FreeBSD : chromium -- multiple vulnerabilities (b8f0a391-7910-11e1-8a43-00262d5ed8ee)

This script is Copyright (C) 2012-2013 Tenable Network Security, Inc.


Synopsis :

The remote FreeBSD host is missing a security-related update.

Description :

Google Chrome Releases reports :

[109574] Medium CVE-2011-3058: Bad interaction possibly leading to XSS
in EUC-JP. Credit to Masato Kinugawa.

[112317] Medium CVE-2011-3059: Out-of-bounds read in SVG text
handling. Credit to Arthur Gerkis.

[114056] Medium CVE-2011-3060: Out-of-bounds read in text fragment
handling. Credit to miaubiz.

[116398] Medium CVE-2011-3061: SPDY proxy certificate checking error.
Credit to Leonidas Kontothanassis of Google.

[116524] High CVE-2011-3062: Off-by-one in OpenType Sanitizer. Credit
to Mateusz Jurczyk of the Google Security Team.

[117417] Low CVE-2011-3063: Validate navigation requests from the
renderer more carefully. Credit to kuzzcc, Sergey Glazunov, PinkiePie
and scarybeasts (Google Chrome Security Team).

[117471] High CVE-2011-3064: Use-after-free in SVG clipping. Credit to
Atte Kettunen of OUSPG.

[117588] High CVE-2011-3065: Memory corruption in Skia. Credit to
Omair.

[117794] Medium CVE-2011-3057: Invalid read in v8. Credit to Christian
Holler.

See also :

http://www.nessus.org/u?29fa020e
http://www.nessus.org/u?de57180b

Solution :

Update the affected package.

Risk factor :

Critical / CVSS Base Score : 10.0
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)

Family: FreeBSD Local Security Checks

Nessus Plugin ID: 58521 ()

Bugtraq ID:

CVE ID: CVE-2011-3057
CVE-2011-3058
CVE-2011-3059
CVE-2011-3060
CVE-2011-3061
CVE-2011-3062
CVE-2011-3063
CVE-2011-3064
CVE-2011-3065

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now