Page Menu
Home
FreeBSD
Search
Configure Global Search
Log In
Files
F131444917
D13065.id35175.diff
No One
Temporary
Actions
View File
Edit File
Delete File
View Transforms
Subscribe
Mute Notifications
Flag For Later
Award Token
Size
2 KB
Referenced Files
None
Subscribers
None
D13065.id35175.diff
View Options
Index: irc/konversation/Makefile
===================================================================
--- irc/konversation/Makefile
+++ irc/konversation/Makefile
@@ -2,8 +2,7 @@
# $FreeBSD$
PORTNAME= konversation
-PORTVERSION= 1.7.2
-PORTREVISION= 1
+PORTVERSION= 1.7.3
CATEGORIES= irc kde
MASTER_SITES= KDE/stable/${PORTNAME}/${DISTVERSION}/src
Index: irc/konversation/distinfo
===================================================================
--- irc/konversation/distinfo
+++ irc/konversation/distinfo
@@ -1,3 +1,3 @@
-TIMESTAMP = 1495708683
-SHA256 (konversation-1.7.2.tar.xz) = 5ff96e84cee4e1eefc404a31d778067ea50dddd8a6c848911fac70bd52812618
-SIZE (konversation-1.7.2.tar.xz) = 3736968
+TIMESTAMP = 1510520681
+SHA256 (konversation-1.7.3.tar.xz) = 5e6bf0afc682aad870b6258b20001c1f119c0784946dd4265b8554678563dcd8
+SIZE (konversation-1.7.3.tar.xz) = 3739124
Index: security/vuxml/vuln.xml
===================================================================
--- security/vuxml/vuln.xml
+++ security/vuxml/vuln.xml
@@ -58,6 +58,32 @@
* Do not forget port variants (linux-f10-libxml2, libxml2, etc.)
-->
<vuxml xmlns="http://www.vuxml.org/apps/vuxml-1">
+ <vuln vid="795ccee1-c7ed-11e7-ad7d-001e2a3f778d">
+ <topic>konversation -- crash in IRC message parsing</topic>
+ <affects>
+ <package>
+ <name>konversation</name>
+ <range><lt>1.7.3</lt></range>
+ </package>
+ </affects>
+ <description>
+ <body xmlns="http://www.w3.org/1999/xhtml">
+ <p>KDE reports:</p>
+ <blockquote cite="https://www.kde.org/info/security/advisory-20171112-1.txt">
+ <p>Konversation has support for colors in IRC messages. Any malicious user connected to the same IRC network can send a carefully crafted message that will crash the Konversation user client.</p>
+ </blockquote>
+ </body>
+ </description>
+ <references>
+ <cvename>CVE-2017-15923</cvename>
+ <url>https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15923</url>
+ </references>
+ <dates>
+ <discovery>2017-10-27</discovery>
+ <entry>2017-11-12</entry>
+ </dates>
+ </vuln>
+
<vuln vid="f622608c-c53c-11e7-a633-009c02a2ab30">
<topic>roundcube -- file disclosure vulnerability</topic>
<affects>
File Metadata
Details
Attached
Mime Type
text/plain
Expires
Thu, Oct 9, 3:29 AM (21 h, 54 m)
Storage Engine
blob
Storage Format
Raw Data
Storage Handle
23482410
Default Alt Text
D13065.id35175.diff (2 KB)
Attached To
Mode
D13065: Update irc/konversation to 1.7.3
Attached
Detach File
Event Timeline
Log In to Comment