FreeBSD Bugzilla – Attachment 161114 Details for
Bug 203096
[patch][maintainer update] update www/h2o to 1.4.5
Home
|
New
|
Browse
|
Search
|
[?]
|
Reports
|
Help
|
New Account
|
Log In
Remember
[x]
|
Forgot Password
Login:
[x]
[patch]
CVE-2015-5638
vuxml.diff (text/plain), 1.53 KB, created by
Dave Cottlehuber
on 2015-09-16 10:52:38 UTC
(
hide
)
Description:
CVE-2015-5638
Filename:
MIME Type:
Creator:
Dave Cottlehuber
Created:
2015-09-16 10:52:38 UTC
Size:
1.53 KB
patch
obsolete
>diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml >index 3d53e58..c3c93f1 100644 >--- a/security/vuxml/vuln.xml >+++ b/security/vuxml/vuln.xml >@@ -58,6 +58,38 @@ Notes: > > --> > <vuxml xmlns="http://www.vuxml.org/apps/vuxml-1"> >+ <vuln vid="31ea7f73-5c55-11e5-8607-74d02b9a84d5"> >+ <topic>h2o directory traversal vulnerability</topic> >+ <affects> >+ <package> >+ <name>h2o</name> >+ <range><lt>1.4.5</lt></range> >+ </package> >+ </affects> >+ <description> >+ <body xmlns="http://www.w3.org/1999/xhtml"> >+ <p>Yakuzo reports:</p> >+ <blockquote cite="https://h2o.examp1e.net/vulnerabilities.html"> >+ <p>H2O (up to version 1.4.4 / 1.5.0-beta1) contains a flaw in its URL >+ normalization logic. When file.dir directive is used, this flaw >+ allows a remote attacker to retrieve arbitrary files that exist >+ outside the directory specified by the directive. H2O version 1.4.5 >+ and version 1.5.0-beta2 have been released to address this >+ vulnerability. Users are advised to upgrade their servers >+ immediately. The vulnerability was reported by: Yusuke OSUMI.</p> >+ </blockquote> >+ </body> >+ </description> >+ <references> >+ <cvename>CVE-2015-5638</cvename> >+ <url>http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5638</url> >+ </references> >+ <dates> >+ <discovery>2015-09-14</discovery> >+ <entry>2015-09-16</entry> >+ </dates> >+ </vuln> >+ > <vuln vid="f4ce64c2-5bd4-11e5-9040-3c970e169bc2"> > <topic>wordpress -- multiple vulnerabilities</topic> > <affects>
You cannot view the attachment while viewing its details because your browser does not support IFRAMEs.
View the attachment on a separate page
.
View Attachment As Diff
View Attachment As Raw
Flags:
dch
:
maintainer-approval+
Actions:
View
|
Diff
Attachments on
bug 203096
:
161112
| 161114