From owner-svn-ports-all@freebsd.org Mon Mar 14 12:10:30 2016
Return-Path:
Delivered-To: svn-ports-all@mailman.ysv.freebsd.org
Received: from mx1.freebsd.org (mx1.freebsd.org
[IPv6:2001:1900:2254:206a::19:1])
by mailman.ysv.freebsd.org (Postfix) with ESMTP id D3302AD0DF1;
Mon, 14 Mar 2016 12:10:30 +0000 (UTC)
(envelope-from jbeich@FreeBSD.org)
Received: from repo.freebsd.org (repo.freebsd.org
[IPv6:2610:1c1:1:6068::e6a:0])
(using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits))
(Client did not present a certificate)
by mx1.freebsd.org (Postfix) with ESMTPS id A0DA51377;
Mon, 14 Mar 2016 12:10:30 +0000 (UTC)
(envelope-from jbeich@FreeBSD.org)
Received: from repo.freebsd.org ([127.0.1.37])
by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id u2ECATE5053267;
Mon, 14 Mar 2016 12:10:29 GMT (envelope-from jbeich@FreeBSD.org)
Received: (from jbeich@localhost)
by repo.freebsd.org (8.15.2/8.15.2/Submit) id u2ECATT5053266;
Mon, 14 Mar 2016 12:10:29 GMT (envelope-from jbeich@FreeBSD.org)
Message-Id: <201603141210.u2ECATT5053266@repo.freebsd.org>
X-Authentication-Warning: repo.freebsd.org: jbeich set sender to
jbeich@FreeBSD.org using -f
From: Jan Beich
Date: Mon, 14 Mar 2016 12:10:29 +0000 (UTC)
To: ports-committers@freebsd.org, svn-ports-all@freebsd.org,
svn-ports-head@freebsd.org
Subject: svn commit: r411058 - head/security/vuxml
X-SVN-Group: ports-head
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
X-BeenThere: svn-ports-all@freebsd.org
X-Mailman-Version: 2.1.21
Precedence: list
List-Id: SVN commit messages for the ports tree
List-Unsubscribe: ,
List-Archive:
List-Post:
List-Help:
List-Subscribe: ,
X-List-Received-Date: Mon, 14 Mar 2016 12:10:30 -0000
Author: jbeich
Date: Mon Mar 14 12:10:29 2016
New Revision: 411058
URL: https://svnweb.freebsd.org/changeset/ports/411058
Log:
Document one more graphite2 vulnerability
Modified:
head/security/vuxml/vuln.xml (contents, props changed)
Modified: head/security/vuxml/vuln.xml
==============================================================================
--- head/security/vuxml/vuln.xml Mon Mar 14 12:04:26 2016 (r411057)
+++ head/security/vuxml/vuln.xml Mon Mar 14 12:10:29 2016 (r411058)
@@ -550,10 +550,18 @@ Notes:
memory, out-of-bounds read, and out-of-bounds write errors
when working with fuzzed graphite fonts.
+
+ Security researcher James Clawson used the Address
+ Sanitizer tool to discover an out-of-bounds write in the
+ Graphite 2 library when loading a crafted Graphite font
+ file. This results in a potentially exploitable crash.
+