FreeBSD Bugzilla – Attachment 179678 Details for
Bug 216847
audio/wavpack: update to 5.1.0, fix 4 CVE's
Home
|
New
|
Browse
|
Search
|
[?]
|
Reports
|
Help
|
New Account
|
Log In
Remember
[x]
|
Forgot Password
Login:
[x]
[patch]
vuxml patch
vuxml.patch (text/plain), 1.47 KB, created by
Piotr Kubaj
on 2017-02-06 14:55:34 UTC
(
hide
)
Description:
vuxml patch
Filename:
MIME Type:
Creator:
Piotr Kubaj
Created:
2017-02-06 14:55:34 UTC
Size:
1.47 KB
patch
obsolete
>Index: vuln.xml >=================================================================== >--- vuln.xml (revision 433476) >+++ vuln.xml (working copy) >@@ -58,6 +58,38 @@ > * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) > --> > <vuxml xmlns="http://www.vuxml.org/apps/vuxml-1"> >+ <vuln vid="65d5e27c-ec7b-11e6-8cfd-589cfc0654e1"> >+ <topic>wavpack -- multiple vulnerabilities</topic> >+ <affects> >+ <package> >+ <name>wavpack</name> >+ <range><lt>5.1.0</lt></range> >+ </package> >+ </affects> >+ <description> >+ <body xmlns="http://www.w3.org/1999/xhtml"> >+ <p>David Bryant reports:</p> >+ <blockquote cite="http://www.openwall.com/lists/oss-security/2017/01/23/4"> >+ <p>global buffer overread in read_code / read_words.c</p> >+ <p>heap out of bounds read in WriteCaffHeader / caff.c</p> >+ <p>heap out of bounds read in unreorder_channels / wvunpack.c</p> >+ <p>heap oob read in read_new_config_info / open_utils.c</p> >+ </blockquote> >+ </body> >+ </description> >+ <references> >+ <url>http://www.openwall.com/lists/oss-security/2017/01/23/4</url> >+ <cvename>CVE-2016-10169</cvename> >+ <cvename>CVE-2016-10170</cvename> >+ <cvename>CVE-2016-10171</cvename> >+ <cvename>CVE-2016-10172</cvename> >+ </references> >+ <dates> >+ <discovery>2017-01-21</discovery> >+ <entry>2017-02-06</entry> >+ </dates> >+ </vuln> >+ > <vuln vid="2b63e964-eb04-11e6-9ac1-a4badb2f4699"> > <topic>mantis -- XSS vulnerability</topic> > <affects>
You cannot view the attachment while viewing its details because your browser does not support IFRAMEs.
View the attachment on a separate page
.
View Attachment As Diff
View Attachment As Raw
Actions:
View
|
Diff
Attachments on
bug 216847
: 179678 |
179679