Bug 115387 - archivers/lha-ac is affected CVE-2006-4335 and CVE-2006-4337.
Summary: archivers/lha-ac is affected CVE-2006-4335 and CVE-2006-4337.
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: Normal Affects Only Me
Assignee: Dirk Meyer
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2007-08-10 18:30 UTC by Takamichi Tateoka
Modified: 2007-08-12 15:37 UTC (History)
1 user (show)

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Takamichi Tateoka 2007-08-10 18:30:01 UTC
  lha-ac-1.14i_8 uses lha-1.14i-ac20050924 distribution.  However,
it has secrity problem described in CVE-2006-4335 and CVE-2006-4337.
It should use lha-1.14i-ac20050924p1, which fixed the problems.

  You can see lha-1.14i-ac20050924 branch changelog on following URL:
http://cvs.sourceforge.jp/cgi-bin/viewcvs.cgi/lha/lha/src/maketbl.c?only_with_tag=ac-20050924-branch

Fix: 

Update to lha-1.14i-ac20050924p1.
Comment 1 Edwin Groothuis freebsd_committer freebsd_triage 2007-08-11 00:10:45 UTC
Responsible Changed
From-To: freebsd-ports-bugs->dinoex

Over to maintainer
Comment 2 dfilter service freebsd_committer freebsd_triage 2007-08-11 18:01:29 UTC
dinoex      2007-08-11 17:01:22 UTC

  FreeBSD ports repository

  Modified files:
    archivers/lha-ac     Makefile distinfo 
  Log:
  - security update to ac20050924p1
  Security: CVE-2006-4335
  Security: CVE-2006-4337
  Security: CVE-2006-4338
  PR:             115387
  
  - make portlint happier
  
  Revision  Changes    Path
  1.5       +4 -4      ports/archivers/lha-ac/Makefile
  1.3       +3 -3      ports/archivers/lha-ac/distinfo
_______________________________________________
cvs-all@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/cvs-all
To unsubscribe, send any mail to "cvs-all-unsubscribe@freebsd.org"
Comment 3 Dirk Meyer freebsd_committer freebsd_triage 2007-08-12 15:37:44 UTC
State Changed
From-To: open->closed

update committed, thanks.