svn commit: r362128 - branches/2014Q3/security/vuxml
Rene Ladan
rene at FreeBSD.org
Thu Jul 17 09:50:37 UTC 2014
Author: rene
Date: Thu Jul 17 09:50:36 2014
New Revision: 362128
URL: http://svnweb.freebsd.org/changeset/ports/362128
QAT: https://qat.redports.org/buildarchive/r362128/
Log:
MFH: r362122
Document new vulnerabilities in www/chromium < 36.0.1985.125
Submitted by: Carlos Jacobo Puga Medina <cpm at fbsd.es> via freebsd-chromium
Obtained from: http://googlechromereleases.blogspot.nl/
Approved by: portmgr (erwin)
Modified:
branches/2014Q3/security/vuxml/vuln.xml
Directory Properties:
branches/2014Q3/ (props changed)
Modified: branches/2014Q3/security/vuxml/vuln.xml
==============================================================================
--- branches/2014Q3/security/vuxml/vuln.xml Thu Jul 17 09:49:24 2014 (r362127)
+++ branches/2014Q3/security/vuxml/vuln.xml Thu Jul 17 09:50:36 2014 (r362128)
@@ -57,6 +57,39 @@ Notes:
-->
<vuxml xmlns="http://www.vuxml.org/apps/vuxml-1">
+ <vuln vid="3718833e-0d27-11e4-89db-000c6e25e3e9">
+ <topic>chromium -- multiple vulnerabilities</topic>
+ <affects>
+ <package>
+ <name>chromium</name>
+ <range><lt>36.0.1985.125</lt></range>
+ </package>
+ </affects>
+ <description>
+ <body xmlns="http://www.w3.org/1999/xhtml">
+ <p>Google Chrome Releases reports:</p>
+ <blockquote cite="http://googlechromereleases.blogspot.nl">
+ <p>26 security fixes in this release, including</p>
+ <ul>
+ <li>[380885] Medium CVE-2014-3160: Same-Origin-Policy bypass in SVG. Credit
+ to Christian Schneider.</li>
+ <li>[393765] CVE-2014-3162: Various fixes from internal audits, fuzzing and
+ other initiatives.</li>
+ </ul>
+ </blockquote>
+ </body>
+ </description>
+ <references>
+ <cvename>CVE-2014-3160</cvename>
+ <cvename>CVE-2014-3162</cvename>
+ <url>http://googlechromereleases.blogspot.nl</url>
+ </references>
+ <dates>
+ <discovery>2014-07-16</discovery>
+ <entry>2014-07-16</entry>
+ </dates>
+ </vuln>
+
<vuln vid="4a114331-0d24-11e4-8dd2-5453ed2e2b49">
<topic>kdelibs4 -- KMail/KIO POP3 SSL Man-in-the-middle Flaw</topic>
<affects>
More information about the svn-ports-branches
mailing list