drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Mehrere Probleme in chromium-browser
Name: |
Mehrere Probleme in chromium-browser |
|
ID: |
DSA-2706-1 |
|
Distribution: |
Debian |
|
Plattformen: |
Debian sid, Debian wheezy, Debian jessie |
|
Datum: |
Di, 11. Juni 2013, 08:37 |
|
Referenzen: |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2855
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2856
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2857
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2858
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2859
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2860
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2861
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2862
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2863
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2865 |
|
Applikationen: |
Chromium |
|
Originalnachricht |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1
- ------------------------------------------------------------------------- Debian Security Advisory DSA-2706-1 security@debian.org http://www.debian.org/security/ Giuseppe Iuculano June 10, 2013 http://www.debian.org/security/faq - -------------------------------------------------------------------------
Package : chromium-browser Vulnerability : several Problem type : remote Debian-specific: no CVE ID : CVE-2013-2855 CVE-2013-2856 CVE-2013-2857 CVE-2013-2858 CVE-2013-2859 CVE-2013-2860 CVE-2013-2861 CVE-2013-2862 CVE-2013-2863 CVE-2013-2865
Several vulnerabilities have been discovered in the chromium web browser.
CVE-2013-2855
The Developer Tools API in Chromium before 27.0.1453.110 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
CVE-2013-2856
Use-after-free vulnerability in Chromium before 27.0.1453.110 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of input.
CVE-2013-2857
Use-after-free vulnerability in Chromium before 27.0.1453.110 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of images.
CVE-2013-2858
Use-after-free vulnerability in the HTML5 Audio implementation in Chromium before 27.0.1453.110 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
CVE-2013-2859
Chromium before 27.0.1453.110 allows remote attackers to bypass the Same Origin Policy and trigger namespace pollution via unspecified vectors.
CVE-2013-2860
Use-after-free vulnerability in Chromium before 27.0.1453.110 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving access to a database API by a worker process.
CVE-2013-2861
Use-after-free vulnerability in the SVG implementation in Chromium before 27.0.1453.110 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
CVE-2013-2862
Skia, as used in Chromium before 27.0.1453.110, does not properly handle GPU acceleration, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
CVE-2013-2863
Chromium before 27.0.1453.110 does not properly handle SSL sockets, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
CVE-2013-2865
Multiple unspecified vulnerabilities in Chromium before 27.0.1453.110 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
For the stable distribution (wheezy), these problems have been fixed in version 27.0.1453.110-1~deb7u1.
For the testing distribution (jessie), these problems have been fixed in version 27.0.1453.110-1.
For the unstable distribution (sid), these problems have been fixed in version 27.0.1453.110-1.
We recommend that you upgrade your chromium-browser packages.
Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/
Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux)
iEYEARECAAYFAlG2EQUACgkQNxpp46476aoVswCfTT3tgaA0Wpkmb/8x+jvc43GK o3gAn3plraTpR6vKqtXrVTLN9m6irBL+ =PLYK -----END PGP SIGNATURE-----
-- To UNSUBSCRIBE, email to debian-security-announce-REQUEST@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org Archive: http://lists.debian.org/20130610174645.GB7324@SD6-Casa.iuculano.it
|
|
|
|