--- /var/db/pkg/vuln.xml 2015-03-19 03:19:20.329192949 +0100 +++ /usr/ports/security/vuxml/vuln.xml 2015-03-19 21:23:55.532704000 +0100 @@ -57,6 +57,47 @@ --> + + Multiple vulnerabilities found in LibreSSL + + + libressl + 2.1.5 + + + + +

The LibreSSL project reports

+
+

* Fixes for the following issues are integrated into LibreSSL 2.1.6: + - CVE-2015-0209 - Use After Free following d2i_ECPrivatekey error + - CVE-2015-0286 - Segmentation fault in ASN1_TYPE_cmp + - CVE-2015-0287 - ASN.1 structure reuse memory corruption + - CVE-2015-0288 - X509_to_X509_REQ NULL pointer deref + - CVE-2015-0289 - PKCS7 NULL pointer dereferences + + * The fix for CVE-2015-0207 - Segmentation fault in DTLSv1_listen + is integrated for safety, but LibreSSL is not vulnerable. +

+
+ +
+ + ports/198681 + CVE-2015-0209 + CVE-2015-0286 + CVE-2015-0287 + CVE-2015-0288 + CVE-2015-0289 + https://openssl.org/news/secadv_20150319.txt + + + 2015-03-19 + 2015-03-19 + +
+ libXfont -- BDF parsing issues