From nobody Sat Oct 26 13:13:19 2024 X-Original-To: dev-commits-ports-main@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4XbKpS1MwXz5Zk4T; Sat, 26 Oct 2024 13:13:20 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R10" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4XbKpS0h5Sz4JjN; Sat, 26 Oct 2024 13:13:20 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1729948400; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=F9vgEwzzZcrJwjHaZhv8K9W1SFVVMwA9sGZjr7OEWTY=; b=iGzjHnPL74bVZ7MpW5pNoehxXjuYfqQMJB8E8hBMHs/rTaFM6xdG1/OngsF8POGAzkT8tT ZHn+A4897gs4eofLAXMW+lCB8qadaegCJk3ayeBvWH4k+7iPsnUsmiHYFlEtvfMGXYDUYp e6X7W33RUMGWmaItz+uqGFZlrPh0dneBJyidPmLzH5Ixzmsv3imGR5pbJTp37hUzCgP/dh 2kYxFWwDFEQijDkPyKGtOe3O2/gcCivapi6L2iGfdb2zMvo/IIaWARCSaZJnr4ZPjxjsRJ ex++LKQEuoAyDonBphCxS5P8uU3Pl9h8khLpXGxydwD+2PETLVuQ5dSTLOZJMw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1729948400; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=F9vgEwzzZcrJwjHaZhv8K9W1SFVVMwA9sGZjr7OEWTY=; b=QYSCXfRz8CUV9LdDRJgbYwV3ik3xmzTC2Ph5i47XCWGpTFRlWUKZ3yyIKcOWCFZ0YgHoMJ FkwaGBG6GK7yrfVpEbG30YCVIDGcJqs7+GwqYripJnbUAV4jCf5H50g6TF+MReRoJPT7RG GcHNQMCAyF8a+fVqXzb3CGGAM/7kQqSNx4TIW1+ybxlBmn+i9OxAyuq88VL+MVf/Fe/Tvc JhS0qxEXk2E+FTteEpK51vzpEgNGKtkauVsmrxOUYvRELVlF7HKlynDfcmbVOm1od9il6/ ZVkW9joTNgROCwSZlrgsRfiXBIQ5PhBuMwUgCCuY7Jzmpgz26HImsSQL2td+yw== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1729948400; a=rsa-sha256; cv=none; b=FSYTNHYSjP4sPDVGcrrx9gSYc3C0+N98GJFZyaiijCMlLeFxeyjkkO+zDMIEqZwpS23PXT uKjGKjvTqYCA5v7rn06Y5+FjKDZuHkSuP0dcI7riuZBgRsBHac8V0NjNHuULUPbzW1+2Sf QuahRC+cIso9a61o6pO22tVj7216FZlVj+TzugRmb6kR74UQ7GoDe6YrrVI14ESyOarQfD tePxZqKSiofoAil4PPLNDGguPdlLe1wVsv23cv0G7X8sOS/k1U3y0Rf3J+qKsDFw+I2ClR 43JAZ1IrfKPN3JHmxsLnVHAlzCdyB+JU9Wjy1wAXJOjLglYZGnNSZHf/H9LG1A== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4XbKpS0HDKz1BM5; Sat, 26 Oct 2024 13:13:20 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.18.1/8.18.1) with ESMTP id 49QDDJH5099056; Sat, 26 Oct 2024 13:13:19 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.18.1/8.18.1/Submit) id 49QDDJhL099053; Sat, 26 Oct 2024 13:13:19 GMT (envelope-from git) Date: Sat, 26 Oct 2024 13:13:19 GMT Message-Id: <202410261313.49QDDJhL099053@gitrepo.freebsd.org> To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-main@FreeBSD.org From: Robert Nagy Subject: git: de651c997869 - main - security/vuxml: add www/*chromium < 130.0.6723.{58,69} List-Id: Commits to the main branch of the FreeBSD ports repository List-Archive: https://lists.freebsd.org/archives/dev-commits-ports-main List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-ports-main@freebsd.org Sender: owner-dev-commits-ports-main@FreeBSD.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: rnagy X-Git-Repository: ports X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: de651c9978691d94ab21c802c489e61e0dbc076b Auto-Submitted: auto-generated The branch main has been updated by rnagy: URL: https://cgit.FreeBSD.org/ports/commit/?id=de651c9978691d94ab21c802c489e61e0dbc076b commit de651c9978691d94ab21c802c489e61e0dbc076b Author: Robert Nagy AuthorDate: 2024-10-26 13:12:25 +0000 Commit: Robert Nagy CommitDate: 2024-10-26 13:12:25 +0000 security/vuxml: add www/*chromium < 130.0.6723.{58,69} Obtained from: https://chromereleases.googleblog.com/2024/10/stable-channel-update-for-desktop_22.html Obtained from: https://chromereleases.googleblog.com/2024/10/stable-channel-update-for-desktop_15.html --- security/vuxml/vuln/2024.xml | 94 ++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 94 insertions(+) diff --git a/security/vuxml/vuln/2024.xml b/security/vuxml/vuln/2024.xml index fef96db2d3e5..8843fc4150ea 100644 --- a/security/vuxml/vuln/2024.xml +++ b/security/vuxml/vuln/2024.xml @@ -1,3 +1,97 @@ + + chromium -- multiple security fixes + + + chromium + 130.0.6723.69 + + + ungoogled-chromium + 130.0.6723.69 + + + + +

Chrome Releases reports:

+
+

This update includes 3 security fixes:

+
    +
  • [371011220] High CVE-2024-10229: Inappropriate implementation in Extensions. Reported by Vsevolod Kokorin (Slonser) of Solidlab on 2024-10-02
  • +
  • [371565065] High CVE-2024-10230: Type Confusion in V8. Reported by Seunghyun Lee (@0x10n) on 2024-10-05
  • +
  • [372269618] High CVE-2024-10231: Type Confusion in V8. Reported by Seunghyun Lee (@0x10n) on 2024-10-09
  • +
+
+ +
+ + CVE-2024-10229 + CVE-2024-10230 + CVE-2024-10231 + https://chromereleases.googleblog.com/2024/10/stable-channel-update-for-desktop_22.html + + + 2024-10-22 + 2024-10-26 + +
+ + + chromium -- multiple security fixes + + + chromium + 130.0.6723.58 + + + ungoogled-chromium + 130.0.6723.58 + + + + +

Chrome Releases reports:

+
+

This update includes 17 security fixes:

+
    +
  • [367755363] High CVE-2024-9954: Use after free in AI. Reported by DarkNavy on 2024-09-18
  • +
  • [370133761] Medium CVE-2024-9955: Use after free in Web Authentication. Reported by anonymous on 2024-09-29
  • +
  • [370482421] Medium CVE-2024-9956: Inappropriate implementation in Web Authentication. Reported by mastersplinter on 2024-09-30
  • +
  • [358151317] Medium CVE-2024-9957: Use after free in UI. Reported by lime(@limeSec_) and fmyy(@binary_fmyy) From TIANGONG Team of Legendsec at QI-ANXIN Group on 2024-08-08
  • +
  • [40076120] Medium CVE-2024-9958: Inappropriate implementation in PictureInPicture. Reported by Lyra Rebane (rebane2001) on 2023-11-02
  • +
  • [368672129] Medium CVE-2024-9959: Use after free in DevTools. Reported by Sakana.S on 2024-09-21
  • +
  • [354748063] Medium CVE-2024-9960: Use after free in Dawn. Reported by Anonymous on 2024-07-23
  • +
  • [357776197] Medium CVE-2024-9961: Use after free in Parcel Tracking. Reported by lime(@limeSec_) and fmyy(@binary_fmyy) From TIANGONG Team of Legendsec at QI-ANXIN Group on 2024-08-06
  • +
  • [364508693] Medium CVE-2024-9962: Inappropriate implementation in Permissions. Reported by Shaheen Fazim on 2024-09-04
  • +
  • [328278718] Medium CVE-2024-9963: Insufficient data validation in Downloads. Reported by Anonymous on 2024-03-06
  • +
  • [361711121] Low CVE-2024-9964: Inappropriate implementation in Payments. Reported by Hafiizh on 2024-08-23
  • +
  • [352651673] Low CVE-2024-9965: Insufficient data validation in DevTools. Reported by Shaheen Fazim on 2024-07-12
  • +
  • [364773822] Low CVE-2024-9966: Inappropriate implementation in Navigations. Reported by Harry Chen on 2024-09-05
  • +
+
+ +
+ + CVE-2024-9954 + CVE-2024-9955 + CVE-2024-9956 + CVE-2024-9957 + CVE-2024-9958 + CVE-2024-9959 + CVE-2024-9960 + CVE-2024-9961 + CVE-2024-9962 + CVE-2024-9963 + CVE-2024-9964 + CVE-2024-9965 + CVE-2024-9966 + https://chromereleases.googleblog.com/2024/10/stable-channel-update-for-desktop_15.html + + + 2024-10-15 + 2024-10-26 + +
+ electron31 -- multiple vulnerabilities