Date: Fri, 26 Jan 2018 13:23:59 +0000 (UTC) From: Christoph Moench-Tegeder <cmt@FreeBSD.org> To: ports-committers@freebsd.org, svn-ports-all@freebsd.org, svn-ports-head@freebsd.org Subject: svn commit: r459991 - head/security/vuxml Message-ID: <201801261323.w0QDNxah068243@repo.freebsd.org>
next in thread | raw e-mail | index | archive | help
Author: cmt Date: Fri Jan 26 13:23:59 2018 New Revision: 459991 URL: https://svnweb.freebsd.org/changeset/ports/459991 Log: document recent clamav vulnerabilities See: http://blog.clamav.net/2018/01/clamav-0993-has-been-released.html Modified: head/security/vuxml/vuln.xml Modified: head/security/vuxml/vuln.xml ============================================================================== --- head/security/vuxml/vuln.xml Fri Jan 26 12:41:50 2018 (r459990) +++ head/security/vuxml/vuln.xml Fri Jan 26 13:23:59 2018 (r459991) @@ -58,6 +58,49 @@ Notes: * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> <vuxml xmlns="http://www.vuxml.org/apps/vuxml-1"> + <vuln vid="b464f61b-84c7-4e1c-8ad4-6cf9efffd025"> + <topic>clamav -- multiple vulnerabilities</topic> + <affects> + <package> + <name>clamav</name> + <range><lt>0.99.3</lt></range> + </package> + </affects> + <description> + <body xmlns="http://www.w3.org/1999/xhtml"> + <p>ClamAV project reports:</p> + <blockquote cite="http://blog.clamav.net/2018/01/clamav-0993-has-been-released.html"> + <p>Join us as we welcome ClamAV 0.99.3 to the family!.</p> + <p>This release is a security release and is recommended for + all ClamAV users.</p> + <p>CVE-2017-12374 ClamAV UAF (use-after-free) Vulnerabilities</p> + <p>CVE-2017-12375 ClamAV Buffer Overflow Vulnerability</p> + <p>CVE-2017-12376 ClamAV Buffer Overflow in handle_pdfname + Vulnerability</p> + <p>CVE-2017-12377 ClamAV Mew Packet Heap Overflow Vulnerability</p> + <p>CVE-2017-12378 ClamAV Buffer Over Read Vulnerability</p> + <p>CVE-2017-12379 ClamAV Buffer Overflow in messageAddArgument + Vulnerability</p> + <p>CVE-2017-12380 ClamAV Null Dereference Vulnerability</p> + </blockquote> + </body> + </description> + <references> + <url>http://blog.clamav.net/2018/01/clamav-0993-has-been-released.html</url> + <cvename>CVE-2017-12374</cvename> + <cvename>CVE-2017-12375</cvename> + <cvename>CVE-2017-12376</cvename> + <cvename>CVE-2017-12377</cvename> + <cvename>CVE-2017-12378</cvename> + <cvename>CVE-2017-12379</cvename> + <cvename>CVE-2017-12380</cvename> + </references> + <dates> + <discovery>2018-01-25</discovery> + <entry>2018-01-26</entry> + </dates> + </vuln> + <vuln vid="a891c5b4-3d7a-4de9-9c71-eef3fd698c77"> <topic>mozilla -- multiple vulnerabilities</topic> <affects>
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?201801261323.w0QDNxah068243>