Index: head/security/vuxml/vuln.xml =================================================================== --- head/security/vuxml/vuln.xml +++ head/security/vuxml/vuln.xml @@ -58,6 +58,34 @@ * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> + + diffoscope -- arbitrary file write + + + py35-diffoscope + 6776 + + + + +

Ximin Luo reports:

+
+

[v67] introduced a security hole where diffoscope may write to + arbitrary locations on disk depending on the contents of an + untrusted archive.

+
+ +
+ + CVE-2017-0359 + https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=854723 + + + 2017-02-09 + 2017-02-14 + +
+ ffmpeg -- heap overflow in lavf/mov.c