buffers.

CVE-2011-3881 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3881):
  Google Chrome before 15.0.874.102 allows remote attackers to bypass the Same
  Origin Policy via unspecified vectors.

CVE-2011-3880 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3880):
  Google Chrome before 15.0.874.102 does not prevent use of an unspecified
  special character as a delimiter in HTTP headers, which has unknown impact
  and remote attack vectors.

CVE-2011-3879 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3879):
  Google Chrome before 15.0.874.102 does not prevent redirects to chrome:
  URLs, which has unspecified impact and remote attack vectors.

CVE-2011-3878 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3878):
  Race condition in Google Chrome before 15.0.874.102 allows remote attackers
  to cause a denial of service or possibly have unspecified other impact via
  vectors related to worker process initialization.

CVE-2011-3877 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3877):
  Cross-site scripting (XSS) vulnerability in the appcache internals page in
  Google Chrome before 15.0.874.102 allows remote attackers to inject
  arbitrary web script or HTML via unspecified vectors.

CVE-2011-3876 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3876):
  Google Chrome before 15.0.874.102 does not properly handle downloading files
  that have whitespace characters at the end of a filename, which has
  unspecified impact and user-assisted remote attack vectors.

CVE-2011-3875 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3875):
  Google Chrome before 15.0.874.102 does not properly handle drag and drop
  operations on URL strings, which allows user-assisted remote attackers to
  spoof the URL bar via unspecified vectors.

CVE-2011-2845 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2845):
  Google Chrome before 15.0.874.102 does not properly handle history data,
  which allows user-assisted remote attackers to spoof the URL bar via
  unspecified vectors.
Comment 6 Paweł Hajdan, Jr. (RETIRED) gentoo-dev 2011-10-28 13:51:38 UTC
x86 stable, all arches done

Security team, please proceed with the GLSA, the draft is ready.
Comment 7 GLSAMaker/CVETool Bot gentoo-dev 2011-11-01 10:03:31 UTC
This issue was resolved and addressed in
 GLSA 201111-01 at http://security.gentoo.org/glsa/glsa-201111-01.xml
by GLSA coordinator Alex Legler (a3li).
Comment 8 GLSAMaker/CVETool Bot gentoo-dev 2011-11-01 10:04:18 UTC
This issue was resolved and addressed in
 GLSA 201111-01 at http://security.gentoo.org/glsa/glsa-201111-01.xml
by GLSA coordinator Alex Legler (a3li).