diff options
author | nectar <nectar@FreeBSD.org> | 2004-03-26 15:29:13 +0000 |
---|---|---|
committer | nectar <nectar@FreeBSD.org> | 2004-03-26 15:29:13 +0000 |
commit | 8a312ba3745c995f423b5b42cde7cf41464995cf (patch) | |
tree | 00b46dfa1f1f4cd142354fc376c7d4588feb857f /security/vuxml | |
parent | 1d337dd97a3e21ff9002726b12b1e4f49b60f346 (diff) | |
download | FreeBSD-ports-8a312ba3745c995f423b5b42cde7cf41464995cf.zip FreeBSD-ports-8a312ba3745c995f423b5b42cde7cf41464995cf.tar.gz |
Add squid ACL bypass.
Add xine temporary file handling issue. [1]
Submitted by: Frankye Fattarelli <frankye@ipv5.net> [1]
Diffstat (limited to 'security/vuxml')
-rw-r--r-- | security/vuxml/vuln.xml | 56 |
1 files changed, 56 insertions, 0 deletions
diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index 1825de6..64f7af5 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -32,6 +32,62 @@ EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. "http://www.vuxml.org/dtd/vuxml-1/vuxml-10.dtd"> <vuxml xmlns="http://www.vuxml.org/apps/vuxml-1"> + <vuln vid="705e003a-7f36-11d8-9645-0020ed76ef5a"> + <topic></topic> + <affects> + <package> + <name>squid</name> + <range><lt>squid-2.5.5</lt></range> + </package> + </affects> + <description> + <body xmlns="http://www.w3.org/1999/xhtml"> + <p>From the Squid advisory:</p> + <blockquote + cite="http://www.squid-cache.org/Advisories/SQUID-2004_1.txt"> + <p> Squid versions 2.5.STABLE4 and earlier contain a bug + in the "%xx" URL decoding function. It may insert a NUL + character into decoded URLs, which may allow users to bypass + url_regex ACLs.</p> + </blockquote> + </body> + </description> + <references> + <url>http://www.squid-cache.org/Advisories/SQUID-2004_1.txt</url> + <cvename>CVE-2004-0189</cvename> + </references> + <dates> + <discovery>2004-02-29</discovery> + <entry>2004-03-26</entry> + </dates> + </vuln> + + <vuln vid="fde53204-7ea6-11d8-9645-0020ed76ef5a"> + <topic>insecure temporary file creation in xine-check, + xine-bugreport</topic> + <affects> + <package> + <name>xine</name> + <range><ge>0</ge></range> + </package> + </affects> + <description> + <body xmlns="http://www.w3.org/1999/xhtml"> + <p>Some scripts installed with xine create temporary files + insecurely. It is recommended that these scripts (xine-check, + xine-bugreport) not be used. They are not needed for normal + operation.</p> + </body> + </description> + <references> + <url>http://marc.theaimsgroup.com/?l=bugtraq&m=107997911025558</url> + </references> + <dates> + <discovery>2004-03-20</discovery> + <entry>2004-03-26</entry> + </dates> + </vuln> + <vuln vid="c551ae17-7f00-11d8-868e-000347dd607f"> <topic>multiple vulnerabilities in phpBB</topic> <affects> |