Page MenuHomeFreeBSD

security/vuxml: document vulnerability in rubygem-redcarpet <3.2.3
ClosedPublic

Authored by mmoll on May 14 2015, 10:32 PM.
Tags
None
Referenced Files
Unknown Object (File)
Tue, Jan 14, 2:51 AM
Unknown Object (File)
Tue, Jan 14, 2:45 AM
Unknown Object (File)
Sun, Jan 12, 8:14 PM
Unknown Object (File)
Dec 22 2024, 10:57 PM
Unknown Object (File)
Nov 26 2024, 9:33 AM
Unknown Object (File)
Nov 20 2024, 9:08 PM
Unknown Object (File)
Nov 11 2024, 3:53 PM
Unknown Object (File)
Nov 7 2024, 2:18 AM
Subscribers
None

Details

Reviewers
swills
mat
Summary

Proposed commit message:

security/vuxml: document vulnerability in rubygem-redcarpet <3.2.3

PR:		200195
Submitted by:	Sevan Janiyan <venture37@geeklan.co.uk>
Approved by:	swills (mentor), mat (mentor)
Test Plan

make validate and pkg audit:

mmoll@marduk:/svn/ports/security/vuxml$ make validate
/bin/sh /svn/ports/security/vuxml/files/tidy.sh "/svn/ports/security/vuxml/files/tidy.xsl" "/svn/ports/security/vuxml/vuln.xml" > "/svn/ports/security/vuxml/vuln.xml.tidy"
>>> Validating...
/usr/local/bin/xmllint --valid --noout /svn/ports/security/vuxml/vuln.xml
>>> Successful.
Checking if tidy differs...
... seems okay
Checking for space/tab...
... seems okay
/usr/local/bin/python2.7 /svn/ports/security/vuxml/files/extra-validation.py
mmoll@marduk:/svn/ports/security/vuxml$ env PKG_DBDIR=/svn/ports/security/vuxml pkg audit rubygem-redcarpet-3.2.2
rubygem-redcarpet-3.2.2 is vulnerable:
rubygem-redcarpet -- XSS vulnerability
WWW: http://vuxml.FreeBSD.org/freebsd/c368155a-fa83-11e4-bc58-001e67150279.html

1 problem(s) in the installed packages found.
mmoll@marduk:/svn/ports/security/vuxml$ env PKG_DBDIR=/svn/ports/security/vuxml pkg audit rubygem-redcarpet-3.2.3
0 problem(s) in the installed packages found.

Diff Detail

Repository
rP FreeBSD ports repository
Lint
No Lint Coverage
Unit
No Test Coverage

Event Timeline

mmoll retitled this revision from to security/vuxml: document vulnerability in rubygem-redcarpet <3.2.3.
mmoll updated this object.
mmoll edited the test plan for this revision. (Show Details)
mmoll added reviewers: swills, mat.
mat edited edge metadata.
This revision is now accepted and ready to land.May 15 2015, 8:23 AM