Proposed commit message:
Mark mini_httpd < 1.30 as vulnerable as per:
http://acme.com/updates/archive/211.html
The issue is arbitrary file disclosure in some circumstances. Reviewed by: ? (mentor) Approved by: ? (mentor) Differential Revision: ?
Differential D17718
security/vuxml: Mark mini_httpd < 1.30 as vulnerable leres on Oct 26 2018, 11:03 PM. Authored by Tags None Referenced Files
Subscribers
Details
Proposed commit message: Mark mini_httpd < 1.30 as vulnerable as per: http://acme.com/updates/archive/211.html The issue is arbitrary file disclosure in some circumstances. Reviewed by: ? (mentor) Approved by: ? (mentor) Differential Revision: ?
Diff Detail
Event TimelineComment Actions This seems to always happens with MFH. My new theory is that I need to populate the "Differential Revision" for both the commit (which I did) and with MFH commit (which I did not). Comment Actions Doesn't MFH copy the commit message from the original commit anyhow, including the Differential Revision tag? Hmmm... plus is it relevant for this particular review? As I recall, we only MFH the update to the vulnerable package, not the vuxml bits. |