Date: Thu, 7 Jul 2022 16:17:18 GMT From: Rene Ladan <rene@FreeBSD.org> To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-main@FreeBSD.org Subject: git: 2205902b2303 - main - security/vuxml: add www/chromium < 103.0.5060.114 Message-ID: <202207071617.267GHI8u075039@gitrepo.freebsd.org>
next in thread | raw e-mail | index | archive | help
The branch main has been updated by rene: URL: https://cgit.FreeBSD.org/ports/commit/?id=2205902b230373b2090cfad78c4e3f3f23117b01 commit 2205902b230373b2090cfad78c4e3f3f23117b01 Author: Rene Ladan <rene@FreeBSD.org> AuthorDate: 2022-07-07 16:14:33 +0000 Commit: Rene Ladan <rene@FreeBSD.org> CommitDate: 2022-07-07 16:15:20 +0000 security/vuxml: add www/chromium < 103.0.5060.114 Obtained from: https://chromereleases.googleblog.com/2022/07/stable-channel-update-for-desktop.html --- security/vuxml/vuln-2022.xml | 33 +++++++++++++++++++++++++++++++++ 1 file changed, 33 insertions(+) diff --git a/security/vuxml/vuln-2022.xml b/security/vuxml/vuln-2022.xml index 9a4f093ac4fb..3a246ae7f48c 100644 --- a/security/vuxml/vuln-2022.xml +++ b/security/vuxml/vuln-2022.xml @@ -1,3 +1,36 @@ + <vuln vid="744ec9d7-fe0f-11ec-bcd2-3065ec8fd3ec"> + <topic>chromium -- multiple vulnerabilities</topic> + <affects> + <package> + <name>chromium</name> + <range><lt>103.0.5060.114</lt></range> + </package> + </affects> + <description> + <body xmlns="http://www.w3.org/1999/xhtml"> + <p>Chrome Releases reports:</p> + <blockquote cite="https://chromereleases.googleblog.com/2022/07/stable-channel-update-for-desktop.html"> + <p>This release contains 4 security fixes, including:</p> + <ul> + <li>[1341043] High CVE-2022-2294: Heap buffer overflow in WebRTC. Reported by Jan Vojtesek from the Avast Threat Intelligence team on 2022-07-01</li> + <li>[1336869] High CVE-2022-2295: Type Confusion in V8. Reported by avaue and Buff3tts at S.S.L. on 2022-06-16</li> + <li>[1327087] High CVE-2022-2296: Use after free in Chrome OS Shell. Reported by Khalil Zhani on 2022-05-19</li> + </ul> + </blockquote> + </body> + </description> + <references> + <cvename>CVE-2022-2294</cvename> + <cvename>CVE-2022-2295</cvename> + <cvename>CVE-2022-2296</cvename> + <url>https://chromereleases.googleblog.com/2022/07/stable-channel-update-for-desktop.html</url> + </references> + <dates> + <discovery>2022-07-04</discovery> + <entry>2022-07-07</entry> + </dates> + </vuln> + <vuln vid="a28e8b7e-fc70-11ec-856e-d4c9ef517024"> <topic>OpenSSL -- AES OCB fails to encrypt some bytes</topic> <affects>
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?202207071617.267GHI8u075039>