diff options
author | naddy <naddy@FreeBSD.org> | 2014-11-26 05:42:42 +0800 |
---|---|---|
committer | naddy <naddy@FreeBSD.org> | 2014-11-26 05:42:42 +0800 |
commit | affb20cd1819e3cb310150d4a72cccaacc7fc419 (patch) | |
tree | e0f7afee5bf1298a8bf38195999a28d044794f00 /security | |
parent | a4ea348cd16249bc5e7d3e266ff4cd1a5f1668d0 (diff) | |
download | freebsd-ports-gnome-affb20cd1819e3cb310150d4a72cccaacc7fc419.tar.gz freebsd-ports-gnome-affb20cd1819e3cb310150d4a72cccaacc7fc419.tar.zst freebsd-ports-gnome-affb20cd1819e3cb310150d4a72cccaacc7fc419.zip |
Document CVE-2014-8962 and CVE-2014-9028 in audio/flac.
Diffstat (limited to 'security')
-rw-r--r-- | security/vuxml/vuln.xml | 33 |
1 files changed, 33 insertions, 0 deletions
diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index 7d14e5209abd..fbc4070dec5b 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -57,6 +57,39 @@ Notes: --> <vuxml xmlns="http://www.vuxml.org/apps/vuxml-1"> + <vuln vid="a33addf6-74e6-11e4-a615-f8b156b6dcc8"> + <topic>flac -- Multiple vulnerabilities</topic> + <affects> + <package> + <name>flac</name> + <range><lt>1.3.0_3</lt></range> + </package> + </affects> + <description> + <body xmlns="http://www.w3.org/1999/xhtml"> + <p>Erik de Castro Lopo reports:</p> + <blockquote cite="http://lists.xiph.org/pipermail/flac-dev/2014-November/005226.html"> + <p>Google Security Team member, Michele Spagnuolo, recently + found two potential problems in the FLAC code base. They are:</p> + <ul> + <li>CVE-2014-9028: Heap buffer write overflow.</li> + <li>CVE-2014-8962: Heap buffer read overflow.</li> + </ul> + </blockquote> + </body> + </description> + <references> + <url>https://git.xiph.org/?p=flac.git;a=commit;h=5b3033a2b355068c11fe637e14ac742d273f076e</url> + <cvename>CVE-2014-8962</cvename> + <url>https://git.xiph.org/?p=flac.git;a=commit;h=fcf0ba06ae12ccd7c67cee3c8d948df15f946b85</url> + <cvename>CVE-2014-9028</cvename> + </references> + <dates> + <discovery>2014-11-25</discovery> + <entry>2014-11-25</entry> + </dates> + </vuln> + <vuln vid="7bfd797c-716d-11e4-b008-001999f8d30b"> <topic>asterisk -- Multiple vulnerabilities</topic> <affects> |