Date: Sat, 6 Feb 2021 00:05:23 +0000 (UTC) From: Rene Ladan <rene@FreeBSD.org> To: ports-committers@freebsd.org, svn-ports-all@freebsd.org, svn-ports-head@freebsd.org Subject: svn commit: r564167 - head/security/vuxml Message-ID: <202102060005.11605NS5053960@repo.freebsd.org>
next in thread | raw e-mail | index | archive | help
Author: rene Date: Sat Feb 6 00:05:23 2021 New Revision: 564167 URL: https://svnweb.freebsd.org/changeset/ports/564167 Log: Document new vulnerability in www/chromium < 88.0.4324.150 Obtained from: https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop_4.html Modified: head/security/vuxml/vuln.xml Modified: head/security/vuxml/vuln.xml ============================================================================== --- head/security/vuxml/vuln.xml Fri Feb 5 23:44:11 2021 (r564166) +++ head/security/vuxml/vuln.xml Sat Feb 6 00:05:23 2021 (r564167) @@ -77,6 +77,34 @@ Notes: * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> <vuxml xmlns="http://www.vuxml.org/apps/vuxml-1"> + <vuln vid="3e01aad2-680e-11eb-83e2-e09467587c17"> + <topic>chromium -- heap buffer overflow in V8</topic> + <affects> + <package> + <name>chromium</name> + <range><lt>88.0.4324.150</lt></range> + </package> + </affects> + <description> + <body xmlns="http://www.w3.org/1999/xhtml"> + <p>Chrome Releases reports:</p> + <blockquote cite="https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop_4.html"> + <p>[1170176] High CVE-2021-21148: Heap buffer overflow in V8. + Reported by Mattias Buelens on 2021-01-24. Google is aware of + reports that an exploit for CVE-2021-21148 exists in the wild.</p> + </blockquote> + </body> + </description> + <references> + <cvename>CVE-2021-21148</cvename> + <url>https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop_4.html</url> + </references> + <dates> + <discovery>2021-02-04</discovery> + <entry>2021-02-05</entry> + </dates> + </vuln> + <vuln vid="479fdfda-6659-11eb-83e2-e09467587c17"> <topic>www/chromium -- multiple vulnerabilities</topic> <affects>
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?202102060005.11605NS5053960>