aboutsummaryrefslogtreecommitdiff
path: root/security/vuxml/vuln.xml
diff options
context:
space:
mode:
authorSimon L. B. Nielsen <simon@FreeBSD.org>2005-08-15 20:38:54 +0000
committerSimon L. B. Nielsen <simon@FreeBSD.org>2005-08-15 20:38:54 +0000
commit2836760398abe44c35e5ec0d75566d23ca09416d (patch)
treeb169d438d2e75815f238881053e8a83b84e52e51 /security/vuxml/vuln.xml
parent1843e3c18f2ba4bff454f04f8c8cb4597e519981 (diff)
downloadports-2836760398abe44c35e5ec0d75566d23ca09416d.tar.gz
ports-2836760398abe44c35e5ec0d75566d23ca09416d.zip
Notes
Diffstat (limited to 'security/vuxml/vuln.xml')
-rw-r--r--security/vuxml/vuln.xml16
1 files changed, 15 insertions, 1 deletions
diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml
index 24e88563f1ed..c7ec9264080f 100644
--- a/security/vuxml/vuln.xml
+++ b/security/vuxml/vuln.xml
@@ -39,6 +39,14 @@ EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
<name>pear-XML_RPC</name>
<range><lt>1.4.0</lt></range>
</package>
+ <package>
+ <name>phpmyfaq</name>
+ <range><lt>1.4.11</lt></range>
+ </package>
+ <package>
+ <name>drupal</name>
+ <range><lt>4.6.3</lt></range>
+ </package>
</affects>
<description>
<body xmlns="http://www.w3.org/1999/xhtml">
@@ -56,11 +64,17 @@ EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
the evaluation string, which obviously results in
arbitrary code execution.</p>
</blockquote>
+ <p>Note that several applications contains an embedded version
+ on XML_RPC, therefor making them the vulnerable to the same
+ code injection vulnerability.</p>
</body>
</description>
<references>
<cvename>CAN-2005-2498</cvename>
+ <url>http://drupal.org/files/sa-2005-004/advisory.txt</url>
<url>http://www.hardened-php.net/advisory_142005.66.html</url>
+ <url>http://www.hardened-php.net/advisory_152005.67.html</url>
+ <url>http://www.phpmyfaq.de/advisory_2005-08-15.php</url>
</references>
<dates>
<discovery>2005-08-15</discovery>
@@ -274,7 +288,7 @@ EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
thereby filling up the /tmp partition, when opening a
specially crafted PDF file.</p>
<p>Note that several applications contains an embedded version
- on xpdf, therefor making them the vulnerable to the same
+ of xpdf, therefor making them the vulnerable to the same
DoS. In CUPS this vulnerability would cause the pdftops
filter to crash.</p>
</body>