From owner-freebsd-ports-bugs@FreeBSD.ORG Wed Aug 28 08:50:01 2013 Return-Path: Delivered-To: freebsd-ports-bugs@smarthost.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTP id 3418398D for ; Wed, 28 Aug 2013 08:50:01 +0000 (UTC) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (freefall.freebsd.org [IPv6:2001:1900:2254:206c::16:87]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mx1.freebsd.org (Postfix) with ESMTPS id 1289A2668 for ; Wed, 28 Aug 2013 08:50:01 +0000 (UTC) Received: from freefall.freebsd.org (localhost [127.0.0.1]) by freefall.freebsd.org (8.14.7/8.14.7) with ESMTP id r7S8o0iN049186 for ; Wed, 28 Aug 2013 08:50:00 GMT (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.14.7/8.14.7/Submit) id r7S8o05w049185; Wed, 28 Aug 2013 08:50:00 GMT (envelope-from gnats) Resent-Date: Wed, 28 Aug 2013 08:50:00 GMT Resent-Message-Id: <201308280850.r7S8o05w049185@freefall.freebsd.org> Resent-From: FreeBSD-gnats-submit@FreeBSD.org (GNATS Filer) Resent-To: freebsd-ports-bugs@FreeBSD.org Resent-Reply-To: FreeBSD-gnats-submit@FreeBSD.org, Rodrigo (ros) OSORIO Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTP id DD5A7972 for ; Wed, 28 Aug 2013 08:49:49 +0000 (UTC) (envelope-from rodrigo@bebik.net) Received: from smtp3-g21.free.fr (smtp3-g21.free.fr [IPv6:2a01:e0c:1:1599::12]) by mx1.freebsd.org (Postfix) with ESMTP id 6EB0A2662 for ; Wed, 28 Aug 2013 08:49:47 +0000 (UTC) Received: from oldfaithful.bebik.local (unknown [82.227.164.69]) by smtp3-g21.free.fr (Postfix) with ESMTP id 63746A626A for ; Wed, 28 Aug 2013 10:49:43 +0200 (CEST) Received: by oldfaithful.bebik.local (Postfix, from userid 1001) id 2DB0C800A5C; Wed, 28 Aug 2013 10:38:40 +0200 (CEST) Message-Id: <20130828083840.2DB0C800A5C@oldfaithful.bebik.local> Date: Wed, 28 Aug 2013 10:38:40 +0200 (CEST) From: Rodrigo (ros) OSORIO To: FreeBSD-gnats-submit@freebsd.org X-Send-Pr-Version: 3.113 Subject: ports/181606: vuxml database update - cati vulnerabilities have been discovered X-BeenThere: freebsd-ports-bugs@freebsd.org X-Mailman-Version: 2.1.14 Precedence: list Reply-To: "Rodrigo OSORIO \(ros\)" List-Id: Ports bug reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 28 Aug 2013 08:50:01 -0000 >Number: 181606 >Category: ports >Synopsis: vuxml database update - cati vulnerabilities have been discovered >Confidential: no >Severity: critical >Priority: high >Responsible: freebsd-ports-bugs >State: open >Quarter: >Keywords: >Date-Required: >Class: change-request >Submitter-Id: current-users >Arrival-Date: Wed Aug 28 08:50:00 UTC 2013 >Closed-Date: >Last-Modified: >Originator: Rodrigo (ros) OSORIO >Release: FreeBSD 9.0-RELEASE amd64 >Organization: >Environment: System: FreeBSD sisko 9.0-RELEASE FreeBSD 9.0-RELEASE #0: Tue Jan 3 07:46:30 UTC 2012 root@farrell.cse.buffalo.edu:/usr/obj/usr/src/sys/GENERIC amd64 >Description: >How-To-Repeat: >Fix: --- vuxml.diff begins here --- Index: vuln.xml =================================================================== --- vuln.xml (revision 325514) +++ vuln.xml (working copy) @@ -51,6 +51,35 @@ --> + + cacti -- allow remote attackers to execute arbitrary SQL commands + + + cacti + 0.8.8b + + + + +

Cacti release reports:

+
+

Multiple security vulnerabilities have been fixed:

+
    +
  • SQL injection vulnerabilities
  • +
+
+ +
+ + CVE-2013-1434 + http://www.cacti.net/release_notes_0_8_8b.php + + + 2013-08-23 + 2013-08-28 + +
+ chromium -- multiple vulnerabilities --- vuxml.diff ends here --- >Release-Note: >Audit-Trail: >Unformatted: