Date: Tue, 15 Mar 2022 22:46:45 GMT From: Rene Ladan <rene@FreeBSD.org> To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-main@FreeBSD.org Subject: git: 6568a56607da - main - security/vuxml: add www/chromium < 99.0.4844.74 Message-ID: <202203152246.22FMkjQr039684@gitrepo.freebsd.org>
next in thread | raw e-mail | index | archive | help
The branch main has been updated by rene: URL: https://cgit.FreeBSD.org/ports/commit/?id=6568a56607da9d87991cad708eb9af3c23b6d163 commit 6568a56607da9d87991cad708eb9af3c23b6d163 Author: Rene Ladan <rene@FreeBSD.org> AuthorDate: 2022-03-15 22:45:57 +0000 Commit: Rene Ladan <rene@FreeBSD.org> CommitDate: 2022-03-15 22:45:57 +0000 security/vuxml: add www/chromium < 99.0.4844.74 Obtained from: https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop_15.html --- security/vuxml/vuln-2022.xml | 60 ++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 60 insertions(+) diff --git a/security/vuxml/vuln-2022.xml b/security/vuxml/vuln-2022.xml index d02c61a9e641..efedcc39aa5a 100644 --- a/security/vuxml/vuln-2022.xml +++ b/security/vuxml/vuln-2022.xml @@ -1,3 +1,63 @@ + <vuln vid="857be71a-a4b0-11ec-95fc-3065ec8fd3ec"> + <topic>chromium -- multiple vulnerabilities</topic> + <affects> + <package> + <name>chromium</name> + <range><lt>98.0.4844.74</lt></range> + </package> + </affects> + <description> + <body xmlns="http://www.w3.org/1999/xhtml"> + <p>Chrome Releases reports:</p> + <blockquote cite="https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop_15.html"> + <p>This release contains 11 security fixes, including:</p> + <ul> + <li>[1299422] Critical CVE-2022-0971: Use after free in Blink + Layout. Reported by Sergei Glazunov of Google Project Zero on + 2022-02-21</li> + <li>[1301320] High CVE-2022-0972: Use after free in Extensions. + Reported by Sergei Glazunov of Google Project Zero on + 2022-02-28</li> + <li>[1297498] High CVE-2022-0973: Use after free in Safe Browsing. + Reported by avaue and Buff3tts at S.S.L. on 2022-02-15</li> + <li>[1291986] High CVE-2022-0974: Use after free in Splitscreen. + Reported by @ginggilBesel on 2022-01-28</li> + <li>[1295411] High CVE-2022-0975: Use after free in ANGLE. Reported + by SeongHwan Park (SeHwa) on 2022-02-09</li> + <li>[1296866] High CVE-2022-0976: Heap buffer overflow in GPU. + Reported by Omair on 2022-02-13</li> + <li>[1299225] High CVE-2022-0977: Use after free in Browser UI. + Reported by Khalil Zhani on 2022-02-20</li> + <li>[1299264] High CVE-2022-0978: Use after free in ANGLE. Reported + by Cassidy Kim of Amber Security Lab, OPPO Mobile + Telecommunications Corp. Ltd. on 2022-02-20</li> + <li>[1302644] High CVE-2022-0979: Use after free in Safe Browsing. + Reported by anonymous on 2022-03-03</li> + <li>[1302157] Medium CVE-2022-0980: Use after free in New Tab Page. + Reported by Krace on 2022-03-02</li> + </ul> + </blockquote> + </body> + </description> + <references> + <cvename>CVE-2022-0971</cvename> + <cvename>CVE-2022-0972</cvename> + <cvename>CVE-2022-0973</cvename> + <cvename>CVE-2022-0974</cvename> + <cvename>CVE-2022-0975</cvename> + <cvename>CVE-2022-0976</cvename> + <cvename>CVE-2022-0977</cvename> + <cvename>CVE-2022-0978</cvename> + <cvename>CVE-2022-0979</cvename> + <cvename>CVE-2022-0980</cvename> + <url>https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop_15.html</url> + </references> + <dates> + <discovery>2022-03-15</discovery> + <entry>2022-03-15</entry> + </dates> + </vuln> + <vuln vid="6601c08d-a46c-11ec-8be6-d4c9ef517024"> <topic>Apache httpd -- Multiple vulnerabilities</topic> <affects>
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?202203152246.22FMkjQr039684>