FreeBSD Bugzilla – Attachment 157999 Details for
Bug 201061
security/vuxml: document devel/rubygem-bson CVE-2015-4412 in already fixed port
Home
|
New
|
Browse
|
Search
|
[?]
|
Reports
|
Help
|
New Account
|
Log In
Remember
[x]
|
Forgot Password
Login:
[x]
[patch]
security/vuxml entry for CVE-2015-4412 in devel/rubygem-bson
bson.diff (text/plain), 1.47 KB, created by
Jason Unovitch
on 2015-06-22 23:39:38 UTC
(
hide
)
Description:
security/vuxml entry for CVE-2015-4412 in devel/rubygem-bson
Filename:
MIME Type:
Creator:
Jason Unovitch
Created:
2015-06-22 23:39:38 UTC
Size:
1.47 KB
patch
obsolete
>Index: vuln.xml >=================================================================== >--- vuln.xml (revision 390343) >+++ vuln.xml (working copy) >@@ -57,6 +57,36 @@ > > --> > <vuxml xmlns="http://www.vuxml.org/apps/vuxml-1"> >+ <vuln vid="f5225b23-192d-11e5-a1cf-002590263bf5"> >+ <topic>rubygem-bson -- DoS and possible injection</topic> >+ <affects> >+ <package> >+ <name>rubygem-bson</name> >+ <range><lt>3.0.4</lt></range> >+ </package> >+ </affects> >+ <description> >+ <body xmlns="http://www.w3.org/1999/xhtml"> >+ <p>Phill MV reports:</p> >+ <blockquote cite="http://www.openwall.com/lists/oss-security/2015/06/06/1"> >+ <p>By submitting a specially crafted string to a service relying on >+ the bson rubygem, an attacker may trigger denials of service or even >+ inject data into victim's MongoDB instances.</p> >+ </blockquote> >+ </body> >+ </description> >+ <references> >+ <cvename>CVE-2015-4412</cvename> >+ <mlist>http://www.openwall.com/lists/oss-security/2015/06/06/1</mlist> >+ <url>http://sakurity.com/blog/2015/06/04/mongo_ruby_regexp.html</url> >+ <url>https://github.com/mongodb/bson-ruby/compare/7446d7c6764dfda8dc4480ce16d5c023e74be5ca...28f34978a85b689a4480b4d343389bf4886522e7</url> >+ </references> >+ <dates> >+ <discovery>2015-06-04</discovery> >+ <entry>2015-06-22</entry> >+ </dates> >+ </vuln> >+ > <vuln vid="a4460ac7-192c-11e5-9c01-bcaec55be5e5"> > <topic>devel/ipython -- remote execution</topic> > <affects>
You cannot view the attachment while viewing its details because your browser does not support IFRAMEs.
View the attachment on a separate page
.
View Attachment As Diff
View Attachment As Raw
Actions:
View
|
Diff
Attachments on
bug 201061
: 157999