1
0
mirror of https://git.FreeBSD.org/ports.git synced 2024-12-29 05:38:00 +00:00

security/vuxml: Document LibreSSL vulnerability

This commit is contained in:
Bernard Spil 2020-12-11 10:38:39 +00:00
parent 6fdeda4e86
commit ec16fd7f75
Notes: svn2git 2021-03-31 03:12:20 +00:00
svn path=/head/; revision=557712

View File

@ -58,6 +58,36 @@ Notes:
* Do not forget port variants (linux-f10-libxml2, libxml2, etc.)
-->
<vuxml xmlns="http://www.vuxml.org/apps/vuxml-1">
<vuln vid="88dfd92f-3b9c-11eb-929d-d4c9ef517024">
<topic>LibreSSL -- NULL pointer dereference</topic>
<affects>
<package>
<name>libressl</name>
<range><lt>3.2.3</lt></range>
</package>
<package>
<name>libressl-devel</name>
<range><lt>3.3.1</lt></range>
</package>
</affects>
<description>
<body xmlns="http://www.w3.org/1999/xhtml">
<p>The LibreSSL project reports:</p>
<blockquote cite="https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-3.2.3-relnotes.txt">
<p>Malformed ASN.1 in a certificate revocation list or a timestamp
response token can lead to a NULL pointer dereference.</p>
</blockquote>
</body>
</description>
<references>
<url>https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-3.2.3-relnotes.txt</url>
</references>
<dates>
<discovery>2020-12-08</discovery>
<entry>2020-12-11</entry>
</dates>
</vuln>
<vuln vid="b3695b08-3b3a-11eb-af2a-080027dbe4b7">
<topic>glpi -- Public GLPIKEY can be used to decrypt any data</topic>
<affects>