Page MenuHomeFreeBSD

sysutils/bchunk: Update to 1.2.2; Fixed 3 security vulnerabilities
AbandonedPublic

Authored by yuri on Feb 10 2018, 8:46 PM.
Tags
None
Referenced Files
Unknown Object (File)
Sep 25 2024, 10:55 AM
Unknown Object (File)
Sep 20 2024, 12:29 PM
Unknown Object (File)
Sep 4 2024, 11:08 AM
Unknown Object (File)
Aug 31 2024, 7:09 PM
Unknown Object (File)
Aug 19 2024, 7:07 AM
Unknown Object (File)
Jul 8 2024, 11:03 PM
Unknown Object (File)
Jul 3 2024, 1:28 PM
Unknown Object (File)
Jun 16 2024, 1:58 PM
Subscribers

Details

Reviewers
tcberner
adamw
Summary

https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=225772

I had some doubts as for trivialness of this update, so creating this review.

freebsd_ports@k-worx.org takes maintainership

Vulnerabilities:

  • CVE-2017-15953 and CVE-2017-15954: a heap-based buffer overflow.
  • CVE-2017-15955: Access violation near NULL on destination operand and crash when processing a malformed CUE (.cue) file.

Additional port changes:

  • Changed to DISTVERSION
  • Added LICENSE/LICENSE_FILE
  • Minor formatting change in do-build

VuXML will be committed first. Then the port.

Diff Detail

Repository
rP FreeBSD ports repository
Lint
No Lint Coverage
Unit
No Test Coverage
Build Status
Buildable 14945
Build 15057: arc lint + arc unit