Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 4 Jul 2016 01:46:35 +0000 (UTC)
From:      Jason Unovitch <junovitch@FreeBSD.org>
To:        ports-committers@freebsd.org, svn-ports-all@freebsd.org, svn-ports-head@freebsd.org
Subject:   svn commit: r418007 - head/security/vuxml
Message-ID:  <201607040146.u641kZBI044552@repo.freebsd.org>

next in thread | raw e-mail | index | archive | help
Author: junovitch
Date: Mon Jul  4 01:46:35 2016
New Revision: 418007
URL: https://svnweb.freebsd.org/changeset/ports/418007

Log:
  Add fixed entries for Python 2.7, 3.4, 3.5 for urllib vulnerability.
  
  Reset 3.3 as unfixed.
  
  PR:		210539
  PR:		210541
  Reported by:	Vladimir Krstulja <vlad-fbsd@acheronmedia.com>
  Security:	CVE-2016-5699
  Security:	https://vuxml.FreeBSD.org/freebsd/a61374fc-3a4d-11e6-a671-60a44ce6887b.html

Modified:
  head/security/vuxml/vuln.xml

Modified: head/security/vuxml/vuln.xml
==============================================================================
--- head/security/vuxml/vuln.xml	Mon Jul  4 00:29:01 2016	(r418006)
+++ head/security/vuxml/vuln.xml	Mon Jul  4 01:46:35 2016	(r418007)
@@ -603,8 +603,20 @@ Notes:
     <topic>Python -- HTTP Header Injection in Python urllib</topic>
     <affects>
       <package>
+	<name>python27</name>
+	<range><lt>2.7.10</lt></range>
+      </package>
+      <package>
 	<name>python33</name>
-	<range><lt>3.3.6</lt></range>
+	<range><ge>0</ge></range>
+      </package>
+      <package>
+	<name>python34</name>
+	<range><lt>3.4.4</lt></range>
+      </package>
+      <package>
+	<name>python35</name>
+	<range><lt>3.5.0</lt></range>
       </package>
     </affects>
     <description>
@@ -626,6 +638,7 @@ Notes:
     <dates>
       <discovery>2014-11-24</discovery>
       <entry>2016-06-30</entry>
+      <modified>2016-07-04</modified>
     </dates>
   </vuln>
 



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?201607040146.u641kZBI044552>