Executive Summary

Summary
Title chromium-browser security update
Informations
Name DSA-2862 First vendor Publication 2014-02-16
Vendor Debian Last vendor Modification 2014-02-16
Severity (Vendor) N/A Revision 1

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P)
Cvss Base Score 7.5 Attack Range Network
Cvss Impact Score 6.4 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Several vulnerabilities have been discovered in the chromium web browser.

CVE-2013-6641

Atte Kettunen discovered a use-after-free issue in Blink/Webkit form elements.

CVE-2013-6643

Joao Lucas Melo Brasio discovered a Google account information disclosure issue related to the one-click sign-on feature.

CVE-2013-6644

The chrome development team discovered and fixed multiple issues with potential security impact.

CVE-2013-6645

Khalil Zhani discovered a use-after-free issue related to speech input.

CVE-2013-6646

Colin Payne discovered a use-after-free issue in the web workers implementation.

CVE-2013-6649

Atte Kettunen discovered a use-after-free issue in the Blink/Webkit SVG implementation.

CVE-2013-6650

Christian Holler discovered a memory corruption in the v8 javascript library.

For the stable distribution (wheezy), these problems have been fixed in version 32.0.1700.123-1~deb7u1.

For the testing distribution (jessie), these problems will be fixed soon.

For the unstable distribution (sid), these problems have been fixed in version 32.0.1700.123-1.

We recommend that you upgrade your chromium-browser packages.

Original Source

Url : http://www.debian.org/security/2014/dsa-2862

CWE : Common Weakness Enumeration

% Id Name
57 % CWE-416 Use After Free
14 % CWE-399 Resource Management Errors
14 % CWE-287 Improper Authentication
14 % CWE-20 Improper Input Validation

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:22028
 
Oval ID: oval:org.mitre.oval:def:22028
Title: Vulnerability in Google Chrome before 32.0.1700.102 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via vectors that trigger incorrect handling of "popular pages"
Description: The StoreBuffer::ExemptPopularPages function in store-buffer.cc in Google V8 before 3.22.24.16, as used in Google Chrome before 32.0.1700.102, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via vectors that trigger incorrect handling of "popular pages."
Family: windows Class: vulnerability
Reference(s): CVE-2013-6650
Version: 3
Platform(s): Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Vista
Microsoft Windows 7
Microsoft Windows 8
Microsoft Windows 8.1
Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Product(s): Google Chrome
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:22082
 
Oval ID: oval:org.mitre.oval:def:22082
Title: Vulnerability in Google Chrome before 32.0.1700.102 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a zero-size SVG image
Description: Use-after-free vulnerability in the RenderSVGImage::paint function in core/rendering/svg/RenderSVGImage.cpp in Blink, as used in Google Chrome before 32.0.1700.102, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a zero-size SVG image.
Family: windows Class: vulnerability
Reference(s): CVE-2013-6649
Version: 3
Platform(s): Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Vista
Microsoft Windows 7
Microsoft Windows 8
Microsoft Windows 8.1
Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Product(s): Google Chrome
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:22094
 
Oval ID: oval:org.mitre.oval:def:22094
Title: Use-after-free vulnerability in the Web Workers implementation in Google Chrome before 32.0.1700.76 allows remote attackers to cause a denial of service or possibly have unspecified other impact
Description: Use-after-free vulnerability in the Web Workers implementation in Google Chrome before 32.0.1700.76 on Windows and before 32.0.1700.77 on Mac OS X and Linux allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the shutting down of a worker process.
Family: windows Class: vulnerability
Reference(s): CVE-2013-6646
Version: 4
Platform(s): Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Vista
Microsoft Windows 7
Microsoft Windows 8
Microsoft Windows 8.1
Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Product(s): Google Chrome
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:22272
 
Oval ID: oval:org.mitre.oval:def:22272
Title: Vulnerability in Google Chrome before 32.0.1700.76 on Windows allows attackers to trigger a sync with an arbitrary Google account by leveraging improper handling of the closing of an untrusted signin confirm dialog
Description: The OneClickSigninBubbleView::WindowClosing function in browser/ui/views/sync/one_click_signin_bubble_view.cc in Google Chrome before 32.0.1700.76 on Windows and before 32.0.1700.77 on Mac OS X and Linux allows attackers to trigger a sync with an arbitrary Google account by leveraging improper handling of the closing of an untrusted signin confirm dialog.
Family: windows Class: vulnerability
Reference(s): CVE-2013-6643
Version: 4
Platform(s): Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Vista
Microsoft Windows 7
Microsoft Windows 8
Microsoft Windows 8.1
Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Product(s): Google Chrome
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:22307
 
Oval ID: oval:org.mitre.oval:def:22307
Title: Multiple unspecified vulnerabilities in Google Chrome before 32.0.1700.76 on Windows allow attackers to cause a denial of service or possibly have other impact via unknown vectors
Description: Multiple unspecified vulnerabilities in Google Chrome before 32.0.1700.76 on Windows and before 32.0.1700.77 on Mac OS X and Linux allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
Family: windows Class: vulnerability
Reference(s): CVE-2013-6644
Version: 3
Platform(s): Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Vista
Microsoft Windows 7
Microsoft Windows 8
Microsoft Windows 8.1
Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Product(s): Google Chrome
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:22340
 
Oval ID: oval:org.mitre.oval:def:22340
Title: Use-after-free vulnerability in Google Chrome before 32.0.1700.76 on Windows allows attackers to trigger a sync with an arbitrary Google account by leveraging improper handling of the closing of an untrusted signin confirm dialog
Description: Use-after-free vulnerability in the FormAssociatedElement::formRemovedFromTree function in core/html/FormAssociatedElement.cpp in Blink, as used in Google Chrome before 32.0.1700.76 on Windows and before 32.0.1700.77 on Mac OS X and Linux, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging improper handling of the past names map of a FORM element.
Family: windows Class: vulnerability
Reference(s): CVE-2013-6641
Version: 3
Platform(s): Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Vista
Microsoft Windows 7
Microsoft Windows 8
Microsoft Windows 8.1
Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Product(s): Google Chrome
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:22367
 
Oval ID: oval:org.mitre.oval:def:22367
Title: Use-after-free vulnerability in Google Chrome before 32.0.1700.76 allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact
Description: Use-after-free vulnerability in the OnWindowRemovingFromRootWindow function in content/browser/web_contents/web_contents_view_aura.cc in Google Chrome before 32.0.1700.76 on Windows and before 32.0.1700.77 on Mac OS X and Linux allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving certain print-preview and tab-switch actions that interact with a speech input element.
Family: windows Class: vulnerability
Reference(s): CVE-2013-6645
Version: 4
Platform(s): Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Vista
Microsoft Windows 7
Microsoft Windows 8
Microsoft Windows 8.1
Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Product(s): Google Chrome
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:24212
 
Oval ID: oval:org.mitre.oval:def:24212
Title: DSA-2862-1 chromium-browser - several
Description: Several vulnerabilities have been discovered in the chromium web browser.
Family: unix Class: patch
Reference(s): DSA-2862-1
CVE-2013-6641
CVE-2013-6643
CVE-2013-6644
CVE-2013-6645
CVE-2013-6646
CVE-2013-6649
CVE-2013-6650
Version: 5
Platform(s): Debian GNU/Linux 7
Debian GNU/kFreeBSD 7
Product(s): chromium-browser
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 3380
Os 2
Os 3
Os 2

Information Assurance Vulnerability Management (IAVM)

Date Description
2014-01-31 IAVM : 2014-B-0007 - Multiple Security Vulnerabilities in Google Chrome
Severity : Category I - VMSKEY : V0043878
2014-01-16 IAVM : 2014-B-0003 - Multiple Security Vulnerabilities in Google Chrome
Severity : Category I - VMSKEY : V0043401

Nessus® Vulnerability Scanner

Date Description
2014-06-13 Name : The remote openSUSE host is missing a security update.
File : openSUSE-2014-135.nasl - Type : ACT_GATHER_INFO
2014-03-10 Name : The remote Fedora host is missing a security update.
File : fedora_2014-3222.nasl - Type : ACT_GATHER_INFO
2014-03-10 Name : The remote Fedora host is missing a security update.
File : fedora_2014-3253.nasl - Type : ACT_GATHER_INFO
2014-03-06 Name : The remote Gentoo host is missing one or more security-related patches.
File : gentoo_GLSA-201403-01.nasl - Type : ACT_GATHER_INFO
2014-02-17 Name : The remote Debian host is missing a security-related update.
File : debian_DSA-2862.nasl - Type : ACT_GATHER_INFO
2014-01-28 Name : The remote FreeBSD host is missing a security-related update.
File : freebsd_pkg_f9810c4387a511e3921400262d5ed8ee.nasl - Type : ACT_GATHER_INFO
2014-01-28 Name : The remote host contains a web browser that is affected by multiple vulnerabi...
File : google_chrome_32_0_1700_102.nasl - Type : ACT_GATHER_INFO
2014-01-28 Name : The remote Mac OS X host contains a web browser that is affected by multiple ...
File : macosx_google_chrome_32_0_1700_102.nasl - Type : ACT_GATHER_INFO
2014-01-16 Name : The remote FreeBSD host is missing a security-related update.
File : freebsd_pkg_5acf46387e2c11e39fba00262d5ed8ee.nasl - Type : ACT_GATHER_INFO
2014-01-15 Name : The remote host contains a web browser that is affected by multiple vulnerabi...
File : google_chrome_32_0_1700_76.nasl - Type : ACT_GATHER_INFO
2014-01-15 Name : The remote Mac OS X host contains a web browser that is affected by multiple ...
File : macosx_google_chrome_32_0_1700_77.nasl - Type : ACT_GATHER_INFO

Alert History

If you want to see full details history, please login or register.
0
1
Date Informations
2014-02-18 15:32:59
  • Multiple Updates
2014-02-16 21:19:11
  • First insertion