Date: Sat, 23 May 2020 09:22:21 +0000 (UTC) From: Jochen Neumeister <joneum@FreeBSD.org> To: ports-committers@freebsd.org, svn-ports-all@freebsd.org, svn-ports-head@freebsd.org Subject: svn commit: r536276 - head/security/vuxml Message-ID: <202005230922.04N9MLr9028661@repo.freebsd.org>
next in thread | raw e-mail | index | archive | help
Author: joneum Date: Sat May 23 09:22:21 2020 New Revision: 536276 URL: https://svnweb.freebsd.org/changeset/ports/536276 Log: Add entry for tomcat PR: 246657 Sponsored by: Netzkommune GmbH Modified: head/security/vuxml/vuln.xml Modified: head/security/vuxml/vuln.xml ============================================================================== --- head/security/vuxml/vuln.xml Sat May 23 09:20:02 2020 (r536275) +++ head/security/vuxml/vuln.xml Sat May 23 09:22:21 2020 (r536276) @@ -58,6 +58,45 @@ Notes: * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> <vuxml xmlns="http://www.vuxml.org/apps/vuxml-1"> + <vuln vid="676ca486-9c1e-11ea-8b5e-b42e99a1b9c3"> + <topic>Apache Tomcat Remote Code Execution via session persistence</topic> + <affects> + <package> + <name>tomcat7</name> + <range><lt>7.0.104</lt></range> + </package> + <package> + <name>tomcat85</name> + <range><lt>8.5.55</lt></range> + </package> + <package> + <name>tomcat9</name> + <range><lt>9.0.35</lt></range> + </package> + <package> + <name>tomcat-devel</name> + <range><lt>10.0.0.M5</lt></range> + </package> + </affects> + <description> + <body xmlns="http://www.w3.org/1999/xhtml"> + <p>The Apache Software Foundation reports:</p> + <p>Under certain circumstances an attacker will be able to trigger remote code execution via deserialization of the file under their control</p> + </body> + </description> + <references> + <url>http://tomcat.apache.org/security-7.html</url> + <url>http://tomcat.apache.org/security-8.html</url> + <url>http://tomcat.apache.org/security-9.html</url> + <url>http://tomcat.apache.org/security-10.html</url> + <cvename>CVE-2020-9484</cvename> + </references> + <dates> + <discovery>2020-05-12</discovery> + <entry>2020-05-22</entry> + </dates> + </vuln> + <vuln vid="a2cb7c31-9c79-11ea-a9c2-d05099c0ae8c"> <topic>unbound -- mutliple vulnerabilities</topic> <affects>
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?202005230922.04N9MLr9028661>