From owner-svn-ports-all@FreeBSD.ORG Fri Jul 20 14:53:04 2012 Return-Path: Delivered-To: svn-ports-all@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 3A589106567E; Fri, 20 Jul 2012 14:53:04 +0000 (UTC) (envelope-from crees@FreeBSD.org) Received: from svn.freebsd.org (svn.freebsd.org [IPv6:2001:4f8:fff6::2c]) by mx1.freebsd.org (Postfix) with ESMTP id 0C0C08FC28; Fri, 20 Jul 2012 14:53:04 +0000 (UTC) Received: from svn.freebsd.org (localhost [127.0.0.1]) by svn.freebsd.org (8.14.4/8.14.4) with ESMTP id q6KEr3sL008138; Fri, 20 Jul 2012 14:53:03 GMT (envelope-from crees@svn.freebsd.org) Received: (from crees@localhost) by svn.freebsd.org (8.14.4/8.14.4/Submit) id q6KEr3nC008136; Fri, 20 Jul 2012 14:53:03 GMT (envelope-from crees@svn.freebsd.org) Message-Id: <201207201453.q6KEr3nC008136@svn.freebsd.org> From: Chris Rees Date: Fri, 20 Jul 2012 14:53:03 +0000 (UTC) To: ports-committers@freebsd.org, svn-ports-all@freebsd.org, svn-ports-head@freebsd.org X-SVN-Group: ports-head MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Cc: Subject: svn commit: r301228 - head/security/vuxml X-BeenThere: svn-ports-all@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: SVN commit messages for the ports tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 20 Jul 2012 14:53:04 -0000 Author: crees Date: Fri Jul 20 14:53:03 2012 New Revision: 301228 URL: http://svn.freebsd.org/changeset/ports/301228 Log: Document nsd vulnerability The referenced PR contains a fix that bumps PORTREVISION, so the entry will not match fixed versions. PR: ports/170024 Obtained from: http://www.nlnetlabs.nl/downloads/CVE-2012-2978.txt Security: CVE-2012-2978 Modified: head/security/vuxml/vuln.xml Modified: head/security/vuxml/vuln.xml ============================================================================== --- head/security/vuxml/vuln.xml Fri Jul 20 14:41:24 2012 (r301227) +++ head/security/vuxml/vuln.xml Fri Jul 20 14:53:03 2012 (r301228) @@ -52,6 +52,37 @@ Note: Please add new entries to the beg --> + + dns/nsd -- DoS vulnerability from non-standard DNS packet + + + nsd + 3.2.11_2 + + + + +

Marek Vavrusa and Lubos Slovak report:

+
+

It is possible to crash (SIGSEGV) a NSD child server process + by sending it a non-standard DNS packet from any host on the + internet. A crashed child process will automatically be restarted + by the parent process, but an attacker may keep the NSD server + occupied restarting child processes by sending it a stream of + such packets effectively preventing the NSD server to serve.

+
+ +
+ + CVE-2012-2978 + ports/170024 + + + 2012-07-19 + 2012-07-20 + +
+ libjpeg-turbo -- heap-based buffer overflow