1
0
mirror of https://git.FreeBSD.org/ports.git synced 2025-01-24 09:25:01 +00:00

Document vulnerability in net/opendchub.

Based on submission by:	Niels Heinen <niels.heinen@ubizen.com>
This commit is contained in:
Josef El-Rayes 2004-11-29 21:04:59 +00:00
parent e516c5f20e
commit 5a21690f3e
Notes: svn2git 2021-03-31 03:12:20 +00:00
svn path=/head/; revision=122769

View File

@ -32,6 +32,32 @@ EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
-->
<vuxml xmlns="http://www.vuxml.org/apps/vuxml-1">
<vuln vid="cdf14b68-3ff9-11d9-8405-00065be4b5b6">
<topic>Open Dc Hub -- remote buffer overflow vulnerability</topic>
<affects>
<package>
<name>opendchub</name>
<range><le>0.7.14_1</le></range>
</package>
</affects>
<description>
<body xmlns="http://www.w3.org/1999/xhtml">
<p>Donato Ferrante reported an exploitable buffer overflow in
this software package. Any user that can login with 'admin'
privileges can abuse it, trough the $RedirectAll command,
to execute arbitrary code.</p>
</body>
</description>
<references>
<mlist msgid="20041124155429.893852455E@chernobyl.investici.org">http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110144606411674</mlist>
<url>http://www.gentoo.org/security/en/glsa/glsa-200411-37.xml</url>
</references>
<dates>
<discovery>2004-11-24</discovery>
<entry>2004-11-27</entry>
</dates>
</vuln>
<vuln vid="a163baff-3fe1-11d9-a9e7-0001020eed82">
<topic>unarj -- long filename buffer overflow</topic>
<affects>