diff options
author | Matthias Andree <mandree@FreeBSD.org> | 2012-08-15 07:17:56 +0800 |
---|---|---|
committer | Matthias Andree <mandree@FreeBSD.org> | 2012-08-15 07:17:56 +0800 |
commit | 32fc11f5a8589f7f66283f2de220d761cca711d5 (patch) | |
tree | 59d6a063c6090bf59a7afccf51ff4602e066a379 /security | |
parent | b5cc599cbf4c14549ce59ea7454b97e57569cf09 (diff) | |
download | freebsd-ports-gnome-32fc11f5a8589f7f66283f2de220d761cca711d5.tar.gz freebsd-ports-gnome-32fc11f5a8589f7f66283f2de220d761cca711d5.tar.zst freebsd-ports-gnome-32fc11f5a8589f7f66283f2de220d761cca711d5.zip |
Document CVE-2012-3482 for fetchmail, one DoS and one information disclosure
vulnerability in non-default NTLM code.
Also see ports/170613 which is pending maintainer feedback.
Diffstat (limited to 'security')
-rw-r--r-- | security/vuxml/vuln.xml | 31 |
1 files changed, 31 insertions, 0 deletions
diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index c05d08090616..3e7514864559 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -52,6 +52,37 @@ Note: Please add new entries to the beginning of this file. --> <vuxml xmlns="http://www.vuxml.org/apps/vuxml-1"> + <vuln vid="83f9e943-e664-11e1-a66d-080027ef73ec"> + <topic>fetchmail -- two vulnerabilities in NTLM authentication</topic> + <affects> + <package> + <name>fetchmail</name> + <range><ge>5.0.8</ge><lt>6.3.22</lt></range> + </package> + </affects> + <description> + <body xmlns="http://www.w3.org/1999/xhtml"> + <p>Matthias Andree reports:</p> + <blockquote cite="http://gitorious.org/fetchmail/fetchmail/blobs/raw/legacy_63/fetchmail-SA-2012-02.txt"> + <p>With NTLM support enabled, fetchmail might mistake a server-side + error message during NTLM protocol exchange for protocol data, + leading to a SIGSEGV.</p> + <p>Also, with a carefully crafted NTLM challenge, a malicious server + might cause fetchmail to read from a bad memory location, betraying + confidential data. It is deemed hard, although not impossible, to + steal other accounts' data.</p> + </blockquote> + </body> + </description> + <references> + <cvename>CVE-2012-3482</cvename> + </references> + <dates> + <discovery>2012-08-12</discovery> + <entry>2012-08-14</entry> + </dates> + </vuln> + <vuln vid="55b498e2-e56c-11e1-bbd5-001c25e46b1d"> <topic>Several vulnerabilities found in IcedTea-Web</topic> <affects> |