git: 21d5e4f1531b - main - security/vuxml: Add graphics/libcaca < 0.99.b20
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Fri, 07 Feb 2025 06:56:38 UTC
The branch main has been updated by jhale: URL: https://cgit.FreeBSD.org/ports/commit/?id=21d5e4f1531b107005cee63285ae53fbec211fb2 commit 21d5e4f1531b107005cee63285ae53fbec211fb2 Author: Jason E. Hale <jhale@FreeBSD.org> AuthorDate: 2025-02-07 06:52:31 +0000 Commit: Jason E. Hale <jhale@FreeBSD.org> CommitDate: 2025-02-07 06:52:31 +0000 security/vuxml: Add graphics/libcaca < 0.99.b20 --- security/vuxml/vuln/2025.xml | 43 +++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 43 insertions(+) diff --git a/security/vuxml/vuln/2025.xml b/security/vuxml/vuln/2025.xml index f70870b2975f..0e0d816c5a45 100644 --- a/security/vuxml/vuln/2025.xml +++ b/security/vuxml/vuln/2025.xml @@ -1,3 +1,46 @@ + <vuln vid="c10b639c-e51c-11ef-9e76-4ccc6adda413"> + <topic>libcaca -- Multiple vulnerabilities</topic> + <affects> + <package> + <name>libcaca</name> + <range><lt>0.99.b20</lt></range> + </package> + </affects> + <description> + <body xmlns="http://www.w3.org/1999/xhtml"> + <p>Sam Hocevar reports:</p> + <blockquote cite="https://github.com/cacalabs/libcaca/releases/tag/v0.99.beta20"> + <p>Multiple memory leaks and invalid memory accesses:</p> + <ul> + <li>CVE-2018-20545: Illegal WRITE memory access at common-image.c</li> + <li>CVE-2018-20546: Illegal READ memory access at caca/dither.c</li> + <li>CVE-2018-20547: Illegal READ memory access at caca/dither.c</li> + <li>CVE-2018-20548: Illegal WRITE memory access at common-image.c</li> + <li>CVE-2018-20549: Illegal WRITE memory access at caca/file.c</li> + <li>CVE-2021-3410: Buffer overflow in libcaca/caca/canvas.c in function caca_resize</li> + <li>CVE-2021-30498: Heap buffer overflow in export.c in function export_tga</li> + <li>CVE-2021-30499: Buffer overflow in export.c in function export_troff</li> + </ul> + </blockquote> + </body> + </description> + <references> + <cvename>CVE-2018-20545</cvename> + <cvename>CVE-2018-20546</cvename> + <cvename>CVE-2018-20547</cvename> + <cvename>CVE-2018-20548</cvename> + <cvename>CVE-2018-20549</cvename> + <cvename>CVE-2021-3410</cvename> + <cvename>CVE-2021-30498</cvename> + <cvename>CVE-2021-30499</cvename> + <url>https://github.com/cacalabs/libcaca/releases/tag/v0.99.beta20</url> + </references> + <dates> + <discovery>2021-10-19</discovery> + <entry>2025-02-07</entry> + </dates> + </vuln> + <vuln vid="e7974ca5-e4c8-11ef-aab3-40b034429ecf"> <topic>cacti -- Multiple vulnerabilities</topic> <affects>