diff options
author | Rene Ladan <rene@FreeBSD.org> | 2020-04-12 10:06:00 +0000 |
---|---|---|
committer | Rene Ladan <rene@FreeBSD.org> | 2020-04-12 10:06:00 +0000 |
commit | 09fb8fcc25248eef07df5f633f2a2cb511186b80 (patch) | |
tree | 65d8e661e4f755b2093504deb069bb323fc793cc | |
parent | The Wine Staging patchset is now available for Wine 5.6 (which is enabled (diff) |
Document new vulnerabilities in www/chromium < 81.0.4044.92
Notes
Notes:
svn path=/head/; revision=531501
-rw-r--r-- | security/vuxml/vuln.xml | 106 |
1 files changed, 106 insertions, 0 deletions
diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index 217577843c1d..83112a94d064 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -58,6 +58,112 @@ Notes: * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> <vuxml xmlns="http://www.vuxml.org/apps/vuxml-1"> + <vuln vid="6e3b700a-7ca3-11ea-b594-3065ec8fd3ec"> + <topic>chromium -- multiple vulnerabilities</topic> + <affects> + <package> + <name>chromium</name> + <range><lt>81.0.4044.92</lt></range> + </package> + </affects> + <description> + <body xmlns="http://www.w3.org/1999/xhtml"> + <p>Google Chrome Releases reports:</p> + <blockquote cite="https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_7.html"> + <p>This updates includes 32 security fixes, including:</p> + <ul> + <li>[1019161] High CVE-2020-6454: Use after free in extensions. + Reported by Leecraso and Guang Gong of Alpha Lab, Qihoo 360 on + 2019-10-29</li> + <li>[1043446] High CVE-2020-6423: Use after free in audio. + Reported by Anonymous on 2020-01-18</li> + <li>[1059669] High CVE-2020-6455: Out of bounds read in WebSQL. + Reported by Nan Wang(@eternalsakura13) and Guang Gong of Alpha Lab, + Qihoo 360 on 2020-03-09</li> + <li>[1031479] Medium CVE-2020-6430: Type Confusion in V8. + Reported by Avihay Cohen @ SeraphicAlgorithms on 2019-12-06</li> + <li>[1040755] Medium CVE-2020-6456: Insufficient validation of + untrusted input in clipboard. Reported by MichaĆ Bentkowski of + Securitum on 2020-01-10</li> + <li>[852645] Medium CVE-2020-6431: Insufficient policy + enforcement in full screen. Reported by Luan Herrera (@lbherrera_) + on 2018-06-14</li> + <li>[965611] Medium CVE-2020-6432: Insufficient policy + enforcement in navigations. Reported by David Erceg on + 2019-05-21</li> + <li>[1043965] Medium CVE-2020-6433: Insufficient policy + enforcement in extensions. Reported by David Erceg on + 2020-01-21</li> + <li>[1048555] Medium CVE-2020-6434: Use after free in devtools. + Reported by HyungSeok Han (DaramG) of Theori on 2020-02-04</li> + <li>[1032158] Medium CVE-2020-6435: Insufficient policy + enforcement in extensions. Reported by Sergei Glazunov of Google + Project Zero on 2019-12-09</li> + <li>[1034519] Medium CVE-2020-6436: Use after free in window + management. Reported by Igor Bukanov from Vivaldi on 2019-12-16</li> + <li>[639173] Low CVE-2020-6437: Inappropriate implementation in + WebView. Reported by Jann Horn on 2016-08-19</li> + <li>[714617] Low CVE-2020-6438: Insufficient policy enforcement in + extensions. Reported by Ng Yik Phang on 2017-04-24</li> + <li>[868145] Low CVE-2020-6439: Insufficient policy enforcement in + navigations. Reported by remkoboonstra on 2018-07-26</li> + <li>[894477] Low CVE-2020-6440: Inappropriate implementation in + extensions. Reported by David Erceg on 2018-10-11</li> + <li>[959571] Low CVE-2020-6441: Insufficient policy enforcement in + omnibox. Reported by David Erceg on 2019-05-04</li> + <li>[1013906] Low CVE-2020-6442: Inappropriate implementation in + cache. Reported by B@rMey on 2019-10-12</li> + <li>[1040080] Low CVE-2020-6443: Insufficient data validation in + developer tools. Reported by @lovasoa (Ophir LOJKINE) on + 2020-01-08</li> + <li>[922882] Low CVE-2020-6444: Uninitialized Use in WebRTC. + Reported by mlfbrown on 2019-01-17</li> + <li>[933171] Low CVE-2020-6445: Insufficient policy enforcement in + trusted types. Reported by Jun Kokatsu, Microsoft Browser + Vulnerability Research on 2019-02-18</li> + <li>[933172] Low CVE-2020-6446: Insufficient policy enforcement in + trusted types. Reported by Jun Kokatsu, Microsoft Browser + Vulnerability Research on 2019-02-18</li> + <li>[991217] Low CVE-2020-6447: Inappropriate implementation in + developer tools. Reported by David Erceg on 2019-08-06</li> + <li>[1037872] Low CVE-2020-6448: Use after free in V8. Reported by + Guang Gong of Alpha Lab, Qihoo 360 on 2019-12-26</li> + </ul> + </blockquote> + </body> + </description> + <references> + <cvename>CVE-2020-6423</cvename> + <cvename>CVE-2020-6430</cvename> + <cvename>CVE-2020-6431</cvename> + <cvename>CVE-2020-6432</cvename> + <cvename>CVE-2020-6433</cvename> + <cvename>CVE-2020-6434</cvename> + <cvename>CVE-2020-6435</cvename> + <cvename>CVE-2020-6436</cvename> + <cvename>CVE-2020-6437</cvename> + <cvename>CVE-2020-6438</cvename> + <cvename>CVE-2020-6439</cvename> + <cvename>CVE-2020-6440</cvename> + <cvename>CVE-2020-6441</cvename> + <cvename>CVE-2020-6442</cvename> + <cvename>CVE-2020-6443</cvename> + <cvename>CVE-2020-6444</cvename> + <cvename>CVE-2020-6445</cvename> + <cvename>CVE-2020-6446</cvename> + <cvename>CVE-2020-6447</cvename> + <cvename>CVE-2020-6448</cvename> + <cvename>CVE-2020-6454</cvename> + <cvename>CVE-2020-6455</cvename> + <cvename>CVE-2020-6456</cvename> + <url>https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_7.html</url> + </references> + <dates> + <discovery>2020-04-07</discovery> + <entry>2020-04-12</entry> + </dates> + </vuln> + <vuln vid="9cb57a06-7517-11ea-b594-3065ec8fd3ec"> <topic>chromium -- multiple vulnerabilities</topic> <affects> |