FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The last vuln.xml file processed by FreshPorts is:

Revision:  523993
Date:      2020-01-24
Time:      22:20:00Z
Committer: kai

List all Vulnerabilities, by package

List all Vulnerabilities, by date

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
0d9ba03b-0dbb-42b4-ae0f-60e27af78e22sympa -- buffer overflow in "queue"

Erik Sjölund discovered a vulnerability in Sympa. The queue application processes messages received via aliases. It contains a buffer overflow in the usage of sprintf. In some configurations, it may allow an attacker to execute arbitrary code as the sympa user.

Discovery 2005-02-11
Entry 2005-06-01
lt 4.1.2_1

451a6c79-c92b-11e4-a835-000c292ee6b8sympa -- Remote attackers can read arbitrary files

The Sympa Project reports:

The newsletter posting area in the web interface in Sympa 6.0.x before 6.0.10 and 6.1.x before 6.1.24 allows remote attackers to read arbitrary files via unspecified vectors.

Discovery 2015-01-13
Entry 2015-03-13
lt 6.1.24
78c39232-a345-11e1-9d81-d0df9acfd7e5sympa -- Multiple Security Bypass Vulnerabilities

Secunia team reports:

Multiple vulnerabilities have been reported in Sympa, which can be exploited by malicious people to bypass certain security restrictions.

The vulnerabilities are caused due to the application allowing access to archive functions without checking credentials. This can be exploited to create, download, and delete an archive.

Discovery 2012-05-14
Entry 2012-05-21
lt 6.1.11

de6d8290-aef7-11e1-898f-14dae938ec40mail/sympa* -- Multiple vulnerabilities in Sympa archive management

David Verdin reports:

Multiple vulnerabilities have been discovered in Sympa archive management that allow to skip the scenario-based authorization mechanisms.

This vulnerability allows the attacker to:

  • display the archives management page ('arc_manage')
  • download the list's archives
  • delete the list's archives

Discovery 2012-05-15
Entry 2012-06-05
lt 6.0.7

gt 6.1.* lt 6.1.11