Page MenuHomeFreeBSD

security/vuxml: Add entry for net-p2p/bitcoin CVE-2018-17144
ClosedPublic

Authored by kbowling on Sep 29 2018, 10:00 PM.
Tags
None
Referenced Files
Unknown Object (File)
Tue, Nov 12, 6:19 AM
Unknown Object (File)
Nov 2 2024, 9:22 AM
Unknown Object (File)
Oct 27 2024, 3:26 AM
Unknown Object (File)
Oct 22 2024, 7:18 AM
Unknown Object (File)
Oct 4 2024, 10:09 AM
Unknown Object (File)
Oct 2 2024, 10:14 PM
Unknown Object (File)
Sep 30 2024, 7:48 AM
Unknown Object (File)
Sep 22 2024, 3:54 AM
Subscribers

Diff Detail

Lint
Lint Skipped
Unit
Tests Skipped

Event Timeline

timur requested changes to this revision.Sep 29 2018, 10:53 PM

In general, we are trying not to be too verbose in the description section, at least that's what I see for the other entries in vuln.xml. I believe it's enough to have the first paragraph with the short vulnerability description and not necessary to dive into the details how maintainers reacted on the CVE. That's what the URL is for, if anyone needs more details.

This revision now requires changes to proceed.Sep 29 2018, 10:53 PM

Also, forgive my laziness, but seeing the result of make validate would let me not to check this entry on my system :)

make VID=40a844bf-c430-11e8-96dc-000743165db0 html may be an overkill, but at least take a look on the result to be sure it's clean.

Tidy/xslt get stuck in select() for me regardless of this change :/

Not really your bug, but while you are there - there should be TAB on the indicated place.

/bin/sh /usr/ports/security/vuxml/files/tidy.sh "/usr/ports/security/vuxml/files/tidy.xsl" "/usr/ports/security/vuxml/vuln.xml" > "/usr/ports/security/vuxml/vuln.xml.tidy"
>>> Validating...
/usr/local/bin/xmllint --valid --noout /usr/ports/security/vuxml/vuln.xml
>>> Successful.
Checking if tidy differs...
... seems okay
Checking for space/tab...
--- /usr/ports/security/vuxml/vuln.xml  2018-09-30 01:09:22.506946000 +0200
+++ /usr/ports/security/vuxml/vuln.xml.unexpanded       2018-09-30 01:09:30.943652000 +0200
@@ -117,7 +117,7 @@
     </description>
     <references>
       <url>https://seclists.org/oss-sec/2018/q3/242</url>
-        <cvename>CVE-2017-15705</cvename>
+       <cvename>CVE-2017-15705</cvename>
        <cvename>CVE-2016-1238</cvename>
        <cvename>CVE-2018-11780</cvename>
        <cvename>CVE-2018-11781</cvename>
... see above
Consider using /usr/ports/security/vuxml/vuln.xml.unexpanded for final commit
*** Error code 1

Stop.
make: stopped in /usr/ports/security/vuxml
This revision is now accepted and ready to land.Sep 29 2018, 11:12 PM