security/vuxml: sync with upstream

Taken from: HardenedBSD
This commit is contained in:
Franco Fichtner 2020-02-24 10:08:17 +01:00
parent ffeeaf2e02
commit 83771e63da

View file

@ -58,6 +58,36 @@ Notes:
* Do not forget port variants (linux-f10-libxml2, libxml2, etc.)
-->
<vuxml xmlns="http://www.vuxml.org/apps/vuxml-1">
<vuln vid="8e3f1812-54d9-11ea-8d49-d4c9ef517024">
<topic>WeeChat -- Multiple vulnerabilities</topic>
<affects>
<package>
<name>weechat</name>
<range><lt>2.7.1</lt></range>
</package>
</affects>
<description>
<body xmlns="http://www.w3.org/1999/xhtml">
<p>The WeeChat project reports:</p>
<blockquote cite="https://weechat.org/doc/security/">
<p>Buffer overflow when receiving a malformed IRC message 324 (channel
mode). (CVE-2020-8955)</p>
<p>Buffer overflow when a new IRC message 005 is received with longer
nick prefixes.</p>
<p>Crash when receiving a malformed IRC message 352 (WHO).</p>
</blockquote>
</body>
</description>
<references>
<url>https://weechat.org/doc/security/</url>
<cvename>CVE-2020-8955</cvename>
</references>
<dates>
<discovery>2020-02-20</discovery>
<entry>2020-02-21</entry>
</dates>
</vuln>
<vuln vid="1cb0af4e-d641-4f99-9432-297a89447a97">
<topic>webkit-gtk3 -- Multiple vulnerabilities</topic>
<affects>
@ -406,7 +436,7 @@ whitespace)
<affects>
<package>
<name>ksh93</name>
<range><lt>2020.0.1_1,1</lt></range>
<range><ge>2020.0.0</ge><lt>2020.0.1_1,1</lt></range>
</package>
<package>
<name>ksh93-devel</name>
@ -58887,7 +58917,7 @@ and CVE-2013-0155.</p>
<name>avidemux26</name>
<!-- avidemux-2.6.10 has ffmpeg-2.6.1 -->
<!-- no known fixed version -->
<range><ge>0</ge></range>
<range><le>2.6.11</le></range>
</package>
<package>
<name>kodi</name>
@ -60758,7 +60788,7 @@ and CVE-2013-0155.</p>
<name>avidemux26</name>
<!-- avidemux-2.6.10 has ffmpeg-2.6.1 -->
<!-- no known fixed version -->
<range><ge>0</ge></range>
<range><le>2.6.11</le></range>
</package>
<package>
<name>kodi</name>