diff options
author | Martin Wilke <miwi@FreeBSD.org> | 2009-11-26 14:51:00 +0000 |
---|---|---|
committer | Martin Wilke <miwi@FreeBSD.org> | 2009-11-26 14:51:00 +0000 |
commit | 6dc187825e013d15d737995affa6e00c5f5fc5ca (patch) | |
tree | df06d966a9e261f9e42d92035f06687a57d3372c /security/vuxml | |
parent | 50c0cdfc6bd7bf88dfb24a2ca19396bf4b4b6369 (diff) | |
download | ports-6dc187825e013d15d737995affa6e00c5f5fc5ca.tar.gz ports-6dc187825e013d15d737995affa6e00c5f5fc5ca.zip |
Notes
Diffstat (limited to 'security/vuxml')
-rw-r--r-- | security/vuxml/vuln.xml | 8 |
1 files changed, 4 insertions, 4 deletions
diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index 88f1f12b64ea..0cfa71916063 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -81,7 +81,7 @@ Note: Please add new entries to the beginning of this file. <p>When a bug is in a group, none of its information (other than its status and resolution) should be visible to users outside that group. It was discovered that - as of 3.3.2, Bugzilla was showing the alias of the bug + as of 3.3.2, Bugzilla was showing the alias of the bug (a very short string used as a shortcut for looking up the bug) to users outside of the group, if the protected bug ended up in the "Depends On" or "Blocks" list of any @@ -180,9 +180,9 @@ Note: Please add new entries to the beginning of this file. <p>CVE reports:</p> <blockquote cite="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3627"> <p>The decode_entities function in util.c in HTML-Parser before - 3.63 allows context-dependent attackers to cause a denial of service - (infinite loop) via an incomplete SGML numeric character reference, - which triggers generation of an invalid UTF-8 character.</p> + 3.63 allows context-dependent attackers to cause a denial of service + (infinite loop) via an incomplete SGML numeric character reference, + which triggers generation of an invalid UTF-8 character.</p> </blockquote> </body> </description> |