git: 9519d7a2ea - main - Fix correction dates/revisions on SA-23:15.
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Wed, 29 Nov 2023 20:04:28 UTC
The branch main has been updated by gordon:
URL: https://cgit.FreeBSD.org/doc/commit/?id=9519d7a2ea922b0a997cab9c1b2114309e1b80a0
commit 9519d7a2ea922b0a997cab9c1b2114309e1b80a0
Author: Gordon Tetlow <gordon@FreeBSD.org>
AuthorDate: 2023-11-29 20:03:54 +0000
Commit: Gordon Tetlow <gordon@FreeBSD.org>
CommitDate: 2023-11-29 20:03:54 +0000
Fix correction dates/revisions on SA-23:15.
Approved by: so
---
.../security/advisories/FreeBSD-SA-23:15.stdio.asc | 41 ++++++++++++----------
1 file changed, 23 insertions(+), 18 deletions(-)
diff --git a/website/static/security/advisories/FreeBSD-SA-23:15.stdio.asc b/website/static/security/advisories/FreeBSD-SA-23:15.stdio.asc
index 0e367ac3a7..8af0b2ef17 100644
--- a/website/static/security/advisories/FreeBSD-SA-23:15.stdio.asc
+++ b/website/static/security/advisories/FreeBSD-SA-23:15.stdio.asc
@@ -12,9 +12,9 @@ Module: libc
Announced: 2023-11-07
Credits: inooo
All supported versions of FreeBSD.
-Corrected: 2023-11-07 17:29:20 UTC (stable/14, 14.0-STABLE)
+Corrected: 2023-11-07 17:31:34 UTC (stable/14, 14.0-STABLE)
2023-11-08 00:45:25 UTC (releng/14.0, 14.0-RC4-p1)
- 2023-11-07 18:41:49 UTC (stable/13, 13.2-STABLE)
+ 2023-11-07 18:41:55 UTC (stable/13, 13.2-STABLE)
2023-11-08 00:48:03 UTC (releng/13.2, 13.2-RELEASE-p5)
2023-11-08 14:30:51 UTC (stable/12, 12.4-STABLE)
2023-11-08 01:09:31 UTC (releng/12.4, 12.4-RELEASE-p7)
@@ -24,6 +24,11 @@ For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit <URL:https://security.FreeBSD.org/>.
+0. Revision History
+
+v1.0 2023-11-07 -- Initial release
+v1.1 2023-11-29 -- Corrected stable/14 and stable/13 Correction details
+
I. Background
The FreeBSD C library (libc) Standard I/O (stdio) component provides
@@ -43,7 +48,7 @@ III. Impact
Depending on the nature of an application that calls libc's stdio functions
and the presence of errors returned from the write(2) system call (or an
-overridden stdio write routine) a heap buffer overfly may occur. Such
+overridden stdio write routine) a heap buffer overflow may occur. Such
overflows may lead to data corruption or the execution of arbitrary code at
the privilege level of the calling program.
@@ -108,9 +113,9 @@ revision number in the following stable and release branches:
Branch/path Hash Revision
- -------------------------------------------------------------------------
-stable/14/ abe12d2f4ce3 stable/14-n265706
+stable/14/ d2c65a1c9486 stable/14-n265707
releng/14.0/ 1f9c4610dde5 releng/14.0-n265376
-stable/13/ 59ec3ffdd7ce stable/13-n256680
+stable/13/ 0b7939d725ba stable/13-n256681
releng/13.2/ d51a39b13ee4 releng/13.2-n254639
stable/12/ r373263
releng/12.4/ r373265
@@ -151,17 +156,17 @@ The latest revision of this advisory is available at
<URL:https://security.FreeBSD.org/advisories/FreeBSD-SA-23:15.stdio.asc>
-----BEGIN PGP SIGNATURE-----
-iQIzBAEBCgAdFiEEthUnfoEIffdcgYM7bljekB8AGu8FAmVLKaIACgkQbljekB8A
-Gu/MXBAA1Aayy2tPhgpV7uwRZWHKLsda8Am0/7Ok6fswejrxntVIlOwg+Vyo1pTW
-ojDTG2HS9BovXwdhWdSEObNwk+KxZlF8YIYHMOv5HyU4/iTxiBYVUjnk14J0YQAw
-mywyBjOyULXv1gOlvA8FUMk6M8I/RE9fN8dR0D6xHwdY/a/LUbpqqo3H7fftF5D7
-CVZy4Uw0rSJXvJEZIWhgbaqKRyjydXoClX4NS/aMEfLFGDcSQtblVotUVpDedsRZ
-uhVKLibhNqoaausR75oLB6izclHQXzXz3eh7UefM7Udz4R/M8IfFtxwtpsWl3KGH
-bB/2BfrWgrj6Emhmy455NShd7YDcw4VdIZZUVwofS8kmw9NMxvtU2EgdFp/TITMD
-fo/XqMtrwpNTjuyWPY9xM41QansEeidhVBeHsA6B8kmsiZ1XVo8uaAmj5aHldEZx
-TCCVWOlg8D/OnHHtOY0nBz50f57Lt8z2UcSlR3nZL/wRgxsGDdwh1doeFJupIxbE
-1ZS6x4DoQInUhVNTXmSngMCfNOywatVCaOnS2swZETEawI4xAYKUHVJswpA3E0R4
-MhUEo5gk2dEYhuvvr51eewvNSE9mIt7rPhNxhSU7hioraWkdLqE7rUkv9eeaSOOu
-BWaAaCnyS/Vft6aC5nqTg/+2EeRPNJg7JkTHl+pu00h3Y+Q2g48=
-=wgNS
+iQIzBAEBCgAdFiEEthUnfoEIffdcgYM7bljekB8AGu8FAmVnmQkACgkQbljekB8A
+Gu/QUA/+L3iTtXqyMYWT/uI8JHbc+cFjS89GOd14jV2MKUT9ajkUcmkEDC2atzXT
+rUswGxo1sPWZtuVaKdDQrhT12bTKJzV2C0NK0Doj+f9EDEmphvf9kpleMAwkeloR
+g5idsHgEN+gmQHR4Ki5oofvk6FlvGacan407rTvmRdEdTobO4ZM2zOTeTgcCMwzA
+dyA+CeRSIRluVdzu56PLVLYimgs0Xni/JmEatFXXXjGb25lIb4YDq32uO9Xvdhhi
+7cRX6MiFsh702Tt6mo7ajo5B85khOEH/vlJkvgBQ8dcfaGIwpM00SoZFbL1SHk4y
+XSM92YK42XY8ME0gJDndM7gcEy9aODFJTtUuga57Og676/LRlJBVS8xh3kReT6p1
+QY1fmnYXzCmIalumvcY1DjFWBPLDddLLuGIQoBtTHFPd3DDEg7ZpLSUUUqZGmQ+3
+oJSLxBz5Ig+D50MlgD/R8Zmzn4bMCCjZjYahJtK/cjZzC0u5jlDfiF6lofETAypH
+oU9LM9M1lEOxuPS8a+1oCtJn3HZaYNgPp+8NajJlDeDzXpOo8+9cpm+9M5yjxIOF
+mARYZDD42diF3S8Z4ax6Z3H13CxcwHjTZSqVFf3JYpuZehz5aFgZ0xK7AVBWm5We
+4JZ+vwZqdmvSDL00aEdaVJQ4bGxKREwq2cF2grtXWf5nS4ApB0s=
+=koz0
-----END PGP SIGNATURE-----