FreeBSD : www/chromium -- multiple vulnerabilities (d46ed7b8-1912-11e5-9fdf-00262d5ed8ee)

medium Nessus Plugin ID 84327

Synopsis

The remote FreeBSD host is missing one or more security-related updates.

Description

Google Chrome Releases reports :

4 security fixes in this release :

- [464922] High CVE-2015-1266: Scheme validation error in WebUI.
Credit to anonymous.

- [494640] High CVE-2015-1268: Cross-origin bypass in Blink. Credit to Mariusz Mlynski.

- [497507] Medium CVE-2015-1267: Cross-origin bypass in Blink. Credit to anonymous.

- [461481] Medium CVE-2015-1269: Normalization error in HSTS/HPKP preload list. Credit to Mike Ruddy.

Solution

Update the affected packages.

See Also

http://www.nessus.org/u?4d980895

http://www.nessus.org/u?c76156a6

Plugin Details

Severity: Medium

ID: 84327

File Name: freebsd_pkg_d46ed7b8191211e59fdf00262d5ed8ee.nasl

Version: 2.10

Type: local

Published: 6/23/2015

Updated: 1/6/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:chromium, p-cpe:/a:freebsd:freebsd:chromium-npapi, p-cpe:/a:freebsd:freebsd:chromium-pulse, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 6/22/2015

Vulnerability Publication Date: 6/22/2015

Reference Information

CVE: CVE-2015-1266, CVE-2015-1267, CVE-2015-1268, CVE-2015-1269