Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 12 Apr 2020 10:06:00 +0000 (UTC)
From:      Rene Ladan <rene@FreeBSD.org>
To:        ports-committers@freebsd.org, svn-ports-all@freebsd.org, svn-ports-head@freebsd.org
Subject:   svn commit: r531501 - head/security/vuxml
Message-ID:  <202004121006.03CA6030053792@repo.freebsd.org>

next in thread | raw e-mail | index | archive | help
Author: rene
Date: Sun Apr 12 10:06:00 2020
New Revision: 531501
URL: https://svnweb.freebsd.org/changeset/ports/531501

Log:
  Document new vulnerabilities in www/chromium < 81.0.4044.92

Modified:
  head/security/vuxml/vuln.xml

Modified: head/security/vuxml/vuln.xml
==============================================================================
--- head/security/vuxml/vuln.xml	Sun Apr 12 10:05:03 2020	(r531500)
+++ head/security/vuxml/vuln.xml	Sun Apr 12 10:06:00 2020	(r531501)
@@ -58,6 +58,112 @@ Notes:
   * Do not forget port variants (linux-f10-libxml2, libxml2, etc.)
 -->
 <vuxml xmlns="http://www.vuxml.org/apps/vuxml-1">;
+  <vuln vid="6e3b700a-7ca3-11ea-b594-3065ec8fd3ec">
+    <topic>chromium -- multiple vulnerabilities</topic>
+    <affects>
+      <package>
+	<name>chromium</name>
+	<range><lt>81.0.4044.92</lt></range>
+      </package>
+    </affects>
+    <description>
+      <body xmlns="http://www.w3.org/1999/xhtml">;
+	<p>Google Chrome Releases reports:</p>
+	<blockquote cite="https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_7.html">;
+	  <p>This updates includes 32 security fixes, including:</p>
+	  <ul>
+	    <li>[1019161] High CVE-2020-6454: Use after free in extensions.
+	    Reported by Leecraso and Guang Gong of Alpha Lab, Qihoo 360 on
+	    2019-10-29</li>
+	    <li>[1043446] High CVE-2020-6423: Use after free in audio.
+	    Reported by Anonymous on 2020-01-18</li>
+	    <li>[1059669] High CVE-2020-6455: Out of bounds read in WebSQL.
+	    Reported by Nan Wang(@eternalsakura13) and Guang Gong of Alpha Lab,
+	    Qihoo 360 on 2020-03-09</li>
+	    <li>[1031479] Medium CVE-2020-6430: Type Confusion in V8.
+	    Reported by Avihay Cohen @ SeraphicAlgorithms on 2019-12-06</li>
+	    <li>[1040755] Medium CVE-2020-6456: Insufficient validation of
+	    untrusted input in clipboard. Reported by MichaƂ Bentkowski of
+	    Securitum on 2020-01-10</li>
+	    <li>[852645] Medium CVE-2020-6431: Insufficient policy
+	    enforcement in full screen. Reported by Luan Herrera (@lbherrera_)
+	    on 2018-06-14</li>
+	    <li>[965611] Medium CVE-2020-6432: Insufficient policy
+	    enforcement in navigations. Reported by David Erceg on
+	    2019-05-21</li>
+	    <li>[1043965] Medium CVE-2020-6433: Insufficient policy
+	    enforcement in extensions. Reported by David Erceg on
+	    2020-01-21</li>
+	    <li>[1048555] Medium CVE-2020-6434: Use after free in devtools.
+	    Reported by HyungSeok Han (DaramG) of Theori on 2020-02-04</li>
+	    <li>[1032158] Medium CVE-2020-6435: Insufficient policy
+	    enforcement in extensions. Reported by Sergei Glazunov of Google
+	    Project Zero on 2019-12-09</li>
+	    <li>[1034519] Medium CVE-2020-6436: Use after free in window
+	    management. Reported by Igor Bukanov from Vivaldi on 2019-12-16</li>
+	    <li>[639173] Low CVE-2020-6437: Inappropriate implementation in
+	    WebView. Reported by Jann Horn on 2016-08-19</li>
+	    <li>[714617] Low CVE-2020-6438: Insufficient policy enforcement in
+	    extensions. Reported by Ng Yik Phang on 2017-04-24</li>
+	    <li>[868145] Low CVE-2020-6439: Insufficient policy enforcement in
+	    navigations. Reported by remkoboonstra on 2018-07-26</li>
+	    <li>[894477] Low CVE-2020-6440: Inappropriate implementation in
+	    extensions. Reported by David Erceg on 2018-10-11</li>
+	    <li>[959571] Low CVE-2020-6441: Insufficient policy enforcement in
+	    omnibox. Reported by David Erceg on 2019-05-04</li>
+	    <li>[1013906] Low CVE-2020-6442: Inappropriate implementation in
+	    cache. Reported by B@rMey on 2019-10-12</li>
+	    <li>[1040080] Low CVE-2020-6443: Insufficient data validation in
+	    developer tools. Reported by @lovasoa (Ophir LOJKINE) on
+	    2020-01-08</li>
+	    <li>[922882] Low CVE-2020-6444: Uninitialized Use in WebRTC.
+	    Reported by mlfbrown on 2019-01-17</li>
+	    <li>[933171] Low CVE-2020-6445: Insufficient policy enforcement in
+	    trusted types. Reported by Jun Kokatsu, Microsoft Browser
+	    Vulnerability Research on 2019-02-18</li>
+	    <li>[933172] Low CVE-2020-6446: Insufficient policy enforcement in
+	    trusted types. Reported by Jun Kokatsu, Microsoft Browser
+	    Vulnerability Research on 2019-02-18</li>
+	    <li>[991217] Low CVE-2020-6447: Inappropriate implementation in
+	    developer tools. Reported by David Erceg on 2019-08-06</li>
+	    <li>[1037872] Low CVE-2020-6448: Use after free in V8. Reported by
+	    Guang Gong of Alpha Lab, Qihoo 360 on 2019-12-26</li>
+	  </ul>
+	</blockquote>
+      </body>
+    </description>
+    <references>
+      <cvename>CVE-2020-6423</cvename>
+      <cvename>CVE-2020-6430</cvename>
+      <cvename>CVE-2020-6431</cvename>
+      <cvename>CVE-2020-6432</cvename>
+      <cvename>CVE-2020-6433</cvename>
+      <cvename>CVE-2020-6434</cvename>
+      <cvename>CVE-2020-6435</cvename>
+      <cvename>CVE-2020-6436</cvename>
+      <cvename>CVE-2020-6437</cvename>
+      <cvename>CVE-2020-6438</cvename>
+      <cvename>CVE-2020-6439</cvename>
+      <cvename>CVE-2020-6440</cvename>
+      <cvename>CVE-2020-6441</cvename>
+      <cvename>CVE-2020-6442</cvename>
+      <cvename>CVE-2020-6443</cvename>
+      <cvename>CVE-2020-6444</cvename>
+      <cvename>CVE-2020-6445</cvename>
+      <cvename>CVE-2020-6446</cvename>
+      <cvename>CVE-2020-6447</cvename>
+      <cvename>CVE-2020-6448</cvename>
+      <cvename>CVE-2020-6454</cvename>
+      <cvename>CVE-2020-6455</cvename>
+      <cvename>CVE-2020-6456</cvename>
+      <url>https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_7.html</url>;
+    </references>
+    <dates>
+      <discovery>2020-04-07</discovery>
+      <entry>2020-04-12</entry>
+    </dates>
+  </vuln>
+
   <vuln vid="9cb57a06-7517-11ea-b594-3065ec8fd3ec">
     <topic>chromium -- multiple vulnerabilities</topic>
     <affects>



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?202004121006.03CA6030053792>