Date: Mon, 9 Jan 2017 17:32:04 +0000 (UTC) From: Mark Felder <feld@FreeBSD.org> To: ports-committers@freebsd.org, svn-ports-all@freebsd.org, svn-ports-head@freebsd.org Subject: svn commit: r430987 - head/security/vuxml Message-ID: <201701091732.v09HW4P7095474@repo.freebsd.org>
next in thread | raw e-mail | index | archive | help
Author: feld Date: Mon Jan 9 17:32:03 2017 New Revision: 430987 URL: https://svnweb.freebsd.org/changeset/ports/430987 Log: Document libdwarf vulnerabilities Security: CVE-2016-5027 CVE-2016-5028 CVE-2016-5029 CVE-2016-5030 Security: CVE-2016-5031 CVE-2016-5032 CVE-2016-5033 CVE-2016-5035 Security: CVE-2016-5037 CVE-2016-5040 CVE-2016-5041 CVE-2016-5043 Security: CVE-2016-5044 CVE-2016-7510 CVE-2016-7511 CVE-2016-8679 Security: CVE-2016-8680 CVE-2016-8681 CVE-2016-9275 CVE-2016-9276 Security: CVE-2016-9480 CVE-2016-9558 PR: 215085 Modified: head/security/vuxml/vuln.xml Modified: head/security/vuxml/vuln.xml ============================================================================== --- head/security/vuxml/vuln.xml Mon Jan 9 17:29:55 2017 (r430986) +++ head/security/vuxml/vuln.xml Mon Jan 9 17:32:03 2017 (r430987) @@ -58,6 +58,55 @@ Notes: * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> <vuxml xmlns="http://www.vuxml.org/apps/vuxml-1"> + <vuln vid="83041ca7-d690-11e6-9171-14dae9d210b8"> + <topic>libdwarf -- multiple vulnerabilities</topic> + <affects> + <package> + <name>libdwarf</name> + <range><lt>20161124</lt></range> + </package> + </affects> + <description> + <body xmlns="http://www.w3.org/1999/xhtml"> + <p>Christian Rebischke reports:</p> + <blockquote cite="https://lwn.net/Articles/708092/"> + <p>libdwarf is vulnerable to multiple issues including + arbitrary code execution, information disclosure and denial of + service.</p> + </blockquote> + </body> + </description> + <references> + <url>https://lwn.net/Articles/708092/</url> + <cvename>CVE-2016-5027</cvename> + <cvename>CVE-2016-5028</cvename> + <cvename>CVE-2016-5029</cvename> + <cvename>CVE-2016-5030</cvename> + <cvename>CVE-2016-5031</cvename> + <cvename>CVE-2016-5032</cvename> + <cvename>CVE-2016-5033</cvename> + <cvename>CVE-2016-5035</cvename> + <cvename>CVE-2016-5037</cvename> + <cvename>CVE-2016-5040</cvename> + <cvename>CVE-2016-5041</cvename> + <cvename>CVE-2016-5043</cvename> + <cvename>CVE-2016-5044</cvename> + <cvename>CVE-2016-7510</cvename> + <cvename>CVE-2016-7511</cvename> + <cvename>CVE-2016-8679</cvename> + <cvename>CVE-2016-8680</cvename> + <cvename>CVE-2016-8681</cvename> + <cvename>CVE-2016-9275</cvename> + <cvename>CVE-2016-9276</cvename> + <cvename>CVE-2016-9480</cvename> + <cvename>CVE-2016-9558</cvename> + </references> + <dates> + <discovery>2016-12-04</discovery> + <entry>2017-01-09</entry> + </dates> + </vuln> + <vuln vid="03532a19-d68e-11e6-9171-14dae9d210b8"> <topic>lynx -- multiple vulnerabilities</topic> <affects>
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?201701091732.v09HW4P7095474>