ports/114906: [PATCH] update net/asterisk to 1.4.9

Matthew Seaman m.seaman at infracaninophile.co.uk
Thu Jul 26 09:18:53 UTC 2007


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Phillip N. wrote:

> The motivation of the update is this:
> http://ftp.digium.com/pub/asa/ASA-2007-018.pdf
> "Exhaustion vulnerability in IAX2 channel driver"
> 
> the vulxml contains two thing i cannot figure out.
> These are:
> 	- vid (how is the id generated?)

   <vid> is the VuXML ID -- it's a unique tag per entry that can be
used in eg. URLs.  See uuidgen(1) for how to generate one.

> 	- bid (what is it?)

   <bid> stands for 'Bugtraq ID' -- it's the reference number used
on this site to identify the issue:

    http://www.securityfocus.com/

There are a number of other security related web sites that the
VuXML markup caters for, as well as arbitrary URLs.  None of them
are compulsory to have in a <references> section, but all relevant
references should be provided.

See Jaques Vidrine's presentation for more info -- at

    http://www.vuxml.org/files/VuXML_BSDCan.pdf

	Cheers,

	Matthew

- --
Dr Matthew J Seaman MA, D.Phil.                   7 Priory Courtyard
                                                  Flat 3
PGP: http://www.infracaninophile.co.uk/pgpkey     Ramsgate
                                                  Kent, CT11 9PW
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.4 (FreeBSD)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFGqF7S8Mjk52CukIwRCGSXAKCLdPGQYx+iCFrs+KfJzGE+PI7/6gCdHKDR
Zia7H/D3lnaiDr2D3BbGvUM=
=7EqW
-----END PGP SIGNATURE-----


More information about the freebsd-vuxml mailing list