diff options
author | crees <crees@FreeBSD.org> | 2012-06-05 18:47:38 +0800 |
---|---|---|
committer | crees <crees@FreeBSD.org> | 2012-06-05 18:47:38 +0800 |
commit | d7d690ee7fb6ecf7a7766c985d789808548cafde (patch) | |
tree | 4fe352d7ed1f6dcb944e16fab4dc489e5260deff | |
parent | 7bde634568d23cce47e3a0cd61ee5c16d4fe2064 (diff) | |
download | freebsd-ports-gnome-d7d690ee7fb6ecf7a7766c985d789808548cafde.tar.gz freebsd-ports-gnome-d7d690ee7fb6ecf7a7766c985d789808548cafde.tar.zst freebsd-ports-gnome-d7d690ee7fb6ecf7a7766c985d789808548cafde.zip |
Document sympa vulnerability
-rw-r--r-- | security/vuxml/vuln.xml | 34 |
1 files changed, 34 insertions, 0 deletions
diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index 72886b28dbab..3c77a7338469 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -52,6 +52,40 @@ Note: Please add new entries to the beginning of this file. --> <vuxml xmlns="http://www.vuxml.org/apps/vuxml-1"> + <vuln vid="de6d8290-aef7-11e1-898f-14dae938ec40"> + <topic>mail/sympa* -- Multiple vulnerabilities in Sympa archive management</topic> + <affects> + <package> + <name>sympa</name> + <range><lt>6.0.7</lt></range> + <range><gt>6.1.*</gt><lt>6.1.11</lt></range> + </package> + </affects> + <description> + <body xmlns="http://www.w3.org/1999/xhtml"> + <p>David Verdin reports:</p> + <blockquote cite="http://www.sympa.org/security_advisories#security_breaches_in_archives_management"> + <p>Multiple vulnerabilities have been discovered in Sympa archive + management that allow to skip the scenario-based authorization + mechanisms.</p> + <p>This breach allows to:</p> + <ul> + <li>display the archives management page ('arc_manage')</li> + <li>download the list's archives</li> + <li>delete the list's archives</li> + </ul> + </blockquote> + </body> + </description> + <references> + <url>http://www.sympa.org/security_advisories#security_breaches_in_archives_management</url> + </references> + <dates> + <discovery>2012-05-15</discovery> + <entry>2012-06-05</entry> + </dates> + </vuln> + <vuln vid="1ecc0d3f-ae8e-11e1-965b-0024e88a8c98"> <topic>dns/bind9* -- zero-length RDATA can cause named to terminate, reveal memory</topic> <affects> |