Chromium: Multiple vulnerabilities — GLSA 201203-19

Multiple vulnerabilities have been reported in Chromium, some of which may allow execution of arbitrary code.

Affected packages

www-client/chromium on all architectures
Affected versions < 17.0.963.83
Unaffected versions >= 17.0.963.83

Background

Chromium is an open source web browser project.

Description

Multiple vulnerabilities have been discovered in Chromium. Please review the CVE identifiers and release notes referenced below for details.

Impact

A remote attacker could entice a user to open a specially crafted web site using Chromium, possibly resulting in the execution of arbitrary code with the privileges of the process, a Denial of Service condition, Universal Cross-Site Scripting, or installation of an extension without user interaction.

A remote attacker could also entice a user to install a specially crafted extension that would interfere with browser-issued web requests.

Workaround

There is no known workaround at this time.

Resolution

All Chromium users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=www-client/chromium-17.0.963.83"
 

References

Release date
March 25, 2012

Latest revision
March 25, 2012: 1

Severity
normal

Exploitable
remote

Bugzilla entries