Date: Sun, 21 Jul 2019 03:55:06 +0000 (UTC) From: Jose Alonso Cardenas Marquez <acm@FreeBSD.org> To: ports-committers@freebsd.org, svn-ports-all@freebsd.org, svn-ports-head@freebsd.org Subject: svn commit: r507033 - head/security/vuxml Message-ID: <201907210355.x6L3t6i6059222@repo.freebsd.org>
next in thread | raw e-mail | index | archive | help
Author: acm Date: Sun Jul 21 03:55:06 2019 New Revision: 507033 URL: https://svnweb.freebsd.org/changeset/ports/507033 Log: - Add drupal8 vulnerability entry - Modify 9b8a52fc-89c1-11e9-9ba0-4c72b94353b5 entry. Drupal8 was affected too Modified: head/security/vuxml/vuln.xml Modified: head/security/vuxml/vuln.xml ============================================================================== --- head/security/vuxml/vuln.xml Sun Jul 21 03:48:45 2019 (r507032) +++ head/security/vuxml/vuln.xml Sun Jul 21 03:55:06 2019 (r507033) @@ -58,6 +58,34 @@ Notes: * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> <vuxml xmlns="http://www.vuxml.org/apps/vuxml-1"> + <vuln vid="19d648e0-ab69-11e9-bfef-000ffec0b3e1"> + <topic>drupal -- Drupal core - Access bypass</topic> + <affects> + <package> + <name>drupal8</name> + <range><lt>8.7.5</lt></range> + </package> + </affects> + <description> + <body xmlns="http://www.w3.org/1999/xhtml"> + <p>Drupal Security Team reports:</p> + <blockquote cite="https://www.drupal.org/SA-CORE-2019-008"> + <p>In Drupal 8.7.4, when the experimental Workspaces module is enabled, + an access bypass condition is created.</p> + <p>This can be mitigated by disabling the Workspaces module. It does + not affect any release other than Drupal 8.7.4.</p> + </blockquote> + </body> + </description> + <references> + <url>https://www.drupal.org/SA-CORE-2019-008</url> + </references> + <dates> + <discovery>2019-07-17</discovery> + <entry>2019-07-21</entry> + </dates> + </vuln> + <vuln vid="5914705c-ab03-11e9-a4f9-080027ac955c"> <topic>PuTTY 0.72 -- buffer overflow in SSH-1 and integer overflow in SSH client</topic> <affects> @@ -1372,6 +1400,10 @@ Notes: <package> <name>drupal7</name> <range><lt>7.67</lt></range> + </package> + <package> + <name>drupal8</name> + <range><lt>8.7.1</lt></range> </package> </affects> <description>
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?201907210355.x6L3t6i6059222>