aboutsummaryrefslogtreecommitdiffstats
path: root/security
diff options
context:
space:
mode:
authordelphij <delphij@FreeBSD.org>2015-05-24 15:19:09 +0800
committerdelphij <delphij@FreeBSD.org>2015-05-24 15:19:09 +0800
commit069555f67267674b9cf6f0f44937d0fb0406f1e1 (patch)
treeabaa81aa50680dedabee3cadb225e4929d799d70 /security
parent1056b5b76bcefc3e883334ea053f4a95a27875bc (diff)
downloadfreebsd-ports-gnome-069555f67267674b9cf6f0f44937d0fb0406f1e1.tar.gz
freebsd-ports-gnome-069555f67267674b9cf6f0f44937d0fb0406f1e1.tar.zst
freebsd-ports-gnome-069555f67267674b9cf6f0f44937d0fb0406f1e1.zip
Extend CVE-2015-3456 to cover xen-tools (4.5.0-4.5.0_5: we didn't supported
the feature in earlier version of this port) and VirtualBox cases as well. PR: 200311
Diffstat (limited to 'security')
-rw-r--r--security/vuxml/vuln.xml13
1 files changed, 12 insertions, 1 deletions
diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml
index 313bb6980924..bba5e836e263 100644
--- a/security/vuxml/vuln.xml
+++ b/security/vuxml/vuln.xml
@@ -574,7 +574,7 @@ Notes:
</vuln>
<vuln vid="2780e442-fc59-11e4-b18b-6805ca1d3bb1">
- <topic>qemu -- possible VM escape and code execution ("VENOM")</topic>
+ <topic>qemu, xen and VirtualBox OSE -- possible VM escape and code execution ("VENOM")</topic>
<affects>
<package>
<name>qemu</name>
@@ -586,6 +586,14 @@ Notes:
<name>qemu-sbruno</name>
<range><lt>2.3.50.g20150501_1</lt></range>
</package>
+ <package>
+ <name>virtualbox-ose</name>
+ <range><lt>4.3.28</lt></range>
+ </package>
+ <package>
+ <name>xen-tools</name>
+ <range><gt>4.5.0</gt><lt>4.5.0_5</lt></range>
+ </package>
</affects>
<description>
<body xmlns="http://www.w3.org/1999/xhtml">
@@ -610,10 +618,13 @@ Notes:
<freebsdpr>200256</freebsdpr>
<freebsdpr>200257</freebsdpr>
<url>http://venom.crowdstrike.com/</url>
+ <url>http://www.oracle.com/technetwork/topics/security/alert-cve-2015-3456-2542656.html</url>
+ <url>http://xenbits.xen.org/xsa/advisory-133.html</url>
</references>
<dates>
<discovery>2015-04-29</discovery>
<entry>2015-05-17</entry>
+ <modified>2015-05-23</modified>
</dates>
</vuln>