diff options
author | crees <crees@FreeBSD.org> | 2011-08-13 23:02:29 +0800 |
---|---|---|
committer | crees <crees@FreeBSD.org> | 2011-08-13 23:02:29 +0800 |
commit | 3f37e5016662a202cf9d5581aae5315894a77966 (patch) | |
tree | 8c4b504ef31b0f0e4d2d094730aa7b008c9c4a63 /security/vuxml | |
parent | 66b2b241b4cc9275a627f4cd390d80a379910cd3 (diff) | |
download | freebsd-ports-gnome-3f37e5016662a202cf9d5581aae5315894a77966.tar.gz freebsd-ports-gnome-3f37e5016662a202cf9d5581aae5315894a77966.tar.zst freebsd-ports-gnome-3f37e5016662a202cf9d5581aae5315894a77966.zip |
Document dtc security issues
PR: ports/159736
Submitted by: Ansgar Burchardt <ansgar@debian.org>
Diffstat (limited to 'security/vuxml')
-rw-r--r-- | security/vuxml/vuln.xml | 36 |
1 files changed, 36 insertions, 0 deletions
diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index 0d1d06aa3b89..67b995d5a543 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -34,6 +34,42 @@ Note: Please add new entries to the beginning of this file. --> <vuxml xmlns="http://www.vuxml.org/apps/vuxml-1"> + <vuln vid="879b0242-c5b6-11e0-abd1-0017f22d6707"> + <topic>dtc -- multiple vulnerabilities</topic> + <affects> + <package> + <name>dtc</name> + <range><lt>0.32.9</lt></range> + </package> + </affects> + <description> + <body xmlns="http://www.w3.org/1999/xhtml"> + <p>Ansgar Burchardt reports:</p> + <blockquote cite="http://www.debian.org/security/2011/dsa-2179"> + <p>Ansgar Burchardt discovered several vulnerabilities in DTC, a + web control panel for admin and accounting hosting services: + The bw_per_moth.php graph contains an SQL injection vulnerability; + Insufficient checks in bw_per_month.php can lead to bandwidth + usage information disclosure; After a registration, passwords are + sent in cleartext email messages and Authenticated users could + delete accounts using an obsolete interface which was incorrectly + included in the package.</p> + </blockquote> + </body> + </description> + <references> + <cvename>CVE-2011-0434</cvename> + <cvename>CVE-2011-0435</cvename> + <cvename>CVE-2011-0436</cvename> + <cvename>CVE-2011-0437</cvename> + <url>http://www.debian.org/security/2011/dsa-2179</url> + </references> + <dates> + <discovery>2011-03-02</discovery> + <entry>2011-08-13</entry> + </dates> + </vuln> + <vuln vid="304409c3-c3ef-11e0-8aa5-485d60cb5385"> <topic>libXfont -- possible local privilege escalation</topic> <affects> |