[Bug 256121] [exp-run] texproc/expat2: update to 2.4.1 (fixes CVE-2013-0340/CWE-776)
Date: Mon, 14 Jun 2021 15:51:48 UTC
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=256121
--- Comment #7 from commit-hook@FreeBSD.org ---
A commit in branch 2021Q2 references this bug:
URL:
https://cgit.FreeBSD.org/ports/commit/?id=7735cbdd131003bbbb0c9238f1468db734b89bc4
commit 7735cbdd131003bbbb0c9238f1468db734b89bc4
Author: Tobias C. Berner <tcberner@FreeBSD.org>
AuthorDate: 2021-05-24 14:38:28 +0000
Commit: Tobias C. Berner <tcberner@FreeBSD.org>
CommitDate: 2021-06-14 15:50:41 +0000
textprox/expat2: update to 2.4.1 -- fixes CVE-2013-0340/CWE-776
See [1] for details:
Expat 2.4.0 and follow-up release 2.4.1 have both been released
earlier
today (21-05-23). Release 2.4.0 fixes long known security issue
CVE-2013-0340 by
adding protection against so-called Billion Laughs Attacks, a form
of
denial of service against applications accepting XML input, in all
known
variations, including recent flavor Parameter Laughs.
[1]
https://blog.hartwork.org/posts/cve-2013-0340-billion-laughs-fixed-in-expat-2-4-0
PR: 256121
Exp-run by: antoine
(cherry picked from commit 1454ab40206b85f94edb6390e0d96c9716a07399)
textproc/expat2/Makefile | 13 +++++++++----
textproc/expat2/distinfo | 6 +++---
textproc/expat2/pkg-plist | 8 ++++++--
3 files changed, 18 insertions(+), 9 deletions(-)
--
You are receiving this mail because:
You are on the CC list for the bug.