aboutsummaryrefslogtreecommitdiffstats
path: root/security
diff options
context:
space:
mode:
authoraraujo <araujo@FreeBSD.org>2009-04-19 01:20:19 +0800
committeraraujo <araujo@FreeBSD.org>2009-04-19 01:20:19 +0800
commitaa8cd4a1b7bd716cb9f205fd59588363d179c6be (patch)
tree72a06a54dac2d6cc64102060d0af46ccc57321a7 /security
parent45ca7271fd4ebf135b53899ace282dd094e04462 (diff)
downloadfreebsd-ports-gnome-aa8cd4a1b7bd716cb9f205fd59588363d179c6be.tar.gz
freebsd-ports-gnome-aa8cd4a1b7bd716cb9f205fd59588363d179c6be.tar.zst
freebsd-ports-gnome-aa8cd4a1b7bd716cb9f205fd59588363d179c6be.zip
- Document xpdf -- multiple vulnerabilities
Approved by: portmgr (erwin)
Diffstat (limited to 'security')
-rw-r--r--security/vuxml/vuln.xml40
1 files changed, 40 insertions, 0 deletions
diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml
index a93d5d5dd2fd..d56787ca41d8 100644
--- a/security/vuxml/vuln.xml
+++ b/security/vuxml/vuln.xml
@@ -34,6 +34,46 @@ Note: Please add new entries to the beginning of this file.
-->
<vuxml xmlns="http://www.vuxml.org/apps/vuxml-1">
+ <vuln vid="a21037d5-2c38-11de-ab3b-0017a4cccfc6">
+ <topic> xpdf -- multiple vulnerabilities</topic>
+ <affects>
+ <package>
+ <name>xpdf</name>
+ <range><lt>3.02_11</lt></range>
+ </package>
+ </affects>
+ <description>
+ <body xmlns="http://www.w3.org/1999/xhtml">
+ <p>Vupen reports:</p>
+ <blockquote cite="http://www.vupen.com/english/advisories/2009/1065">
+ <p>Multiple vulnerabilities have been identified in Xpdf, which could
+ be exploited by attackers to cause a denial of service or compromise
+ a vulnerable system. These issues are caused by buffer and integer
+ overflows, and memory corruption errors in the "xpdf/JIG2Stream.cc"
+ file when processing specially crafted data, which could be exploited
+ by attackers to crash an affected application or execute arbitrary
+ code by tricking a user into opening a malicious PDF file.</p>
+ </blockquote>
+ </body>
+ </description>
+ <references>
+ <cvename>CVE-2009-0146</cvename>
+ <cvename>CVE-2009-0147</cvename>
+ <cvename>CVE-2009-0166</cvename>
+ <cvename>CVE-2009-0799</cvename>
+ <cvename>CVE-2009-0800</cvename>
+ <cvename>CVE-2009-1179</cvename>
+ <cvename>CVE-2009-1180</cvename>
+ <cvename>CVE-2009-1181</cvename>
+ <cvename>CVE-2009-1182</cvename>
+ <cvename>CVE-2009-1183</cvename>
+ </references>
+ <dates>
+ <discovery>2009-04-16</discovery>
+ <entry>2009-04-18</entry>
+ </dates>
+ </vuln>
+
<vuln vid="20b4f284-2bfc-11de-bdeb-0030843d3802">
<topic>freetype2 -- multiple vulnerabilities</topic>
<affects>