FreeBSD : chromium -- multiple vulnerabilities (371bbea9-3836-4832-9e70-e8e928727f8c)

high Nessus Plugin ID 88067

Synopsis

The remote FreeBSD host is missing one or more security-related updates.

Description

Google Chrome Releases reports :

This update includes 37 security fixes, including :

- [497632] High CVE-2016-1612: Bad cast in V8.

- [572871] High CVE-2016-1613: Use-after-free in PDFium.

- [544691] Medium CVE-2016-1614: Information leak in Blink.

- [468179] Medium CVE-2016-1615: Origin confusion in Omnibox.

- [541415] Medium CVE-2016-1616: URL Spoofing.

- [544765] Medium CVE-2016-1617: History sniffing with HSTS and CSP.

- [552749] Medium CVE-2016-1618: Weak random number generator in Blink.

- [557223] Medium CVE-2016-1619: Out-of-bounds read in PDFium.

- [579625] CVE-2016-1620: Various fixes from internal audits, fuzzing and other initiatives.

- Multiple vulnerabilities in V8 fixed at the tip of the 4.8 branch.

Solution

Update the affected packages.

See Also

http://www.nessus.org/u?be197a18

http://www.nessus.org/u?c8407975

Plugin Details

Severity: High

ID: 88067

File Name: freebsd_pkg_371bbea9383648329e70e8e928727f8c.nasl

Version: 2.8

Type: local

Published: 1/22/2016

Updated: 1/4/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: High

Base Score: 9.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS v3

Risk Factor: High

Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:chromium, p-cpe:/a:freebsd:freebsd:chromium-npapi, p-cpe:/a:freebsd:freebsd:chromium-pulse, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 1/21/2016

Vulnerability Publication Date: 1/20/2016

Reference Information

CVE: CVE-2016-1612, CVE-2016-1613, CVE-2016-1614, CVE-2016-1615, CVE-2016-1616, CVE-2016-1617, CVE-2016-1618, CVE-2016-1619, CVE-2016-1620