aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorcrees <crees@FreeBSD.org>2012-06-05 18:47:38 +0800
committercrees <crees@FreeBSD.org>2012-06-05 18:47:38 +0800
commitd7d690ee7fb6ecf7a7766c985d789808548cafde (patch)
tree4fe352d7ed1f6dcb944e16fab4dc489e5260deff
parent7bde634568d23cce47e3a0cd61ee5c16d4fe2064 (diff)
downloadfreebsd-ports-gnome-d7d690ee7fb6ecf7a7766c985d789808548cafde.tar.gz
freebsd-ports-gnome-d7d690ee7fb6ecf7a7766c985d789808548cafde.tar.zst
freebsd-ports-gnome-d7d690ee7fb6ecf7a7766c985d789808548cafde.zip
Document sympa vulnerability
-rw-r--r--security/vuxml/vuln.xml34
1 files changed, 34 insertions, 0 deletions
diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml
index 72886b28dbab..3c77a7338469 100644
--- a/security/vuxml/vuln.xml
+++ b/security/vuxml/vuln.xml
@@ -52,6 +52,40 @@ Note: Please add new entries to the beginning of this file.
-->
<vuxml xmlns="http://www.vuxml.org/apps/vuxml-1">
+ <vuln vid="de6d8290-aef7-11e1-898f-14dae938ec40">
+ <topic>mail/sympa* -- Multiple vulnerabilities in Sympa archive management</topic>
+ <affects>
+ <package>
+ <name>sympa</name>
+ <range><lt>6.0.7</lt></range>
+ <range><gt>6.1.*</gt><lt>6.1.11</lt></range>
+ </package>
+ </affects>
+ <description>
+ <body xmlns="http://www.w3.org/1999/xhtml">
+ <p>David Verdin reports:</p>
+ <blockquote cite="http://www.sympa.org/security_advisories#security_breaches_in_archives_management">
+ <p>Multiple vulnerabilities have been discovered in Sympa archive
+ management that allow to skip the scenario-based authorization
+ mechanisms.</p>
+ <p>This breach allows to:</p>
+ <ul>
+ <li>display the archives management page ('arc_manage')</li>
+ <li>download the list's archives</li>
+ <li>delete the list's archives</li>
+ </ul>
+ </blockquote>
+ </body>
+ </description>
+ <references>
+ <url>http://www.sympa.org/security_advisories#security_breaches_in_archives_management</url>
+ </references>
+ <dates>
+ <discovery>2012-05-15</discovery>
+ <entry>2012-06-05</entry>
+ </dates>
+ </vuln>
+
<vuln vid="1ecc0d3f-ae8e-11e1-965b-0024e88a8c98">
<topic>dns/bind9* -- zero-length RDATA can cause named to terminate, reveal memory</topic>
<affects>