Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 10 Jan 2017 03:13:53 +0000 (UTC)
From:      Jason Unovitch <junovitch@FreeBSD.org>
To:        ports-committers@freebsd.org, svn-ports-all@freebsd.org, svn-ports-head@freebsd.org
Subject:   svn commit: r431063 - head/security/vuxml
Message-ID:  <201701100313.v0A3Dr4b041647@repo.freebsd.org>

next in thread | raw e-mail | index | archive | help
Author: junovitch
Date: Tue Jan 10 03:13:52 2017
New Revision: 431063
URL: https://svnweb.freebsd.org/changeset/ports/431063

Log:
  Mention pcsc-lite CVE (it was in next message in cited URL)
  
  While here, fix spacing
  
  PR:		215834

Modified:
  head/security/vuxml/vuln.xml

Modified: head/security/vuxml/vuln.xml
==============================================================================
--- head/security/vuxml/vuln.xml	Tue Jan 10 03:06:36 2017	(r431062)
+++ head/security/vuxml/vuln.xml	Tue Jan 10 03:13:52 2017	(r431063)
@@ -273,29 +273,30 @@ Notes:
     <topic>Use-After-Free Vulnerability in pcsc-lite</topic>
     <affects>
       <package>
- <name>pcsc-lite</name>
-    <range><ge>1.6.0</ge><lt>1.8.20</lt></range>
+	<name>pcsc-lite</name>
+	<range><ge>1.6.0</ge><lt>1.8.20</lt></range>
       </package>
     </affects>
     <description>
       <body xmlns="http://www.w3.org/1999/xhtml">;
- <p>Peter Wu on Openwall mailing-list reports:</p>
-    <blockquote cite="http://www.openwall.com/lists/oss-security/2017/01/03/2">;
- <p>The issue allows a local attacker to cause a Denial of Service,
-   but can potentially result in Privilege Escalation since
-   the daemon is running as root. while any local user can
-   connect to the Unix socket.
-   Fixed by patch which is released with hpcsc-lite 1.8.20.</p>
- </blockquote>
+	<p>Peter Wu on Openwall mailing-list reports:</p>
+	<blockquote cite="http://www.openwall.com/lists/oss-security/2017/01/03/2">;
+	  <p>The issue allows a local attacker to cause a Denial of Service,
+	    but can potentially result in Privilege Escalation since
+	    the daemon is running as root. while any local user can
+	    connect to the Unix socket.
+	    Fixed by patch which is released with hpcsc-lite 1.8.20.</p>
+	</blockquote>
       </body>
     </description>
     <references>
+      <cvename>CVE-2016-10109</cvename>
       <url>http://www.openwall.com/lists/oss-security/2017/01/03/2</url>;
     </references>
     <dates>
       <discovery>2017-01-03</discovery>
       <entry>2017-01-06</entry>
-      <modified>2017-01-09</modified>
+      <modified>2017-01-10</modified>
     </dates>
   </vuln>
 



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?201701100313.v0A3Dr4b041647>