Date: Mon, 28 Apr 2014 21:47:09 +0200 (CEST) From: mohawk <mohawk@bsdsx.fr> To: FreeBSD-gnats-submit@freebsd.org Subject: ports/189082: [patch] [vuxml] www/mohawk: multiple vulnerabilities Message-ID: <201404281947.s3SJl9nU096806@blade.bsdsx.fr> Resent-Message-ID: <201404281950.s3SJo0CS064006@freefall.freebsd.org>
next in thread | raw e-mail | index | archive | help
>Number: 189082 >Category: ports >Synopsis: [patch] [vuxml] www/mohawk: multiple vulnerabilities >Confidential: no >Severity: serious >Priority: high >Responsible: freebsd-ports-bugs >State: open >Quarter: >Keywords: >Date-Required: >Class: sw-bug >Submitter-Id: current-users >Arrival-Date: Mon Apr 28 19:50:00 UTC 2014 >Closed-Date: >Last-Modified: >Originator: mohawk >Release: FreeBSD 10.0-RELEASE amd64 >Organization: mohawk@bsdsx.fr >Environment: System: FreeBSD blade.bsdsx.fr 10.0-RELEASE FreeBSD 10.0-RELEASE #0 r260789: Thu Jan 16 22:34:59 UTC 2014 root@snap.freebsd.org:/usr/obj/usr/src/sys/GENERIC amd64 >Description: Version of mohawk < 2.0.12 have multiple vulnerabilities >How-To-Repeat: >Fix: --- vuxml.patch begins here --- --- vuln.xml.orig 2014-04-27 20:49:08.000000000 +0200 +++ vuln.xml 2014-04-28 20:36:54.000000000 +0200 @@ -51,6 +51,32 @@ --> <vuxml xmlns="http://www.vuxml.org/apps/vuxml-1"> + <vuln vid="670d732a-cdd4-11e3-aac2-0022fb6fcf92"> + <topic>mohawk -- multiple vulnerabilities</topic> + <affects> + <package> + <name>mohawk</name> + <range><lt>2.0.12</lt></range> + </package> + </affects> + <description> + <body xmlns="http://www.w3.org/1999/xhtml"> + <p>The mohawk project reports:</p> + <blockquote cite="http://fossil.bsdsx.fr/mohawk/tktview?name=1707f0e351"> + <p>Segfault when parsing malformed / unescaped url, coredump when setting syslog facility.</p> + </blockquote> + </body> + </description> + <references> + <url>http://fossil.bsdsx.fr/mohawk/tktview?name=1707f0e351</url> + <url>http://fossil.bsdsx.fr/mohawk/tktview?name=1c7565019e</url> + </references> + <dates> + <discovery>2014-04-10</discovery> + <entry>2014-04-27</entry> + </dates> + </vuln> + <vuln vid="59e72db2-cae6-11e3-8420-00e0814cab4e"> <topic>django -- multiple vulnerabilities</topic> <affects> --- vuxml.patch ends here --- >Release-Note: >Audit-Trail: >Unformatted:
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?201404281947.s3SJl9nU096806>