FreeBSD Bugzilla – Attachment 208539 Details for
Bug 241424
sysutils/file: Update to 5.37, Fix CVE-2019-18218
Home
|
New
|
Browse
|
Search
|
[?]
|
Reports
|
Help
|
New Account
|
Log In
Remember
[x]
|
Forgot Password
Login:
[x]
[patch]
VuXML entry
0001-sysutils-file-add-vuxml-entry.patch (text/plain), 1.69 KB, created by
Nathan
on 2019-10-23 20:18:41 UTC
(
hide
)
Description:
VuXML entry
Filename:
MIME Type:
Creator:
Nathan
Created:
2019-10-23 20:18:41 UTC
Size:
1.69 KB
patch
obsolete
>From ecd7262e0db8bcc1eddc1c3ee451d79e98f10151 Mon Sep 17 00:00:00 2001 >From: Nathan Owens <ndowens04@gmail.com> >Date: Wed, 23 Oct 2019 15:12:00 -0500 >Subject: [PATCH] sysutils/file: add vuxml entry > >--- > security/vuxml/vuln.xml | 27 +++++++++++++++++++++++++++ > 1 file changed, 27 insertions(+) > >diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml >index 4bd89d2ca9ab..c143b86f758b 100644 >--- a/security/vuxml/vuln.xml >+++ b/security/vuxml/vuln.xml >@@ -58,6 +58,33 @@ Notes: > * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) > --> > <vuxml xmlns="http://www.vuxml.org/apps/vuxml-1"> >+ <vuln vid="381deebb-f5c9-11e9-9c4f-74d435e60b7c"> >+ <topic>Heap buffer overflow possible</topic> >+ <affects> >+ <package> >+ <name>file</name> >+ <range><lt>5.37</lt></range> >+ <range><eq>5.37</eq></range> >+ </package> >+ </affects> >+ <description> >+ <body xmlns="http://www.w3.org/1999/xhtml"> >+ <p>mitre reports</p> >+ <blockquote cite="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18218"> >+ <p>cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write). </p> >+ </blockquote> >+ </body> >+ </description> >+ <references> >+ <url>https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=16780</url> >+ <url>https://github.com/file/file/commit/46a8443f76cec4b41ec736eca396984c74664f84</url> >+ </references> >+ <dates> >+ <discovery>2019-08-26</discovery> >+ <entry>2019-10-21</entry> >+ </dates> >+ </vuln> >+ > <vuln vid="a90d040e-f5b0-11e9-acc4-4576b265fda6"> > <topic>Loofah -- XSS vulnerability</topic> > <affects> >-- >2.23.0 >
You cannot view the attachment while viewing its details because your browser does not support IFRAMEs.
View the attachment on a separate page
.
View Attachment As Diff
View Attachment As Raw
Actions:
View
|
Diff
Attachments on
bug 241424
:
208516
| 208539