This page displays vulnerability information about FreeBSD Ports.
The last vuln.xml file processed by FreshPorts is:
Revision: 321338 Date: 2013-06-19 Time: 21:56:56Z Committer: jgh
List all Vulnerabilities, by package
List all Vulnerabilities, by date
These are the vulnerabilities relating to the commit you have selected:
| VuXML ID | Description |
|---|---|
| 207f8ff3-f697-11d8-81b0-000347a4fa7d | nss -- exploitable buffer overflow in SSLv2 protocol handler ISS X-Force reports that a remotely exploitable buffer overflow exists in the Netscape Security Services (NSS) library's implementation of SSLv2. From their advisory:
Note that the vulnerable NSS library is also present in Mozilla-based browsers. However, it is not believed that browsers are affected, as the vulnerability is present only in code used by SSLv2 *servers*. Discovery 2004-08-23 Entry 2004-08-27 nss lt 3.9.2 http://xforce.iss.net/xforce/alerts/id/180 http://www.osvdb.org/9116 http://secunia.com/advisories/12362 11015 |
| aa5bc971-d635-11e0-b3cf-080027ef73ec | nss/ca_root_nss -- fraudulent certificates issued by DigiNotar.nl Heather Adkins, Google's Information Security Manager, reported that Google received
VASCO Data Security International Inc., owner of DigiNotar, issued a press statement confirming this incident:
Mozilla, maintainer of the NSS package, from which FreeBSD derived ca_root_nss, stated that they:
Discovery 2011-07-19 Entry 2011-09-03 Modified 2011-09-06 nss lt 3.12.11 ca_root_nss lt 3.12.11 firefox gt 3.6.*,1 lt 3.6.22,1 gt 4.0.*,1 lt 6.0.2,1 seamonkey lt 2.3.2 linux-firefox lt 3.6.22,1 thunderbird gt 3.1.* lt 3.1.14 gt 5.0.* lt 6.0.2 linux-thunderbird lt 3.1.14 linux-seamonkey lt 2.3.2 http://www.vasco.com/company/press_room/news_archive/2011/news_diginotar_reports_security_incident.aspx http://www.mozilla.org/security/announce/2011/mfsa2011-34.html http://googleonlinesecurity.blogspot.com/2011/08/update-on-attempted-man-in-middle.html |
| 207f8ff3-f697-11d8-81b0-000347a4fa7d | nss -- exploitable buffer overflow in SSLv2 protocol handler ISS X-Force reports that a remotely exploitable buffer overflow exists in the Netscape Security Services (NSS) library's implementation of SSLv2. From their advisory:
Note that the vulnerable NSS library is also present in Mozilla-based browsers. However, it is not believed that browsers are affected, as the vulnerability is present only in code used by SSLv2 *servers*. Discovery 2004-08-23 Entry 2004-08-27 nss lt 3.9.2 http://xforce.iss.net/xforce/alerts/id/180 http://www.osvdb.org/9116 http://secunia.com/advisories/12362 11015 |
| aa5bc971-d635-11e0-b3cf-080027ef73ec | nss/ca_root_nss -- fraudulent certificates issued by DigiNotar.nl Heather Adkins, Google's Information Security Manager, reported that Google received
VASCO Data Security International Inc., owner of DigiNotar, issued a press statement confirming this incident:
Mozilla, maintainer of the NSS package, from which FreeBSD derived ca_root_nss, stated that they:
Discovery 2011-07-19 Entry 2011-09-03 Modified 2011-09-06 nss lt 3.12.11 ca_root_nss lt 3.12.11 firefox gt 3.6.*,1 lt 3.6.22,1 gt 4.0.*,1 lt 6.0.2,1 seamonkey lt 2.3.2 linux-firefox lt 3.6.22,1 thunderbird gt 3.1.* lt 3.1.14 gt 5.0.* lt 6.0.2 linux-thunderbird lt 3.1.14 linux-seamonkey lt 2.3.2 http://www.vasco.com/company/press_room/news_archive/2011/news_diginotar_reports_security_incident.aspx http://www.mozilla.org/security/announce/2011/mfsa2011-34.html http://googleonlinesecurity.blogspot.com/2011/08/update-on-attempted-man-in-middle.html |