Document new vulnerabilities in www/chromium < 32.0.1700.77

Obtained from:	http://googlechromereleases.blogspot.nl/
MFH:		2014Q1
This commit is contained in:
Rene Ladan 2014-01-15 21:41:15 +00:00
parent ced6ff062e
commit 8ecb19f477
Notes: svn2git 2021-03-31 03:12:20 +00:00
svn path=/head/; revision=339825

View file

@ -51,6 +51,51 @@ Note: Please add new entries to the beginning of this file.
-->
<vuxml xmlns="http://www.vuxml.org/apps/vuxml-1">
<vuln vid="5acf4638-7e2c-11e3-9fba-00262d5ed8ee">
<topic>chromium -- multiple vulnerabilities</topic>
<affects>
<package>
<name>chromium</name>
<range><lt>32.0.1700.77</lt></range>
</package>
</affects>
<description>
<body xmlns="http://www.w3.org/1999/xhtml">
<p>Google Chrome Releases reports:</p>
<blockquote cite="http://googlechromereleases.blogspot.nl/">
<p>11 security fixes in this release, including:</p>
<ul>
<li>[249502] High CVE-2013-6646: Use-after-free in web workers.
Credit to Collin Payne.</li>
<li>[326854] High CVE-2013-6641: Use-after-free related to forms.
Credit to Atte Kettunen of OUSPG.</li>
<li>[324969] High CVE-2013-6642: Address bar spoofing in Chrome for
Android. Credit to lpilorz.</li>
<li>[321940] High CVE-2013-6643: Unprompted sync with an attackers
Google account. Credit to Joao Lucas Melo Brasio.</li>
<li>[318791] Medium CVE-2013-6645 Use-after-free related to speech
input elements. Credit to Khalil Zhani.</li>
<li>[333036] CVE-2013-6644: Various fixes from internal audits,
fuzzing and other initiatives.</li>
</ul>
</blockquote>
</body>
</description>
<references>
<cvename>CVE-2013-6641</cvename>
<cvename>CVE-2013-6642</cvename>
<cvename>CVE-2013-6643</cvename>
<cvename>CVE-2013-6644</cvename>
<cvename>CVE-2013-6645</cvename>
<cvename>CVE-2013-6646</cvename>
<url>http://googlechromereleases.blogspot.nl/</url>
</references>
<dates>
<discovery>2014-01-14</discovery>
<entry>2014-01-15</entry>
</dates>
</vuln>
<vuln vid="3d95c9a7-7d5c-11e3-a8c1-206a8a720317">
<topic>ntpd DRDoS / Amplification Attack using ntpdc monlist command</topic>
<affects>