Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

Debian: Security Advisory for chromium (DSA-4917-1)

Information

Severity

Severity

Medium

Family

Family

Debian Local Security Checks

CVSSv2 Base

CVSSv2 Base

5.0

CVSSv2 Vector

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:N/A:N

Solution Type

Solution Type

Vendor Patch

Created

Created

2 years ago

Modified

Modified

2 years ago

Summary

The remote host is missing an update for the 'chromium' package(s) announced via the DSA-4917-1 advisory.

Insight

Insight

Several vulnerabilities have been discovered in the chromium web browser. CVE-2021-30506 @retsew0x01 discovered an error in the Web App installation interface. CVE-2021-30507 Alison Huffman discovered an error in the Offline mode. CVE-2021-30508 Leecraso and Guang Gong discovered a buffer overflow issue in the Media Feeds implementation. CVE-2021-30509 David Erceg discovered an out-of-bounds write issue in the Tab Strip implementation. CVE-2021-30510 Weipeng Jiang discovered a race condition in the aura window manager. CVE-2021-30511 David Erceg discovered an out-of-bounds read issue in the Tab Strip implementation. CVE-2021-30512 ZhanJia Song discovered a use-after-free issue in the notifications implementation. CVE-2021-30513 Man Yue Mo discovered an incorrect type in the v8 javascript library. CVE-2021-30514 koocola and Wang discovered a use-after-free issue in the Autofill feature. CVE-2021-30515 Rong Jian and Guang Gong discovered a use-after-free issue in the file system access API. CVE-2021-30516 ZhanJia Song discovered a buffer overflow issue in the browsing history. CVE-2021-30517 Jun Kokatsu discovered a buffer overflow issue in the reader mode. CVE-2021-30518 laural discovered use of an incorrect type in the v8 javascript library. CVE-2021-30519 asnine discovered a use-after-free issue in the Payments feature. CVE-2021-30520 Khalil Zhani discovered a use-after-free issue in the Tab Strip implementation.

Affected Software

Affected Software

'chromium' package(s) on Debian Linux.

Detection Method

Detection Method

Checks if a vulnerable package version is present on the target host.

Solution

Solution

For the stable distribution (buster), these problems have been fixed in version 90.0.4430.212-1~deb10u1. We recommend that you upgrade your chromium packages.