aboutsummaryrefslogtreecommitdiffstats
path: root/security
diff options
context:
space:
mode:
authorbrnrd <brnrd@FreeBSD.org>2016-11-02 16:11:15 +0800
committerbrnrd <brnrd@FreeBSD.org>2016-11-02 16:11:15 +0800
commita3fa386bf78105d7d8f80896eaa81faca4e469bf (patch)
tree5c9189ce75a090fb8b753334f137e272adae4147 /security
parentb9fa7b5b2ef914bf1ced8e7b8be94d9f4ecef842 (diff)
downloadfreebsd-ports-graphics-a3fa386bf78105d7d8f80896eaa81faca4e469bf.tar.gz
freebsd-ports-graphics-a3fa386bf78105d7d8f80896eaa81faca4e469bf.tar.zst
freebsd-ports-graphics-a3fa386bf78105d7d8f80896eaa81faca4e469bf.zip
security/vuxml: Document 2016-11-02 cURL vulnerabilities
Diffstat (limited to 'security')
-rw-r--r--security/vuxml/vuln.xml48
1 files changed, 48 insertions, 0 deletions
diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml
index 3f4a8e2361d..f0f68f06cfd 100644
--- a/security/vuxml/vuln.xml
+++ b/security/vuxml/vuln.xml
@@ -58,6 +58,54 @@ Notes:
* Do not forget port variants (linux-f10-libxml2, libxml2, etc.)
-->
<vuxml xmlns="http://www.vuxml.org/apps/vuxml-1">
+ <vuln vid="765feb7d-a0d1-11e6-a881-b499baebfeaf">
+ <topic>cURL -- multiple vulnerabilities</topic>
+ <affects>
+ <package>
+ <name>curl</name>
+ <range><ge>7.1</ge><lt>7.51.0</lt></range>
+ </package>
+ </affects>
+ <description>
+ <body xmlns="http://www.w3.org/1999/xhtml">
+ <p>The cURL project reports</p>
+ <blockquote cite="https://curl.haxx.se/docs/security.html">
+ <ul>
+ <li>cookie injection for other servers</li>
+ <li>case insensitive password comparison</li>
+ <li>OOB write via unchecked multiplication</li>
+ <li>double-free in curl_maprintf</li>
+ <li>double-free in krb5 code</li>
+ <li>glob parser write/read out of bounds</li>
+ <li>curl_getdate read out of bounds</li>
+ <li>URL unescape heap overflow via integer truncation</li>
+ <li>Use-after-free via shared cookies</li>
+ <li>invalid URL parsing with '#'</li>
+ <li>IDNA 2003 makes curl use wrong host</li>
+ </ul>
+ </blockquote>
+ </body>
+ </description>
+ <references>
+ <url>https://curl.haxx.se/docs/security.html</url>
+ <cvename>CVE-2016-8615</cvename>
+ <cvename>CVE-2016-8616</cvename>
+ <cvename>CVE-2016-8617</cvename>
+ <cvename>CVE-2016-8618</cvename>
+ <cvename>CVE-2016-8619</cvename>
+ <cvename>CVE-2016-8620</cvename>
+ <cvename>CVE-2016-8621</cvename>
+ <cvename>CVE-2016-8622</cvename>
+ <cvename>CVE-2016-8623</cvename>
+ <cvename>CVE-2016-8624</cvename>
+ <cvename>CVE-2016-8625</cvename>
+ </references>
+ <dates>
+ <discovery>2016-11-02</discovery>
+ <entry>2016-11-02</entry>
+ </dates>
+ </vuln>
+
<vuln vid="0b8d01a4-a0d2-11e6-9ca2-d050996490d0">
<topic>BIND -- Remote Denial of Service vulnerability</topic>
<affects>
2:30 +0800'>2010-02-073-4/+13 * - update to jpeg-8dinoex2010-02-057-4/+7 * Add missing runtime dependency on qt4-imageformats.makc2010-01-241-2/+3 * - Fix handling of common directories in plistfluffy2009-12-226-76/+68 * - Connect koffice-kde4-l10n to the buildmiwi2009-12-221-0/+1 * The FreeBSD KDE is please to announce the release of KDE 4.3.4,miwi2009-12-023-4/+191 * - Add missing Manpagesmiwi2009-11-271-0/+9 * The KDE FreeBSD team is proud to announce the release of KDE 4.3.3miwi2009-11-273-5/+545 * The FreeBSD KDE is please to announce the release of KDE 4.3.1,tabthorpe2009-09-022-12/+110 * - Switch SourceForge ports to the new File Release System: categories startin...amdmi32009-08-224-6/+4 * clean upmakc2009-08-081-3/+0 * - Fix build with qt 4.5miwi2009-08-051-2/+2 * The KDE FreeBSD team is proud to announce the release of KDE 4.3.0miwi2009-08-053-148/+45 * - bump all port that indirectly depends on libjpeg and have not yet been bump...dinoex2009-07-317-2/+7 * The KDE FreeBSD team is pleased to announce KDE 4.2.4, the last bugfixmiwi2009-06-031-3/+3 * Remove qt4 build tools from run dependencies.makc2009-05-282-2/+4 * - Restore patch to fix the buildmiwi2009-05-171-0/+11 * - Update to 0.6.5.2miwi2009-05-177-80/+32 * Update KDE ports to 4.2.3makc2009-05-102-3/+104 * Connect qfaktury to buildmakc2009-05-081-0/+1 * Add new port polish/qfaktury:makc2009-05-086-0/+120 * - Drop maintainershipmiwi2009-05-051-1/+1 * Remove expired port polish/gnugadu: use polish/gnugadu2 instead.linimon2009-04-125-117/+0 * The KDE FreeBSD team is proud to announce the release of KDE 4.2.2miwi2009-04-022-7/+13 * bump PORTREVISION after cmake updatemakc2009-03-251-0/+1 * Fix build on 6-STABLE after adding --with-pthread to polish/libgadumakc2009-03-222-2/+2 * Update to 0.6.5.1makc2009-03-168-328/+139 * Enable pthread to fix crash in Kopetemakc2009-03-161-1/+2 * Update KDE to 4.2.1.makc2009-03-092-3/+32 * The KDE FreeBSD team is proud to announce the release of KDE 4.2.0miwi2009-02-092-202/+57 * - Update X.org ports to 7.4+ (few ports are more recent than the katamari).flz2009-01-241-1/+1 * Bump the version of the curl shared library after the ftp/curl updateroam2009-01-231-1/+2 * kde@freebsd team is pleased to announce KDE 4.1.4, the last bugfix release in...makc2009-01-143-6/+160 * - Update to 1.8.2miwi2008-11-092-4/+4 * Assign to new maintainer.linimon2008-09-052-2/+2 * The KDE FreeBSD team is proud to announce the release of KDE 4.1.1miwi2008-09-032-9/+11 * Reset alex@bsdguru.org due to maintainer-timeouts and no response to email.linimon2008-09-035-5/+5 * The KDE FreeBSD team is proud to announce the releasemiwi2008-08-292-3/+6 * Update CONFIGURE_ARGS for how we pass CONFIGURE_TARGET to configure script.rafan2008-08-211-1/+0 * The KDE FreeBSD team is proud to announce the releasemiwi2008-08-182-10/+66 * - Fix categoriemiwi2008-08-101-1/+1 * The KDE FreeBSD team is proud to announce the release of KDE 4.1.0miwi2008-08-105-1506/+219 * - Update to 1.8.1.lippe2008-07-272-5/+4 * - Remove USE_GCC where it can be satisfied with base compiler on followingpav2008-07-252-2/+0 * - Remove duplicates from MAKE_ENV after inclusion of CC and CXX in default MA...pav2008-07-251-2/+2 * - Update to 0.6.0.2rafan2008-07-143-41/+8 * Fix pkg-plistedwin2008-07-051-0/+2 * Add QT component rccedwin2008-07-051-1/+1 * [NEW PORT] polish/qnapiedwin2008-07-059-0/+151 * Bump portrevision due to upgrade of devel/gettext.edwin2008-06-066-3/+6 * - Unbreak after latest polish/libgadu commitrafan2008-05-192-33/+15 * - Fix SSL bug and unbreak polish/gnugadu2 too.lippe2008-05-171-3/+14 * - Add openssl optionbeech2008-04-241-2/+7 * - Remove unneeded dependency from gtk12/gtk20 [1]miwi2008-04-205-13/+11 * - Mark BROKEN: does not configurepav2008-04-171-0/+2 * - Fix build with gcc 4rafan2008-04-041-0/+14 * - Update to 0.6.0pav2008-03-275-134/+325 * - Add missing dependensmiwi2008-03-271-1/+2 * - Upgrade to 1.8.0.lippe2008-03-264-12/+19 * - Remove USE_XLIB/USE_X_PREFIX/USE_XPM in favor of USE_XORGmiwi2008-03-241-1/+0 * - Remove USE_XLIB/USE_X_PREFIX/USE_XPM in favor of USE_XORGmiwi2008-03-231-1/+0 * Update to KDE 3.5.8lofi2007-10-304-8/+62 * Presenting GNOME 2.20.1 and all related works for FreeBSD. The officialmarcus2007-10-253-13/+3 * Remove always-false/true conditions based on OSVERSION 500000edwin2007-10-041-3/+0 * - Update to 0.1.1.trasz2007-09-08