LWN.net Logo

chromium-browser: multiple vulnerabilities

Package(s):chromium-browser CVE #(s):CVE-2011-0779 CVE-2011-1290
Created:March 15, 2011 Updated:March 16, 2011
Description: From the Debian advisory:

CVE-2011-0779: Google Chrome before 9.0.597.84 does not properly handle a missing key in an extension, which allows remote attackers to cause a denial of service (application crash) via a crafted extension.

CVE-2011-1290: Integer overflow in WebKit allows remote attackers to execute arbitrary code via unknown vectors, as demonstrated by Vincenzo Iozzo, Willem Pinckaers, and Ralf-Philipp Weinmann during a Pwn2Own competition at CanSecWest 2011.

Alerts:
Debian DSA-2192-1 2011-03-15

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds