Page MenuHomeFreeBSD

sysutils/bchunk: Update to 1.2.2; Fixed 3 security vulnerabilities
AbandonedPublic

Authored by yuri on Feb 10 2018, 8:46 PM.
Tags
None
Referenced Files
Unknown Object (File)
Fri, Apr 26, 9:29 PM
Unknown Object (File)
Fri, Apr 26, 9:29 PM
Unknown Object (File)
Fri, Apr 26, 9:28 PM
Unknown Object (File)
Fri, Apr 26, 5:40 PM
Unknown Object (File)
Feb 13 2024, 2:19 PM
Unknown Object (File)
Jan 20 2024, 5:09 AM
Unknown Object (File)
Dec 21 2023, 7:01 PM
Unknown Object (File)
Nov 11 2023, 3:09 AM
Subscribers

Details

Reviewers
tcberner
adamw
Summary

https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=225772

I had some doubts as for trivialness of this update, so creating this review.

freebsd_ports@k-worx.org takes maintainership

Vulnerabilities:

  • CVE-2017-15953 and CVE-2017-15954: a heap-based buffer overflow.
  • CVE-2017-15955: Access violation near NULL on destination operand and crash when processing a malformed CUE (.cue) file.

Additional port changes:

  • Changed to DISTVERSION
  • Added LICENSE/LICENSE_FILE
  • Minor formatting change in do-build

VuXML will be committed first. Then the port.

Diff Detail

Repository
rP FreeBSD ports repository
Lint
No Lint Coverage
Unit
No Test Coverage
Build Status
Buildable 14945
Build 15057: arc lint + arc unit