From owner-freebsd-security@FreeBSD.ORG Thu Apr 23 16:10:34 2015 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id EE5CAC4C for ; Thu, 23 Apr 2015 16:10:34 +0000 (UTC) Received: from mail-oi0-x22b.google.com (mail-oi0-x22b.google.com [IPv6:2607:f8b0:4003:c06::22b]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (Client CN "smtp.gmail.com", Issuer "Google Internet Authority G2" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id C17F71228 for ; Thu, 23 Apr 2015 16:10:34 +0000 (UTC) Received: by oiko83 with SMTP id o83so18390681oik.1 for ; Thu, 23 Apr 2015 09:10:34 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:date:message-id:subject:from:to:content-type; bh=0sL6TdFLH9j7GZlydIzqN8oj3H7rcY4oklWyT9hyPUY=; b=rwyWEQbTaUnaorbe8p16MbvkSHEn+AODtv4DK28tYNjenZ84+fhz1MOSRTehzxTkLU QLWi156IVXoD/MOQz86ilUWELsGom6ZXddr92OqLrXl4JaEvgbEh04oUxPLrbzWD0V6B zBRoDlf3WefVpEHBJXv2gAqJOFM+S6k4LZEDsd2NIoJpphH1x1ZrZ04oEc14wtlie8y0 d1Ds+AaLG4exUDada5npvrXItL9xckm4rhH4I7AAuy4Pjlm3WV2w6fLTf8HhoGJAv9AB 48+ZhhWHu3/tXsqRhv/SFfc65ozosLg36trSMBrsQR/BKab1bpqYfjpNRDnjKeB3ayIf x4wg== MIME-Version: 1.0 X-Received: by 10.202.223.131 with SMTP id w125mr2957037oig.108.1429805434020; Thu, 23 Apr 2015 09:10:34 -0700 (PDT) Received: by 10.76.86.42 with HTTP; Thu, 23 Apr 2015 09:10:33 -0700 (PDT) Date: Thu, 23 Apr 2015 17:10:33 +0100 Message-ID: Subject: base/release/10.1.0/contrib/file vulnerabilities? From: "Sevan / Venture37" To: freebsd-security@freebsd.org Content-Type: text/plain; charset=UTF-8 X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.20 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 23 Apr 2015 16:10:35 -0000 Hi, I raised a bug report about CVE-2014-9620, CVE-2014-9621 & CVE-2014-9653 in base/release/10.1.0/contrib/file but yet to hear a response, I was wondering if anyone here could shed some light on the issue. https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=198912 Regards Sevan / Venture37