View previous topic :: View next topic |
Author |
Message |
GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Sat Nov 19, 2011 5:26 pm Post subject: [ GLSA 201111-05 ] Chromium, V8: Multiple vulnerabilities |
|
|
Gentoo Linux Security Advisory
Title: Chromium, V8: Multiple vulnerabilities (GLSA 201111-05)
Severity: normal
Exploitable: remote
Date: November 19, 2011
Bug(s): #390113, #390779
ID: 201111-05
Synopsis
Multiple vulnerabilities have been reported in Chromium and V8,
some of which may allow execution of arbitrary code.
Background
Chromium is an open-source web browser project. V8 is Google's open
source JavaScript engine.
Affected Packages
Package: www-client/chromium
Vulnerable: < 15.0.874.121
Unaffected: >= 15.0.874.121
Architectures: All supported architectures
Package: dev-lang/v8
Vulnerable: < 3.5.10.24
Unaffected: >= 3.5.10.24
Architectures: All supported architectures
Description
Multiple vulnerabilities have been discovered in Chromium and V8. Please
review the CVE identifiers and release notes referenced below for
details.
Impact
A context-dependent attacker could entice a user to open a specially
crafted web site or JavaScript program using Chromium or V8, possibly
resulting in the execution of arbitrary code with the privileges of the
process, or a Denial of Service condition. The attacker also could cause
a Java applet to run without user confirmation.
Workaround
There is no known workaround at this time.
Resolution
All Chromium users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose
">=www-client/chromium-15.0.874.121"
| All V8 users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=dev-lang/v8-3.5.10.24"
|
References
CVE-2011-3892
CVE-2011-3893
CVE-2011-3894
CVE-2011-3895
CVE-2011-3896
CVE-2011-3897
CVE-2011-3898
CVE-2011-3900
Release Notes 15.0.874.120
Release Notes 15.0.874.121
Last edited by GLSA on Sat Mar 31, 2012 4:28 am; edited 4 times in total |
|
Back to top |
|
|
|
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
|