{"id":"MGASA-2013-0234","summary":"Updated chromium-browser-stable packages fix security vulnerabilities","details":"Updated chromium-browser-stable packages fix security vulnerabilities:\n\nThe HTTPS implementation does not ensure that headers are terminated by\n\\r\\n\\r\\n (carriage return, newline, carriage return, newline)\n(CVE-2013-2853).\n\nChrome does not properly prevent pop-under windows (CVE-2013-2867).\n\ncommon/extensions/sync_helper.cc proceeds with sync operations for NPAPI\nextensions without checking for a certain plugin permission setting\n(CVE-2013-2868).\n\nDenial of service (out-of-bounds read) via a crafted JPEG2000 image\n(CVE-2013-2869).\n\nUse-after-free vulnerability in network sockets (CVE-2013-2870).\n\nUse-after-free vulnerability in input handling (CVE-2013-2871).\n\nUse-after-free vulnerability in resource loading (CVE-2013-2873).\n\nOut-of-bounds read in SVG file handling (CVE-2013-2875).\n\nChrome does not properly enforce restrictions on the capture of screenshots\nby extensions, which could lead to information disclosure from previous page\nvisits (CVE-2013-2876).\n\nOut-of-bounds read in text handling (CVE-2013-2878).\n\nThe circumstances in which a renderer process can be considered a trusted\nprocess for sign-in and subsequent sync operations were not propertly\nchecked (CVE-2013-2879).\n\nThe chrome 28 development team found various issues from internal fuzzing,\naudits, and other studies (CVE-2013-2880).\n","modified":"2026-04-16T04:44:47.827220650Z","published":"2013-07-26T11:52:03Z","upstream":["CVE-2013-2853","CVE-2013-2867","CVE-2013-2868","CVE-2013-2869","CVE-2013-2870","CVE-2013-2871","CVE-2013-2873","CVE-2013-2875","CVE-2013-2876","CVE-2013-2878","CVE-2013-2879","CVE-2013-2880"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2013-0234.html"},{"type":"WEB","url":"http://googlechromereleases.blogspot.com/2013/07/stable-channel-update.html"},{"type":"WEB","url":"http://www.debian.org/security/2013/dsa-2724"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=10804"}],"affected":[{"package":{"name":"chromium-browser-stable","ecosystem":"Mageia:2","purl":"pkg:rpm/mageia/chromium-browser-stable?arch=source&distro=mageia-2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"28.0.1500.71-1.mga2"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2013-0234.json"}},{"package":{"name":"chromium-browser-stable","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/chromium-browser-stable?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"28.0.1500.71-1.mga3"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2013-0234.json"}},{"package":{"name":"chromium-browser-stable","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/chromium-browser-stable?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"28.0.1500.71-1.mga3.tainted"}]}],"ecosystem_specific":{"section":"tainted"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2013-0234.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}