View | Details | Raw Unified | Return to bug 223962
Collapse All | Expand All

(-)security/vuxml/vuln.xml (+33 lines)
Lines 58-63 Link Here
58
  * Do not forget port variants (linux-f10-libxml2, libxml2, etc.)
58
  * Do not forget port variants (linux-f10-libxml2, libxml2, etc.)
59
-->
59
-->
60
<vuxml xmlns="http://www.vuxml.org/apps/vuxml-1">
60
<vuxml xmlns="http://www.vuxml.org/apps/vuxml-1">
61
  <vuln vid="5e1d8d78-d4ef-11e7-a633-009c02a2ab30">
62
    <topic>curl -- multiple vulnerabilities</topic>
63
    <affects>
64
      <package>
65
	<name>curl</name>
66
	<range><ge>7.21.0</ge><le>7.56.1</le></range>
67
      </package>
68
    </affects>
69
    <description>
70
      <body xmlns="http://www.w3.org/1999/xhtml">
71
	<p>curl developers report:</p>
72
	<blockquote cite="https://curl.haxx.se/docs/security.html">
73
	  <p>CVE-2017-8816: NTLM buffer overflow via integer overflow.</p>
74
	  <p>CVE-2017-8817: FTP wildcard out of bounds read.</p>
75
	  <p>CVE-2017-8818: SSL out of buffer access.</p>
76
	  <p>Please refer to the CVE list for details.</p>
77
	</blockquote>
78
      </body>
79
    </description>
80
    <references>
81
	<url>https://curl.haxx.se/docs/adv_2017-12e7.html</url>
82
	<url>https://curl.haxx.se/docs/adv_2017-ae72.html</url>
83
	<url>https://curl.haxx.se/docs/adv_2017-af0a.html</url>
84
	<cvename>CVE-2017-8816</cvename>
85
	<cvename>CVE-2017-8817</cvename>
86
	<cvename>CVE-2017-8818</cvename>
87
    </references>
88
    <dates>
89
      <discovery>2017-11-29</discovery>
90
      <entry>2017-11-29</entry>
91
    </dates>
92
  </vuln>
93
61
  <vuln vid="0d369972-d4ba-11e7-bfca-005056925db4">
94
  <vuln vid="0d369972-d4ba-11e7-bfca-005056925db4">
62
    <topic>borgbackup -- remote users can override repository restrictions</topic>
95
    <topic>borgbackup -- remote users can override repository restrictions</topic>
63
    <affects>
96
    <affects>

Return to bug 223962