svn commit: r362569 - branches/2014Q3/security/vuxml
Raphael Kubo da Costa
rakuco at FreeBSD.org
Tue Jul 22 19:30:29 UTC 2014
Author: rakuco
Date: Tue Jul 22 19:30:28 2014
New Revision: 362569
URL: http://svnweb.freebsd.org/changeset/ports/362569
QAT: https://qat.redports.org/buildarchive/r362569/
Log:
MFH: r362280
Document qt4-gui/qt5-gui vulnerability.
Approved by: portmgr (erwin)
Modified:
branches/2014Q3/security/vuxml/vuln.xml
Directory Properties:
branches/2014Q3/ (props changed)
Modified: branches/2014Q3/security/vuxml/vuln.xml
==============================================================================
--- branches/2014Q3/security/vuxml/vuln.xml Tue Jul 22 19:01:20 2014 (r362568)
+++ branches/2014Q3/security/vuxml/vuln.xml Tue Jul 22 19:30:28 2014 (r362569)
@@ -57,6 +57,40 @@ Notes:
-->
<vuxml xmlns="http://www.vuxml.org/apps/vuxml-1">
+ <vuln vid="904d78b8-0f7e-11e4-8b71-5453ed2e2b49">
+ <topic>qt4-gui, qt5-gui -- DoS vulnerability in the GIF image handler</topic>
+ <affects>
+ <package>
+ <name>qt4-gui</name>
+ <range><lt>4.8.6_2</lt></range>
+ </package>
+ <package>
+ <name>qt5-gui</name>
+ <range><lt>5.2.1_3</lt></range>
+ </package>
+ </affects>
+ <description>
+ <body xmlns="http://www.w3.org/1999/xhtml">
+ <p>Richard J. Moore reports:</p>
+ <blockquote cite="http://lists.qt-project.org/pipermail/announce/2014-April/000045.html">
+ <p>The builtin GIF decoder in QtGui prior to Qt 5.3 contained a bug
+ that would lead to a null pointer dereference when loading certain
+ hand crafted corrupt GIF files. This in turn would cause the
+ application loading these hand crafted GIFs to crash.</p>
+ </blockquote>
+ </body>
+ </description>
+ <references>
+ <cvename>CVE-2014-0190</cvename>
+ <bid>67087</bid>
+ <mlist>http://lists.qt-project.org/pipermail/announce/2014-April/000045.html</mlist>
+ </references>
+ <dates>
+ <discovery>2014-04-24</discovery>
+ <entry>2014-07-19</entry>
+ </dates>
+ </vuln>
+
<vuln vid="3718833e-0d27-11e4-89db-000c6e25e3e9">
<topic>chromium -- multiple vulnerabilities</topic>
<affects>
More information about the svn-ports-all
mailing list