Bug 207574

Summary: security/vuxml: Entry for graphics/silgraphite missing or insufficient information (vid 8f10fa04-cf6a-11e5-96d6-14dae9d210b8)
Product: Ports & Packages Reporter: Sevan Janiyan <venture37>
Component: Individual Port(s)Assignee: Mark Felder <feld>
Status: Closed FIXED    
Severity: Affects Some People CC: ports-secteam
Priority: --- Keywords: security
Version: Latest   
Hardware: Any   
OS: Any   

Description Sevan Janiyan 2016-02-29 01:28:36 UTC
In vuln id 8f10fa04-cf6a-11e5-96d6-14dae9d210b8 , silgraphite is listed as affected by the issue. This is wrong, the files referenced in the CVEs do not exist nor the SillMap::readFace function in silgraphite.
Comment 1 Raphael Kubo da Costa freebsd_committer freebsd_triage 2016-03-01 11:53:56 UTC
Assigning to feld, who wrote the vuxml entry.
Comment 2 Mark Felder freebsd_committer freebsd_triage 2016-03-01 22:32:35 UTC
CVE details:

http://www.talosintel.com/reports/TALOS-2016-0061/

Don Lewis <truckman@FreeBSD.org> crafted the following patch to mitigate the issue in silgraphite.

https://svnweb.freebsd.org/ports/head/graphics/silgraphite/files/patch-engine_src_font_TtfUtil.cpp?revision=409139&view=markup


This patch looks to be relevant to the CVE and to be solving the same issue to me. I have not taken a detailed look or examined any discussions on the internet, so I'm not aware if there is wider discussion detailing the reason that silgraphite is not actually affected.
Comment 3 Sevan Janiyan 2016-03-02 01:26:17 UTC
Hi Mark,
Vuln id 8f10fa04-cf6a-11e5-96d6-14dae9d210b8 is pointing to http://blog.talosintel.com/2016/02/vulnerability-spotlight-libgraphite.html however. This is what caused my false alarm. It seems that this link & the one you referenced cover CVE-2016-1521. This has highlighted that I need to double check things my end as I missed http://www.talosintel.com/reports/TALOS-2016-0061/

Apologies.
Comment 4 Mark Felder freebsd_committer freebsd_triage 2016-03-02 13:51:51 UTC
Thanks for the feedback. Let me know what you find.
Comment 5 commit-hook freebsd_committer freebsd_triage 2016-03-02 13:54:00 UTC
A commit references this bug:

Author: feld
Date: Wed Mar  2 13:53:06 UTC 2016
New revision: 409939
URL: https://svnweb.freebsd.org/changeset/ports/409939

Log:
  Update graphite vuxml entry to add another relevant URL

  PR:		207574

Changes:
  head/security/vuxml/vuln.xml
Comment 6 VK 2016-10-07 09:49:17 UTC
Update summary so that summary with state closed:fixed is meaningful and closer to actual problem.