This script is Copyright (C) 2012-2014 Tenable Network Security, Inc.
The remote Gentoo host is missing one or more security-related
The remote host is affected by the vulnerability described in GLSA-201202-01
(Chromium: Multiple vulnerabilities)
Multiple vulnerabilities have been discovered in Chromium. Please review
the CVE identifiers and release notes referenced below for details.
A remote attacker could entice a user to open a specially crafted web
site using Chromium, possibly resulting in the execution of arbitrary
code with the privileges of the process, a Denial of Service condition,
information leak (clipboard contents), bypass of the Same Origin Policy,
or escape from NativeClient's sandbox.
A remote attacker could also entice the user to perform a set of UI
actions (drag and drop) to trigger an URL bar spoofing vulnerability.
There is no known workaround at this time.
See also :
All Chromium users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose '>=www-client/chromium-17.0.963.56'
Risk factor :
High / CVSS Base Score : 9.3
CVSS Temporal Score : 8.1
Public Exploit Available : false
Family: Gentoo Local Security Checks
Nessus Plugin ID: 58025 ()
CVE ID: CVE-2011-3016