From nobody Sat Jan 25 08:12:06 2025 X-Original-To: dev-commits-ports-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4Yg6pv1GGtz5mCvL; Sat, 25 Jan 2025 08:12:07 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R11" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4Yg6pv0cgtz3LbC; Sat, 25 Jan 2025 08:12:07 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1737792727; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=ebl6zCi9E5GpIXVUqyg8KiZoNFAi1BIay4laGxwvjt8=; b=KPnOCWLOzTpawdO0S37tnO5K3SnVqeDFuQicZi7b/aThXqKK+GGHYznlj5ZagM4uyUC0Ib JHrlM3UJJtE5OZSeSKFeQ4Tp8qTkEuy9GNMZKHU8NIlgNgGVao2/XsRD9pb0DU6PDDsUBM LwiMMq40A/KYwu7XG18vgfb/VeRrvoeBU+TJlrtoQEVwXiPNTFWsWyDFjf12RbYid9Ec6G nHQJdpVZBX9AaqrmG1vy+oeciLmwsf4KxA00MdPud8JNLSRg4oNTo3zI4WzjCauxvXdycx 1HEhlJiro7VkOnlNV+md6Nk4ws60u8tAjmu37yW0JnbISBBz3Dfx9OxGe+5CrQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1737792727; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=ebl6zCi9E5GpIXVUqyg8KiZoNFAi1BIay4laGxwvjt8=; b=cEcp8Zntb38v/9kolxkCd8ydcOhhWNC8KO8LkGychV8DNMydfIBbY9v5XPzFGkubLBBgeO QhgDLQm/r3pg1ATazTADV3JO4iQw9J+Wby1ri/4xZCFXH7+Kisr3B7sOQCBqzm58OwwfJP qNGW9Kfdu2HjEdvbbnfys1/ktND9e5IAgzltpK1xAz7cg1zjI9aJTcZ09PRNzcH5VR2DPi urkFS3nSYoxfF3UgD+NCWBV7gt13w8YKFFrONMbxtyqfIi7NJkogA5/aidHW/brWsnYBhS e0CAEg0L7nt4N3Lh/OqF6r0x3JwEywkJyFATCxpxJpKOw98VMP1Bu/ub+5rM+w== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1737792727; a=rsa-sha256; cv=none; b=mGzubZRukPFwLA0Z58JtAgvhNqEXaY3xuSJwXEOJ3fi+XzulmhbCI4E5pMIkHuAr5+Op0h IZrOLFH8Cw8UTY7YmZFgr7BxFBkjpL5TcvqXUWenQU7OdrAJ1fqNdPf/9eWr3BNCCPPKG2 Y5UvRBzrpczA+R+zFh5NegtjXa5VNCZRC59p0HOwXlZiPm6rM7VME4UurP8GYkRJR2IC2v 6ywVK6c4sIXAJsDQ70eXFFsmqY26BYWFtr3bDl/EYOuffYLVyBnxAGX7zbzccGUc4w4d59 7GYyDwfpURaJYA7WkD81sw6C6MQwIyl04FABITLiqxXq2HCF0x8lM/Sh24KWlA== ARC-Authentication-Results: i=1; mx1.freebsd.org; none Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4Yg6pv089rz140d; Sat, 25 Jan 2025 08:12:07 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.18.1/8.18.1) with ESMTP id 50P8C65X092954; Sat, 25 Jan 2025 08:12:06 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.18.1/8.18.1/Submit) id 50P8C6qs092951; Sat, 25 Jan 2025 08:12:06 GMT (envelope-from git) Date: Sat, 25 Jan 2025 08:12:06 GMT Message-Id: <202501250812.50P8C6qs092951@gitrepo.freebsd.org> To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-main@FreeBSD.org From: Robert Nagy Subject: git: 2a206e393c54 - main - security/vuxml: add www/*chromium < 132.0.6834.110 List-Id: Commit messages for all branches of the ports repository List-Archive: https://lists.freebsd.org/archives/dev-commits-ports-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-ports-all@freebsd.org Sender: owner-dev-commits-ports-all@FreeBSD.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: rnagy X-Git-Repository: ports X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: 2a206e393c540f0e6312966bec085c7afd68da63 Auto-Submitted: auto-generated The branch main has been updated by rnagy: URL: https://cgit.FreeBSD.org/ports/commit/?id=2a206e393c540f0e6312966bec085c7afd68da63 commit 2a206e393c540f0e6312966bec085c7afd68da63 Author: Robert Nagy AuthorDate: 2025-01-25 08:11:10 +0000 Commit: Robert Nagy CommitDate: 2025-01-25 08:12:01 +0000 security/vuxml: add www/*chromium < 132.0.6834.110 Obtained from: https://chromereleases.googleblog.com/2025/01/stable-channel-update-for-desktop_22.html Obtained from: https://chromereleases.googleblog.com/2025/01/stable-channel-update-for-desktop_14.html --- security/vuxml/vuln/2025.xml | 92 ++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 92 insertions(+) diff --git a/security/vuxml/vuln/2025.xml b/security/vuxml/vuln/2025.xml index 614f4116ffac..cc3105d6abe1 100644 --- a/security/vuxml/vuln/2025.xml +++ b/security/vuxml/vuln/2025.xml @@ -1,3 +1,95 @@ + + chromium -- multiple security fixes + + + chromium + 132.0.6834.110 + + + ungoogled-chromium + 132.0.6834.110 + + + + +

Chrome Releases reports:

+
+

This update includes 3 security fixes:

+
    +
  • [386143468] High CVE-2025-0611: Object corruption in V8. Reported by 303f06e3 on 2024-12-26
  • +
  • [385155406] High CVE-2025-0612: Out of bounds memory access in V8. Reported by Alan Goodman on 2024-12-20
  • +
+
+ +
+ + CVE-2025-0611 + CVE-2025-0612 + https://chromereleases.googleblog.com/2025/01/stable-channel-update-for-desktop_22.html + + + 2025-01-22 + 2025-01-25 + +
+ + + chromium -- multiple security fixes + + + chromium + 132.0.6834.83 + + + ungoogled-chromium + 132.0.6834.83 + + + + +

Chrome Releases reports:

+
+

This update includes 16 security fixes:

+
    +
  • [374627491] High CVE-2025-0434: Out of bounds memory access in V8. Reported by ddme on 2024-10-21
  • +
  • [379652406] High CVE-2025-0435: Inappropriate implementation in Navigation. Reported by Alesandro Ortiz on 2024-11-18
  • +
  • [382786791] High CVE-2025-0436: Integer overflow in Skia. Reported by Han Zheng (HexHive) on 2024-12-08
  • +
  • [378623799] High CVE-2025-0437: Out of bounds read in Metrics. Reported by Xiantong Hou of Wuheng Lab and Pisanbao on 2024-11-12
  • +
  • [384186539] High CVE-2025-0438: Stack buffer overflow in Tracing. Reported by Han Zheng (HexHive) on 2024-12-15
  • +
  • [371247941] Medium CVE-2025-0439: Race in Frames. Reported by Hafiizh on 2024-10-03
  • +
  • [40067914] Medium CVE-2025-0440: Inappropriate implementation in Fullscreen. Reported by Umar Farooq on 2023-07-22
  • +
  • [368628042] Medium CVE-2025-0441: Inappropriate implementation in Fenced Frames. Reported by someoneverycurious on 2024-09-21
  • +
  • [40940854] Medium CVE-2025-0442: Inappropriate implementation in Payments. Reported by Ahmed ElMasry on 2023-11-08
  • +
  • [376625003] Medium CVE-2025-0443: Insufficient data validation in Extensions. Reported by Anonymous on 2024-10-31
  • +
  • [359949844] Low CVE-2025-0446: Inappropriate implementation in Extensions. Reported by Hafiizh on 2024-08-15
  • +
  • [375550814] Low CVE-2025-0447: Inappropriate implementation in Navigation. Reported by Khiem Tran (@duckhiem) on 2024-10-25
  • +
  • [377948403] Low CVE-2025-0448: Inappropriate implementation in Compositing. Reported by Dahyeon Park on 2024-11-08
  • +
+
+ +
+ + CVE-2025-0434 + CVE-2025-0435 + CVE-2025-0436 + CVE-2025-0437 + CVE-2025-0438 + CVE-2025-0439 + CVE-2025-0440 + CVE-2025-0441 + CVE-2025-0442 + CVE-2025-0443 + CVE-2025-0446 + CVE-2025-0447 + CVE-2025-0448 + https://chromereleases.googleblog.com/2025/01/stable-channel-update-for-desktop_14.html + + + 2025-01-14 + 2025-01-25 + +
+ electron32 -- multiple vulnerabilities