From owner-freebsd-ports-bugs@FreeBSD.ORG Mon Feb 12 13:40:22 2007 Return-Path: X-Original-To: freebsd-ports-bugs@hub.freebsd.org Delivered-To: freebsd-ports-bugs@hub.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [69.147.83.52]) by hub.freebsd.org (Postfix) with ESMTP id 0780A16A401 for ; Mon, 12 Feb 2007 13:40:22 +0000 (UTC) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (freefall.freebsd.org [69.147.83.40]) by mx1.freebsd.org (Postfix) with ESMTP id DB93613C4A7 for ; Mon, 12 Feb 2007 13:40:21 +0000 (UTC) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (gnats@localhost [127.0.0.1]) by freefall.freebsd.org (8.13.4/8.13.4) with ESMTP id l1CDeLhW015468 for ; Mon, 12 Feb 2007 13:40:21 GMT (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.13.4/8.13.4/Submit) id l1CDeLIV015467; Mon, 12 Feb 2007 13:40:21 GMT (envelope-from gnats) Resent-Date: Mon, 12 Feb 2007 13:40:21 GMT Resent-Message-Id: <200702121340.l1CDeLIV015467@freefall.freebsd.org> Resent-From: FreeBSD-gnats-submit@FreeBSD.org (GNATS Filer) Resent-To: freebsd-ports-bugs@FreeBSD.org Resent-Reply-To: FreeBSD-gnats-submit@FreeBSD.org, KOMATSU Shinichiro Received: from mx1.freebsd.org (mx1.freebsd.org [69.147.83.52]) by hub.freebsd.org (Postfix) with ESMTP id C34B416A408 for ; Mon, 12 Feb 2007 13:38:29 +0000 (UTC) (envelope-from nobody@FreeBSD.org) Received: from www.freebsd.org (www.freebsd.org [69.147.83.33]) by mx1.freebsd.org (Postfix) with ESMTP id 9ACB313C471 for ; Mon, 12 Feb 2007 13:38:29 +0000 (UTC) (envelope-from nobody@FreeBSD.org) Received: from www.freebsd.org (localhost [127.0.0.1]) by www.freebsd.org (8.13.1/8.13.1) with ESMTP id l1CDcTPs091491 for ; Mon, 12 Feb 2007 13:38:29 GMT (envelope-from nobody@www.freebsd.org) Received: (from nobody@localhost) by www.freebsd.org (8.13.1/8.13.1/Submit) id l1CDcTBg091468; Mon, 12 Feb 2007 13:38:29 GMT (envelope-from nobody) Message-Id: <200702121338.l1CDcTBg091468@www.freebsd.org> Date: Mon, 12 Feb 2007 13:38:29 GMT From: KOMATSU Shinichiro To: freebsd-gnats-submit@FreeBSD.org X-Send-Pr-Version: www-3.0 Cc: Subject: ports/109086: security/vuxml: fix the entries of tdiary X-BeenThere: freebsd-ports-bugs@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Ports bug reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 12 Feb 2007 13:40:22 -0000 >Number: 109086 >Category: ports >Synopsis: security/vuxml: fix the entries of tdiary >Confidential: no >Severity: serious >Priority: medium >Responsible: freebsd-ports-bugs >State: open >Quarter: >Keywords: >Date-Required: >Class: doc-bug >Submitter-Id: current-users >Arrival-Date: Mon Feb 12 13:40:18 GMT 2007 >Closed-Date: >Last-Modified: >Originator: KOMATSU Shinichiro >Release: FreeBSD 6.2-RELEASE i386 >Organization: >Environment: FreeBSD 6.2-RELEASE i386 >Description: Fix the VuXML entries of recently discovered tdiary vulnerabilities ("fefd93d8-8af5-11db-9d01-0016179b2dd5" and "666b8c9e-8212-11db-851e-0016179b2dd5") as follows: - correct the affected version numbers - package name of www/tdiary-devel is "tdiary-devel", not "tdiary" - add ja-tdiary and ja-tdiary-devel to affected packages >How-To-Repeat: >Fix: Patch attached with submission follows: Index: security/vuxml/vuln.xml =================================================================== RCS file: /home/ncvs/ports/security/vuxml/vuln.xml,v retrieving revision 1.1270 diff -u -r1.1270 vuln.xml --- security/vuxml/vuln.xml 17 Jan 2007 22:17:49 -0000 1.1270 +++ security/vuxml/vuln.xml 12 Feb 2007 13:25:01 -0000 @@ -725,9 +725,14 @@ tdiary -- injection vulnerability + ja-tdiary tdiary - 2.0.3 - 2.12.1.4.20061126 + 2.0.3 + + + ja-tdiary-devel + tdiary-devel + 2.12.1.4_2 @@ -741,7 +746,7 @@ 2006-12-10 2006-12-13 - 2006-12-15 + 2007-02-12 @@ -1039,9 +1044,14 @@ tdiary -- cross site scripting vulnerability + ja-tdiary tdiary - 2.0.2 - 2.12.1.4.20061115 + 2.0.2 + + + ja-tdiary-devel + tdiary-devel + 2.12.1.4_1 @@ -1056,6 +1066,7 @@ 2006-11-26 2006-12-02 + 2007-02-12 >Release-Note: >Audit-Trail: >Unformatted: