From e06063046239d0f56c798a98777ed4b27e858c17 Mon Sep 17 00:00:00 2001 From: rene Date: Thu, 5 Dec 2013 12:07:00 +0000 Subject: Document new vulnerabilities in www/chromium < 31.0.1650.63 Obtained from: http://googlechromereleases.blogspot.nl/ --- security/vuxml/vuln.xml | 51 +++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 51 insertions(+) (limited to 'security/vuxml') diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index 3d145f4c4c44..899bd4f05385 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -51,6 +51,57 @@ Note: Please add new entries to the beginning of this file. --> + + chromium -- multiple vulnerabilities + + + chromium + 31.0.1650.63 + + + + +

Google Chrome Releases reports:

+
+

15 security fixes in this release, including:

+
    +
  • [307159] Medium CVE-2013-6634: Session fixation in sync related + to 302 redirects. Credit to Andrey Labunets.
  • +
  • [314469] High CVE-2013-6635: Use-after-free in editing. Credit + to cloudfuzzer.
  • +
  • [322959] Medium CVE-2013-6636: Address bar spoofing related to + modal dialogs. Credit to Bas Venis.
  • +
  • [325501] CVE-2013-6637: Various fixes from internal audits, + fuzzing and other initiatives.
  • +
  • [319722] Medium CVE-2013-6638: Buffer overflow in v8. This + issue was fixed in v8 version 3.22.24.7. Credit to Jakob Kummerow + of the Chromium project.
  • +
  • [319835] High CVE-2013-6639: Out of bounds write in v8. This + issue was fixed in v8 version 3.22.24.7. Credit to Jakob Kummerow + of the Chromium project.
  • +
  • [319860] Medium CVE-2013-6640: Out of bounds read in v8. This + issue was fixed in v8 version 3.22.24.7. Credit to Jakob Kummerow + of the Chromium project.
  • +
+
+ +
+ + CVE-2013-6634 + CVE-2013-6635 + CVE-2013-6636 + CVE-2013-6637 + CVE-2013-6638 + CVE-2013-6639 + CVE-2013-6640 + http://googlechromereleases.blogspot.nl/ + + + 2013-12-04 + 2013-12-05 + +
+ Joomla! -- Core XSS Vulnerabilities -- cgit