Vulnerability Solutions

The Nimsoft Cloud Monitor Periodic Vulnerability Scan checks for the vulnerability below. To see the most recently added vulnerability solutions that are scanned by WatchMouse, go to the Vulnerability Solutions overview

Category: Gentoo Local Security Checks Risk factor: Medium Added: 31 Jan 2012
Synopsis:

The remote Gentoo host is missing one or more security-related
patches.

Description:

The remote host is affected by the vulnerability described in GLSA-201201-17
(Chromium: Multiple vulnerabilities)

Multiple vulnerabilities have been discovered in Chromium. Please review the CVE identifiers and release notes referenced below for details.

Impact :

A remote attacker could entice a user to open a specially crafted web site using Chromium, possibly resulting in the execution of arbitrary code with the privileges of the process, or a Denial of Service condition.

Workaround :

There is no known workaround at this time.

See also:

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3924
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3925
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3926
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3927
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3928
http://www.nessus.org/u?0feecd9f
http://www.gentoo.org/security/en/glsa/glsa-201201-17.xml

Solution:

All Chromium users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose '>=www-client/chromium-16.0.912.77'

Risk factor:

Medium