This page displays vulnerability information about FreeBSD Ports.
The last vuln.xml file processed by FreshPorts is:
Revision: 318877 Date: 2013-05-23 Time: 15:30:07Z Committer: flo
List all Vulnerabilities, by package
List all Vulnerabilities, by date
These are the vulnerabilities relating to the commit you have selected:
| VuXML ID | Description |
|---|---|
| aa5bc971-d635-11e0-b3cf-080027ef73ec | nss/ca_root_nss -- fraudulent certificates issued by DigiNotar.nl Heather Adkins, Google's Information Security Manager, reported that Google received
VASCO Data Security International Inc., owner of DigiNotar, issued a press statement confirming this incident:
Mozilla, maintainer of the NSS package, from which FreeBSD derived ca_root_nss, stated that they:
Discovery 2011-07-19 Entry 2011-09-03 Modified 2011-09-06 nss lt 3.12.11 ca_root_nss lt 3.12.11 firefox gt 3.6.*,1 lt 3.6.22,1 gt 4.0.*,1 lt 6.0.2,1 seamonkey lt 2.3.2 linux-firefox lt 3.6.22,1 thunderbird gt 3.1.* lt 3.1.14 gt 5.0.* lt 6.0.2 linux-thunderbird lt 3.1.14 linux-seamonkey lt 2.3.2 http://www.vasco.com/company/press_room/news_archive/2011/news_diginotar_reports_security_incident.aspx http://www.mozilla.org/security/announce/2011/mfsa2011-34.html http://googleonlinesecurity.blogspot.com/2011/08/update-on-attempted-man-in-middle.html |
| aa5bc971-d635-11e0-b3cf-080027ef73ec | nss/ca_root_nss -- fraudulent certificates issued by DigiNotar.nl Heather Adkins, Google's Information Security Manager, reported that Google received
VASCO Data Security International Inc., owner of DigiNotar, issued a press statement confirming this incident:
Mozilla, maintainer of the NSS package, from which FreeBSD derived ca_root_nss, stated that they:
Discovery 2011-07-19 Entry 2011-09-03 Modified 2011-09-06 nss lt 3.12.11 ca_root_nss lt 3.12.11 firefox gt 3.6.*,1 lt 3.6.22,1 gt 4.0.*,1 lt 6.0.2,1 seamonkey lt 2.3.2 linux-firefox lt 3.6.22,1 thunderbird gt 3.1.* lt 3.1.14 gt 5.0.* lt 6.0.2 linux-thunderbird lt 3.1.14 linux-seamonkey lt 2.3.2 http://www.vasco.com/company/press_room/news_archive/2011/news_diginotar_reports_security_incident.aspx http://www.mozilla.org/security/announce/2011/mfsa2011-34.html http://googleonlinesecurity.blogspot.com/2011/08/update-on-attempted-man-in-middle.html |
| 1b27af46-d6f6-11e0-89a6-080027ef73ec | ca_root_nss -- extraction of explicitly-untrusted certificates into trust bundle Matthias Andree reports that the ca-bundle.pl used in older versions of the ca_root_nss FreeBSD port before 3.12.11 did not take the Mozilla/NSS/CKBI untrusted markers into account and would add certificates to the trust bundle that were marked unsafe by Mozilla. Discovery 2011-09-04 Entry 2011-09-04 ca_root_nss lt 3.12.11 ports/160455 |
| 1b27af46-d6f6-11e0-89a6-080027ef73ec | ca_root_nss -- extraction of explicitly-untrusted certificates into trust bundle Matthias Andree reports that the ca-bundle.pl used in older versions of the ca_root_nss FreeBSD port before 3.12.11 did not take the Mozilla/NSS/CKBI untrusted markers into account and would add certificates to the trust bundle that were marked unsafe by Mozilla. Discovery 2011-09-04 Entry 2011-09-04 ca_root_nss lt 3.12.11 ports/160455 |