diff options
author | nectar <nectar@FreeBSD.org> | 2005-02-12 07:29:30 +0800 |
---|---|---|
committer | nectar <nectar@FreeBSD.org> | 2005-02-12 07:29:30 +0800 |
commit | c6b04d5860dcf76c1139b4f648b0ef5c178e0ef1 (patch) | |
tree | 4442df632a3f2a7a311b16b3bfd554f76ac64af9 /security/vuxml | |
parent | 8d58338be3e2afd05ab5ad232e547df8722fe1f4 (diff) | |
download | freebsd-ports-gnome-c6b04d5860dcf76c1139b4f648b0ef5c178e0ef1.tar.gz freebsd-ports-gnome-c6b04d5860dcf76c1139b4f648b0ef5c178e0ef1.tar.zst freebsd-ports-gnome-c6b04d5860dcf76c1139b4f648b0ef5c178e0ef1.zip |
Expand HTML entity reference in latest VuXML entry.
Diffstat (limited to 'security/vuxml')
-rw-r--r-- | security/vuxml/vuln.xml | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index c7441831b6ab..d55680dcd255 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -44,7 +44,7 @@ EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. </affects> <description> <body xmlns="http://www.w3.org/1999/xhtml"> - <p>Erik Sjölund discovered several issues in enscript: + <p>Erik Sjölund discovered several issues in enscript: it suffers from several buffer overflows, quotes and shell escape characters are insufficiently sanitized in filenames, and it supported taking input from an arbitrary command |