From owner-svn-ports-all@FreeBSD.ORG Thu Mar 19 21:21:05 2015 Return-Path: Delivered-To: svn-ports-all@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id 9BAA7E5D; Thu, 19 Mar 2015 21:21:05 +0000 (UTC) Received: from svn.freebsd.org (svn.freebsd.org [IPv6:2001:1900:2254:2068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 6C5E2AD9; Thu, 19 Mar 2015 21:21:05 +0000 (UTC) Received: from svn.freebsd.org ([127.0.1.70]) by svn.freebsd.org (8.14.9/8.14.9) with ESMTP id t2JLL49B086316; Thu, 19 Mar 2015 21:21:04 GMT (envelope-from delphij@FreeBSD.org) Received: (from delphij@localhost) by svn.freebsd.org (8.14.9/8.14.9/Submit) id t2JLL4cJ086315; Thu, 19 Mar 2015 21:21:04 GMT (envelope-from delphij@FreeBSD.org) Message-Id: <201503192121.t2JLL4cJ086315@svn.freebsd.org> X-Authentication-Warning: svn.freebsd.org: delphij set sender to delphij@FreeBSD.org using -f From: Xin LI Date: Thu, 19 Mar 2015 21:21:04 +0000 (UTC) To: ports-committers@freebsd.org, svn-ports-all@freebsd.org, svn-ports-head@freebsd.org Subject: svn commit: r381694 - head/security/vuxml X-SVN-Group: ports-head MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-ports-all@freebsd.org X-Mailman-Version: 2.1.18-1 Precedence: list List-Id: SVN commit messages for the ports tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 19 Mar 2015 21:21:05 -0000 Author: delphij Date: Thu Mar 19 21:21:03 2015 New Revision: 381694 URL: https://svnweb.freebsd.org/changeset/ports/381694 QAT: https://qat.redports.org/buildarchive/r381694/ Log: Document OpenSSL multiple vulnerabilities. Modified: head/security/vuxml/vuln.xml Modified: head/security/vuxml/vuln.xml ============================================================================== --- head/security/vuxml/vuln.xml Thu Mar 19 21:11:38 2015 (r381693) +++ head/security/vuxml/vuln.xml Thu Mar 19 21:21:03 2015 (r381694) @@ -57,6 +57,57 @@ Notes: --> + + OpenSSL -- multiple vulnerabilities + + + openssl + 1.0.11.0.1_19 + + + mingw32-openssl + 1.0.11.0.1m + + + linux-c6-openssl + 0 + + + + +

OpenSSL project reports:

+
+

Reclassified: RSA silently downgrades to EXPORT_RSA + [Client] (CVE-2015-0204)

+

Segmentation fault in ASN1_TYPE_cmp (CVE-2015-0286)

+

ASN.1 structure reuse memory corruption (CVE-2015-0287)

+

PKCS7 NULL pointer dereferences (CVE-2015-0289)

+

Base64 decode (CVE-2015-0292)

+

DoS via reachable assert in SSLv2 servers + (CVE-2015-0293)

+

Use After Free following d2i_ECPrivatekey error + (CVE-2015-0209)

+

X509_to_X509_REQ NULL pointer deref (CVE-2015-0288)

+
+ +
+ + CVE-2015-0204 + CVE-2015-0286 + CVE-2015-0287 + CVE-2015-0289 + CVE-2015-0292 + CVE-2015-0293 + CVE-2015-0209 + CVE-2015-0288 + https://www.openssl.org/news/secadv_20150319.txt + + + 2015-03-19 + 2015-03-19 + +
+ libXfont -- BDF parsing issues