From owner-svn-ports-all@FreeBSD.ORG Tue Nov 18 18:32:23 2014 Return-Path: Delivered-To: svn-ports-all@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id 36D7121B; Tue, 18 Nov 2014 18:32:23 +0000 (UTC) Received: from svn.freebsd.org (svn.freebsd.org [IPv6:2001:1900:2254:2068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 22C4EB8; Tue, 18 Nov 2014 18:32:23 +0000 (UTC) Received: from svn.freebsd.org ([127.0.1.70]) by svn.freebsd.org (8.14.9/8.14.9) with ESMTP id sAIIWNAR093556; Tue, 18 Nov 2014 18:32:23 GMT (envelope-from rene@FreeBSD.org) Received: (from rene@localhost) by svn.freebsd.org (8.14.9/8.14.9/Submit) id sAIIWM1n093555; Tue, 18 Nov 2014 18:32:22 GMT (envelope-from rene@FreeBSD.org) Message-Id: <201411181832.sAIIWM1n093555@svn.freebsd.org> X-Authentication-Warning: svn.freebsd.org: rene set sender to rene@FreeBSD.org using -f From: Rene Ladan Date: Tue, 18 Nov 2014 18:32:22 +0000 (UTC) To: ports-committers@freebsd.org, svn-ports-all@freebsd.org, svn-ports-head@freebsd.org Subject: svn commit: r372740 - head/security/vuxml X-SVN-Group: ports-head MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-ports-all@freebsd.org X-Mailman-Version: 2.1.18-1 Precedence: list List-Id: SVN commit messages for the ports tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 18 Nov 2014 18:32:23 -0000 Author: rene Date: Tue Nov 18 18:32:22 2014 New Revision: 372740 URL: https://svnweb.freebsd.org/changeset/ports/372740 QAT: https://qat.redports.org/buildarchive/r372740/ Log: Document new vulnerabilities in www/chromium < 39.0.2171.65 Obtained from: http://googlechromereleases.blogspot.nl/2014/11/stable-channel-update_18.html Modified: head/security/vuxml/vuln.xml Modified: head/security/vuxml/vuln.xml ============================================================================== --- head/security/vuxml/vuln.xml Tue Nov 18 16:52:24 2014 (r372739) +++ head/security/vuxml/vuln.xml Tue Nov 18 18:32:22 2014 (r372740) @@ -57,6 +57,77 @@ Notes: --> + + chromium -- multiple vulnerabilities + + + chromium + 39.0.2171.65 + + + chromium-pulse + 39.0.2171.65 + + + + +

Google Chrome Releases reports:

+
+

42 security fixes in this release, including:

+
    +
  • [389734] High CVE-2014-7899: Address bar spoofing. Credit to + Eli Grey.
  • +
  • [406868] High CVE-2014-7900: Use-after-free in pdfium. Credit + to Atte Kettunen from OUSPG.
  • +
  • [413375] High CVE-2014-7901: Integer overflow in pdfium. Credit + to cloudfuzzer.
  • +
  • [414504] High CVE-2014-7902: Use-after-free in pdfium. Credit + to cloudfuzzer.
  • +
  • [414525] High CVE-2014-7903: Buffer overflow in pdfium. Credit + to cloudfuzzer.
  • +
  • [418161] High CVE-2014-7904: Buffer overflow in Skia. Credit to + Atte Kettunen from OUSPG.
  • +
  • [421817] High CVE-2014-7905: Flaw allowing navigation to + intents that do not have the BROWSABLE category. Credit to + WangTao(neobyte) of Baidu X-Team.
  • +
  • [423030] High CVE-2014-7906: Use-after-free in pepper plugins. + Credit to Chen Zhang (demi6od) of the NSFOCUS Security Team.
  • +
  • [423703] High CVE-2014-0574: Double-free in Flash. Credit to + biloulehibou.
  • +
  • [424453] High CVE-2014-7907: Use-after-free in blink. Credit to + Chen Zhang (demi6od) of the NSFOCUS Security Team.
  • +
  • [425980] High CVE-2014-7908: Integer overflow in media. Credit + to Christoph Diehl.
  • +
  • [391001] Medium CVE-2014-7909: Uninitialized memory read in + Skia. Credit to miaubiz.
  • +
  • CVE-2014-7910: Various fixes from internal audits, fuzzing and + other initiatives.
  • +
+
+ +
+ + CVE-2014-0574 + CVE-2014-7899 + CVE-2014-7900 + CVE-2014-7901 + CVE-2014-7902 + CVE-2014-7903 + CVE-2014-7904 + CVE-2014-7905 + CVE-2014-7906 + CVE-2014-7907 + CVE-2014-7908 + CVE-2014-7909 + CVE-2014-7910 + http://googlechromereleases.blogspot.nl/2014/11/stable-channel-update_18.html + + + 2014-11-18 + 2014-11-18 + +
+ kde-workspace -- privilege escalation