Summary: | [patch] [vuxml] comms/mgetty+sendfax: fix and document CVE-2008-4936 | ||
---|---|---|---|
Product: | Ports & Packages | Reporter: | Eygene Ryabinkin <rea-fbsd> |
Component: | Individual Port(s) | Assignee: | Martin Wilke <miwi> |
Status: | Closed FIXED | ||
Severity: | Affects Only Me | ||
Priority: | Normal | ||
Version: | Latest | ||
Hardware: | Any | ||
OS: | Any |
Description
Eygene Ryabinkin
2008-12-06 20:20:01 UTC
Responsible Changed From-To: freebsd-ports-bugs->miwi miwi@ wants his PRs (via the GNATS Auto Assign Tool) miwi 2008-12-07 11:41:32 UTC FreeBSD ports repository Modified files: security/vuxml vuln.xml Log: - Document mgetty+sendfax -- symlink attack via insecure temporary files PR: based on 129471 Submitted by: Eygene Ryabinkin <rea-fbsd@codelabs.ru> Revision Changes Path 1.1780 +31 -1 ports/security/vuxml/vuln.xml _______________________________________________ cvs-all@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/cvs-all To unsubscribe, send any mail to "cvs-all-unsubscribe@freebsd.org" State Changed From-To: open->closed documented with some changes, also added patch. Thanks for your submission. miwi 2008-12-07 11:47:22 UTC FreeBSD ports repository Modified files: comms/mgetty+sendfax Makefile Added files: comms/mgetty+sendfax/files patch-CVE-2008-4936 Log: - Fix symlink attack via insecure temporary files PR: 129471 Submitted by: Eygene Ryabinkin <rea-fbsd@codelabs.ru> Obtained from: debian Security: http://www.vuxml.org/freebsd/44ee8160-c453-11dd-a721-0030843d3802.html Revision Changes Path 1.57 +1 -1 ports/comms/mgetty+sendfax/Makefile 1.1 +52 -0 ports/comms/mgetty+sendfax/files/patch-CVE-2008-4936 (new) _______________________________________________ cvs-all@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/cvs-all To unsubscribe, send any mail to "cvs-all-unsubscribe@freebsd.org" Martin, good evening. Sun, Dec 07, 2008 at 11:43:00AM +0000, miwi@FreeBSD.org wrote: > Synopsis: [patch] [vuxml] comms/mgetty+sendfax: fix and document CVE-2008-4936 > > State-Changed-From-To: open->closed > State-Changed-By: miwi > State-Changed-When: Sun Dec 7 11:42:59 UTC 2008 > State-Changed-Why: > documented with some changes, also added patch. Thanks for your > submission. Thanks! One neat: VuXML entry should read "faxspool in mgetty...", not the "axspool in mgetty'. -- Eygene _ ___ _.--. # \`.|\..----...-'` `-._.-'_.-'` # Remember that it is hard / ' ` , __.--' # to read the on-line manual )/' _/ \ `-_, / # while single-stepping the kernel. `-'" `"\_ ,_.-;_.-\_ ', fsc/as # _.-'_./ {_.' ; / # -- FreeBSD Developers handbook {_.-``-' {_/ # |