ports/128998: [vuxml] document vulnerabilities in textproc/libxml2

Eygene Ryabinkin rea-fbsd at codelabs.ru
Wed Nov 19 14:04:35 PST 2008


Wed, Nov 19, 2008 at 11:41:01PM +0300, Eygene Ryabinkin wrote:
> The fix for the CVE-2008-4225 and CVE-2008-4226 was commited to the
> textproc/libxml2 just an hour ago, but vulnerabilities seem to be left
> undocumented.  At least I was not able to find the corresponding PR and
> reporting channels are not clear from the commit comment.

The entry was added shortly after this PR by tabthorpe@, so I think
that this PR can be closed now.
-- 
Eygene
 _                ___       _.--.   #
 \`.|\..----...-'`   `-._.-'_.-'`   #  Remember that it is hard
 /  ' `         ,       __.--'      #  to read the on-line manual   
 )/' _/     \   `-_,   /            #  while single-stepping the kernel.
 `-'" `"\_  ,_.-;_.-\_ ',  fsc/as   #
     _.-'_./   {_.'   ; /           #    -- FreeBSD Developers handbook 
    {_.-``-'         {_/            #
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 195 bytes
Desc: not available
Url : http://lists.freebsd.org/pipermail/freebsd-security/attachments/20081119/742fa030/attachment.pgp


More information about the freebsd-security mailing list