Date: Wed, 12 Dec 2012 11:33:17 +0000 (UTC) From: Rene Ladan <rene@FreeBSD.org> To: ports-committers@freebsd.org, svn-ports-all@freebsd.org, svn-ports-head@freebsd.org Subject: svn commit: r308757 - head/security/vuxml Message-ID: <201212121133.qBCBXHB5034575@svn.freebsd.org>
next in thread | raw e-mail | index | archive | help
Author: rene Date: Wed Dec 12 11:33:16 2012 New Revision: 308757 URL: http://svnweb.freebsd.org/changeset/ports/308757 Log: Document vulnerabilities in www/chromium < 23.0.1271.97 Obtained from: http://googlechromereleases.blogspot.nl/search/label/Stable%20updates Modified: head/security/vuxml/vuln.xml Modified: head/security/vuxml/vuln.xml ============================================================================== --- head/security/vuxml/vuln.xml Wed Dec 12 11:12:54 2012 (r308756) +++ head/security/vuxml/vuln.xml Wed Dec 12 11:33:16 2012 (r308757) @@ -51,6 +51,49 @@ Note: Please add new entries to the beg --> <vuxml xmlns="http://www.vuxml.org/apps/vuxml-1"> + <vuln vid="51f84e28-444e-11e2-8306-00262d5ed8ee"> + <topic>chromium -- multiple vulnerabilities</topic> + <affects> + <package> + <name>chromium</name> + <range><lt>23.0.1271.97</lt></range> + </package> + </affects> + <description> + <body xmlns="http://www.w3.org/1999/xhtml"> + <p>Google Chrome Releases reports:</p> + <blockquote cite="http://googlechromereleases.blogspot.nl/search/label/Stable%20updates"> + <p>[158204] High CVE-2012-5139: Use-after-free with visibility + events. Credit to Chamal de Silva.</p> + <p>[159429] High CVE-2012-5140: Use-after-free in URL loader. Credit + to Chamal de Silva.</p> + <p>[160456] Medium CVE-2012-5141: Limit Chromoting client plug-in + instantiation. Credit to Google Chrome Security Team (Jüri + Aedla).</p> + <p>[160803] Critical CVE-2012-5142: Crash in history navigation. + Credit to Michal Zalewski of Google Security Team.</p> + <p>[160926] Medium CVE-2012-5143: Integer overflow in PPAPI image + buffers. Credit to Google Chrome Security Team (Cris Neckar).</p> + <p>[161639] High CVE-2012-5144: Stack corruption in AAC decoding. + Credit to pawlkt.</p> + </blockquote> + </body> + </description> + <references> + <cvename>CVE-2012-5139</cvename> + <cvename>CVE-2012-5140</cvename> + <cvename>CVE-2012-5141</cvename> + <cvename>CVE-2012-5142</cvename> + <cvename>CVE-2012-5143</cvename> + <cvename>CVE-2012-5144</cvename> + <url>http://googlechromereleases.blogspot.nl/search/label/Stable%20updates</url> + </references> + <dates> + <discovery>2012-12-11</discovery> + <entry>2012-12-12</entry> + </dates> + </vuln> + <vuln vid="f599dfc4-3ec2-11e2-8ae1-001a8056d0b5"> <topic>tomcat -- multiple vulnerabilities</topic> <affects>
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?201212121133.qBCBXHB5034575>