ports/109086: security/vuxml: fix the entries of tdiary
KOMATSU Shinichiro
koma2 at lovepeers.org
Mon Feb 12 13:40:22 UTC 2007
>Number: 109086
>Category: ports
>Synopsis: security/vuxml: fix the entries of tdiary
>Confidential: no
>Severity: serious
>Priority: medium
>Responsible: freebsd-ports-bugs
>State: open
>Quarter:
>Keywords:
>Date-Required:
>Class: doc-bug
>Submitter-Id: current-users
>Arrival-Date: Mon Feb 12 13:40:18 GMT 2007
>Closed-Date:
>Last-Modified:
>Originator: KOMATSU Shinichiro
>Release: FreeBSD 6.2-RELEASE i386
>Organization:
>Environment:
FreeBSD 6.2-RELEASE i386
>Description:
Fix the VuXML entries of recently discovered tdiary vulnerabilities
("fefd93d8-8af5-11db-9d01-0016179b2dd5" and "666b8c9e-8212-11db-851e-0016179b2dd5")
as follows:
- correct the affected version numbers
- package name of www/tdiary-devel is "tdiary-devel", not "tdiary"
- add ja-tdiary and ja-tdiary-devel to affected packages
>How-To-Repeat:
>Fix:
Patch attached with submission follows:
Index: security/vuxml/vuln.xml
===================================================================
RCS file: /home/ncvs/ports/security/vuxml/vuln.xml,v
retrieving revision 1.1270
diff -u -r1.1270 vuln.xml
--- security/vuxml/vuln.xml 17 Jan 2007 22:17:49 -0000 1.1270
+++ security/vuxml/vuln.xml 12 Feb 2007 13:25:01 -0000
@@ -725,9 +725,14 @@
<topic>tdiary -- injection vulnerability</topic>
<affects>
<package>
+ <name>ja-tdiary</name>
<name>tdiary</name>
- <range><lt>2.0.3</lt></range>
- <range><gt>2.1</gt><lt>2.1.4.20061126</lt></range>
+ <range><le>2.0.3</le></range>
+ </package>
+ <package>
+ <name>ja-tdiary-devel</name>
+ <name>tdiary-devel</name>
+ <range><gt>2.1</gt><lt>2.1.4_2</lt></range>
</package>
</affects>
<description>
@@ -741,7 +746,7 @@
<dates>
<discovery>2006-12-10</discovery>
<entry>2006-12-13</entry>
- <modified>2006-12-15</modified>
+ <modified>2007-02-12</modified>
</dates>
</vuln>
@@ -1039,9 +1044,14 @@
<topic>tdiary -- cross site scripting vulnerability</topic>
<affects>
<package>
+ <name>ja-tdiary</name>
<name>tdiary</name>
- <range><lt>2.0.2</lt></range>
- <range><gt>2.1</gt><lt>2.1.4.20061115</lt></range>
+ <range><le>2.0.2</le></range>
+ </package>
+ <package>
+ <name>ja-tdiary-devel</name>
+ <name>tdiary-devel</name>
+ <range><gt>2.1</gt><lt>2.1.4_1</lt></range>
</package>
</affects>
<description>
@@ -1056,6 +1066,7 @@
<dates>
<discovery>2006-11-26</discovery>
<entry>2006-12-02</entry>
+ <modified>2007-02-12</modified>
</dates>
</vuln>
>Release-Note:
>Audit-Trail:
>Unformatted:
More information about the freebsd-ports-bugs
mailing list