Bug 204413

Summary: archivers/unzip multiple vulnerabilities
Product: Ports & Packages Reporter: Sevan Janiyan <venture37>
Component: Individual Port(s)Assignee: Emanuel Haupt <ehaupt>
Status: Closed FIXED    
Severity: Affects Only Me CC: feld, ports-secteam
Priority: --- Keywords: needs-patch, security
Version: LatestFlags: bugzilla: maintainer-feedback? (ehaupt)
Hardware: Any   
OS: Any   
Attachments:
Description Flags
Patch to fix CVE-2015-7696 and CVE-2015-7697
none
VuXML entry to be added none

Description Sevan Janiyan 2015-11-10 01:03:39 UTC
CVE-2015-7696 CVE-2015-7697
Comment 1 Emanuel Haupt freebsd_committer freebsd_triage 2016-01-04 14:38:40 UTC
Created attachment 165057 [details]
Patch to fix CVE-2015-7696 and CVE-2015-7697
Comment 2 Mark Felder freebsd_committer freebsd_triage 2016-01-05 02:46:05 UTC
Emanual, let me know if you need any assistance with the vuxml entry
Comment 3 Emanuel Haupt freebsd_committer freebsd_triage 2016-01-05 06:00:16 UTC
(In reply to Mark Felder from comment #2)
Thank you for the offer to review the VuXML entry. Bernard Spil kindly helped me with the entry (attached). I would appreciate your review.
Comment 4 Emanuel Haupt freebsd_committer freebsd_triage 2016-01-05 06:01:17 UTC
Created attachment 165091 [details]
VuXML entry to be added

VuXML entry kindly provided by brnrd
Comment 5 commit-hook freebsd_committer freebsd_triage 2016-01-05 13:09:24 UTC
A commit references this bug:

Author: ehaupt
Date: Tue Jan  5 13:08:35 UTC 2016
New revision: 405286
URL: https://svnweb.freebsd.org/changeset/ports/405286

Log:
  Fix multiple vulnerabilities.

  PR:		204413 (based on)
  Notified by:	venture37@geeklan.co.uk
  Security:	CVE-2015-7696, CVE-2015-7697
  MFH:		2016Q1

Changes:
  head/archivers/unzip/Makefile
  head/archivers/unzip/files/patch-crypt.c
  head/archivers/unzip/files/patch-extract.c
Comment 6 commit-hook freebsd_committer freebsd_triage 2016-01-05 13:13:26 UTC
A commit references this bug:

Author: ehaupt
Date: Tue Jan  5 13:12:57 UTC 2016
New revision: 405287
URL: https://svnweb.freebsd.org/changeset/ports/405287

Log:
  MFH: r405286

  Fix multiple vulnerabilities.

  PR:		204413 (based on)
  Notified by:	venture37@geeklan.co.uk
  Security:	CVE-2015-7696, CVE-2015-7697
  Approved by:	ports-secteam (feld)

Changes:
_U  branches/2016Q1/
  branches/2016Q1/archivers/unzip/Makefile
  branches/2016Q1/archivers/unzip/files/patch-crypt.c
  branches/2016Q1/archivers/unzip/files/patch-extract.c