Created attachment 175199 [details] Add libgd, php56-gd, php70-gd vulns to vuxml Add vuln entries for libgd, php56-gd and php70-gd. CC maintainers of php56-gd and php70-gd. * Issue (with further links): https://github.com/libgd/libgd/issues/308 Note: The PHP issue is #73003, and the patches were added to master before the 5.6.26 and 7.0.11 were tagged, however it looks to me the fix did not end up in those PHP versions. The changelogs also don't mention #73003. Someone please re-check after me, in case I missed something.
A commit references this bug: Author: ale Date: Wed Sep 28 08:20:47 UTC 2016 New revision: 422858 URL: https://svnweb.freebsd.org/changeset/ports/422858 Log: Fix integer overflow in gdImageWebpCtx and bump PORTREVISION. PR: 213023 Submitted by: Vladimir Krstulja <vlad-fbsd@acheronmedia.com> Changes: head/graphics/php55-gd/Makefile head/graphics/php55-gd/files/patch-config.m4 head/graphics/php55-gd/files/patch-libgd_gd_webp.c head/graphics/php56-gd/Makefile head/graphics/php56-gd/files/patch-config.m4 head/graphics/php56-gd/files/patch-libgd_gd_webp.c
Bump. Please note, ale@ fixed php, but no VuXML entry has been added for either.
vuxml entry committed, thanks!
A commit references this bug: Author: feld Date: Wed Oct 12 01:28:23 UTC 2016 New revision: 423816 URL: https://svnweb.freebsd.org/changeset/ports/423816 Log: Document libgd vulnerabilities PR: 213023 Changes: head/security/vuxml/vuln.xml