LWN.net Logo

chromium: multiple vulnerabilities

Package(s):chromium, v8 CVE #(s):CVE-2012-2807 CVE-2012-2815 CVE-2012-2816 CVE-2012-2817 CVE-2012-2818 CVE-2012-2819 CVE-2012-2820 CVE-2012-2821 CVE-2012-2823 CVE-2012-2825 CVE-2012-2826 CVE-2012-2829 CVE-2012-2830 CVE-2012-2831 CVE-2012-2834
Created:July 3, 2012 Updated:September 26, 2012
Description: From the openSUSE advisory:

- Update Chromium to 22.0.1190

  • * Security Fixes (bnc#769181):
  • * CVE-2012-2815: Leak of iframe fragment id
  • * CVE-2012-2816: Prevent sandboxed processes interfering with each other
  • * CVE-2012-2817: Use-after-free in table section handling
  • * CVE-2012-2818: Use-after-free in counter layout
  • * CVE-2012-2819: Crash in texture handling
  • * CVE-2012-2820: Out-of-bounds read in SVG filter handling
  • * CVE-2012-2821: Autofill display problem
  • * CVE-2012-2823: Use-after-free in SVG resource handling
  • * CVE-2012-2826: Out-of-bounds read in texture conversion
  • * CVE-2012-2829: Use-after-free in first-letter handling
  • * CVE-2012-2830: Wild pointer in array value setting
  • * CVE-2012-2831: Use-after-free in SVG reference handling
  • * CVE-2012-2834: Integer overflow in Matroska container
  • * CVE-2012-2825: Wild read in XSL handling
  • * CVE-2012-2807: Integer overflows in libxml
  • * Fix update-alternatives within the spec-file
Alerts:
openSUSE openSUSE-SU-2012:0813-1 2012-07-03
Mageia MGASA-2012-0177 2012-07-21
Debian DSA-2521-1 2012-08-04
Mandriva MDVSA-2012:126 2012-08-08
openSUSE openSUSE-SU-2012:0975-1 2012-08-09
Mageia MGASA-2012-0213 2012-08-12
Gentoo 201208-03 2012-08-14
Red Hat RHSA-2012:1288-01 2012-09-18
CentOS CESA-2012:1288 2012-09-18
Oracle ELSA-2012-1288 2012-09-18
Oracle ELSA-2012-1288 2012-09-18
Scientific Linux SL-libx-20120918 2012-09-18
CentOS CESA-2012:1288 2012-09-20
Fedora FEDORA-2012-13820 2012-09-26
Fedora FEDORA-2012-13824 2012-09-27
Ubuntu USN-1587-1 2012-09-27
Mandriva MDVSA-2013:047 2013-04-05
Mandriva MDVSA-2013:056 2013-04-08

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds