From nobody Tue Mar 15 22:46:45 2022 X-Original-To: dev-commits-ports-main@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 32D4A1A1583E; Tue, 15 Mar 2022 22:46:46 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4KJ7nL0wbCz3rQY; Tue, 15 Mar 2022 22:46:46 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1647384406; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=l/cpQ1dhpDMiNps+IUWrg7ca9IhJoSK+Ydo/+R+vkpc=; b=yXkg4jSsgLG/YmUkqbGx52hvdddcn6rWIn568UvzaIAWYAMumT8+c9QjtxZJyPjXz5SWse yNfh1RaufEJAh295gGftjjaaQ4UPFNvIAknONjEPqhbT2H/g9ml02+izAv2XeFo+LyMQ+F f4E2pVpOwTu4R35NqMyUmjCgb0eqxFwo7b49KxmD33XAeB8sXuPtyTk2pfk4Y9IktTWLGP w/5EOlVIoKw6uHa1Lf9RNAcPDbThDKfXhYAVERfpTEu4UIT/501yHvmHi0yhiwocFFs49e yX7lkEpalOqKXUj2uky5DknA+StpODQqNtfbALVsdgWrSzpk6ZIfd5PZwMmM8g== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 0012824C8; Tue, 15 Mar 2022 22:46:45 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.16.1/8.16.1) with ESMTP id 22FMkjbR039685; Tue, 15 Mar 2022 22:46:45 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.16.1/8.16.1/Submit) id 22FMkjQr039684; Tue, 15 Mar 2022 22:46:45 GMT (envelope-from git) Date: Tue, 15 Mar 2022 22:46:45 GMT Message-Id: <202203152246.22FMkjQr039684@gitrepo.freebsd.org> To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-main@FreeBSD.org From: Rene Ladan Subject: git: 6568a56607da - main - security/vuxml: add www/chromium < 99.0.4844.74 List-Id: Commits to the main branch of the FreeBSD ports repository List-Archive: https://lists.freebsd.org/archives/dev-commits-ports-main List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-dev-commits-ports-main@freebsd.org X-BeenThere: dev-commits-ports-main@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: rene X-Git-Repository: ports X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: 6568a56607da9d87991cad708eb9af3c23b6d163 Auto-Submitted: auto-generated ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1647384406; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=l/cpQ1dhpDMiNps+IUWrg7ca9IhJoSK+Ydo/+R+vkpc=; b=dah/NUPflkR7v/YmWCYF8zFEUi93fQyaGu6SbxvWlPZyiX47AWJWJPp3hEDrfJOM1wKkfL Hcei54+GDlb3WgNjDSODlEd0hfNxuv5L/8niPC+3sWUcJIYlT0kVdqYV1/28TTh7ZbBpwW 8lK72P2pTzHFoBx2oTJjq63HuBYKH33bBh2p5d46BKmqdQULud0G0qVmBqltCsK5kwNzH+ JT03FKFtZEYW5DQPbLdlmvs+MyS1ZKO+HRv/heMsjp/BFw+KDLcxYAcowLDxm08b/W14iz +m165V9CJbhjJvp9Tm9PO1Xw9eQ+YrzjMQcCPnFkLPQSKAIWdZQZELBkct96/w== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1647384406; a=rsa-sha256; cv=none; b=WNahKK2xOArPMV6iMli1Ga/4+PBczsny8uDBAVnmkSp/ouz3IeiCMGQGvhbkOEZJ/5Co9E CmhFrsrpaD1pdFG+2i09V5j8P3Kj+UaOBfCSGKIGf8flD2Cs2e93WB9dRCvQDEbbyHbxAE DMLTzSBScVGupyzcrmxieagHAJ4RcEmFzW5y1vMb9gwS8Yn6bZ8yP3XFJ5EvmVlcV+wdu8 n7cWL0E5H6Ver940P+QUOrdgfALUF5/NvArEF0Aa9ZW3koyTS4NuJzdoPIQrgC06dWLFCP Go0fu7or4OTBmWCSr9NeebHI17FWzLlDXb+7RJXoRF6oWAw8gm1ZEzYsmAH9xw== ARC-Authentication-Results: i=1; mx1.freebsd.org; none X-ThisMailContainsUnwantedMimeParts: N The branch main has been updated by rene: URL: https://cgit.FreeBSD.org/ports/commit/?id=6568a56607da9d87991cad708eb9af3c23b6d163 commit 6568a56607da9d87991cad708eb9af3c23b6d163 Author: Rene Ladan AuthorDate: 2022-03-15 22:45:57 +0000 Commit: Rene Ladan CommitDate: 2022-03-15 22:45:57 +0000 security/vuxml: add www/chromium < 99.0.4844.74 Obtained from: https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop_15.html --- security/vuxml/vuln-2022.xml | 60 ++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 60 insertions(+) diff --git a/security/vuxml/vuln-2022.xml b/security/vuxml/vuln-2022.xml index d02c61a9e641..efedcc39aa5a 100644 --- a/security/vuxml/vuln-2022.xml +++ b/security/vuxml/vuln-2022.xml @@ -1,3 +1,63 @@ + + chromium -- multiple vulnerabilities + + + chromium + 98.0.4844.74 + + + + +

Chrome Releases reports:

+
+

This release contains 11 security fixes, including:

+
    +
  • [1299422] Critical CVE-2022-0971: Use after free in Blink + Layout. Reported by Sergei Glazunov of Google Project Zero on + 2022-02-21
  • +
  • [1301320] High CVE-2022-0972: Use after free in Extensions. + Reported by Sergei Glazunov of Google Project Zero on + 2022-02-28
  • +
  • [1297498] High CVE-2022-0973: Use after free in Safe Browsing. + Reported by avaue and Buff3tts at S.S.L. on 2022-02-15
  • +
  • [1291986] High CVE-2022-0974: Use after free in Splitscreen. + Reported by @ginggilBesel on 2022-01-28
  • +
  • [1295411] High CVE-2022-0975: Use after free in ANGLE. Reported + by SeongHwan Park (SeHwa) on 2022-02-09
  • +
  • [1296866] High CVE-2022-0976: Heap buffer overflow in GPU. + Reported by Omair on 2022-02-13
  • +
  • [1299225] High CVE-2022-0977: Use after free in Browser UI. + Reported by Khalil Zhani on 2022-02-20
  • +
  • [1299264] High CVE-2022-0978: Use after free in ANGLE. Reported + by Cassidy Kim of Amber Security Lab, OPPO Mobile + Telecommunications Corp. Ltd. on 2022-02-20
  • +
  • [1302644] High CVE-2022-0979: Use after free in Safe Browsing. + Reported by anonymous on 2022-03-03
  • +
  • [1302157] Medium CVE-2022-0980: Use after free in New Tab Page. + Reported by Krace on 2022-03-02
  • +
+
+ +
+ + CVE-2022-0971 + CVE-2022-0972 + CVE-2022-0973 + CVE-2022-0974 + CVE-2022-0975 + CVE-2022-0976 + CVE-2022-0977 + CVE-2022-0978 + CVE-2022-0979 + CVE-2022-0980 + https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop_15.html + + + 2022-03-15 + 2022-03-15 + +
+ Apache httpd -- Multiple vulnerabilities