Date: Sun, 10 Dec 2017 11:37:03 +0000 (UTC) From: Christoph Moench-Tegeder <cmt@FreeBSD.org> To: ports-committers@freebsd.org, svn-ports-all@freebsd.org, svn-ports-head@freebsd.org Subject: svn commit: r455890 - head/security/vuxml Message-ID: <201712101137.vBABb3Oa093477@repo.freebsd.org>
next in thread | raw e-mail | index | archive | help
Author: cmt Date: Sun Dec 10 11:37:02 2017 New Revision: 455890 URL: https://svnweb.freebsd.org/changeset/ports/455890 Log: document latest wireshark vulnerabilities Modified: head/security/vuxml/vuln.xml Modified: head/security/vuxml/vuln.xml ============================================================================== --- head/security/vuxml/vuln.xml Sun Dec 10 11:25:40 2017 (r455889) +++ head/security/vuxml/vuln.xml Sun Dec 10 11:37:02 2017 (r455890) @@ -58,6 +58,60 @@ Notes: * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> <vuxml xmlns="http://www.vuxml.org/apps/vuxml-1"> + <vuln vid="4b228e69-22e1-4019-afd0-8aa716d0ec0b"> + <topic>wireshark -- multiple security issues</topic> + <affects> + <package> + <name>wireshark</name> + <range><ge>2.2.0</ge><le>2.2.10</le></range> + <range><ge>2.4.0</ge><le>2.4.2</le></range> + </package> + <package> + <name>wireshark-lite</name> + <range><ge>2.2.0</ge><le>2.2.10</le></range> + <range><ge>2.4.0</ge><le>2.4.2</le></range> + </package> + <package> + <name>wireshark-qt5</name> + <range><ge>2.2.0</ge><le>2.2.10</le></range> + <range><ge>2.4.0</ge><le>2.4.2</le></range> + </package> + <package> + <name>tshark</name> + <range><ge>2.2.0</ge><le>2.2.10</le></range> + <range><ge>2.4.0</ge><le>2.4.2</le></range> + </package> + <package> + <name>tshark-lite</name> + <range><ge>2.2.0</ge><le>2.2.10</le></range> + <range><ge>2.4.0</ge><le>2.4.2</le></range> + </package> + </affects> + <description> + <body xmlns="http://www.w3.org/1999/xhtml"> + <p>wireshark developers reports:</p> + <blockquote cite="https://www.wireshark.org/security/"> + <p>wnpa-sec-2017-47: The IWARP_MPA dissector could crash. (CVE-2017-17084)</p> + <p>wnpa-sec-2017-48: The NetBIOS dissector could crash. Discovered by Kamil Frankowicz. (CVE-2017-17083)</p> + <p>wnpa-sec-2017-49: The CIP Safety dissector could crash. (CVE-2017-17085)</p> + </blockquote> + </body> + </description> + <references> + <url>https://www.wireshark.org/security/</url> + <url>https://www.wireshark.org/security/wnpa-sec-2017-47.html</url> + <url>https://www.wireshark.org/security/wnpa-sec-2017-48.html</url> + <url>https://www.wireshark.org/security/wnpa-sec-2017-49.html</url> + <cvename>CVE-2017-17083</cvename> + <cvename>CVE-2017-17084</cvename> + <cvename>CVE-2017-17085</cvename> + </references> + <dates> + <discovery>2017-11-30</discovery> + <entry>2017-12-10</entry> + </dates> + </vuln> + <vuln vid="3bb451fc-db64-11e7-ac58-b499baebfeaf"> <topic>OpenSSL -- multiple vulnerabilities</topic> <affects>
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?201712101137.vBABb3Oa093477>