Executive Summary
Summary | |
---|---|
Title | chromium-browser security update |
Informations | |||
---|---|---|---|
Name | DSA-2959 | First vendor Publication | 2014-06-14 |
Vendor | Debian | Last vendor Modification | 2014-06-14 |
Severity (Vendor) | N/A | Revision | 1 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 7.5 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Several vulnerabilities have been discovered in the chromium web browser. CVE-2014-3154 Collin Payne discovered a use-after-free issue in the filesystem API. CVE-2014-3155 James March, Daniel Sommermann, and Alan Frindell discovered several out-of-bounds read issues in the SPDY protocol implementation. CVE-2014-3156 Atte Kettunen discovered a buffer overflow issue in bitmap handling in the clipboard implementation. CVE-2014-3157 A heap-based buffer overflow issue was discovered in chromium's ffmpeg media filter. In addition, this version corrects a regression in the previous update. Support for older i386 processors had been dropped. This functionality is now restored. For the stable distribution (wheezy), these problems have been fixed in version 35.0.1916.153-1~deb7u1. For the testing (jessie) and unstable (sid) distribution, these problems have been fixed in version 35.0.1916.153-1. We recommend that you upgrade your chromium-browser packages. |
Original Source
Url : http://www.debian.org/security/2014/dsa-2959 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:24791 | |||
Oval ID: | oval:org.mitre.oval:def:24791 | ||
Title: | Vulnerability in Google Chrome before 35.0.1916.153, allows remote attackers to cause a denial of service or possibly have unspecified other impact | ||
Description: | Buffer overflow in the clipboard implementation in Google Chrome before 35.0.1916.153 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger unexpected bitmap data, related to content/renderer/renderer_clipboard_client.cc and content/renderer/webclipboard_impl.cc. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2014-3156 | Version: | 3 |
Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Server 2008 Microsoft Windows Server 2008 R2 Microsoft Windows Vista Microsoft Windows 7 Microsoft Windows 8 Microsoft Windows 8.1 Microsoft Windows Server 2012 Microsoft Windows Server 2012 R2 | Product(s): | Google Chrome |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:24831 | |||
Oval ID: | oval:org.mitre.oval:def:24831 | ||
Title: | Heap-based buffer overflow vulnerability in Google Chrome before 35.0.1916.153, allows remote attackers to cause a denial of service or possibly have unspecified other impact | ||
Description: | Heap-based buffer overflow in the FFmpegVideoDecoder::GetVideoBuffer function in media/filters/ffmpeg_video_decoder.cc in Google Chrome before 35.0.1916.153 allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging VideoFrame data structures that are too small for proper interaction with an underlying FFmpeg library. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2014-3157 | Version: | 3 |
Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Server 2008 Microsoft Windows Server 2008 R2 Microsoft Windows Vista Microsoft Windows 7 Microsoft Windows 8 Microsoft Windows 8.1 Microsoft Windows Server 2012 Microsoft Windows Server 2012 R2 | Product(s): | Google Chrome |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:25017 | |||
Oval ID: | oval:org.mitre.oval:def:25017 | ||
Title: | Vulnerability in Google Chrome before 35.0.1916.153, allows remote attackers to cause a denial of service (out-of-bounds read) | ||
Description: | net/spdy/spdy_write_queue.cc in the SPDY implementation in Google Chrome before 35.0.1916.153 allows remote attackers to cause a denial of service (out-of-bounds read) by leveraging incorrect queue maintenance. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2014-3155 | Version: | 3 |
Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Server 2008 Microsoft Windows Server 2008 R2 Microsoft Windows Vista Microsoft Windows 7 Microsoft Windows 8 Microsoft Windows 8.1 Microsoft Windows Server 2012 Microsoft Windows Server 2012 R2 | Product(s): | Google Chrome |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:25028 | |||
Oval ID: | oval:org.mitre.oval:def:25028 | ||
Title: | Use-after-free vulnerability in Google Chrome before 35.0.1916.153, allows remote attackers to cause a denial of service or possibly have unspecified other impact | ||
Description: | Use-after-free vulnerability in the ChildThread::Shutdown function in content/child/child_thread.cc in the filesystem API in Google Chrome before 35.0.1916.153 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to a Blink shutdown. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2014-3154 | Version: | 3 |
Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Server 2008 Microsoft Windows Server 2008 R2 Microsoft Windows Vista Microsoft Windows 7 Microsoft Windows 8 Microsoft Windows 8.1 Microsoft Windows Server 2012 Microsoft Windows Server 2012 R2 | Product(s): | Google Chrome |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:25078 | |||
Oval ID: | oval:org.mitre.oval:def:25078 | ||
Title: | DSA-2959-1 chromium-browser - security update | ||
Description: | Several vulnerabilities have been discovered in the chromium web browser. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-2959-1 CVE-2014-3154 CVE-2014-3155 CVE-2014-3156 CVE-2014-3157 | Version: | 3 |
Platform(s): | Debian GNU/Linux 7.0 Debian GNU/kFreeBSD 7.0 | Product(s): | chromium-browser |
Definition Synopsis: | |||
CPE : Common Platform Enumeration
Information Assurance Vulnerability Management (IAVM)
Date | Description |
---|---|
2014-06-12 | IAVM : 2014-B-0071 - Multiple Vulnerabilities in Google Chrome Severity : Category I - VMSKEY : V0052483 |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2014-08-30 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201408-16.nasl - Type : ACT_GATHER_INFO |
2014-08-12 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2014-483.nasl - Type : ACT_GATHER_INFO |
2014-07-24 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-2298-1.nasl - Type : ACT_GATHER_INFO |
2014-06-16 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-2959.nasl - Type : ACT_GATHER_INFO |
2014-06-12 | Name : The remote FreeBSD host is missing a security-related update. File : freebsd_pkg_0b0fb9b0f0fb11e39bcd000c6e25e3e9.nasl - Type : ACT_GATHER_INFO |
2014-06-11 | Name : The remote host contains a web browser that is affected by multiple vulnerabi... File : google_chrome_35_0_1916_153.nasl - Type : ACT_GATHER_INFO |
2014-06-11 | Name : The remote Mac OS X host contains a web browser that is affected by multiple ... File : macosx_google_chrome_35_0_1916_153.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-06-17 13:25:40 |
|
2014-06-15 00:20:58 |
|