aboutsummaryrefslogtreecommitdiffstats
path: root/security
diff options
context:
space:
mode:
authornobutaka <nobutaka@FreeBSD.org>2007-01-02 22:12:36 +0800
committernobutaka <nobutaka@FreeBSD.org>2007-01-02 22:12:36 +0800
commit235e02b85f6c63bcdcd5e1f1be0db106acb39e95 (patch)
treec2302229075d2ec4e5b46494ae395552bf6438b9 /security
parentcfc0b1f388a8976b7b71d1d9ad2e95ea30f55a86 (diff)
downloadfreebsd-ports-gnome-235e02b85f6c63bcdcd5e1f1be0db106acb39e95.tar.gz
freebsd-ports-gnome-235e02b85f6c63bcdcd5e1f1be0db106acb39e95.tar.zst
freebsd-ports-gnome-235e02b85f6c63bcdcd5e1f1be0db106acb39e95.zip
Document a format string vulnerability of w3m.
Diffstat (limited to 'security')
-rw-r--r--security/vuxml/vuln.xml35
1 files changed, 35 insertions, 0 deletions
diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml
index aaa73d842cf3..27d33d57cfa1 100644
--- a/security/vuxml/vuln.xml
+++ b/security/vuxml/vuln.xml
@@ -34,6 +34,41 @@ Note: Please add new entries to the beginning of this file.
-->
<vuxml xmlns="http://www.vuxml.org/apps/vuxml-1">
+ <vuln vid="9347d82d-9a66-11db-b271-000e35248ad7">
+ <topic>w3m -- format string vulnerability</topic>
+ <affects>
+ <package>
+ <name>w3m</name>
+ <name>w3m-img</name>
+ <name>w3m-m17n</name>
+ <name>w3m-m17n-img</name>
+ <name>ja-w3m</name>
+ <name>ja-w3m-img</name>
+ <range><lt>0.5.1_6</lt></range>
+ </package>
+ </affects>
+ <description>
+ <body xmlns="http://www.w3.org/1999/xhtml">
+ <p>An anonymous person reports:</p>
+ <blockquote cite="http://sourceforge.net/tracker/index.php?func=detail&aid=1612792&group_id=39518&atid=425439">
+ <p>w3m-0.5.1 crashes when using the -dump or -backend options to
+ open a HTTPS URL with a SSL certificate where the CN contains
+ "%n%n%n%n%n%n".</p>
+ </blockquote>
+ </body>
+ </description>
+ <references>
+ <bid>21735</bid>
+ <cvename>CVE-2006-6772</cvename>
+ <url>http://sourceforge.net/tracker/index.php?func=detail&aid=1612792&group_id=39518&atid=425439</url>
+ <url>http://secunia.com/advisories/23492/</url>
+ </references>
+ <dates>
+ <discovery>2006-12-10</discovery>
+ <entry>2007-01-02</entry>
+ </dates>
+ </vuln>
+
<vuln vid="f4ff7434-9505-11db-9ddc-0011098b2f36">
<topic>plone -- user can masquerade as a group</topic>
<affects>