FreeBSD Bugzilla – Attachment 208540 Details for
Bug 241422
textproc/unoconv: Update to 0.8.2, Fix CVE-2019-17400
Home
|
New
|
Browse
|
Search
|
[?]
|
Reports
|
Help
|
New Account
|
Log In
Remember
[x]
|
Forgot Password
Login:
[x]
[patch]
VuXML entry
0001-textproc-uniconv-add-vuxml-entry.patch (text/plain), 1.59 KB, created by
Nathan
on 2019-10-23 20:20:03 UTC
(
hide
)
Description:
VuXML entry
Filename:
MIME Type:
Creator:
Nathan
Created:
2019-10-23 20:20:03 UTC
Size:
1.59 KB
patch
obsolete
>From 84014f14365da2a15b0ddd4feb25f5867c10033e Mon Sep 17 00:00:00 2001 >From: Nathan Owens <ndowens04@gmail.com> >Date: Wed, 23 Oct 2019 15:14:12 -0500 >Subject: [PATCH] textproc/uniconv: add vuxml entry > >--- > security/vuxml/vuln.xml | 27 +++++++++++++++++++++++++++ > 1 file changed, 27 insertions(+) > >diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml >index 4bd89d2ca9ab..73732db76122 100644 >--- a/security/vuxml/vuln.xml >+++ b/security/vuxml/vuln.xml >@@ -58,6 +58,33 @@ Notes: > * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) > --> > <vuxml xmlns="http://www.vuxml.org/apps/vuxml-1"> >+ <vuln vid="c8360ee9-f5cb-11e9-9c4f-74d435e60b7c"> >+ <topic>SSRF and local file inclusion</topic> >+ <affects> >+ <package> >+ <name>unoconv</name> >+ <range><lt>0.9</lt></range> >+ </package> >+ </affects> >+ <description> >+ <body xmlns="http://www.w3.org/1999/xhtml"> >+ <p>mitre</p> >+ <blockquote cite="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17400"> >+ <p>escription >+ The unoconv package before 0.9 mishandles untrusted pathnames, leading to SSRF and local file inclusion.</p> >+ </blockquote> >+ </body> >+ </description> >+ <references> >+ <url>https://buer.haus/2019/10/18/a-tale-of-exploitation-in-spreadsheet-file-conversions/</url> >+ <url>https://github.com/unoconv/unoconv/pull/510</url> >+ </references> >+ <dates> >+ <discovery>2019-10-09</discovery> >+ <entry>2019-10-21</entry> >+ </dates> >+ </vuln> >+ > <vuln vid="a90d040e-f5b0-11e9-acc4-4576b265fda6"> > <topic>Loofah -- XSS vulnerability</topic> > <affects> >-- >2.23.0 >
You cannot view the attachment while viewing its details because your browser does not support IFRAMEs.
View the attachment on a separate page
.
View Attachment As Diff
View Attachment As Raw
Flags:
ndowens04
:
maintainer-approval+
Actions:
View
|
Diff
Attachments on
bug 241422
:
208513
|
208514
| 208540