ports/109086: security/vuxml: fix the entries of tdiary

KOMATSU Shinichiro koma2 at lovepeers.org
Mon Feb 12 13:40:22 UTC 2007


>Number:         109086
>Category:       ports
>Synopsis:       security/vuxml: fix the entries of tdiary
>Confidential:   no
>Severity:       serious
>Priority:       medium
>Responsible:    freebsd-ports-bugs
>State:          open
>Quarter:        
>Keywords:       
>Date-Required:
>Class:          doc-bug
>Submitter-Id:   current-users
>Arrival-Date:   Mon Feb 12 13:40:18 GMT 2007
>Closed-Date:
>Last-Modified:
>Originator:     KOMATSU Shinichiro
>Release:        FreeBSD 6.2-RELEASE i386
>Organization:
>Environment:
FreeBSD 6.2-RELEASE i386
>Description:
Fix the VuXML entries of recently discovered tdiary vulnerabilities
("fefd93d8-8af5-11db-9d01-0016179b2dd5" and "666b8c9e-8212-11db-851e-0016179b2dd5")
as follows:

- correct the affected version numbers
- package name of www/tdiary-devel is "tdiary-devel", not "tdiary"
- add ja-tdiary and ja-tdiary-devel to affected packages

>How-To-Repeat:

>Fix:


Patch attached with submission follows:

Index: security/vuxml/vuln.xml
===================================================================
RCS file: /home/ncvs/ports/security/vuxml/vuln.xml,v
retrieving revision 1.1270
diff -u -r1.1270 vuln.xml
--- security/vuxml/vuln.xml	17 Jan 2007 22:17:49 -0000	1.1270
+++ security/vuxml/vuln.xml	12 Feb 2007 13:25:01 -0000
@@ -725,9 +725,14 @@
     <topic>tdiary -- injection vulnerability</topic>
     <affects>
       <package>
+	<name>ja-tdiary</name>
 	<name>tdiary</name>
-	<range><lt>2.0.3</lt></range>
-        <range><gt>2.1</gt><lt>2.1.4.20061126</lt></range>
+	<range><le>2.0.3</le></range>
+      </package>
+      <package>
+	<name>ja-tdiary-devel</name>
+	<name>tdiary-devel</name>
+        <range><gt>2.1</gt><lt>2.1.4_2</lt></range>
       </package>
     </affects>
     <description>
@@ -741,7 +746,7 @@
     <dates>
       <discovery>2006-12-10</discovery>
       <entry>2006-12-13</entry>
-      <modified>2006-12-15</modified>
+      <modified>2007-02-12</modified>
     </dates>
   </vuln>
 
@@ -1039,9 +1044,14 @@
     <topic>tdiary  -- cross site scripting vulnerability</topic>
     <affects>
       <package>
+	<name>ja-tdiary</name>
 	<name>tdiary</name>
-	<range><lt>2.0.2</lt></range>
-        <range><gt>2.1</gt><lt>2.1.4.20061115</lt></range>
+	<range><le>2.0.2</le></range>
+      </package>
+      <package>
+	<name>ja-tdiary-devel</name>
+	<name>tdiary-devel</name>
+        <range><gt>2.1</gt><lt>2.1.4_1</lt></range>
       </package>
     </affects>
     <description>
@@ -1056,6 +1066,7 @@
     <dates>
       <discovery>2006-11-26</discovery>
       <entry>2006-12-02</entry>
+      <modified>2007-02-12</modified>
     </dates>
   </vuln>
 

>Release-Note:
>Audit-Trail:
>Unformatted:



More information about the freebsd-ports-bugs mailing list