Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 26 Mar 2018 09:13:40 +0000 (UTC)
From:      Christoph Moench-Tegeder <cmt@FreeBSD.org>
To:        ports-committers@freebsd.org, svn-ports-all@freebsd.org, svn-ports-head@freebsd.org
Subject:   svn commit: r465568 - head/security/vuxml
Message-ID:  <201803260913.w2Q9DehS072657@repo.freebsd.org>

next in thread | raw e-mail | index | archive | help
Author: cmt
Date: Mon Mar 26 09:13:40 2018
New Revision: 465568
URL: https://svnweb.freebsd.org/changeset/ports/465568

Log:
  thunderbird: fix affected versions for CVE-2018-5146
  
  according to https://www.mozilla.org/en-US/security/advisories/mfsa2018-09/ ,
  CVE-2018-5146 has been fixed in thunderbird 52.7.0 (and CVE-2018-5147
  affects Android platforms as per it's description).
  Add link to the thunderbird security advisory MFSA 2018-09, as this has
  the info for thunderbird.

Modified:
  head/security/vuxml/vuln.xml

Modified: head/security/vuxml/vuln.xml
==============================================================================
--- head/security/vuxml/vuln.xml	Mon Mar 26 09:13:27 2018	(r465567)
+++ head/security/vuxml/vuln.xml	Mon Mar 26 09:13:40 2018	(r465568)
@@ -438,7 +438,7 @@ Notes:
 	<name>libxul</name>
 	<name>thunderbird</name>
 	<name>linux-thunderbird</name>
-	<range><lt>52.7.2</lt></range>
+	<range><lt>52.7.0</lt></range>
       </package>
       <package>
 	<name>palemoon</name>
@@ -463,6 +463,7 @@ Notes:
       <cvename>CVE-2018-5146</cvename>
       <cvename>CVE-2018-5147</cvename>
       <url>https://www.mozilla.org/security/advisories/mfsa2018-08/</url>;
+      <url>https://www.mozilla.org/security/advisories/mfsa2018-09/</url>;
     </references>
     <dates>
       <discovery>2018-03-16</discovery>



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?201803260913.w2Q9DehS072657>