aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rw-r--r--security/vuxml/vuln.xml34
1 files changed, 34 insertions, 0 deletions
diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml
index 40b34a0fb1ca..ebe57f051bad 100644
--- a/security/vuxml/vuln.xml
+++ b/security/vuxml/vuln.xml
@@ -34,6 +34,40 @@ Note: Please add new entries to the beginning of this file.
-->
<vuxml xmlns="http://www.vuxml.org/apps/vuxml-1">
+ <vuln vid="848539dc-0458-11df-8dd7-002170daae37">
+ <topic>dokuwiki -- multiple vulnerabilities</topic>
+ <affects>
+ <package>
+ <name>dokuwiki</name>
+ <range><lt>20091225_2</lt></range>
+ </package>
+ </affects>
+ <description>
+ <body xmlns="http://www.w3.org/1999/xhtml">
+ <p>Dokuwiki reports:</p>
+ <blockquote cite="http://bugs.splitbrain.org/index.php?do=details&amp;task_id=1853">
+ <p>The plugin does no checks against cross-site request
+ forgeries (CSRF) which can be exploited to e.g. change
+ the access control rules by tricking a logged in
+ administrator into visiting a malicious web site.</p>
+ </blockquote>
+ <blockquote cite="http://bugs.splitbrain.org/index.php?do=details&amp;task_id=1847">
+ <p>The bug allows listing the names of arbitrary file on
+ the webserver - not their contents. This could leak
+ private information about wiki pages and server structure.</p>
+ </blockquote>
+ </body>
+ </description>
+ <references>
+ <url>http://bugs.splitbrain.org/index.php?do=details&amp;task_id=1847</url>
+ <url>http://bugs.splitbrain.org/index.php?do=details&amp;task_id=1853</url>
+ </references>
+ <dates>
+ <discovery>2010-01-17</discovery>
+ <entry>2010-01-18</entry>
+ </dates>
+ </vuln>
+
<vuln vid="c9263916-006f-11df-94cb-0050568452ac">
<topic>Zend Framework -- multiple vulnerabilities</topic>
<affects>
s='deletions'>-1/+1 * Chase editors/emacs update.ashish2011-08-281-1/+1 * - Get Rid MD5 supportmiwi2011-03-201-1/+0 * - update to 1.4.1dinoex2010-03-281-1/+1 * - update to jpeg-8dinoex2010-02-051-1/+1 * Fix build error with xemacs21-mule.nobutaka2010-01-271-0/+1 * Changes to editors/emacs and Mk/bsd.emacs.mk were taken frombsam2009-12-211-2/+3 * Update to 1.14.9.nobutaka2009-09-232-5/+4 * - bump all port that indirectly depends on libjpeg and have not yet been bump...dinoex2009-07-311-1/+1 * Fix build error with WRKDIRPREFIX.nobutaka2009-05-181-16/+16 * Add build support for emacs-devel.nobutaka2009-02-221-2/+2 * Correct pkg-plist.* for NOPORTDOCS=yes.nobutaka2008-07-213-17/+17 * Bump portrevision due to upgrade of devel/gettext.edwin2008-06-06