git: 6568a56607da - main - security/vuxml: add www/chromium < 99.0.4844.74

From: Rene Ladan <rene_at_FreeBSD.org>
Date: Tue, 15 Mar 2022 22:46:45 UTC
The branch main has been updated by rene:

URL: https://cgit.FreeBSD.org/ports/commit/?id=6568a56607da9d87991cad708eb9af3c23b6d163

commit 6568a56607da9d87991cad708eb9af3c23b6d163
Author:     Rene Ladan <rene@FreeBSD.org>
AuthorDate: 2022-03-15 22:45:57 +0000
Commit:     Rene Ladan <rene@FreeBSD.org>
CommitDate: 2022-03-15 22:45:57 +0000

    security/vuxml: add www/chromium < 99.0.4844.74
    
    Obtained from:  https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop_15.html
---
 security/vuxml/vuln-2022.xml | 60 ++++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 60 insertions(+)

diff --git a/security/vuxml/vuln-2022.xml b/security/vuxml/vuln-2022.xml
index d02c61a9e641..efedcc39aa5a 100644
--- a/security/vuxml/vuln-2022.xml
+++ b/security/vuxml/vuln-2022.xml
@@ -1,3 +1,63 @@
+  <vuln vid="857be71a-a4b0-11ec-95fc-3065ec8fd3ec">
+    <topic>chromium -- multiple vulnerabilities</topic>
+    <affects>
+      <package>
+	<name>chromium</name>
+	<range><lt>98.0.4844.74</lt></range>
+      </package>
+    </affects>
+    <description>
+      <body xmlns="http://www.w3.org/1999/xhtml">
+	<p>Chrome Releases reports:</p>
+	<blockquote cite="https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop_15.html">
+	  <p>This release contains 11 security fixes, including:</p>
+	  <ul>
+	    <li>[1299422] Critical CVE-2022-0971: Use after free in Blink
+	      Layout. Reported by Sergei Glazunov of Google Project Zero on
+	      2022-02-21</li>
+	    <li>[1301320] High CVE-2022-0972: Use after free in Extensions.
+	      Reported by Sergei Glazunov of Google Project Zero on
+	      2022-02-28</li>
+	    <li>[1297498] High CVE-2022-0973: Use after free in Safe Browsing.
+	      Reported by avaue and Buff3tts at S.S.L. on 2022-02-15</li>
+	    <li>[1291986] High CVE-2022-0974: Use after free in Splitscreen.
+	      Reported by @ginggilBesel on 2022-01-28</li>
+	    <li>[1295411] High CVE-2022-0975: Use after free in ANGLE. Reported
+	      by SeongHwan Park (SeHwa) on 2022-02-09</li>
+	    <li>[1296866] High CVE-2022-0976: Heap buffer overflow in GPU.
+	      Reported by Omair on 2022-02-13</li>
+	    <li>[1299225] High CVE-2022-0977: Use after free in Browser UI.
+	      Reported by Khalil Zhani on 2022-02-20</li>
+	    <li>[1299264] High CVE-2022-0978: Use after free in ANGLE. Reported
+	      by Cassidy Kim of Amber Security Lab, OPPO Mobile
+	      Telecommunications Corp. Ltd. on 2022-02-20</li>
+	    <li>[1302644] High CVE-2022-0979: Use after free in Safe Browsing.
+	      Reported by anonymous on 2022-03-03</li>
+	    <li>[1302157] Medium CVE-2022-0980: Use after free in New Tab Page.
+	      Reported by Krace on 2022-03-02</li>
+	  </ul>
+	</blockquote>
+      </body>
+    </description>
+    <references>
+      <cvename>CVE-2022-0971</cvename>
+      <cvename>CVE-2022-0972</cvename>
+      <cvename>CVE-2022-0973</cvename>
+      <cvename>CVE-2022-0974</cvename>
+      <cvename>CVE-2022-0975</cvename>
+      <cvename>CVE-2022-0976</cvename>
+      <cvename>CVE-2022-0977</cvename>
+      <cvename>CVE-2022-0978</cvename>
+      <cvename>CVE-2022-0979</cvename>
+      <cvename>CVE-2022-0980</cvename>
+      <url>https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop_15.html</url>
+    </references>
+    <dates>
+      <discovery>2022-03-15</discovery>
+      <entry>2022-03-15</entry>
+    </dates>
+  </vuln>
+
   <vuln vid="6601c08d-a46c-11ec-8be6-d4c9ef517024">
     <topic>Apache httpd -- Multiple vulnerabilities</topic>
     <affects>