aboutsummaryrefslogtreecommitdiffstats
path: root/security/vuxml
diff options
context:
space:
mode:
authorfeld <feld@FreeBSD.org>2015-09-24 04:24:28 +0800
committerfeld <feld@FreeBSD.org>2015-09-24 04:24:28 +0800
commit148969552e49db2446bf7ce282cd218861016200 (patch)
treed9e730b6f7e335efa2d6bbc93ddefa6d6b5b961a /security/vuxml
parentaf5a2e1476924ca3c168d80b7ed459b5951c8062 (diff)
downloadfreebsd-ports-gnome-148969552e49db2446bf7ce282cd218861016200.tar.gz
freebsd-ports-gnome-148969552e49db2446bf7ce282cd218861016200.tar.zst
freebsd-ports-gnome-148969552e49db2446bf7ce282cd218861016200.zip
Fix older ruby vuxml entry
If you follow official instructions to change your default ruby version it alters the ruby package name and vuxml will produce false positives. This change will solve these scenarios. PR: 203227
Diffstat (limited to 'security/vuxml')
-rw-r--r--security/vuxml/vuln.xml10
1 files changed, 7 insertions, 3 deletions
diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml
index 26c528be5a9f..4beb71312e49 100644
--- a/security/vuxml/vuln.xml
+++ b/security/vuxml/vuln.xml
@@ -10304,16 +10304,19 @@ Notes:
<topic>Ruby -- OpenSSL Hostname Verification Vulnerability</topic>
<affects>
<package>
+ <name>ruby</name>
<name>ruby20</name>
- <range><lt>2.0.0.645,1</lt></range>
+ <range><ge>2.0,1</ge><lt>2.0.0.645,1</lt></range>
</package>
<package>
<name>ruby</name>
- <range><lt>2.1.6,1</lt></range>
+ <name>ruby21</name>
+ <range><ge>2.1,1</ge><lt>2.1.6,1</lt></range>
</package>
<package>
+ <name>ruby</name>
<name>ruby22</name>
- <range><lt>2.2.2,1</lt></range>
+ <range><ge>2.2,1</ge><lt>2.2.2,1</lt></range>
</package>
</affects>
<description>
@@ -10337,6 +10340,7 @@ Notes:
<dates>
<discovery>2015-04-13</discovery>
<entry>2015-04-14</entry>
+ <modified>2015-09-23</modified>
</dates>
</vuln>