Date: Thu, 11 Jun 2020 13:24:06 +0000 (UTC) From: Emanuel Haupt <ehaupt@FreeBSD.org> To: ports-committers@freebsd.org, svn-ports-all@freebsd.org, svn-ports-head@freebsd.org Subject: svn commit: r538483 - head/security/vuxml Message-ID: <202006111324.05BDO6FF075089@repo.freebsd.org>
next in thread | raw e-mail | index | archive | help
Author: ehaupt Date: Thu Jun 11 13:24:05 2020 New Revision: 538483 URL: https://svnweb.freebsd.org/changeset/ports/538483 Log: Document net-mgmt/tcpreplay vulnerabilities Modified: head/security/vuxml/vuln.xml Modified: head/security/vuxml/vuln.xml ============================================================================== --- head/security/vuxml/vuln.xml Thu Jun 11 13:15:58 2020 (r538482) +++ head/security/vuxml/vuln.xml Thu Jun 11 13:24:05 2020 (r538483) @@ -58,6 +58,39 @@ Notes: * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> <vuxml xmlns="http://www.vuxml.org/apps/vuxml-1"> + <vuln vid="045e46e8-abe6-11ea-99cb-10bf48e1088e"> + <topic>tcpreplay -- Multiple vulnerabilities</topic> + <affects> + <package> + <name>tcpreplay</name> + <range><lt>4.3.2</lt></range> + </package> + </affects> + <description> + <body xmlns="http://www.w3.org/1999/xhtml"> + <p>fklassen on Github reports:</p> + <blockquote cite="https://github.com/appneta/tcpreplay/releases/tag/v4.3.2"> + <p>This release fixes the following security issues:</p> + <ul> + <li>memory access in do_checksum()</li> + <li>NULL pointer dereference get_layer4_v6()</li> + <li>NULL pointer dereference get_ipv6_l4proto()</li> + </ul> + </blockquote> + </body> + </description> + <references> + <url>https://github.com/appneta/tcpreplay/releases/tag/v4.3.2</url> + <cvename>CVE-2019-8381</cvename> + <cvename>CVE-2019-8376</cvename> + <cvename>CVE-2019-8377</cvename> + </references> + <dates> + <discovery>2019-03-12</discovery> + <entry>2020-06-11</entry> + </dates> + </vuln> + <vuln vid="10a24ce0-ab68-11ea-b9b8-641c67a117d8"> <topic>znc -- Authenticated users can trigger an application crash</topic> <affects>
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?202006111324.05BDO6FF075089>