Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2013-2217 #94

Closed
existful opened this issue Jun 23, 2023 · 5 comments
Closed

CVE-2013-2217 #94

existful opened this issue Jun 23, 2023 · 5 comments

Comments

@existful
Copy link

Hello,

Could one of the maintainers come up with a fix for this CVE?

py39-suds-1.1.2 is vulnerable:
py-suds -- vulnerable to symlink attacks
CVE: CVE-2013-2217
WWW: https://vuxml.FreeBSD.org/freebsd/b31f7029-817c-4c1f-b7d3-252de5283393.html

Thanks.

@phillbaker
Copy link
Member

phillbaker commented Jun 23, 2023 via email

@existful
Copy link
Author

After installing the net/py-suds port, the vulmx entry appears.

[08:37] [vr0@yggdrasil]-[~]: doas pkg audit

py39-suds-1.1.2 is vulnerable:
py-suds -- vulnerable to symlink attacks
CVE: CVE-2013-2217
WWW: https://vuxml.FreeBSD.org/freebsd/b31f7029-817c-4c1f-b7d3-252de5283393.html

1 problem(s) in 1 installed package(s) found

Here the database entry from 2023-04-09 in the FreeBSD ports (pkg audit) and the associated commit:

https://cgit.freebsd.org/ports/commit/?id=33ab2b4a207f7a41d472f6d94259cc77d634dcb6

@phillbaker
Copy link
Member

phillbaker commented Jun 24, 2023 via email

@existful
Copy link
Author

It looks like the right upsteam, the source comes from PyPi https://pypi.org/project/suds/#files

SHA256 hash are identical.

/usr/ports/net/py-suds/Makefile

PORTNAME=       suds
PORTVERSION=    1.1.2
CATEGORIES=     net python
MASTER_SITES=   PYPI
PKGNAMEPREFIX=  ${PYTHON_PKGNAMEPREFIX}

MAINTAINER=     sunpoet@FreeBSD.org
COMMENT=        Lightweight SOAP client (community fork)
WWW=            https://github.com/suds-community/suds

LICENSE=        LGPL3
LICENSE_FILE=   ${WRKSRC}/LICENSE.txt

USES=           python:3.6+
USE_PYTHON=     autoplist concurrent distutils pytest

NO_ARCH=        yes

.include <bsd.port.mk>

/usr/ports/net/py-suds/distinfo

TIMESTAMP = 1656522306
SHA256 (suds-1.1.2.tar.gz) = 1d5cfa74117193b244a4233f246c483d9f41198b448c5f14a8bad11c4f649f2b
SIZE (suds-1.1.2.tar.gz) = 285336

@phillbaker
Copy link
Member

phillbaker commented Jun 24, 2023 via email

freebsd-git pushed a commit to freebsd/freebsd-ports that referenced this issue Jul 9, 2023
@existful existful closed this as completed Jul 9, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants