FreeBSD : chromium -- multiple vulnerabilities (371bbea9-3836-4832-9e70-e8e928727f8c)

High Nessus Plugin ID 88067


The remote FreeBSD host is missing one or more security-related updates.


Google Chrome Releases reports :

This update includes 37 security fixes, including :

- [497632] High CVE-2016-1612: Bad cast in V8.

- [572871] High CVE-2016-1613: Use-after-free in PDFium.

- [544691] Medium CVE-2016-1614: Information leak in Blink.

- [468179] Medium CVE-2016-1615: Origin confusion in Omnibox.

- [541415] Medium CVE-2016-1616: URL Spoofing.

- [544765] Medium CVE-2016-1617: History sniffing with HSTS and CSP.

- [552749] Medium CVE-2016-1618: Weak random number generator in Blink.

- [557223] Medium CVE-2016-1619: Out-of-bounds read in PDFium.

- [579625] CVE-2016-1620: Various fixes from internal audits, fuzzing and other initiatives.

- Multiple vulnerabilities in V8 fixed at the tip of the 4.8 branch.


Update the affected packages.

See Also

Plugin Details

Severity: High

ID: 88067

File Name: freebsd_pkg_371bbea9383648329e70e8e928727f8c.nasl

Version: $Revision: 2.6 $

Type: local

Published: 2016/01/22

Modified: 2016/10/19

Dependencies: 12634

Risk Information

Risk Factor: High


Base Score: 9.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C


Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:chromium, p-cpe:/a:freebsd:freebsd:chromium-npapi, p-cpe:/a:freebsd:freebsd:chromium-pulse, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 2016/01/21

Vulnerability Publication Date: 2016/01/20

Reference Information

CVE: CVE-2016-1612, CVE-2016-1613, CVE-2016-1614, CVE-2016-1615, CVE-2016-1616, CVE-2016-1617, CVE-2016-1618, CVE-2016-1619, CVE-2016-1620