LWN.net Logo

chromium: multiple vulnerabilities

Package(s):chromium CVE #(s):CVE-2012-2842 CVE-2012-2843 CVE-2012-2844 CVE-2012-2822 CVE-2012-2824 CVE-2012-2828 CVE-2012-2832 CVE-2012-2833
Created:July 23, 2012 Updated:August 15, 2012
Description: From the CVE entries:

Use-after-free vulnerability in Google Chrome before 20.0.1132.57 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to counter handling. (CVE-2012-2842)

Use-after-free vulnerability in Google Chrome before 20.0.1132.57 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to layout height tracking. (CVE-2012-2843)

The PDF functionality in Google Chrome before 20.0.1132.57 does not properly handle JavaScript code, which allows remote attackers to cause a denial of service (incorrect object access) or possibly have unspecified other impact via a crafted document. (CVE-2012-2844)

The PDF functionality in Google Chrome before 20.0.1132.43 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors. (CVE-2012-2822)

Use-after-free vulnerability in Google Chrome before 20.0.1132.43 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to SVG painting. (CVE-2012-2824)

Multiple integer overflows in the PDF functionality in Google Chrome before 20.0.1132.43 allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document. (CVE-2012-2828)

The image-codec implementation in the PDF functionality in Google Chrome before 20.0.1132.43 does not initialize an unspecified pointer, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document. (CVE-2012-2832)

Buffer overflow in the JS API in the PDF functionality in Google Chrome before 20.0.1132.43 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors. (CVE-2012-2833)

Alerts:
Mageia MGASA-2012-0177 2012-07-21
Gentoo 201208-03 2012-08-14
openSUSE openSUSE-SU-2012:0993-1 2012-08-15

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds