From owner-svn-ports-branches@FreeBSD.ORG Wed Oct 8 12:09:34 2014 Return-Path: Delivered-To: svn-ports-branches@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [8.8.178.115]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id 7FBB5DAB; Wed, 8 Oct 2014 12:09:34 +0000 (UTC) Received: from svn.freebsd.org (svn.freebsd.org [IPv6:2001:1900:2254:2068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 6BCE665C; Wed, 8 Oct 2014 12:09:34 +0000 (UTC) Received: from svn.freebsd.org ([127.0.1.70]) by svn.freebsd.org (8.14.9/8.14.9) with ESMTP id s98C9Y2x049255; Wed, 8 Oct 2014 12:09:34 GMT (envelope-from rene@FreeBSD.org) Received: (from rene@localhost) by svn.freebsd.org (8.14.9/8.14.9/Submit) id s98C9YV7049254; Wed, 8 Oct 2014 12:09:34 GMT (envelope-from rene@FreeBSD.org) Message-Id: <201410081209.s98C9YV7049254@svn.freebsd.org> X-Authentication-Warning: svn.freebsd.org: rene set sender to rene@FreeBSD.org using -f From: Rene Ladan Date: Wed, 8 Oct 2014 12:09:34 +0000 (UTC) To: ports-committers@freebsd.org, svn-ports-all@freebsd.org, svn-ports-branches@freebsd.org Subject: svn commit: r370436 - branches/2014Q4/security/vuxml X-SVN-Group: ports-branches MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-ports-branches@freebsd.org X-Mailman-Version: 2.1.18-1 Precedence: list List-Id: SVN commit messages for all the branches of the ports tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 08 Oct 2014 12:09:34 -0000 Author: rene Date: Wed Oct 8 12:09:33 2014 New Revision: 370436 URL: https://svnweb.freebsd.org/changeset/ports/370436 QAT: https://qat.redports.org/buildarchive/r370436/ Log: MFH: r370422 Document new vulnerabilities in www/chromium < 38.0.2125.101 Obtained from: http://googlechromereleases.blogspot.nl/2014/10/stable-channel-update.html Approved by: portmgr (erwin) Modified: branches/2014Q4/security/vuxml/vuln.xml Directory Properties: branches/2014Q4/ (props changed) Modified: branches/2014Q4/security/vuxml/vuln.xml ============================================================================== --- branches/2014Q4/security/vuxml/vuln.xml Wed Oct 8 12:06:04 2014 (r370435) +++ branches/2014Q4/security/vuxml/vuln.xml Wed Oct 8 12:09:33 2014 (r370436) @@ -57,6 +57,77 @@ Notes: --> + + chromium -- multiple vulnerabilities + + + chromium + chromium-pulse + 38.0.2125.101 + + + + +

Google Chrome Releases reports:

+
+

159 security fixes in this release, including 113 found using + MemorySanitizer:

+
    +
  • [416449] Critical CVE-2014-3188: A special thanks to Jüri Aedla + for a combination of V8 and IPC bugs that can lead to remote code + execution outside of the sandbox.
  • +
  • [398384] High CVE-2014-3189: Out-of-bounds read in PDFium. + Credit to cloudfuzzer.
  • +
  • [400476] High CVE-2014-3190: Use-after-free in Events. Credit + to cloudfuzzer.
  • +
  • [402407] High CVE-2014-3191: Use-after-free in Rendering. + Credit to cloudfuzzer.
  • +
  • [403276] High CVE-2014-3192: Use-after-free in DOM. Credit to + cloudfuzzer.
  • +
  • [399655] High CVE-2014-3193: Type confusion in Session Management. + Credit to miaubiz.
  • +
  • [401115] High CVE-2014-3194: Use-after-free in Web Workers. + Credit to Collin Payne.
  • +
  • [403409] Medium CVE-2014-3195: Information Leak in V8. Credit + to Jüri Aedla.
  • +
  • [338538] Medium CVE-2014-3196: Permissions bypass in Windows + Sandbox. Credit to James Forshaw.
  • +
  • [396544] Medium CVE-2014-3197: Information Leak in XSS Auditor. + Credit to Takeshi Terada.
  • +
  • [415307] Medium CVE-2014-3198: Out-of-bounds read in PDFium. + Credit to Atte Kettunen of OUSPG.
  • +
  • [395411] Low CVE-2014-3199: Release Assert in V8 bindings. + Credit to Collin Payne.
  • +
  • [420899] CVE-2014-3200: Various fixes from internal audits, + fuzzing and other initiatives (Chrome 38).
  • +
  • Multiple vulnerabilities in V8 fixed at the tip of the 3.28 + branch (currently 3.28.71.15).
  • +
+
+ +
+ + CVE-2014-3188 + CVE-2014-3189 + CVE-2014-3190 + CVE-2014-3191 + CVE-2014-3192 + CVE-2014-3193 + CVE-2014-3194 + CVE-2014-3195 + CVE-2014-3196 + CVE-2014-3197 + CVE-2014-3198 + CVE-2014-3199 + CVE-2014-3200 + http://googlechromereleases.blogspot.nl/2014/10/stable-channel-update.html + + + 2014-10-07 + 2014-10-08 + +
+ Bugzilla multiple security issues