Date: Sun, 9 Aug 2020 08:00:28 +0000 (UTC) From: Kurt Jaeger <pi@FreeBSD.org> To: ports-committers@freebsd.org, svn-ports-all@freebsd.org, svn-ports-head@freebsd.org Subject: svn commit: r544548 - head/security/vuxml Message-ID: <202008090800.07980S6H011580@repo.freebsd.org>
next in thread | raw e-mail | index | archive | help
Author: pi Date: Sun Aug 9 08:00:28 2020 New Revision: 544548 URL: https://svnweb.freebsd.org/changeset/ports/544548 Log: security/vuxml: add www/trafficserver entry for CVE-2020-9494 PR: 247713 Submitted by: spam123@bitbert.com Modified: head/security/vuxml/vuln.xml Modified: head/security/vuxml/vuln.xml ============================================================================== --- head/security/vuxml/vuln.xml Sun Aug 9 07:57:54 2020 (r544547) +++ head/security/vuxml/vuln.xml Sun Aug 9 08:00:28 2020 (r544548) @@ -58,6 +58,32 @@ Notes: * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> <vuxml xmlns="http://www.vuxml.org/apps/vuxml-1"> + <vuln vid="6fd773d3-bc5a-11ea-b38d-f0def1d0c3ea"> + <topic>trafficserver -- resource consumption</topic> + <affects> + <package> + <name>trafficserver</name> + <range><lt>8.0.8</lt></range> + </package> + </affects> + <description> + <body xmlns="http://www.w3.org/1999/xhtml"> + <p>Bryan Call reports:</p> + <blockquote cite="https://lists.apache.org/thread.html/rf7f86917f42fdaf904d99560cba0c016e03baea6244c47efeb60ecbe%40%3Cdev.trafficserver.apache.org%3E"> + <p>ATS is vulnerable to certain types of HTTP/2 HEADERS frames that can cause the server to allocate a large amount of memory and spin the thread.</p> + </blockquote> + </body> + </description> + <references> + <url>https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9494</url> + <cvename>CVE-2020-9494</cvename> + </references> + <dates> + <discovery>2020-06-24</discovery> + <entry>2020-07-02</entry> + </dates> + </vuln> + <vuln vid="76700d2f-d959-11ea-b53c-d4c9ef517024"> <topic>Apache httpd -- Multiple vulnerabilities</topic> <affects>
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?202008090800.07980S6H011580>