svn commit: r431063 - head/security/vuxml
Jason Unovitch
junovitch at FreeBSD.org
Tue Jan 10 03:13:54 UTC 2017
Author: junovitch
Date: Tue Jan 10 03:13:52 2017
New Revision: 431063
URL: https://svnweb.freebsd.org/changeset/ports/431063
Log:
Mention pcsc-lite CVE (it was in next message in cited URL)
While here, fix spacing
PR: 215834
Modified:
head/security/vuxml/vuln.xml
Modified: head/security/vuxml/vuln.xml
==============================================================================
--- head/security/vuxml/vuln.xml Tue Jan 10 03:06:36 2017 (r431062)
+++ head/security/vuxml/vuln.xml Tue Jan 10 03:13:52 2017 (r431063)
@@ -273,29 +273,30 @@ Notes:
<topic>Use-After-Free Vulnerability in pcsc-lite</topic>
<affects>
<package>
- <name>pcsc-lite</name>
- <range><ge>1.6.0</ge><lt>1.8.20</lt></range>
+ <name>pcsc-lite</name>
+ <range><ge>1.6.0</ge><lt>1.8.20</lt></range>
</package>
</affects>
<description>
<body xmlns="http://www.w3.org/1999/xhtml">
- <p>Peter Wu on Openwall mailing-list reports:</p>
- <blockquote cite="http://www.openwall.com/lists/oss-security/2017/01/03/2">
- <p>The issue allows a local attacker to cause a Denial of Service,
- but can potentially result in Privilege Escalation since
- the daemon is running as root. while any local user can
- connect to the Unix socket.
- Fixed by patch which is released with hpcsc-lite 1.8.20.</p>
- </blockquote>
+ <p>Peter Wu on Openwall mailing-list reports:</p>
+ <blockquote cite="http://www.openwall.com/lists/oss-security/2017/01/03/2">
+ <p>The issue allows a local attacker to cause a Denial of Service,
+ but can potentially result in Privilege Escalation since
+ the daemon is running as root. while any local user can
+ connect to the Unix socket.
+ Fixed by patch which is released with hpcsc-lite 1.8.20.</p>
+ </blockquote>
</body>
</description>
<references>
+ <cvename>CVE-2016-10109</cvename>
<url>http://www.openwall.com/lists/oss-security/2017/01/03/2</url>
</references>
<dates>
<discovery>2017-01-03</discovery>
<entry>2017-01-06</entry>
- <modified>2017-01-09</modified>
+ <modified>2017-01-10</modified>
</dates>
</vuln>
More information about the svn-ports-head
mailing list