git: d1a91ac3af2d - main - graphics/p5-Image-ExifTool: Add an vuxml entry for update 12.42

From: Neel Chauhan <nc_at_FreeBSD.org>
Date: Tue, 21 Jun 2022 21:09:41 UTC
The branch main has been updated by nc:

URL: https://cgit.FreeBSD.org/ports/commit/?id=d1a91ac3af2def2af574b9d6266ead4811aaf6fd

commit d1a91ac3af2def2af574b9d6266ead4811aaf6fd
Author:     Rafael Grether <devnull@apt322.org>
AuthorDate: 2022-06-21 21:05:51 +0000
Commit:     Neel Chauhan <nc@FreeBSD.org>
CommitDate: 2022-06-21 21:09:38 +0000

    graphics/p5-Image-ExifTool: Add an vuxml entry for update 12.42
    
    PR:     264618
---
 security/vuxml/vuln-2022.xml | 25 +++++++++++++++++++++++++
 1 file changed, 25 insertions(+)

diff --git a/security/vuxml/vuln-2022.xml b/security/vuxml/vuln-2022.xml
index 869f4468d15b..290b8df3b177 100644
--- a/security/vuxml/vuln-2022.xml
+++ b/security/vuxml/vuln-2022.xml
@@ -1,3 +1,28 @@
+  <vuln vid="482456fb-e9af-11ec-93b6-318d1419ea39">
+    <topic> Security Vulnerability found in ExifTool leading to RCE </topic>
+    <affects>
+      <package>
+	<name>p5-Image-ExifTool</name>
+	<range><lt>12.38</lt></range>
+      </package>
+    </affects>
+    <description>
+      <body xmlns="http://www.w3.org/1999/xhtml">
+	<p>Debian Security tracker reports:</p>
+	<blockquote cite="https://security-tracker.debian.org/tracker/CVE-2022-23935">
+	  <p>ExifTool.pm in ExifTool before 12.38 mishandles a file special characters check, leading to command injection</p>
+	</blockquote>
+      </body>
+    </description>
+    <references>
+      <cvename>CVE-2022-23935</cvename>
+      <url>https://www.cvedetails.com/cve/CVE-2022-23935</url>
+    </references>
+    <dates>
+      <discovery>2022-01-25</discovery>
+      <entry>2022-06-11</entry>
+    </dates>
+  </vuln>
   <vuln vid="ad37a349-ebb7-11ec-b9f7-21427354249d">
     <topic>mitmproxy -- Insufficient Protection against HTTP Request Smuggling</topic>
     <affects>