From owner-freebsd-bugs@FreeBSD.ORG Sun Aug 18 19:00:00 2013 Return-Path: Delivered-To: freebsd-bugs@smarthost.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTP id E13C167A for ; Sun, 18 Aug 2013 19:00:00 +0000 (UTC) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (freefall.freebsd.org [IPv6:2001:1900:2254:206c::16:87]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mx1.freebsd.org (Postfix) with ESMTPS id A708F2646 for ; Sun, 18 Aug 2013 19:00:00 +0000 (UTC) Received: from freefall.freebsd.org (localhost [127.0.0.1]) by freefall.freebsd.org (8.14.7/8.14.7) with ESMTP id r7IJ00Om091113 for ; Sun, 18 Aug 2013 19:00:00 GMT (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.14.7/8.14.7/Submit) id r7IJ00gQ091112; Sun, 18 Aug 2013 19:00:00 GMT (envelope-from gnats) Resent-Date: Sun, 18 Aug 2013 19:00:00 GMT Resent-Message-Id: <201308181900.r7IJ00gQ091112@freefall.freebsd.org> Resent-From: FreeBSD-gnats-submit@FreeBSD.org (GNATS Filer) Resent-To: freebsd-bugs@FreeBSD.org Resent-Reply-To: FreeBSD-gnats-submit@FreeBSD.org, Derek Schrock Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTP id 302C461D for ; Sun, 18 Aug 2013 18:51:45 +0000 (UTC) (envelope-from nobody@FreeBSD.org) Received: from oldred.freebsd.org (oldred.freebsd.org [8.8.178.121]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by mx1.freebsd.org (Postfix) with ESMTPS id 1D7A32615 for ; Sun, 18 Aug 2013 18:51:45 +0000 (UTC) Received: from oldred.freebsd.org ([127.0.1.6]) by oldred.freebsd.org (8.14.5/8.14.7) with ESMTP id r7IIpi8n095749 for ; Sun, 18 Aug 2013 18:51:44 GMT (envelope-from nobody@oldred.freebsd.org) Received: (from nobody@localhost) by oldred.freebsd.org (8.14.5/8.14.5/Submit) id r7IIpihV095745; Sun, 18 Aug 2013 18:51:44 GMT (envelope-from nobody) Message-Id: <201308181851.r7IIpihV095745@oldred.freebsd.org> Date: Sun, 18 Aug 2013 18:51:44 GMT From: Derek Schrock To: freebsd-gnats-submit@FreeBSD.org X-Send-Pr-Version: www-3.1 Subject: misc/181384: /var/db/pkg/auditfile has a type for lcms2 X-BeenThere: freebsd-bugs@freebsd.org X-Mailman-Version: 2.1.14 Precedence: list List-Id: Bug reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 18 Aug 2013 19:00:01 -0000 >Number: 181384 >Category: misc >Synopsis: /var/db/pkg/auditfile has a type for lcms2 >Confidential: no >Severity: non-critical >Priority: low >Responsible: freebsd-bugs >State: open >Quarter: >Keywords: >Date-Required: >Class: update >Submitter-Id: current-users >Arrival-Date: Sun Aug 18 19:00:00 UTC 2013 >Closed-Date: >Last-Modified: >Originator: Derek Schrock >Release: FreeBSD 9.1-RELEASE-p5 >Organization: >Environment: >Description: /var/db/pkg/auditfile has a typo for lcms2 $ grep ^lcms2 /var/db/pkg/auditfile lcms2>0|http://portaudit.FreeBSD.org/9a0a892e-05d8-11e3-ba09-000c29784fd1.html|lcms2 -- Null Pointer Dereference Denial of Service Vulnerability Unless I'm reading the bug incorrectly teh CVE was fixed in 2.5: https://bugs.mageia.org/show_bug.cgi?id=10816 graphics/lcms2 is lcms 2.5 >How-To-Repeat: Building from port fails: $ sudo make -C /usr/ports/graphics/lcms2/ ===> lcms2-2.5 has known vulnerabilities: lcms2-2.5 is vulnerable: lcms2 -- Null Pointer Dereference Denial of Service Vulnerability WWW: http://portaudit.FreeBSD.org/9a0a892e-05d8-11e3-ba09-000c29784fd1.html => Please update your ports tree and try again. *** [check-vulnerable] Error code 1 Stop in /usr/ports/graphics/lcms2. *** [build] Error code 1 Stop in /usr/ports/graphics/lcms2. >Fix: Change /var/db/pkg/auditfile lcms2 entry to <2.5: lcms2<2.5|http://portaudit.FreeBSD.org/9a0a892e-05d8-11e3-ba09-000c29784fd1.html|lcms2 -- Null Pointer Dereference Denial of Service Vulnerability >Release-Note: >Audit-Trail: >Unformatted: