From owner-svn-ports-head@FreeBSD.ORG Sun Dec 30 20:10:43 2012 Return-Path: Delivered-To: svn-ports-head@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [69.147.83.52]) by hub.freebsd.org (Postfix) with ESMTP id 228C6FF3; Sun, 30 Dec 2012 20:10:43 +0000 (UTC) (envelope-from cs@FreeBSD.org) Received: from svn.freebsd.org (svn.freebsd.org [IPv6:2001:1900:2254:2068::e6a:0]) by mx1.freebsd.org (Postfix) with ESMTP id 0578C8FC0C; Sun, 30 Dec 2012 20:10:43 +0000 (UTC) Received: from svn.freebsd.org (svn.FreeBSD.org [8.8.178.70]) by svn.freebsd.org (8.14.5/8.14.5) with ESMTP id qBUKAgVO071993; Sun, 30 Dec 2012 20:10:42 GMT (envelope-from cs@svn.freebsd.org) Received: (from cs@localhost) by svn.freebsd.org (8.14.5/8.14.5/Submit) id qBUKAgOE071992; Sun, 30 Dec 2012 20:10:42 GMT (envelope-from cs@svn.freebsd.org) Message-Id: <201212302010.qBUKAgOE071992@svn.freebsd.org> From: Carlo Strub Date: Sun, 30 Dec 2012 20:10:42 +0000 (UTC) To: ports-committers@freebsd.org, svn-ports-all@freebsd.org, svn-ports-head@freebsd.org Subject: svn commit: r309688 - head/security/vuxml X-SVN-Group: ports-head MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-ports-head@freebsd.org X-Mailman-Version: 2.1.14 Precedence: list List-Id: SVN commit messages for the ports tree for head List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 30 Dec 2012 20:10:43 -0000 Author: cs Date: Sun Dec 30 20:10:42 2012 New Revision: 309688 URL: http://svnweb.freebsd.org/changeset/ports/309688 Log: Add OTRS vulnerabilities Modified: head/security/vuxml/vuln.xml Modified: head/security/vuxml/vuln.xml ============================================================================== --- head/security/vuxml/vuln.xml Sun Dec 30 20:07:54 2012 (r309687) +++ head/security/vuxml/vuln.xml Sun Dec 30 20:10:42 2012 (r309688) @@ -51,6 +51,97 @@ Note: Please add new entries to the beg --> + + otrs -- XSS vulnerability + + + otrs + 3.1.11 + + + + +

OTRS Security Advisory reports:

+
+

This advisory covers vulnerabilities discovered in the OTRS core +system. This is a variance of the XSS vulnerability, where an attacker could +send a specially prepared HTML email to OTRS which would cause JavaScript code +to be executed in your browser while displaying the email. In this case this is +achieved by using javascript source attributes with whitespaces.

+
+ +
+ + CVE-2012-4751 + http://www.otrs.com/en/open-source/community-news/security-advisories/security-advisory-2012-03/ +http://www.kb.cert.org/vuls/id/603276 + + + 2012-10-16 + 2012-12-30 + +
+ + + otrs -- XSS vulnerability in Firefox and Opera + + + otrs + 3.1.10 + + + + +

OTRS Security Advisory reports:

+
+

This advisory covers vulnerabilities discovered in the OTRS core +system. This is a variance of the XSS vulnerability, where an attacker could +send a specially prepared HTML email to OTRS which would cause JavaScript code +to be executed in your browser while displaying the email in Firefox and Opera. +In this case this is achieved with an invalid HTML structure with nested tags. +

+
+ +
+ +CVE-2012-4600 + http://www.otrs.com/open-source/community-news/security-advisories/security-advisory-2012-02/ + + + 2012-08-30 + 2012-12-30 + +
+ + + otrs -- XSS vulnerability in Internet Explorer + + + otrs + 3.1.9 + + + + +

OTRS Security Advisory reports:

+
+

This advisory covers vulnerabilities discovered in the OTRS core +system. Due to the XSS vulnerability in Internet Explorer an attacker could send +a specially prepared HTML email to OTRS which would cause JavaScript code to be +executed in your Internet Explorer while displaying the email.

+
+ +
+ + CVE-2012-2582 + http://www.otrs.com/open-source/community-news/security-advisories/security-advisory-2012-01/ + + + 2012-08-22 + 2012-12-30 + +
+ squid -- denial of service