FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The VUXML data was last processed by FreshPorts on 2024-03-27 18:04:16 UTC

List all Vulnerabilities, by package

List all Vulnerabilities, by date

k68

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
4e8344a3-ca52-11de-8ee8-00215c6a37bbgd -- '_gdGetColors' remote buffer overflow vulnerability

CVE reports:

The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.0, and the GD Graphics Library 2.x, does not properly verify a certain colorsTotal structure member, which might allow remote attackers to conduct buffer overflow or buffer over-read attacks via a crafted GD file, a different vulnerability than CVE-2009-3293.


Discovery 2009-10-15
Entry 2009-11-05
Modified 2010-06-17
gd
< 2.0.35_2,1

php5-gd
< 5.2.11_2

php4-gd
< 4.4.9_4

36712
CVE-2009-3546
http://secunia.com/advisories/37069
http://secunia.com/advisories/37080
cdff0af2-1492-11e5-a1cf-002590263bf5php5 -- multiple vulnerabilities

The PHP project reports:

DOM and GD:

  • Fixed bug #69719 (Incorrect handling of paths with NULs).

FTP:

  • Improved fix for bug #69545 (Integer overflow in ftp_genlist() resulting in heap overflow). (CVE-2015-4643)

Postgres:

  • Fixed bug #69667 (segfault in php_pgsql_meta_data). (CVE-2015-4644)

Discovery 2015-06-11
Entry 2015-06-23
php5-dom
php5-ftp
php5-gd
php5-pgsql
< 5.4.42

php55-dom
php55-ftp
php55-gd
php55-pgsql
< 5.5.26

php56-dom
php56-ftp
php56-gd
php56-psql
< 5.6.10

CVE-2015-4643
CVE-2015-4644
http://www.php.net/ChangeLog-5.php#5.4.42
http://www.php.net/ChangeLog-5.php#5.5.26
http://www.php.net/ChangeLog-5.php#5.6.10
http://openwall.com/lists/oss-security/2015/06/18/3