Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.702959
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-2959-1)
Summary:The remote host is missing an update for the Debian 'chromium-browser' package(s) announced via the DSA-2959-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'chromium-browser' package(s) announced via the DSA-2959-1 advisory.

Vulnerability Insight:
Several vulnerabilities have been discovered in the chromium web browser.

CVE-2014-3154

Collin Payne discovered a use-after-free issue in the filesystem API.

CVE-2014-3155

James March, Daniel Sommermann, and Alan Frindell discovered several out-of-bounds read issues in the SPDY protocol implementation.

CVE-2014-3156

Atte Kettunen discovered a buffer overflow issue in bitmap handling in the clipboard implementation.

CVE-2014-3157

A heap-based buffer overflow issue was discovered in chromium's ffmpeg media filter.

In addition, this version corrects a regression in the previous update. Support for older i386 processors had been dropped. This functionality is now restored.

For the stable distribution (wheezy), these problems have been fixed in version 35.0.1916.153-1~
deb7u1.

For the testing (jessie) and unstable (sid) distribution, these problems have been fixed in version 35.0.1916.153-1.

We recommend that you upgrade your chromium-browser packages.

Affected Software/OS:
'chromium-browser' package(s) on Debian 7.

Solution:
Please install the updated package(s).

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2014-3154
BugTraq ID: 67977
http://www.securityfocus.com/bid/67977
Debian Security Information: DSA-2959 (Google Search)
http://www.debian.org/security/2014/dsa-2959
http://security.gentoo.org/glsa/glsa-201408-16.xml
http://secunia.com/advisories/58585
http://secunia.com/advisories/59090
http://secunia.com/advisories/60061
http://secunia.com/advisories/60372
Common Vulnerability Exposure (CVE) ID: CVE-2014-3155
BugTraq ID: 67980
http://www.securityfocus.com/bid/67980
Common Vulnerability Exposure (CVE) ID: CVE-2014-3156
BugTraq ID: 67981
http://www.securityfocus.com/bid/67981
Common Vulnerability Exposure (CVE) ID: CVE-2014-3157
BugTraq ID: 67972
http://www.securityfocus.com/bid/67972
CopyrightCopyright (C) 2014 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.