ALT-BU-2021-3737-13
Branch p9 update bulletin.
Closed vulnerabilities
BDU:2021-00913
Уязвимость графической библиотеки Skia браузера Google Chrome, позволяющая нарушителю проводить спуфинг-атаки
BDU:2021-00915
Уязвимость обработчика JavaScript-сценариев V8 браузера Google Chrome, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2021-01022
Уязвимость компонента Fonts браузера Google Chrome, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
BDU:2021-01043
Уязвимость компонента Extensions браузера Google Chrome, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
BDU:2021-01048
Уязвимость компонента Tab Groups браузера Google Chrome, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
BDU:2021-01049
Уязвимость компонента Payments браузера Google Chrome, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
BDU:2021-01065
Уязвимость компонента Navigation браузера Google Chrome, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
Modified: 2024-11-21
CVE-2021-21142
Use after free in Payments in Google Chrome on Mac prior to 88.0.4324.146 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
- https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop.html
- https://crbug.com/1169317
- https://crbug.com/1169317
- FEDORA-2021-7fb30b9381
- FEDORA-2021-7fb30b9381
- FEDORA-2021-05afa65d39
- FEDORA-2021-05afa65d39
- GLSA-202104-08
- GLSA-202104-08
Modified: 2024-11-21
CVE-2021-21143
Heap buffer overflow in Extensions in Google Chrome prior to 88.0.4324.146 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.
- https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop.html
- https://crbug.com/1163504
- https://crbug.com/1163504
- FEDORA-2021-7fb30b9381
- FEDORA-2021-7fb30b9381
- FEDORA-2021-05afa65d39
- FEDORA-2021-05afa65d39
- GLSA-202104-08
- GLSA-202104-08
Modified: 2024-11-21
CVE-2021-21144
Heap buffer overflow in Tab Groups in Google Chrome prior to 88.0.4324.146 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.
- https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop.html
- https://crbug.com/1163845
- https://crbug.com/1163845
- FEDORA-2021-7fb30b9381
- FEDORA-2021-7fb30b9381
- FEDORA-2021-05afa65d39
- FEDORA-2021-05afa65d39
- GLSA-202104-08
- GLSA-202104-08
Modified: 2024-11-21
CVE-2021-21145
Use after free in Fonts in Google Chrome prior to 88.0.4324.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop.html
- https://crbug.com/1154965
- https://crbug.com/1154965
- FEDORA-2021-7fb30b9381
- FEDORA-2021-7fb30b9381
- FEDORA-2021-05afa65d39
- FEDORA-2021-05afa65d39
- GLSA-202104-08
- GLSA-202104-08
Modified: 2024-11-21
CVE-2021-21146
Use after free in Navigation in Google Chrome prior to 88.0.4324.146 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
- https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop.html
- https://crbug.com/1161705
- https://crbug.com/1161705
- FEDORA-2021-7fb30b9381
- FEDORA-2021-7fb30b9381
- FEDORA-2021-05afa65d39
- FEDORA-2021-05afa65d39
- GLSA-202104-08
- GLSA-202104-08
Modified: 2024-11-21
CVE-2021-21147
Inappropriate implementation in Skia in Google Chrome prior to 88.0.4324.146 allowed a local attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
- https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop.html
- https://crbug.com/1162942
- https://crbug.com/1162942
- FEDORA-2021-7fb30b9381
- FEDORA-2021-7fb30b9381
- FEDORA-2021-05afa65d39
- FEDORA-2021-05afa65d39
- GLSA-202104-08
- GLSA-202104-08
Modified: 2025-02-05
CVE-2021-21148
Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.150 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- http://packetstormsecurity.com/files/162579/Chrome-Array-Transfer-Bypass.html
- http://packetstormsecurity.com/files/162579/Chrome-Array-Transfer-Bypass.html
- https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop_4.html
- https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop_4.html
- https://crbug.com/1170176
- https://crbug.com/1170176
- FEDORA-2021-7fb30b9381
- FEDORA-2021-7fb30b9381
- FEDORA-2021-05afa65d39
- FEDORA-2021-05afa65d39
- GLSA-202104-08
- GLSA-202104-08
- DSA-4858
- DSA-4858
Package chromium-gost updated to version 88.0.4324.150-alt0.1.p9 for branch p9 in task 266042.
Closed vulnerabilities
BDU:2021-00913
Уязвимость графической библиотеки Skia браузера Google Chrome, позволяющая нарушителю проводить спуфинг-атаки
BDU:2021-00915
Уязвимость обработчика JavaScript-сценариев V8 браузера Google Chrome, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2021-01022
Уязвимость компонента Fonts браузера Google Chrome, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
BDU:2021-01043
Уязвимость компонента Extensions браузера Google Chrome, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
BDU:2021-01048
Уязвимость компонента Tab Groups браузера Google Chrome, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
BDU:2021-01049
Уязвимость компонента Payments браузера Google Chrome, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
BDU:2021-01065
Уязвимость компонента Navigation браузера Google Chrome, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
Modified: 2024-11-21
CVE-2021-21142
Use after free in Payments in Google Chrome on Mac prior to 88.0.4324.146 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
- https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop.html
- https://crbug.com/1169317
- https://crbug.com/1169317
- FEDORA-2021-7fb30b9381
- FEDORA-2021-7fb30b9381
- FEDORA-2021-05afa65d39
- FEDORA-2021-05afa65d39
- GLSA-202104-08
- GLSA-202104-08
Modified: 2024-11-21
CVE-2021-21143
Heap buffer overflow in Extensions in Google Chrome prior to 88.0.4324.146 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.
- https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop.html
- https://crbug.com/1163504
- https://crbug.com/1163504
- FEDORA-2021-7fb30b9381
- FEDORA-2021-7fb30b9381
- FEDORA-2021-05afa65d39
- FEDORA-2021-05afa65d39
- GLSA-202104-08
- GLSA-202104-08
Modified: 2024-11-21
CVE-2021-21144
Heap buffer overflow in Tab Groups in Google Chrome prior to 88.0.4324.146 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.
- https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop.html
- https://crbug.com/1163845
- https://crbug.com/1163845
- FEDORA-2021-7fb30b9381
- FEDORA-2021-7fb30b9381
- FEDORA-2021-05afa65d39
- FEDORA-2021-05afa65d39
- GLSA-202104-08
- GLSA-202104-08
Modified: 2024-11-21
CVE-2021-21145
Use after free in Fonts in Google Chrome prior to 88.0.4324.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop.html
- https://crbug.com/1154965
- https://crbug.com/1154965
- FEDORA-2021-7fb30b9381
- FEDORA-2021-7fb30b9381
- FEDORA-2021-05afa65d39
- FEDORA-2021-05afa65d39
- GLSA-202104-08
- GLSA-202104-08
Modified: 2024-11-21
CVE-2021-21146
Use after free in Navigation in Google Chrome prior to 88.0.4324.146 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
- https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop.html
- https://crbug.com/1161705
- https://crbug.com/1161705
- FEDORA-2021-7fb30b9381
- FEDORA-2021-7fb30b9381
- FEDORA-2021-05afa65d39
- FEDORA-2021-05afa65d39
- GLSA-202104-08
- GLSA-202104-08
Modified: 2024-11-21
CVE-2021-21147
Inappropriate implementation in Skia in Google Chrome prior to 88.0.4324.146 allowed a local attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
- https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop.html
- https://crbug.com/1162942
- https://crbug.com/1162942
- FEDORA-2021-7fb30b9381
- FEDORA-2021-7fb30b9381
- FEDORA-2021-05afa65d39
- FEDORA-2021-05afa65d39
- GLSA-202104-08
- GLSA-202104-08
Modified: 2025-02-05
CVE-2021-21148
Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.150 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- http://packetstormsecurity.com/files/162579/Chrome-Array-Transfer-Bypass.html
- http://packetstormsecurity.com/files/162579/Chrome-Array-Transfer-Bypass.html
- https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop_4.html
- https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop_4.html
- https://crbug.com/1170176
- https://crbug.com/1170176
- FEDORA-2021-7fb30b9381
- FEDORA-2021-7fb30b9381
- FEDORA-2021-05afa65d39
- FEDORA-2021-05afa65d39
- GLSA-202104-08
- GLSA-202104-08
- DSA-4858
- DSA-4858
Closed bugs
Исчез webclient
Closed vulnerabilities
BDU:2021-03159
Уязвимость расширения SOAP интерпретатора PHP, позволяющая нарушителю вызвать аварийное завершение работы приложения
Modified: 2024-11-21
CVE-2021-21702
In PHP versions 7.3.x below 7.3.27, 7.4.x below 7.4.15 and 8.0.x below 8.0.2, when using SOAP extension to connect to a SOAP server, a malicious SOAP server could return malformed XML data as a response that would cause PHP to access a null pointer and thus cause a crash.
- https://bugs.php.net/bug.php?id=80672
- https://bugs.php.net/bug.php?id=80672
- [debian-lts-announce] 20210715 [SECURITY] [DLA 2708-1] php7.0 security update
- [debian-lts-announce] 20210715 [SECURITY] [DLA 2708-1] php7.0 security update
- GLSA-202105-23
- GLSA-202105-23
- https://security.netapp.com/advisory/ntap-20210312-0005/
- https://security.netapp.com/advisory/ntap-20210312-0005/
- DSA-4856
- DSA-4856
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://www.tenable.com/security/tns-2021-14
- https://www.tenable.com/security/tns-2021-14