Date: Sun, 5 Jul 2020 00:45:52 +0000 (UTC) From: "Timur I. Bakeyev" <timur@FreeBSD.org> To: ports-committers@freebsd.org, svn-ports-all@freebsd.org, svn-ports-head@freebsd.org Subject: svn commit: r541244 - head/security/vuxml Message-ID: <202007050045.0650jqre009053@repo.freebsd.org>
next in thread | raw e-mail | index | archive | help
Author: timur Date: Sun Jul 5 00:45:52 2020 New Revision: 541244 URL: https://svnweb.freebsd.org/changeset/ports/541244 Log: Add entry about Samba vulnerabilities CVE-2020-10730, CVE-2020-10745, CVE-2020-10760, CVE-2020-14303 PR: 247725 Security: CVE-2020-10730 CVE-2020-10745 CVE-2020-10760 CVE-2020-14303 Modified: head/security/vuxml/vuln.xml Modified: head/security/vuxml/vuln.xml ============================================================================== --- head/security/vuxml/vuln.xml Sun Jul 5 00:27:27 2020 (r541243) +++ head/security/vuxml/vuln.xml Sun Jul 5 00:45:52 2020 (r541244) @@ -58,6 +58,52 @@ Notes: * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> <vuxml xmlns="http://www.vuxml.org/apps/vuxml-1"> + <vuln vid="ae599263-bca2-11ea-b78f-b42e99a1b9c3"> + <topic>samba -- Multiple Vulnerabilities</topic> + <affects> + <package> + <name>samba410</name> + <range><lt>4.10.17</lt></range> + </package> + <package> + <name>samba411</name> + <range><lt>4.11.11</lt></range> + </package> + <package> + <name>samba412</name> + <range><lt>4.12.4</lt></range> + </package> + </affects> + <description> + <body xmlns="http://www.w3.org/1999/xhtml"> + <p>The Samba Team reports:</p> + <blockquote cite="https://www.samba.org/samba/history/security.html"> + <p>Four vulnerabilities were fixed in samba:</p> + <ul> + <li>CVE-2020-10730: NULL pointer de-reference and use-after-free in Samba AD DC LDAP Server with ASQ, VLV and paged_results</li> + <li>CVE-2020-10745: Parsing and packing of NBT and DNS packets can consume excessive CPU in the AD DC (only)</li> + <li>CVE-2020-10760: LDAP Use-after-free in Samba AD DC Global Catalog with paged_results and VLV</li> + <li>CVE-2020-14303: Empty UDP packet DoS in Samba AD DC nbtd</li> + </ul> + </blockquote> + </body> + </description> + <references> + <url>https://www.samba.org/samba/security/CVE-2020-10730.html</url> + <url>https://www.samba.org/samba/security/CVE-2020-10745.html</url> + <url>https://www.samba.org/samba/security/CVE-2020-10760.html</url> + <url>https://www.samba.org/samba/security/CVE-2020-14303.html</url> + <cvename>CVE-2020-10730</cvename> + <cvename>CVE-2020-10745</cvename> + <cvename>CVE-2020-10760</cvename> + <cvename>CVE-2020-14303</cvename> + </references> + <dates> + <discovery>2020-07-02</discovery> + <entry>2020-07-02</entry> + </dates> + </vuln> + <vuln vid="4344861a-be0b-11ea-9172-4c72b94353b5"> <topic>Anydesk -- Multiple Vulnerabilities</topic> <affects>
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?202007050045.0650jqre009053>