Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 11 Jul 2018 13:26:57 -0400
From:      Jung-uk Kim <jkim@FreeBSD.org>
To:        "N.J. Mann" <njm@njm.me.uk>
Cc:        svn-ports-all@freebsd.org
Subject:   Re: svn commit: r474467 - head/security/vuxml
Message-ID:  <672e0d22-78e4-1499-a060-eaf0eb2e6c9b@FreeBSD.org>
In-Reply-To: <FA8EAA8E63D708A49EA6ED34@triton.njm.me.uk>
References:  <201807111644.w6BGiQVJ014595@repo.freebsd.org> <FA8EAA8E63D708A49EA6ED34@triton.njm.me.uk>

next in thread | previous in thread | raw e-mail | index | archive | help
This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--Zc287nEO3eCN1OkdEfg3j7CGBkAXNJSqL
Content-Type: multipart/mixed; boundary="aML6Kc2vCyrpbE6HiZgww5yKiqeSBEKCg";
 protected-headers="v1"
From: Jung-uk Kim <jkim@FreeBSD.org>
To: "N.J. Mann" <njm@njm.me.uk>
Cc: svn-ports-all@freebsd.org
Message-ID: <672e0d22-78e4-1499-a060-eaf0eb2e6c9b@FreeBSD.org>
Subject: Re: svn commit: r474467 - head/security/vuxml
References: <201807111644.w6BGiQVJ014595@repo.freebsd.org>
 <FA8EAA8E63D708A49EA6ED34@triton.njm.me.uk>
In-Reply-To: <FA8EAA8E63D708A49EA6ED34@triton.njm.me.uk>

--aML6Kc2vCyrpbE6HiZgww5yKiqeSBEKCg
Content-Type: text/plain; charset=utf-8
Content-Language: en-US
Content-Transfer-Encoding: quoted-printable

On 07/11/2018 13:06, N.J. Mann wrote:
> Hi,
>=20
> On Wednesday, July 11, 2018 16:44:26 +0000 Jung-uk Kim <jkim@FreeBSD.or=
g> wrote:
>> Author: jkim
>> Date: Wed Jul 11 16:44:25 2018
>> New Revision: 474467
>> URL: https://svnweb.freebsd.org/changeset/ports/474467
>>
>> Log:
>>   Document the latest Flash Player vulnerabilities.
>>  =20
>>   https://helpx.adobe.com/security/products/flash-player/apsb18-24.htm=
l
>>
>> Modified:
>>   head/security/vuxml/vuln.xml
>>
>> Modified: head/security/vuxml/vuln.xml
>> =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D
>> --- head/security/vuxml/vuln.xml	Wed Jul 11 16:36:45 2018	(r474466)
>> +++ head/security/vuxml/vuln.xml	Wed Jul 11 16:44:25 2018	(r474467)
>> @@ -58,6 +58,38 @@ Notes:
>>    * Do not forget port variants (linux-f10-libxml2, libxml2, etc.)
>>  -->
>>  <vuxml xmlns=3D"http://www.vuxml.org/apps/vuxml-1">;
>> +  <vuln vid=3D"e78732b2-8528-11e8-9c42-6451062f0f7a">
>> +    <topic>Flash Player -- multiple vulnerabilities</topic>
>> +    <affects>
>> +      <package>
>> +	<name>linux-flashplayer</name>
>> +	<range><lt>30.0.0.134</lt></range>
>> +      </package>
>> +    </affects>
>> +    <description>
>> +      <body xmlns=3D"http://www.w3.org/1999/xhtml">;
>> +	<p>Adobe reports:</p>
>> +	<blockquote cite=3D"https://helpx.adobe.com/security/products/flash-=
player/apsb18-24.html">
>> +	  <ul>
>> +	    <li>This update resolves an out-of-boubds read vulnerability tha=
t
>=20
>                                         ^^^^^^^^^^^^^
> out-of-bounds

Oops, copy-and-pasto.

Fixed in r474471, thanks!

Jung-uk Kim


--aML6Kc2vCyrpbE6HiZgww5yKiqeSBEKCg--

--Zc287nEO3eCN1OkdEfg3j7CGBkAXNJSqL
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQEzBAEBCAAdFiEEl1bqgKaRyqfWXu/CfJ+WJvzb8UYFAltGPeUACgkQfJ+WJvzb
8UaHXgf/cLogjDHRi6RoCbsfBJT6bXica7zRBDRQ6SeJ+GsmaSykWPMasi6weFCo
ECRGrGu7vG/zfPrz8jcUOaymHOeTnVu1bpMtfb3509AU9cV2Id0qr1poKvcrB0nV
zCNXiKuYJJe5Fu0VKmRsKnkUrQy5InovhSeOJQng/kt41mGjH/3FNIMiZc4M5AlZ
SVxxpS8mIwclEs4aNDa2Y09Cj+O/KNXLChz7/4EyhqUREwkan0vvAQ149oaO2lo3
vQEL9DLpaNT83IsIRFkqfK4Gp6ENuRMpd4yWQXXZWVNY0xXuSNwrHcHDih61Rw5h
JEPKdZLO12a4QJ3L+anFgEj8iDeFuQ==
=3EA1
-----END PGP SIGNATURE-----

--Zc287nEO3eCN1OkdEfg3j7CGBkAXNJSqL--



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?672e0d22-78e4-1499-a060-eaf0eb2e6c9b>