Date: Sun, 4 Mar 2018 22:40:44 +0000 (UTC) From: Christoph Moench-Tegeder <cmt@FreeBSD.org> To: ports-committers@freebsd.org, svn-ports-all@freebsd.org, svn-ports-head@freebsd.org Subject: svn commit: r463609 - head/security/vuxml Message-ID: <201803042240.w24MeibH019320@repo.freebsd.org>
next in thread | raw e-mail | index | archive | help
Author: cmt Date: Sun Mar 4 22:40:43 2018 New Revision: 463609 URL: https://svnweb.freebsd.org/changeset/ports/463609 Log: document vulnerabilities for net/wireshark{,-lite,qt5} and net/tshark{,-lite} PR: 226355 Obtained from: https://www.wireshark.org/security/ Modified: head/security/vuxml/vuln.xml Modified: head/security/vuxml/vuln.xml ============================================================================== --- head/security/vuxml/vuln.xml Sun Mar 4 22:34:22 2018 (r463608) +++ head/security/vuxml/vuln.xml Sun Mar 4 22:40:43 2018 (r463609) @@ -58,6 +58,90 @@ Notes: * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> <vuxml xmlns="http://www.vuxml.org/apps/vuxml-1"> + <vuln vid="c5ab620f-4576-4ad5-b51f-93e4fec9cd0e"> + <topic>wireshark -- multiple security issues</topic> + <affects> + <package> + <name>wireshark</name> + <range><ge>2.2.0</ge><lt>2.2.13</lt></range> + <range><ge>2.4.0</ge><lt>2.4.5</lt></range> + </package> + <package> + <name>wireshark-lite</name> + <range><ge>2.2.0</ge><lt>2.2.13</lt></range> + <range><ge>2.4.0</ge><lt>2.4.5</lt></range> + </package> + <package> + <name>wireshark-qt5</name> + <range><ge>2.2.0</ge><lt>2.2.13</lt></range> + <range><ge>2.4.0</ge><lt>2.4.5</lt></range> + </package> + <package> + <name>tshark</name> + <range><ge>2.2.0</ge><lt>2.2.13</lt></range> + <range><ge>2.4.0</ge><lt>2.4.5</lt></range> + </package> + <package> + <name>tshark-lite</name> + <range><ge>2.2.0</ge><lt>2.2.13</lt></range> + <range><ge>2.4.0</ge><lt>2.4.5</lt></range> + </package> + </affects> + <description> + <body xmlns="http://www.w3.org/1999/xhtml"> + <p>wireshark developers reports:</p> + <blockquote cite="https://www.wireshark.org/security/"> + <p>wnpa-sec-2018-05. IEEE 802.11 dissector crash. (CVE-2018-7335)</p> + <p>wnpa-sec-2018-06. Large or infinite loops in multiple dissectors. (CVE-2018-7321 through CVE-2018-7333)</p> + <p>wnpa-sec-2018-07. UMTS MAC dissector crash. (CVE-2018-7334)</p> + <p>wnpa-sec-2018-08. DOCSIS dissector crash. (CVE-2018-7337)</p> + <p>wnpa-sec-2018-09. FCP dissector crash. (CVE-2018-7336)</p> + <p>wnpa-sec-2018-10. SIGCOMP dissector crash. (CVE-2018-7320)</p> + <p>wnpa-sec-2018-11. Pcapng file parser crash.</p> + <p>wnpa-sec-2018-12. IPMI dissector crash.</p> + <p>wnpa-sec-2018-13. SIGCOMP dissector crash.</p> + <p>wnpa-sec-2018-14. NBAP dissector crash.</p> + </blockquote> + </body> + </description> + <references> + <url>https://www.wireshark.org/security/</url> + <url>https://www.wireshark.org/security/wnpa-sec-2018-05.html</url> + <url>https://www.wireshark.org/security/wnpa-sec-2018-06.html</url> + <url>https://www.wireshark.org/security/wnpa-sec-2018-07.html</url> + <url>https://www.wireshark.org/security/wnpa-sec-2018-08.html</url> + <url>https://www.wireshark.org/security/wnpa-sec-2018-09.html</url> + <url>https://www.wireshark.org/security/wnpa-sec-2018-10.html</url> + <url>https://www.wireshark.org/security/wnpa-sec-2018-11.html</url> + <url>https://www.wireshark.org/security/wnpa-sec-2018-12.html</url> + <url>https://www.wireshark.org/security/wnpa-sec-2018-13.html</url> + <url>https://www.wireshark.org/security/wnpa-sec-2018-14.html</url> + <cvename>CVE-2018-7320</cvename> + <cvename>CVE-2018-7321</cvename> + <cvename>CVE-2018-7322</cvename> + <cvename>CVE-2018-7323</cvename> + <cvename>CVE-2018-7324</cvename> + <cvename>CVE-2018-7325</cvename> + <cvename>CVE-2018-7326</cvename> + <cvename>CVE-2018-7327</cvename> + <cvename>CVE-2018-7328</cvename> + <cvename>CVE-2018-7329</cvename> + <cvename>CVE-2018-7330</cvename> + <cvename>CVE-2018-7331</cvename> + <cvename>CVE-2018-7332</cvename> + <cvename>CVE-2018-7333</cvename> + <cvename>CVE-2018-7334</cvename> + <cvename>CVE-2018-7335</cvename> + <cvename>CVE-2018-7336</cvename> + <cvename>CVE-2018-7337</cvename> + <cvename>CVE-2018-7417</cvename> + </references> + <dates> + <discovery>2018-02-23</discovery> + <entry>2018-03-04</entry> + </dates> + </vuln> + <vuln vid="2040c7f5-1e3a-11e8-8ae9-0050569f0b83"> <topic>isc-dhcp -- Multiple vulnerabilities</topic> <affects>
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?201803042240.w24MeibH019320>