aboutsummaryrefslogtreecommitdiff
path: root/security
diff options
context:
space:
mode:
authorTobias Kortkamp <tobik@FreeBSD.org>2018-02-03 10:27:05 +0000
committerTobias Kortkamp <tobik@FreeBSD.org>2018-02-03 10:27:05 +0000
commit32281f864648bb01aca2f90d26af7abf2501d15b (patch)
tree2d77f5137626a9d715489136c77bf455c4b20201 /security
parent315dd49033543cd1eca859a8528741979c3aa002 (diff)
downloadports-32281f864648bb01aca2f90d26af7abf2501d15b.tar.gz
ports-32281f864648bb01aca2f90d26af7abf2501d15b.zip
Notes
Diffstat (limited to 'security')
-rw-r--r--security/vuxml/vuln.xml27
1 files changed, 27 insertions, 0 deletions
diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml
index 50e0a4f3fbd9..e24b3940c086 100644
--- a/security/vuxml/vuln.xml
+++ b/security/vuxml/vuln.xml
@@ -58,6 +58,33 @@ Notes:
* Do not forget port variants (linux-f10-libxml2, libxml2, etc.)
-->
<vuxml xmlns="http://www.vuxml.org/apps/vuxml-1">
+ <vuln vid="5044bd23-08cb-11e8-b08f-00012e582166">
+ <topic>palemoon -- multiple vulnerabilities</topic>
+ <affects>
+ <package>
+ <name>palemoon</name>
+ <range><lt>27.7.2</lt></range>
+ </package>
+ </affects>
+ <description>
+ <body xmlns="http://www.w3.org/1999/xhtml">
+ <p>Pale Moon reports:</p>
+ <blockquote cite="http://www.palemoon.org/releasenotes.shtml">
+ <p>CVE-2018-5102: Use-after-free in HTML media elements</p>
+ <p>CVE-2018-5122: Potential integer overflow in DoCrypt</p>
+ </blockquote>
+ </body>
+ </description>
+ <references>
+ <cvename>CVE-2018-5102</cvename>
+ <cvename>CVE-2018-5122</cvename>
+ </references>
+ <dates>
+ <discovery>2018-01-23</discovery>
+ <entry>2018-02-03</entry>
+ </dates>
+ </vuln>
+
<vuln vid="d696473f-9f32-42c5-a106-bf4536fb1f74">
<topic>Django -- information leakage</topic>
<affects>