Opened 4 years ago

Closed 4 years ago

#49761 closed update (fixed)

nspr @4.10.9_0: update to nspr

Reported by: Schamschula (Marius Schamschula) Owned by: ryandesign (Ryan Schmidt)
Priority: Normal Milestone:
Component: ports Version: 2.3.4
Keywords: haspatch Cc:
Port: nspr

Description

nspr has been updated to version 4.11. The update also includes a security fix from version 4.10.10:

Bug 1205157 (CVE-2015-7183)

A logic bug in the handling of large allocations would allow exceptionally large allocations to be reported as successful, without actually allocating the requested memory. This may allow attackers to bypass security checks and obtain control of arbitrary memory.

Attachments (1)

Portfile-nspr.diff (848 bytes) - added by Schamschula (Marius Schamschula) 4 years ago.

Download all attachments as: .zip

Change History (3)

Changed 4 years ago by Schamschula (Marius Schamschula)

Attachment: Portfile-nspr.diff added

comment:1 Changed 4 years ago by ryandesign (Ryan Schmidt)

Owner: changed from macports-tickets@… to ryandesign@…
Status: newassigned

Thanks.

comment:2 Changed 4 years ago by ryandesign (Ryan Schmidt)

Keywords: haspatch added
Resolution: fixed
Status: assignedclosed
Note: See TracTickets for help on using tickets.