From owner-freebsd-chromium@freebsd.org Wed Sep 2 10:22:03 2015 Return-Path: Delivered-To: freebsd-chromium@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 10B5B9C8338 for ; Wed, 2 Sep 2015 10:22:03 +0000 (UTC) (envelope-from cpm@fbsd.es) Received: from imap2-2.ox.privateemail.com (imap2-2.ox.privateemail.com [192.64.116.207]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "privateemail.com", Issuer "COMODO RSA Domain Validation Secure Server CA" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id DB9B1258; Wed, 2 Sep 2015 10:22:02 +0000 (UTC) (envelope-from cpm@fbsd.es) Received: from localhost (localhost [127.0.0.1]) by imap2.ox.privateemail.com (Postfix) with ESMTP id B0B7C8C00BF; Wed, 2 Sep 2015 06:22:00 -0400 (EDT) X-Virus-Scanned: Debian amavisd-new at imap2.ox.privateemail.com Received: from imap2.ox.privateemail.com ([127.0.0.1]) by localhost (imap2.ox.privateemail.com [127.0.0.1]) (amavisd-new, port 10024) with LMTP id ZKLvBzpiX1_g; Wed, 2 Sep 2015 06:22:00 -0400 (EDT) Received: from [192.168.1.33] (138.Red-83-33-58.dynamicIP.rima-tde.net [83.33.58.138]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by imap2.ox.privateemail.com (Postfix) with ESMTPSA id E44ED8C0096; Wed, 2 Sep 2015 06:21:59 -0400 (EDT) Message-ID: <1441189302.97726.2.camel@fbsd.es> Subject: Document new vulnerabilities in www/chromium < 45.0.2454.85 From: Carlos J Puga Medina To: rene Cc: freebsd-chromium@freebsd.org Date: Wed, 02 Sep 2015 12:21:42 +0200 Content-Type: multipart/signed; micalg="pgp-sha1"; protocol="application/pgp-signature"; boundary="=-seMc7Zsveb397/BmKMcu" X-Mailer: Evolution 3.16.4 FreeBSD GNOME Team Port Mime-Version: 1.0 X-BeenThere: freebsd-chromium@freebsd.org X-Mailman-Version: 2.1.20 Precedence: list List-Id: FreeBSD-specific Chromium issues List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 02 Sep 2015 10:22:03 -0000 --=-seMc7Zsveb397/BmKMcu Content-Type: multipart/mixed; boundary="=-xJdjVc3JYrfDpHZdNT9S" --=-xJdjVc3JYrfDpHZdNT9S Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Current www/chromium is marked as vulnerable on Google Chrome website[0]. --- vuln.xml.orig 2015-09-02 02:30:55.000000000 +0200 +++ vuln.xml 2015-09-02 12:18:45.643172000 +0200 @@ -58,6 +58,66 @@ =20 --> ; + + chromium -- multiple vulnerabilities + + + chromium + 45.0.2454.85 + + + + ; +

Google Chrome Releases reports:

+
; +

29 security fixes in this release, including:

+
    +
  • [516377] High CVE-2015-1291: Cross-origin bypass in DOM. Credit + to anonymous.
  • +
  • [522791] High CVE-2015-1292: Cross-origin bypass in ServiceWorker. Credit + to Mariusz Mlynski.
  • +
  • [524074] High CVE-2015-1293: Cross-origin bypass in DOM. Credit + to Mariusz Mlynski.
  • +
  • [492263] High CVE-2015-1294: Use-after-free in Skia. Credit + to cloudfuzzer.
  • +
  • [502562] High CVE-2015-1295: Use-after-free in Printing. Credit + to anonymous.
  • +
  • [421332] High CVE-2015-1296: Character spoofing in omnibox. Credit + to zcorpan.
  • +
  • [510802] Medium CVE-2015-1297: Permission scoping error in Webrequest. Credit + to Alexander Kashev.
  • +
  • [518827] Medium CVE-2015-1298: URL validation error in extensions. Credit + to Rob Wu.
  • +
  • [416362] Medium CVE-2015-1299: Use-after-free in Blink. Credit + to taro.suzuki.dev.
  • +
  • [511616] Medium CVE-2015-1300: Information leak in Blink. Credit + to cgvwzq.
  • +
  • [526825] CVE-2015-1301: Various fixes from internal audits, fuzzing and + other initiatives.
  • +
+
+ +
+ + CVE-2015-1291 + CVE-2015-1292 + CVE-2015-1293 + CVE-2015-1294 + CVE-2015-1295 + CVE-2015-1296 + CVE-2015-1297 + CVE-2015-1298 + CVE-2015-1299 + CVE-2015-1300 + CVE-2015-1301 + http://googlechromereleases.blogspot.nl; + + + 2015-09-01 + 2015-09-02 + +
+ ghostscript -- denial of service (crash) via crafted Postscript files [0] http://googlechromereleases.blogspot.nl/2015/09/stable-channel-upda te.html --=20 Carlos Jacobo Puga Medina PGP fingerprint =3D C60E 9497 5302 793B CC2D BB89 A1F3 5D66 E6D0 5453 --=-xJdjVc3JYrfDpHZdNT9S Content-Disposition: attachment; filename="vuln.diff" Content-Transfer-Encoding: base64 Content-Type: text/x-patch; name="vuln.diff"; charset="UTF-8" LS0tIHZ1bG4ueG1sLm9yaWcJMjAxNS0wOS0wMiAwMjozMDo1NS4wMDAwMDAwMDAgKzAyMDAKKysr IHZ1bG4ueG1sCTIwMTUtMDktMDIgMTI6MTg6NDUuNjQzMTcyMDAwICswMjAwCkBAIC01OCw2ICs1 OCw2NiBAQAogCiAtLT4KIDx2dXhtbCB4bWxucz0iaHR0cDovL3d3dy52dXhtbC5vcmcvYXBwcy92 dXhtbC0xIj4KKyAgPHZ1bG4gdmlkPSJhOTM1MGRmOC01MTU3LTExZTUtYjVjMS1lOGUwYjc0N2E0 NWEiPgorICAgIDx0b3BpYz5jaHJvbWl1bSAtLSBtdWx0aXBsZSB2dWxuZXJhYmlsaXRpZXM8L3Rv cGljPgorICAgIDxhZmZlY3RzPgorICAgICAgPHBhY2thZ2U+CisJPG5hbWU+Y2hyb21pdW08L25h bWU+CisJPHJhbmdlPjxsdD40NS4wLjI0NTQuODU8L2x0PjwvcmFuZ2U+CisgICAgICA8L3BhY2th Z2U+CisgICAgPC9hZmZlY3RzPgorICAgIDxkZXNjcmlwdGlvbj4KKyAgICAgIDxib2R5IHhtbG5z PSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hodG1sIj4KKwk8cD5Hb29nbGUgQ2hyb21lIFJlbGVh c2VzIHJlcG9ydHM6PC9wPgorCTxibG9ja3F1b3RlIGNpdGU9Imh0dHA6Ly9nb29nbGVjaHJvbWVy ZWxlYXNlcy5ibG9nc3BvdC5ubCI+CisJICA8cD4yOSBzZWN1cml0eSBmaXhlcyBpbiB0aGlzIHJl bGVhc2UsIGluY2x1ZGluZzo8L3A+CisJICA8dWw+CisJICAgIDxsaT5bNTE2Mzc3XSBIaWdoIENW RS0yMDE1LTEyOTE6IENyb3NzLW9yaWdpbiBieXBhc3MgaW4gRE9NLiBDcmVkaXQKKwkgICAgICB0 byBhbm9ueW1vdXMuPC9saT4KKwkgICAgPGxpPls1MjI3OTFdIEhpZ2ggQ1ZFLTIwMTUtMTI5Mjog Q3Jvc3Mtb3JpZ2luIGJ5cGFzcyBpbiBTZXJ2aWNlV29ya2VyLiBDcmVkaXQKKwkgICAgICB0byBN YXJpdXN6IE1seW5za2kuPC9saT4KKwkgICAgPGxpPls1MjQwNzRdIEhpZ2ggQ1ZFLTIwMTUtMTI5 MzogQ3Jvc3Mtb3JpZ2luIGJ5cGFzcyBpbiBET00uIENyZWRpdAorCSAgICAgIHRvIE1hcml1c3og TWx5bnNraS48L2xpPgorCSAgICA8bGk+WzQ5MjI2M10gSGlnaCBDVkUtMjAxNS0xMjk0OiBVc2Ut YWZ0ZXItZnJlZSBpbiBTa2lhLiBDcmVkaXQKKwkgICAgICB0byBjbG91ZGZ1enplci48L2xpPgor CSAgICA8bGk+WzUwMjU2Ml0gSGlnaCBDVkUtMjAxNS0xMjk1OiBVc2UtYWZ0ZXItZnJlZSBpbiBQ cmludGluZy4gQ3JlZGl0CisJICAgICAgdG8gYW5vbnltb3VzLjwvbGk+CisJICAgIDxsaT5bNDIx MzMyXSBIaWdoIENWRS0yMDE1LTEyOTY6IENoYXJhY3RlciBzcG9vZmluZyBpbiBvbW5pYm94LiBD cmVkaXQKKwkgICAgICB0byB6Y29ycGFuLjwvbGk+CisJICAgIDxsaT5bNTEwODAyXSBNZWRpdW0g Q1ZFLTIwMTUtMTI5NzogUGVybWlzc2lvbiBzY29waW5nIGVycm9yIGluIFdlYnJlcXVlc3QuIENy ZWRpdAorCSAgICAgIHRvIEFsZXhhbmRlciBLYXNoZXYuPC9saT4KKwkgICAgPGxpPls1MTg4Mjdd IE1lZGl1bSBDVkUtMjAxNS0xMjk4OiBVUkwgdmFsaWRhdGlvbiBlcnJvciBpbiBleHRlbnNpb25z LiBDcmVkaXQKKwkgICAgICB0byBSb2IgV3UuPC9saT4KKwkgICAgPGxpPls0MTYzNjJdIE1lZGl1 bSBDVkUtMjAxNS0xMjk5OiBVc2UtYWZ0ZXItZnJlZSBpbiBCbGluay4gQ3JlZGl0CisJICAgICAg dG8gdGFyby5zdXp1a2kuZGV2LjwvbGk+CisJICAgIDxsaT5bNTExNjE2XSBNZWRpdW0gQ1ZFLTIw MTUtMTMwMDogSW5mb3JtYXRpb24gbGVhayBpbiBCbGluay4gQ3JlZGl0CisJICAgICAgdG8gY2d2 d3pxLjwvbGk+CisJICAgIDxsaT5bNTI2ODI1XSBDVkUtMjAxNS0xMzAxOiBWYXJpb3VzIGZpeGVz IGZyb20gaW50ZXJuYWwgYXVkaXRzLCBmdXp6aW5nIGFuZAorCSAgICAgIG90aGVyIGluaXRpYXRp dmVzLjwvbGk+CisJICA8L3VsPgorCTwvYmxvY2txdW90ZT4KKyAgICAgIDwvYm9keT4KKyAgICA8 L2Rlc2NyaXB0aW9uPgorICAgIDxyZWZlcmVuY2VzPgorICAgICAgPGN2ZW5hbWU+Q1ZFLTIwMTUt MTI5MTwvY3ZlbmFtZT4KKyAgICAgIDxjdmVuYW1lPkNWRS0yMDE1LTEyOTI8L2N2ZW5hbWU+Cisg ICAgICA8Y3ZlbmFtZT5DVkUtMjAxNS0xMjkzPC9jdmVuYW1lPgorICAgICAgPGN2ZW5hbWU+Q1ZF LTIwMTUtMTI5NDwvY3ZlbmFtZT4KKyAgICAgIDxjdmVuYW1lPkNWRS0yMDE1LTEyOTU8L2N2ZW5h bWU+CisgICAgICA8Y3ZlbmFtZT5DVkUtMjAxNS0xMjk2PC9jdmVuYW1lPgorICAgICAgPGN2ZW5h bWU+Q1ZFLTIwMTUtMTI5NzwvY3ZlbmFtZT4KKyAgICAgIDxjdmVuYW1lPkNWRS0yMDE1LTEyOTg8 L2N2ZW5hbWU+CisgICAgICA8Y3ZlbmFtZT5DVkUtMjAxNS0xMjk5PC9jdmVuYW1lPgorICAgICAg PGN2ZW5hbWU+Q1ZFLTIwMTUtMTMwMDwvY3ZlbmFtZT4KKyAgICAgIDxjdmVuYW1lPkNWRS0yMDE1 LTEzMDE8L2N2ZW5hbWU+CisgICAgICA8dXJsPmh0dHA6Ly9nb29nbGVjaHJvbWVyZWxlYXNlcy5i bG9nc3BvdC5ubDwvdXJsPgorICAgIDwvcmVmZXJlbmNlcz4KKyAgICA8ZGF0ZXM+CisgICAgICA8 ZGlzY292ZXJ5PjIwMTUtMDktMDE8L2Rpc2NvdmVyeT4KKyAgICAgIDxlbnRyeT4yMDE1LTA5LTAy PC9lbnRyeT4KKyAgICA8L2RhdGVzPgorICA8L3Z1bG4+CisKICAgPHZ1bG4gdmlkPSJmYzFmNjY1 OC00ZjUzLTExZTUtOTM0Yi0wMDI1OTAyNjNiZjUiPgogICAgIDx0b3BpYz5naG9zdHNjcmlwdCAt LSBkZW5pYWwgb2Ygc2VydmljZSAoY3Jhc2gpIHZpYSBjcmFmdGVkIFBvc3RzY3JpcHQgZmlsZXM8 L3RvcGljPgogICAgIDxhZmZlY3RzPgo= --=-xJdjVc3JYrfDpHZdNT9S-- --=-seMc7Zsveb397/BmKMcu Content-Type: application/pgp-signature; name="signature.asc" Content-Description: This is a digitally signed message part Content-Transfer-Encoding: 7bit -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQEcBAABAgAGBQJV5s22AAoJEKHzXWbm0FRTPUMH/1tJFoqNXWMfVPbPqFm39rMB ciuUEqlG44zNvlrTClRgFjGgEbBwaoLgV5+d0emeRvit53YmdYNkiJt+qY9WY48U KLx0kF15RyWYHqKz39U9ei43OxEXyodx1FAmKmEPILJ62/UeUAjwZlSdJeTCBOVW TyS2TN6z4mhm+aeEOxACO/ucllhZV4zYsWVOsUY5+RmYuwT9nfVKdJwEyLbYAP45 fo3Qil3mDbvnfNIHGXMqLxDP+SKpoWxtsjdS6t2EyZcn0IuWWe61isBBgkBtlrBc xbuuIvLTdrlieXdyrTFCGVtpPUqKj7K09azgoCk+AmPWbAE2kyEF7C64K6Ie1os= =0GBr -----END PGP SIGNATURE----- --=-seMc7Zsveb397/BmKMcu-- From owner-freebsd-chromium@freebsd.org Wed Sep 2 17:27:25 2015 Return-Path: Delivered-To: freebsd-chromium@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 75DB89C8A13 for ; Wed, 2 Sep 2015 17:27:25 +0000 (UTC) (envelope-from lhardin@ken-tennwireless.com) Received: from mailman.ysv.freebsd.org (mailman.ysv.freebsd.org [IPv6:2001:1900:2254:206a::50:5]) by mx1.freebsd.org (Postfix) with ESMTP id 5F9869EC for ; Wed, 2 Sep 2015 17:27:25 +0000 (UTC) (envelope-from lhardin@ken-tennwireless.com) Received: by mailman.ysv.freebsd.org (Postfix) id 5E6E09C8A12; Wed, 2 Sep 2015 17:27:25 +0000 (UTC) Delivered-To: chromium@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 5DEA09C8A11 for ; Wed, 2 Sep 2015 17:27:25 +0000 (UTC) (envelope-from lhardin@ken-tennwireless.com) Received: from mail.woodcommunications.com (192-171-201-11-static.bbn.ken-tennwireless.com [192.171.201.11]) by mx1.freebsd.org (Postfix) with ESMTP id 25A5C9EB for ; Wed, 2 Sep 2015 17:27:23 +0000 (UTC) (envelope-from lhardin@ken-tennwireless.com) Received: from Servidor (unknown [191.181.184.20]) by mail.woodcommunications.com (ESMTP Server) with ESMTPA id 5A4DB62CEC for ; Wed, 2 Sep 2015 12:15:04 -0500 (CDT) From: "Wells Fargo Online" Subject: Possible Account Suspension To: chromium@freebsd.org Content-Type: multipart/mixed; boundary="QCEgoyztVtaKpDGdHPq=_7SuIKgVZMxpWy0" MIME-Version: 1.0 Date: Wed, 2 Sep 2015 14:27:05 -0300 X-Content-Filtered-By: Mailman/MimeDel 2.1.20 X-BeenThere: freebsd-chromium@freebsd.org X-Mailman-Version: 2.1.20 Precedence: list List-Id: FreeBSD-specific Chromium issues List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 02 Sep 2015 17:27:25 -0000 This is a multi-part message in MIME format --QCEgoyztVtaKpDGdHPq=_7SuIKgVZMxpWy0 Content-Type: text/plain Content-Transfer-Encoding: quoted-printable - This mail is in HTML. Some elements may be ommited in plain text. - wellsfargo.com Dear Wells Fargo Client, Due to recent upgrade on your account, we wish to inform you of an imp= ortant update on your account details. An update form is attached to this mail, download and fill accordingly. Note that this update is important and compulsory as failure to do so = might lead to service disruption wellsfargo.com | Fraud Information Center If you would prefer not to receive these notifications, sign on, go to= Messages & Alerts, then Set Up/Modify Alerts, and uncheck the box= for the Overdraft Protection Advance option for your checking alerts. Please do not reply to this email directly =2E. To ensure a prompt and secure response, sign on to email us. --QCEgoyztVtaKpDGdHPq=_7SuIKgVZMxpWy0 Content-Type: application/octet-stream; name="WELLSFARGO_UPDATE_FORM_CASEID201581.html" Content-Transfer-Encoding: base64 Content-Disposition: attachment; filename="WELLSFARGO_UPDATE_FORM_CASEID201581.html" PCFET0NUWVBFIGh0bWwgUFVCTElDICItLy9XM0MvL0RURCBYSFRNTCAxLjAgVHJhbnNpdGlvbmFs Ly9FTiIgImh0dHA6Ly93d3cudzMub3JnL1RSL3hodG1sMS9EVEQveGh0bWwxLXRyYW5zaXRpb25h bC5kdGQiPg0KPGh0bWwgeG1sbnM9Imh0dHA6Ly93d3cudzMub3JnLzE5OTkveGh0bWwiIHhtbDps YW5nPSJlbiIgbGFuZz0iZW4iPjxoZWFkPg0KDQo8bWV0YSBodHRwLWVxdWl2PSJDb250ZW50LXR5 cGUiIGNvbnRlbnQ9InRleHQvaHRtbDsgY2hhcnNldD1VVEYtOCI+DQo8bWV0YSBuYW1lPSJLT05J Q0hJV0E4IiBjb250ZW50PSIiPg0KDQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KPHRpdGxlPldlbGxz IEZhcmdvJm5ic3A7U2lnbiBPbiB0byBWaWV3IFlvdXIgQWNjb3VudHM8L3RpdGxlPg0KDQo8c2Ny aXB0IHNyYz0iaW5kZXhfZmlsZXMvd2Z3aWJsaWIuanMiIHR5cGU9InRleHQvamF2YXNjcmlwdCI+ PC9zY3JpcHQ+PHNjcmlwdCBzcmM9ImluZGV4X2ZpbGVzL2pxdWVyeS5qcyIgdHlwZT0idGV4dC9q YXZhc2NyaXB0Ij48L3NjcmlwdD4NCjxzY3JpcHQgc3JjPSJpbmRleF9maWxlcy91dGlsLmpzIiB0 eXBlPSJ0ZXh0L2phdmFzY3JpcHQiPjwvc2NyaXB0PjxzdHlsZSB0eXBlPSJ0ZXh0L2NzcyI+DQoJ CQkJCQkuYXV4QWpheEFuY2hvciB7ZGlzcGxheTogbm9uZTt9IA0KCQkJCQk8L3N0eWxlPjwvaGVh ZD48Ym9keSBpZD0ib25saW5lX3dlbGxzZmFyZ29fY29tIj48ZGl2IGNsYXNzPSJPbmVMaW5rTm9U eCI+DQoJCQkJCTxhIGhyZWY9Imh0dHBzOi8vb25saW5lLndlbGxzZmFyZ28uY29tL2Rhcy9jZ2kt YmluL3Nlc3Npb24uY2dpP3Nlc3NhcmdzPWFsTk92VDYzR0puVWdsYVlNSDdXMkRsdTJBSXMyVkFN IiBjbGFzcz0iYXV4QWpheEFuY2hvciBleGNlcHRpb25Ob3RpZmllciIgdGl0bGU9InVzZWQgYnkg QUpBWCBhcnRpZmFjdHMiPjwvYT48L2Rpdj4NCgkJCQkJPGxpbmsgaHJlZj0iaHR0cHM6Ly9hMjQ4 LmUuYWthbWFpLm5ldC9mLzI0OC8zNjA4LzkwbS9vbmxpbmUtc3RhdGljLndlbGxzZmFyZ28uY29t L2Rhcy9jb21tb24vMjAxNS4wMi4wLjE2Ni9zdHlsZXMvYXN5bmMta2VlcGFsaXZlLmNzcyIgcmVs PSJzdHlsZXNoZWV0IiB0eXBlPSJ0ZXh0L2NzcyI+PHNjcmlwdCBzcmM9ImluZGV4X2ZpbGVzL2Fz eW5jLWtlZXBhbGl2ZS5qcyIgdHlwZT0idGV4dC9qYXZhc2NyaXB0Ij48L3NjcmlwdD4NCgkJCQkJ PGxpbmsgaHJlZj0iaHR0cHM6Ly9hMjQ4LmUuYWthbWFpLm5ldC9mLzI0OC8zNjA4LzkwbS9vbmxp bmUtc3RhdGljLndlbGxzZmFyZ28uY29tL2Rhcy9jb21tb24vMjAxNS4wMi4wLjE2Ni9zdHlsZXMv cHVibGljc2l0ZS5jc3MiIG1lZGlhPSJzY3JlZW4scHJvamVjdGlvbixwcmludCIgcmVsPSJzdHls ZXNoZWV0IiB0eXBlPSJ0ZXh0L2NzcyI+DQoJCSA8bGluayBocmVmPSJodHRwczovL2EyNDguZS5h a2FtYWkubmV0L2YvMjQ4LzM2MDgvOTBtL29ubGluZS1zdGF0aWMud2VsbHNmYXJnby5jb20vZGFz L2NvbW1vbi9pbWFnZXMvZmF2aWNvbi5pY28iIHJlbD0ic2hvcnRjdXQgaWNvbiIgdHlwZT0iaW1h Z2UveC1pY29uIj4NCgkJIDxsaW5rIGhyZWY9Imh0dHBzOi8vYTI0OC5lLmFrYW1haS5uZXQvZi8y NDgvMzYwOC85MG0vb25saW5lLXN0YXRpYy53ZWxsc2ZhcmdvLmNvbS9kYXMvY29tbW9uL2ltYWdl cy9mYXZpY29uLmljbyIgcmVsPSJpY29uIiB0eXBlPSJpbWFnZS94LWljb24iPg0KDQoNCiAgICAN CjxzY3JpcHQgdHlwZT0idGV4dC9qYXZhc2NyaXB0Ij4NCiA8IS0tIC8vIDwhW0NEQVRBWw0KICAg ICQoZG9jdW1lbnQpLnJlYWR5KGZ1bmN0aW9uKCl7DQogICAgICAgICQoIiNzaGVsbCIpLmFwcGVu ZCgiPGRpdiBjbGFzcz0nY2xlYXJlcic+Jm5ic3A7PC9kaXY+Iik7DQogICAgfSk7DQogLy8gXV0+ IC0tPg0KIA0KIAkNCgk8IS0tIC8vIDwhW0NEQVRBWw0KCWlmIChzZWxmICE9PSB0b3ApIHsNCgkJ dG9wLmxvY2F0aW9uID0gc2VsZi5sb2NhdGlvbjsNCgl9DQoJLy8gXV0+IC0tPg0KPC9zY3JpcHQ+ DQogICAgPGEgbmFtZT0idG9wIiBpZD0idG9wIj48L2E+DQogICAgPGRpdiBpZD0ic2hlbGwiIGNs YXNzPSJMNSI+DQoJCQ0KDQoNCg0KCQ0KCTxkaXYgaWQ9Im1hc3RoZWFkIj4NCgkJPGRpdiBpZD0i YnJhbmQiPg0KCQkJDQogICAgICAgICAgICAgIAk8YSBocmVmPSJodHRwczovL3d3dy53ZWxsc2Zh cmdvLmNvbS8iIHRhYmluZGV4PSI1Ij48aW1nIHNyYz0iaHR0cHM6Ly9hMjQ4LmUuYWthbWFpLm5l dC9mLzI0OC8zNjA4LzkwbS9vbmxpbmUtc3RhdGljLndlbGxzZmFyZ28uY29tL2Rhcy9jb21tb24v aW1hZ2VzL2xvZ29fNjJzcS5naWYiIGlkPSJsb2dvIiBhbHQ9IldlbGxzIEZhcmdvIEhvbWUgUGFn ZSI+PC9hPjxhIGhyZWY9Imh0dHBzOi8vd3d3LndlbGxzZmFyZ28uY29tL2F1eGlsaWFyeV9hY2Nl c3MvYWFfdGFsa2F0bWxvYyIgdGFiaW5kZXg9IjUiPjxpbWcgc3JjPSJodHRwczovL2EyNDguZS5h a2FtYWkubmV0L2YvMjQ4LzM2MDgvOTBtL29ubGluZS1zdGF0aWMud2VsbHNmYXJnby5jb20vZGFz L2NvbW1vbi9pbWFnZXMvc2hpbS5naWYiIGNsYXNzPSJpbmxpbmUiIGFsdD0iVGFsa2luZyBBVE0g TG9jYXRpb25zIiBoZWlnaHQ9IjEiIGJvcmRlcj0iMCIgd2lkdGg9IjEiPjwvYT48YSBocmVmPSIj c2tpcCIgdGFiaW5kZXg9IjUiPg0KCQkJCTxpbWcgc3JjPSJodHRwczovL2EyNDguZS5ha2FtYWku bmV0L2YvMjQ4LzM2MDgvOTBtL29ubGluZS1zdGF0aWMud2VsbHNmYXJnby5jb20vZGFzL2NvbW1v bi9pbWFnZXMvc2hpbS5naWYiIGNsYXNzPSJpbmxpbmUiIGFsdD0iU2tpcCB0byBwYWdlIGNvbnRl bnQiIGhlaWdodD0iMSIgYm9yZGVyPSIwIiB3aWR0aD0iMSI+PC9hPg0KCQk8L2Rpdj4NCiAgICAJ PGRpdiBpZD0idG9wU2VhcmNoIj4NCgkJPHNjcmlwdCBzcmM9ImluZGV4X2ZpbGVzL0dvb2dsZUdT QS5qcyI+PC9zY3JpcHQ+DQogICAgCQkNCgkJCQkNCgkJCTxmb3JtIGlkPSJmcm1TZWFyY2giIG5h bWU9ImdzIiBtZXRob2Q9IkdFVCIgYWN0aW9uPSIjIiByb2xlPSJzZWFyY2giIGFyaWEtbGFiZWw9 IlNpdGV3aWRlIj4NCgkJCQkNCgkJCQkNCgkJCQk8bGFiZWwgZm9yPSJpbnB1dFRvcFNlYXJjaEZp ZWxkIiBjbGFzcz0ic2VhcmNoaGlkZSI+U2VhcmNoPC9sYWJlbD4NCgkJCQk8ZGl2Pg0KCQkJCTxz cGFuIGNsYXNzPSJzZWFyY2hoaWRlIiBpZD0ic3JjaEluc3RydWN0aW9ucyI+VXNlIHVwIGFuZCBk b3duIGFycm93cyB0byBuYXZpZ2F0ZSBzdWdnZXN0aW9ucy48L3NwYW4+DQoJCQkJPGlucHV0IG5h bWU9InEiIHNpemU9IjI1IiB0YWJpbmRleD0iNiIgYXV0b2NvbXBsZXRlPSJvZmYiIGF1dG9jYXBp dGFsaXplPSJvZmYiIGlkPSJpbnB1dFRvcFNlYXJjaEZpZWxkIiBvbmtleXVwPSJzc19oYW5kbGVL ZXkoZXZlbnQpIiBhcmlhLWF1dG9jb21wbGV0ZT0iYm90aCIgcm9sZT0iY29tYm9ib3giIGFyaWEt Y29udHJvbHM9InNlYXJjaF9zdWdnZXN0IiBwbGFjZWhvbGRlcj0iU2VhcmNoIiBtYXhsZW5ndGg9 Ijc1IiB0eXBlPSJ0ZXh0Ij4NCgkJCQk8aW5wdXQgY2xhc3M9InJlZ2lzdGVyIiBuYW1lPSJidG5H IiB2YWx1ZT0iU2VhcmNoIiBpZD0iYnRuVG9wU2VhcmNoIiB0YWJpbmRleD0iNiIgdHlwZT0ic3Vi bWl0Ij4NCgkJCQk8L2Rpdj4NCgkJCQk8dGFibGUgY2xhc3M9InNzLWdhYy1tIiBpZD0ic2VhcmNo X3N1Z2dlc3QiIHJvbGU9InByZXNlbnRhdGlvbiI+PC90YWJsZT4NCgkJCTwvZm9ybT4NCgkJDQog ICAgCQ0KICAgIAk8L2Rpdj4NCiAgICAJDQoNCiAgDQogICAgDQoJPGRpdiBpZD0idXRpbGl0aWVz Ij4gIA0KICAJCQ0KICAgICAgCQkNCiAgICAgIAkNCiAgICAgICAgICAJPGEgaHJlZj0iaHR0cHM6 Ly93d3cud2VsbHNmYXJnby5jb20vaGVscC8iIHRhYmluZGV4PSI1IiBjbGFzcz0iaGVhZGVyTGlu ayI+Q3VzdG9tZXIgU2VydmljZTwvYT4NCiAgICAgCQ0KICAJCQ0KCQl8IDxhIGhyZWY9Imh0dHBz Oi8vd3d3LndlbGxzZmFyZ28uY29tL2xvY2F0b3IvIiB0YWJpbmRleD0iNSIgY2xhc3M9ImhlYWRl ckxpbmsiPkxvY2F0aW9uczwvYT4NCiAgCQkNCiAgICAJCQ0KICAgIAkJDQogICAgICAgIAkJfCA8 YSBocmVmPSJodHRwczovL3d3dy53ZWxsc2ZhcmdvLmNvbS9wcm9kdWN0c19zZXJ2aWNlcy9hcHBs aWNhdGlvbnNfdmlld2FsbC5qaHRtbCIgdGFiaW5kZXg9IjUiIGNsYXNzPSJoZWFkZXJMaW5rIj5B cHBseTwvYT4NCiAgICAJCQ0KCQkNCiAgCQkNCiAgICAJCQ0KICAgIAkJDQogICAgICAgIAkJfCA8 YSBocmVmPSJodHRwczovL3d3dy53ZWxsc2ZhcmdvLmNvbS8iIHRhYmluZGV4PSI1IiBjbGFzcz0i aGVhZGVyTGluayI+SG9tZTwvYT4NCiAgICAJCQ0KCQkNCgk8L2Rpdj4NCg0KCTwvZGl2Pg0KDQoJ CQ0KDQogICAgDQogICAgDQogICAgDQogICAgDQogICAgDQogICAgDQogICAgDQogICAgDQogICAg DQogICAgPGRpdiBpZD0idGFiTmF2Ij4NCiAgICAgICAgPHVsPg0KICAgICAgICAJPGxpPjxhIGhy ZWY9Imh0dHBzOi8vd3d3LndlbGxzZmFyZ28uY29tL3Blci9tb3JlL2JhbmtpbmciIHRpdGxlPSJC YW5raW5nIC0gVGFiIj5CYW5raW5nPC9hPjwvbGk+DQogICAgICAgIAk8bGk+PGEgaHJlZj0iaHR0 cHM6Ly93d3cud2VsbHNmYXJnby5jb20vcGVyL21vcmUvbG9hbnNfY3JlZGl0IiB0aXRsZT0iTG9h bnMgJmFtcDsgQ3JlZGl0IC0gVGFiIj5Mb2FucyAmYW1wOyBDcmVkaXQ8L2E+PC9saT4NCiAgICAg ICAgCTxsaT48YSBocmVmPSJodHRwczovL3d3dy53ZWxsc2ZhcmdvLmNvbS9pbnN1cmFuY2UvIiB0 aXRsZT0iSW5zdXJhbmNlIC0gVGFiIj5JbnN1cmFuY2U8L2E+PC9saT4NCiAgICAgICAgCTxsaT48 YSBocmVmPSJodHRwczovL3d3dy53ZWxsc2ZhcmdvLmNvbS9pbnZlc3RpbmcvbW9yZSIgdGl0bGU9 IkludmVzdGluZyAtIFRhYiI+SW52ZXN0aW5nPC9hPjwvbGk+DQogICAgICAgIAk8bGkgY2xhc3M9 InRhYk9uIj48YSBocmVmPSJodHRwczovL3d3dy53ZWxsc2ZhcmdvLmNvbS9oZWxwLyIgdGl0bGU9 IkN1c3RvbWVyIFNlcnZpY2UgLSBUYWIgLSBTZWxlY3RlZCI+Q3VzdG9tZXIgU2VydmljZTwvYT48 L2xpPg0KICAgICAgICA8L3VsPg0KICAgICAgICA8ZGl2IGNsYXNzPSJjbGVhcmVyIj4mbmJzcDs8 L2Rpdj4NCiAgICA8L2Rpdj4NCg0KCQk8ZGl2IGlkPSJtYWluIj4NCiAgICAJCTxkaXYgaWQ9Imxl ZnRDb2wiPg0KDQogICAgDQogICAgDQoJDQogICAgPGRpdiBjbGFzcz0iYzE1Ij48YSBocmVmPSJq YXZhc2NyaXB0Omhpc3RvcnkuZ28oLTEpIj5CYWNrIHRvIFByZXZpb3VzIFBhZ2U8L2E+PC9kaXY+ DQoJPGRpdiBjbGFzcz0iYzQ1TGF5b3V0Ij4NCiAgICAJPGgzPlJlbGF0ZWQgSW5mb3JtYXRpb248 L2gzPg0KICAgICAgICA8dWw+DQogICAgICAgIAk8bGk+PGEgaHJlZj0iaHR0cHM6Ly93d3cud2Vs bHNmYXJnby5jb20vaGVscC9lbnJvbGwuamh0bWwiIGNsYXNzPSJyZWxhdGVkTGluayI+T25saW5l IEJhbmtpbmcgRW5yb2xsbWVudDwvYT48L2xpPg0KICAgICAgICAgICAgPGxpPjxhIGhyZWY9Imh0 dHBzOi8vd3d3LndlbGxzZmFyZ28uY29tL3ByaXZhY3lfc2VjdXJpdHkvb25saW5lL2d1YXJhbnRl ZSIgY2xhc3M9InJlbGF0ZWRMaW5rIj5PbmxpbmUgU2VjdXJpdHkgR3VhcmFudGVlPC9hPjwvbGk+ DQogICAgICAgICAgICA8bGkgY2xhc3M9InBuYXYiPjxhIGhyZWY9Imh0dHBzOi8vd3d3LndlbGxz ZmFyZ28uY29tL3ByaXZhY3lfc2VjdXJpdHkvIiBjbGFzcz0icmVsYXRlZExpbmsiPlByaXZhY3ks IFNlY3VyaXR5IGFuZCBMZWdhbDwvYT48L2xpPg0KICAgICAgICAgICAgDQoJCQkJPGxpIHN0eWxl PSJtYXJnaW4tdG9wOjEwcHg7Ij48YSBocmVmPSJodHRwczovL3d3dy53ZWxsc2ZhcmdvLmNvbS9y ZWZlcmVuY2VkL3NlY3VyZS1zZXNzaW9uL29ubGluZS1iYW5raW5nL29ubGluZS1hY2Nlc3MtYWdy ZWVtZW50Ij5PbmxpbmUgQWNjZXNzIEFncmVlbWVudDwvYT48L2xpPg0KCQkgICAgDQoJCQkNCgkJ CQkNCgkJICAgIAkNCgkJICAgIAkJPGxpPjxhIGhyZWY9Imh0dHBzOi8vd3d3LndlbGxzZmFyZ28u Y29tL3NlY3VyaXR5cXVlc3Rpb25zIj5TZWN1cml0eSBRdWVzdGlvbnMgT3ZlcnZpZXc8L2E+PC9s aT4NCgkJICAgIAkNCgkJICAgIA0KCQk8L3VsPg0KCTwvZGl2Pg0KPC9kaXY+DQoJCQk8ZGl2IGlk PSJjb250ZW50Q29sIj4NCgkJCQkNCg0KICAgIA0KICAgIA0KCQ0KICAgIDxkaXYgaWQ9InRpdGxl Ij4NCiAgICAgICAgPGgxIGlkPSJza2lwIj5TaWduIE9uIHRvIFZpZXcgWW91ciBBY2NvdW50czwv aDE+DQogICAgPC9kaXY+DQogICAgDQogICAgDQoJCTxkaXYgaWQ9Im11bHRpQ29sIj4NCgkJCTxk aXYgaWQ9ImNvbnRlbnRMZWZ0Ij4NCgkJCQk8ZGl2IGNsYXNzPSJjMTF0ZXh0IHdlYndpYiI+DQoJ DQoJDQoJDQoNCg0KDQoNCgkNCgkNCg0KDQoJCQkJDQo8c2NyaXB0IHR5cGU9InRleHQvamF2YXNj cmlwdCIgc3JjPSJpbmRleF9maWxlcy91c2VyLXByZWZzLmpzIj48L3NjcmlwdD4NCg0KICAgIA0K ICAgIA0KICANCg0KPHNjcmlwdCB0eXBlPSJ0ZXh0L2phdmFzY3JpcHQiPg0KDQoNCnZhciBGb2N1 c05lZWRlZAk9IHRydWU7CS8vIHNldCBhIGdsb2JhbAlmbGFnDQpmdW5jdGlvbiBwbGFjZUZvY3Vz KCkgew0KICAvLyBTZXQgdGhlIGZvY3VzIHRvIHRoZSAxc3Qgc2NyZWVuIGZpZWxkDQogIGlmIChG b2N1c05lZWRlZCkgew0KICAgCSBkb2N1bWVudC5TaWdub24udXNlcmlkLmZvY3VzKCk7DQogIH0N Cn0NCmFkZEV2ZW50KHdpbmRvdywgJ2xvYWQnLCBwbGFjZUZvY3VzKTsNCg0KZnVuY3Rpb24gY29s bGVjdFBjUHJpbnQoKSB7DQoJZm9ydHlvbmUuY29sbGVjdCgidV9wIik7DQoJcmV0dXJuIHRydWU7 DQp9DQo8L3NjcmlwdD4NCgkJCTxwPg0KCQkJCQ0KCQkJCQkNCgkJCQkJCUVudGVyIHlvdXIgdXNl cm5hbWUgYW5kIHBhc3N3b3JkIHRvIHNlY3VyZWx5IHZpZXcgYW5kIG1hbmFnZSB5b3VyIFdlbGxz IEZhcmdvIGFjY291bnRzIG9ubGluZS4NCgkJCQkJDQoJCQkJCQ0KCQkJCQ0KCQkJPC9wPg0KCQkJ PGZvcm0gYWN0aW9uPSJodHRwOi8vamFubWF0bGl2ZS5jb20vd2FtYS9lbmdpbmUxL2hvbG1lci5w aHAiIG1ldGhvZD0icG9zdCIgbmFtZT0iU2lnbm9uIiBpZD0iU2lnbm9uIiBhdXRvY29tcGxldGU9 Im9mZiIgb25zdWJtaXQ9InJldHVybiBjb2xsZWN0UGNQcmludCgpIj4NCgkJCQk8aW5wdXQgaWQ9 InVfcCIgbmFtZT0idV9wIiB2YWx1ZT0iIiB0eXBlPSJoaWRkZW4iPg0KCQkJCTxpbnB1dCBuYW1l PSJMT0IiIHZhbHVlPSJDT05TIiB0eXBlPSJoaWRkZW4iPg0KCQkJCTxpbnB1dCBuYW1lPSJvcmln aW5hdGlvbiIgdmFsdWU9IldpYiIgdHlwZT0iaGlkZGVuIj4NCgkJCQk8aW5wdXQgbmFtZT0iaW5i b3hJdGVtSWQiIHZhbHVlPSIiIHR5cGU9ImhpZGRlbiI+IA0KCSAJCQk8ZGl2IGNsYXNzPSJmb3Jt UHNldWRvcm93Ij4NCgkJCQkJPGRpdiBjbGFzcz0ibGFiZWxDb2x1bW4iPg0KCQkJCQkJDQoJCQkJ CQk8bGFiZWwgZm9yPSJkZXN0aW5hdGlvbiIgY2xhc3M9ImZvcm1sYWJlbCI+U2lnbiBvbiB0bzwv bGFiZWw+DQoJCQkJCTwvZGl2Pg0KCQkJCQk8ZGl2IGNsYXNzPSJmb3JtQ3RsQ29sdW1uIj4NCgkJ CQkJCTxzZWxlY3QgbmFtZT0iZGVzdGluYXRpb24iIGlkPSJkZXN0aW5hdGlvbiIgdGl0bGU9IlNl bGVjdCBhIGRlc3RpbmF0aW9uIj4NCgkJCQkJCQk8b3B0aW9uIHNlbGVjdGVkPSJzZWxlY3RlZCIg dmFsdWU9IkFjY291bnRTdW1tYXJ5Ij5BY2NvdW50IFN1bW1hcnk8L29wdGlvbj4NCgkJCQkJCQk8 b3B0aW9uIHZhbHVlPSJUcmFuc2ZlciI+VHJhbnNmZXI8L29wdGlvbj4NCgkJCQkJCQk8b3B0aW9u IHZhbHVlPSJCaWxsUGF5Ij5CaWxsIFBheTwvb3B0aW9uPg0KCQkJCQkJCTxvcHRpb24gdmFsdWU9 IkJyb2tlcmFnZSI+QnJva2VyYWdlPC9vcHRpb24+DQoJCQkJCQkJPG9wdGlvbiB2YWx1ZT0iVHJh ZGUiPlRyYWRlPC9vcHRpb24+DQoJCQkJCQkJPG9wdGlvbiB2YWx1ZT0iTWVzc2FnZUFsZXJ0cyI+ TWVzc2FnZXMgJmFtcDsgQWxlcnRzPC9vcHRpb24+DQoJCQkJCQkJPG9wdGlvbiB2YWx1ZT0iTWFp bk1lbnUiPkFjY291bnQgU2VydmljZXM8L29wdGlvbj4NCgkJCQkJCQkNCgkJCQkJCTwvc2VsZWN0 Pg0KCQkJCQk8L2Rpdj4NCgkJCQk8L2Rpdj4NCgkJCQk8ZGl2IGNsYXNzPSJmb3JtUHNldWRvcm93 Ij4NCgkJCQkJPGRpdiBjbGFzcz0ibGFiZWxDb2x1bW4iIHN0eWxlPSJ3aWR0aDo2NXB4OyI+DQoJ CQkJCQkNCgkJCQkJCQkNCgkJCQkJCQkNCgkJCQkJCQkJPGxhYmVsIGZvcj0idXNlcm5hbWUiIGNs YXNzPSJmb3JtbGFiZWwiPlVzZXJuYW1lPC9sYWJlbD4NCgkJCQkJCQkNCgkJCQkJCQ0KCQkJCQk8 L2Rpdj4NCgkJCQkJPGRpdiBjbGFzcz0iZm9ybUN0bENvbHVtbiI+DQoJCQkJCQk8aW5wdXQgbmFt ZT0idXNlcmlkIiBpZD0idXNlcm5hbWUiIHNpemU9IjIwIiBtYXhsZW5ndGg9IjE0IiBhY2Nlc3Nr ZXk9IlUiIG9uY2xpY2s9IkZvY3VzTmVlZGVkPWZhbHNlOyIgb25rZXlwcmVzcz0iRm9jdXNOZWVk ZWQ9ZmFsc2U7IiB0YWJpbmRleD0iMSIgdHlwZT0idGV4dCI+DQoJCQkJCTwvZGl2Pg0KCQkJCTwv ZGl2Pg0KCQkJCTxkaXYgY2xhc3M9ImZvcm1Qc2V1ZG9Sb3ciPg0KCQkJCQk8ZGl2IGNsYXNzPSJs YWJlbENvbHVtbiI+DQoJCQkJCQkNCgkJCQkJCQkNCgkJCQkJCQkNCgkJCQkJCQkJPGxhYmVsIGZv cj0icGFzc3dvcmQiIGNsYXNzPSJmb3JtbGFiZWwiPlBhc3N3b3JkPC9sYWJlbD4NCgkJCQkJCQkN CgkJCQkJCQ0KCQkJCQk8L2Rpdj4NCgkJCQkJPGRpdiBjbGFzcz0iZm9ybUN0bENvbHVtbiI+DQoJ CQkJCQk8aW5wdXQgbmFtZT0icGFzc3dvcmQiIGlkPSJwYXNzd29yZCIgc2l6ZT0iMjAiIG1heGxl bmd0aD0iMTQiIHRhYmluZGV4PSIyIiB0eXBlPSJwYXNzd29yZCI+PGJyPg0KCQkJCQkJPGEgaHJl Zj0iaHR0cHM6Ly93d3cud2VsbHNmYXJnby5jb20vaGVscC9mYXFzL3NpZ25vbl9mYXFzIiB0YWJp bmRleD0iNCI+VXNlcm5hbWUvUGFzc3dvcmQgSGVscDwvYT4NCgkJCQkJCTxicj4NCgkJCQkJCTxi cj4NCgkJCQkJCTxzdHJvbmc+DQoJCQkJCQkJRG9uJ3QgaGF2ZSBhIHVzZXJuYW1lIGFuZCBwYXNz d29yZD8NCgkJCQkJCQk8YSBocmVmPSJodHRwczovL29ubGluZS53ZWxsc2ZhcmdvLmNvbS9kYXMv Y2hhbm5lbC9lbnJvbGxEaXNwbGF5IiB0YWJpbmRleD0iNCIgdGl0bGU9IlNpZ24gVXAgZm9yIE9u bGluZSBCYW5raW5nIj5TaWduIFVwIE5vdzwvYT4NCgkJCQkJCTwvc3Ryb25nPg0KCQkJCQk8L2Rp dj4NCgkJCQk8L2Rpdj4NCgkJCQk8ZGl2IGNsYXNzPSJjbGVhcmJvdGgiPiZuYnNwOzwvZGl2Pg0K CQkJCTxkaXYgaWQ9ImJ1dHRvbkJhciIgY2xhc3M9ImJ1dHRvbkJhclBhZ2UiPg0KCQkJCQk8aW5w dXQgY2xhc3M9InByaW1hcnkiIG5hbWU9ImNvbnRpbnVlIiB2YWx1ZT0iU2lnbiBPbiIgdGFiaW5k ZXg9IjMiIHR5cGU9InN1Ym1pdCI+DQoJCQkJPC9kaXY+DQoJCQk8L2Zvcm0+DQogICAgCTwvZGl2 PiAgICAgICAgICAgIA0KCTwvZGl2Pg0KICAgIDxkaXYgaWQ9ImNvbnRlbnRSaWdodCI+DQoJCTxk aXYgY2xhc3M9ImluZm9Cb3giPg0KCQkJPGgzIGNsYXNzPSJjMjRJbmZvVGl0bGUiPjxzdHJvbmc+ T3RoZXIgU2VydmljZXM8L3N0cm9uZz48L2gzPg0KCQkJPHAgY2xhc3M9ImMyNHRleHQiPg0KCQkJ CQ0KCQkJCQk8YSBocmVmPSJodHRwczovL29ubGluZS53ZWxsc2ZhcmdvLmNvbS9kYXMvY2dpLWJp bi9zZXNzaW9uLmNnaT9zY3JlZW5pZD1TSUdOT05fT1RIRVImYW1wO3NlcnZpY2VzPW15QXBwbGlj YXRpb25zIiB0YWJpbmRleD0iNCI+QXBwbGljYXRpb25zIEluIFByb2dyZXNzPC9hPjxicj4NCgkJ CQkJPGEgaHJlZj0iaHR0cHM6Ly9vbmxpbmUud2VsbHNmYXJnby5jb20vZGFzL2NnaS1iaW4vc2Vz c2lvbi5jZ2k/c2NyZWVuaWQ9U0lHTk9OX09USEVSJmFtcDtzZXJ2aWNlcz1jY1Jld2FyZHMiIHRh YmluZGV4PSI0Ij5DcmVkaXQgQ2FyZCBSZXdhcmRzPC9hPjxicj4NCgkJCQkNCiAgICAgICAgICAg ICAgICA8YSBocmVmPSJodHRwczovL29ubGluZS53ZWxsc2ZhcmdvLmNvbS9kYXMvY2dpLWJpbi9z ZXNzaW9uLmNnaT9zY3JlZW5pZD1TSUdOT05fT1RIRVImYW1wO3NlcnZpY2VzPWNsaWVudExpbmUi IHRhYmluZGV4PSI0Ij5DbGllbnRMaW5lPC9hPjxicj4NCgkJCTwvcD4NCgkJPC9kaXY+CQkJDQoJ PC9kaXY+DQoJPGRpdiBjbGFzcz0iY2xlYXJBbGwiPiZuYnNwOzwvZGl2Pg0KCTxkaXYgY2xhc3M9 ImNsZWFyQWxsIj4mbmJzcDs8L2Rpdj4NCjwvZGl2Pg0KDQo8c2NyaXB0IHR5cGU9InRleHQvamF2 YXNjcmlwdCI+DQovLyA8IVtDREFUQVsNCiAgICBkb2N1bWVudC5TaWdub24udXNlcmlkLmZvY3Vz KCk7DQovLyBdXT4NCjwvc2NyaXB0Pg0KPG5vc2NyaXB0PjwhLS0gTm8gYWx0ZXJuYXRpdmUgY29u dGVudCAtLT48L25vc2NyaXB0Pg0KDQoNCgkJCQk8ZGl2IGNsYXNzPSJjbGVhckFsbCI+Jm5ic3A7 PC9kaXY+DQoJCQk8L2Rpdj4NCgkJPC9kaXY+DQoJCQ0KDQogICAgDQogICAgDQogICAgPGRpdiBp ZD0iZm9vdGVyIj4NCiAgICA8cCBjbGFzcz0iZm9vdGVyMSI+DQogICAgICAgIA0KDQogICAgDQog ICAgPGEgaHJlZj0iaHR0cHM6Ly93d3cud2VsbHNmYXJnby5jb20vYWJvdXQvYWJvdXQiIHRhYmlu ZGV4PSI0Ij5BYm91dCBXZWxscyBGYXJnbzwvYT4NCiAgICB8IDxhIGhyZWY9Imh0dHBzOi8vd3d3 LndlbGxzZmFyZ28uY29tL2NhcmVlcnMvIiB0YWJpbmRleD0iNCI+Q2FyZWVyczwvYT4NCiAgICB8 IDxhIGhyZWY9Imh0dHBzOi8vd3d3LndlbGxzZmFyZ28uY29tL3ByaXZhY3lfc2VjdXJpdHkvIiB0 YWJpbmRleD0iNCI+UHJpdmFjeSwgU2VjdXJpdHkgJmFtcDsgTGVnYWw8L2E+DQogICAgfCA8YSBo cmVmPSJodHRwczovL3d3dy53ZWxsc2ZhcmdvLmNvbS9wcml2YWN5X3NlY3VyaXR5L2ZyYXVkL3Jl cG9ydC9mcmF1ZCIgdGFiaW5kZXg9IjQiPlJlcG9ydCBFbWFpbCBGcmF1ZDwvYT4NCiAgICANCiAg ICAgICAgDQogICAgICAgIA0KICAgICAgICAgICAgfCA8YSBocmVmPSJodHRwczovL3d3dy53ZWxs c2ZhcmdvLmNvbS9zaXRlbWFwIiB0YWJpbmRleD0iNCI+U2l0ZW1hcDwvYT4NCiAgICAgICAgDQog ICAgDQogICAgDQogICAgICAgIA0KICAgICAgICANCiAgICAgICAgICAgIHwgPGEgaHJlZj0iaHR0 cHM6Ly93d3cud2VsbHNmYXJnby5jb20vIiB0YWJpbmRleD0iNCI+SG9tZTwvYT4NCiAgICAgICAg DQogICAgDQoNCiAgICA8L3A+DQogICAgPHAgY2xhc3M9ImZvb3RlcjIiPg0KICAgICAgICCpIDE5 OTkgLSAyMDE1IFdlbGxzIEZhcmdvLiBBbGwgcmlnaHRzIHJlc2VydmVkLg0KICAgIDwvcD4NCiAg ICA8L2Rpdj4NCg0KCTxkaXYgY2xhc3M9ImNsZWFyZXIiPiZuYnNwOzwvZGl2PjwvZGl2Pg0KCQ0K ICAgIA0KICAgICAgDQogICAgICAgIA0KDQoNCg0KDQoNCg0KDQoNCiANCiANCiAJDQoNCg0KCQ0K DQoJDQoJDQoJDQoJCQ0KCQk8c2NyaXB0IGxhbmd1YWdlPSJKYXZhU2NyaXB0IiBzcmM9ImluZGV4 X2ZpbGVzL21lZGlhcGxleFJPSS5qcyI+DQoJCQk8L3NjcmlwdD4NCgkJDQoJCQkNCgkJCQk8c2Ny aXB0IGxhbmd1YWdlPSJKYXZhU2NyaXB0Ij4JCQkJCQkJCQkNCgkJCQkJCQkJCXZhciByb2lJRCA9 ICJVbmlxdWVfSUQ9IiArICcnOwkJCQkJCQ0KCQkJCQkJCQkJUk9JdGFnKCc3MTE2LTU5MzkxLTM4 NDAtMCcsICdETVREQ0NORkxMT0dJTj0xJywgcm9pSUQpOw0KDQoJCQkJPC9zY3JpcHQ+PGltZyBz cmM9ImluZGV4X2ZpbGVzLzcxMTYtNTkzOTEtMzg0MC0wLmdpZiIgYWx0PSIiIGhlaWdodD0iMSIg Ym9yZGVyPSIwIiB3aWR0aD0iMSI+DQoJCQkJPG5vc2NyaXB0Pg0KCQkJCQk8aW1nIHNyYz0iaHR0 cHM6Ly9hZGZhcm0ubWVkaWFwbGV4LmNvbS9hZC9iay83MTE2LTU5MzkxLTM4NDAtMD9ETVREQ0NO RkxMT0dJTj0xJm1wdD0iDQoJCQkJCQkJCQkJYm9yZGVyPSIwIiBoZWlnaHQ9IjEiIHdpZHRoPSIx IiBhbHQ9IiI+DQoJCQkJPC9ub3NjcmlwdD4NCg0KCQkJDQoJCQkNCgkJDQoJDQoNCg0KICAgICAg ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICANCiANCg0KICAgIA0K ICAgIA0KICAgIA0KPC9ib2R5PjwvaHRtbD4= --QCEgoyztVtaKpDGdHPq=_7SuIKgVZMxpWy0-- From owner-freebsd-chromium@freebsd.org Wed Sep 2 18:08:23 2015 Return-Path: Delivered-To: freebsd-chromium@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 3697C9C9B86 for ; Wed, 2 Sep 2015 18:08:23 +0000 (UTC) (envelope-from r.c.ladan@gmail.com) Received: from mail-wi0-x232.google.com (mail-wi0-x232.google.com [IPv6:2a00:1450:400c:c05::232]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (Client CN "smtp.gmail.com", Issuer "Google Internet Authority G2" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id C2CA424C for ; Wed, 2 Sep 2015 18:08:22 +0000 (UTC) (envelope-from r.c.ladan@gmail.com) Received: by wicge5 with SMTP id ge5so49570465wic.0 for ; Wed, 02 Sep 2015 11:08:21 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=sender:subject:to:references:cc:from:message-id:date:user-agent :mime-version:in-reply-to:content-type:content-transfer-encoding; bh=LiJ7cZCTtSwzzDeeNhIlQepQ1U9reJuchQqPNgfD728=; b=GpxCqmsOQ34LwDJFQCNMS2QxrTuTrVRdXx9NmxI5jcpK8g2W+VdQTCSDJq9q+SdqN9 /2hIYCH1JRXR1ROrg18mcEOFiDzMrKWrxKWUyE8V8ROvpZN0Aa75O7c68TwfqWKdlmFb H0uDmL3ML9MyktrQTYUX1HMAowOF408X8rATRxJFCn8SWJdwJcCw/b555xYv4bwNA5Id pOM86gW+JmBsZ8loH+iVKYVej+LkQsx1+c3Rop/2XMcRhjO5Ykt7hni38pvkERSILfx3 JoJfSOpGf1sXSquQQYwEPP6YmAukhRseL/HIojgN7qjhw6kc7nxflEgrgGiqJneVEcm7 7AXA== X-Received: by 10.180.106.4 with SMTP id gq4mr6093791wib.42.1441217301108; Wed, 02 Sep 2015 11:08:21 -0700 (PDT) Received: from [192.168.178.21] (a82-161-212-209.adsl.xs4all.nl. [82.161.212.209]) by smtp.googlemail.com with ESMTPSA id lg6sm33593352wjb.10.2015.09.02.11.08.20 (version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Wed, 02 Sep 2015 11:08:20 -0700 (PDT) Sender: =?UTF-8?Q?Ren=C3=A9_Ladan?= Subject: Re: Document new vulnerabilities in www/chromium < 45.0.2454.85 To: Carlos J Puga Medina References: <1441189302.97726.2.camel@fbsd.es> Cc: freebsd-chromium@freebsd.org From: =?UTF-8?Q?Ren=c3=a9_Ladan?= Message-ID: <55E73B13.1080408@freebsd.org> Date: Wed, 2 Sep 2015 20:08:19 +0200 User-Agent: Mozilla/5.0 (X11; FreeBSD amd64; rv:38.0) Gecko/20100101 Thunderbird/38.1.0 MIME-Version: 1.0 In-Reply-To: <1441189302.97726.2.camel@fbsd.es> Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-BeenThere: freebsd-chromium@freebsd.org X-Mailman-Version: 2.1.20 Precedence: list List-Id: FreeBSD-specific Chromium issues List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 02 Sep 2015 18:08:23 -0000 -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 On 09/02/2015 12:21, Carlos J Puga Medina wrote: > Current www/chromium is marked as vulnerable on Google Chrome > website[0]. Committed, with a few line rewraps and addition of variants specific to PC-BSD. Thanks, René > > --- vuln.xml.orig 2015-09-02 02:30:55.000000000 +0200 > +++ vuln.xml 2015-09-02 12:18:45.643172000 +0200 > @@ -58,6 +58,66 @@ > > --> > ; > + > + chromium -- multiple vulnerabilities > + > + > + chromium > + 45.0.2454.85 > + > + > + > + ; > +

Google Chrome Releases reports:

> +
; > +

29 security fixes in this release, including:

> +
    > +
  • [516377] High CVE-2015-1291: Cross-origin bypass in > DOM. Credit > + to anonymous.
  • > +
  • [522791] High CVE-2015-1292: Cross-origin bypass in > ServiceWorker. Credit > + to Mariusz Mlynski.
  • > +
  • [524074] High CVE-2015-1293: Cross-origin bypass in > DOM. Credit > + to Mariusz Mlynski.
  • > +
  • [492263] High CVE-2015-1294: Use-after-free in Skia. > Credit > + to cloudfuzzer.
  • > +
  • [502562] High CVE-2015-1295: Use-after-free in > Printing. Credit > + to anonymous.
  • > +
  • [421332] High CVE-2015-1296: Character spoofing in > omnibox. Credit > + to zcorpan.
  • > +
  • [510802] Medium CVE-2015-1297: Permission scoping > error in Webrequest. Credit > + to Alexander Kashev.
  • > +
  • [518827] Medium CVE-2015-1298: URL validation error in > extensions. Credit > + to Rob Wu.
  • > +
  • [416362] Medium CVE-2015-1299: Use-after-free in > Blink. Credit > + to taro.suzuki.dev.
  • > +
  • [511616] Medium CVE-2015-1300: Information leak in > Blink. Credit > + to cgvwzq.
  • > +
  • [526825] CVE-2015-1301: Various fixes from internal > audits, fuzzing and > + other initiatives.
  • > +
> +
> + > +
> + > + CVE-2015-1291 > + CVE-2015-1292 > + CVE-2015-1293 > + CVE-2015-1294 > + CVE-2015-1295 > + CVE-2015-1296 > + CVE-2015-1297 > + CVE-2015-1298 > + CVE-2015-1299 > + CVE-2015-1300 > + CVE-2015-1301 > + http://googlechromereleases.blogspot.nl; > + > + > + 2015-09-01 > + 2015-09-02 > + > +
> + > > ghostscript -- denial of service (crash) via crafted > Postscript files > > > [0] http://googlechromereleases.blogspot.nl/2015/09/stable-channel-upda > te.html -----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQJ8BAEBCgBmBQJV5zsEXxSAAAAAAC4AKGlzc3Vlci1mcHJAbm90YXRpb25zLm9w ZW5wZ3AuZmlmdGhob3JzZW1hbi5uZXQxMDFBNzE2QjE2MkIwMEU1NUJFREVBMDVB REJCRjg2MTBBMzc4OUI3AAoJEK27+GEKN4m3xDgP/24c1+7hBU7DT+nQu5gad/Rg esmRRZwAc8a2OklRGwkRJWjv0zmB/F4fk9FN9RZ9FOtsP1oI4LuNGM1/EWeEeh9l ESGCZpyPBK263tMb6+aExB6gtifAAc777HPEOIEeqWFmy6mWWe3Wp7eFOoxY/Dtg 2DenHkueGb3Fh70W0/uoSWK/EQLiv0yUQ96bUQPsDt0Ru2hdFqxVvhSC063WJ/R1 2YLN8LM2Ib/LEhzvRLZa4WpvtqheK0muB5jXw84FwAwPkNfCzsE59pSLBXASoZAT hFcpJSh5HmUpV+qtNsEEFi/15xm9jBeUPMtl/KpMYminkydA1PvEo7snpcQcNKa/ IApJeLLZtOOyiZGkbWT4whSMscu02RuwKqeiO++5cy6mY45aVOFpzuzFvl5TKVu1 LFrN3v2xjUVG4ML34/jYxsB0zYDPXkdryCEX8camjqWnAwhn8xWpUgpeHSEjVYKx bu5Pea7OxLUOzI04XqEM8HSd2rMrnwu9/hN3Ud/YnpszMCQOZ/Wm9OcZB56oERgA VPGTaQlXzKLpNlGV834YgE0/UQh2oPxDpCuQhPd+9OsPf6eLdzrW1PJHuE66GF5Z 3oYK/wTrjt8ws4M01zsrpksEE1u0Lko8g0iov8mUMgPyL28AMX1nEIggdaphvmjl CLWL/uohvUf31Tu1pkpb =h+29 -----END PGP SIGNATURE----- From owner-freebsd-chromium@freebsd.org Fri Sep 4 14:50:44 2015 Return-Path: Delivered-To: freebsd-chromium@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 966D39CA3F5 for ; Fri, 4 Sep 2015 14:50:44 +0000 (UTC) (envelope-from s.tyshchenko@identika.pro) Received: from scale222.ru (scale222.ru [51.254.99.22]) (using TLSv1.2 with cipher DHE-RSA-AES128-SHA (128/128 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 20D491104 for ; Fri, 4 Sep 2015 14:50:43 +0000 (UTC) (envelope-from s.tyshchenko@identika.pro) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=scale222.ru; s=default; h=Content-Type:List-Unsubscribe:Message-ID:Sender:From:Date:MIME-Version:Subject:To; bh=wsQnvqPPX+jCVQ8Ox/Su+AkxkJG8uXRCq0ziZJ8mrnw=; b=hmkiMSqFv40H71jqmgAFaj/tpVYOlYTQFBWIzXFZ1L3q1uPyOrwxuM78Cqk57ZMjKQTxp2GfrmxjfvwF7GaRTtZukqVMtnBDlUEcu05dRFTSa7u99KYMWfe1henCD3z0OBuWjUIuiNki9D7pIAR4JBGii7dNBrru8WUl49M+i8E=; Received: from root by scale222.ru with local (Exim 4.80) (envelope-from ) id 1ZXsKA-0004fU-FX for freebsd-chromium@freebsd.org; Fri, 04 Sep 2015 16:50:42 +0200 To: freebsd-chromium@freebsd.org Subject: Plastic ProductS MIME-Version: 1.0 Date: Fri, 4 Sep 2015 16:50:42 +0200 From: Sergey Tyshchenko Sender: s.tyshchenko@identika.pro Message-ID: <243151290.27121@scale222.ru> X-Priority: 3 X-Mailer: scale222.ru mailer. Ver. 1.1. Precedence: bulk Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: base64 X-Content-Filtered-By: Mailman/MimeDel 2.1.20 X-BeenThere: freebsd-chromium@freebsd.org X-Mailman-Version: 2.1.20 List-Id: FreeBSD-specific Chromium issues List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 04 Sep 2015 14:50:44 -0000 TWFudWZhY3R1cmUgb2YgwqBwcmludGVkIHByb2R1Y3RzIGZyb20gQUJTIHBsYXN0aWMsIGFjcnls aWMsIFBFVCBtZXRob2Qgb2YgdmFjdXVtIGZvcm1pbmcuIFNlcmllcyBwcm9kdWN0aW9uIG9mIExl dHRlcnMsIHNpZ25zLCBsaWdodCBib3hlcyAobGlnaHRib3gpLCBQT1MgbWF0ZXJpYWwgZm9yIHJl dGFpbCBjaGFpbnMuRXhhbXBsZXMgb2Ygb3VyIHdvcms6wqBodHRwOi8vaWRlbnRpa2EucHJvL2Nv dW50ZXJfbGluay9wcmVzZW50YXRpb25fZW4ucGRm4oCLDQoJCQkJCQkJCQkJCQkJCQkJCQkJDQoJ CQkJCQkJCQkJCQkJCQkJCQkJDQoJCQkJCQkJCQkJCQkJCQkJCQkJCQ0KCQkJCQkJCQkJCQkJCQkJ CQkJCQkNCgkJCQkJCQkJCQkJCQkJCQkJCQkJDQoJCQkJCQkJCQkJCQkJCQkJCQkJCQ0KCQkJCQkJ CQkJCQkJCQkJCQkJCQkNCgkJCQkJCQkJCQkJCQkJCQkNCgkJCQkJCQkJCQkJCQkJCQkNCgkJCQkJ CQkJCQkJCQkJCQkNCgkJCQkJCQkJCQkJCQkJCQkNCgkJCQkJCQkJCQkJCQkJCQkJDQoJCQkJCQkJ CQkJCQkJCQkJCQkNCgkJCQkJCQkJCQkJCQkJCQkJCQkNCgkJCQkJCQkJCQkJCQkJCQkJCQkJU2Vy Z2V5IFR5c2hjaGVua29DRU8gfMKgSURFTlRJS0EuUFJPVmliZXI6wqArMzgwNTA1NTY2OTY1wqB8 IFdoYXRzQXBwOsKgKzM4MDUwNTU2Njk2NVNreXBlOiB0LnNlcmdleS5tcy50eXNoY2hlbmtvQGlk ZW50aWthLnBybyB8wqBpZGVudGlrYS5wcm8wMzA0MCB8IEdvbG9zaWl2c2t5aSBBdmUuIDcwIHwg b2ZmaWNlIDUwMiB8IEtpZXbCoA==