bagder: curl-www/docs _security.html,1.10,1.11

[email protected]
Newsgroups gmane.comp.web.curl.www.cvs
Message-ID <[email protected]>
Update of /cvsroot/curl/curl-www/docs
In directory labb:/tmp/cvs-serv17377

Modified Files:
	_security.html 
Log Message:
modified layout, added 'permalinks' all over, added BID to the recent flaw


Index: _security.html
===================================================================
RCS file: /cvsroot/curl/curl-www/docs/_security.html,v
retrieving revision 1.10
retrieving revision 1.11
diff -u -d -r1.10 -r1.11
--- _security.html	13 Oct 2005 21:38:02 -0000	1.10
+++ _security.html	14 Oct 2005 06:42:14 -0000	1.11
@@ -35,16 +35,20 @@
  We appreciate getting notified in advance before you go public with security
  advisories for the sake of our users.
 
+<a name="BID15102"></a><a name="CAN-2005-3185"></a>
 SUBTITLE(libcurl NTLM Buffer Overflow)
 <p>
-  October 13, 2005<br>
-  Mitre: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-3185">CAN-2005-3185</a><br>
-  Affected versions: curl and libcurl 7.10.6 to and including 7.14.1<br>
-  Not affected versions: curl and libcurl 7.10.5 and earlier, 7.15.0 and later<br>
-  Patch: <a href="http://curl.haxx.se/libcurl-ntlmbuf.patch">libcurl-ntlmbuf.patch</a><br>
-  Advisory: <a href="adv_20051013.html">Project cURL Security Advisory</a>,  <a
+<table class="news">
+  <tr><td>Date:</td><td>October 13, 2005</td></tr>
+  <tr><td>ID</td><td><a href="http://www.securityfocus.com/bid/15102">BID 15102</a> <a
+  href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-3185">CAN-2005-3185</a> <small><a href="#BID15102">(permalink)</a></small></td></tr>
+  <tr><td>Affected versions</td><td>curl and libcurl 7.10.6 to and including 7.14.1</td></tr>
+  <tr><td>Not affected versions</td><td>curl and libcurl 7.10.5 and earlier, 7.15.0 and later</td></tr>
+  <tr><td>Patch</td><td><a href="http://curl.haxx.se/libcurl-ntlmbuf.patch">libcurl-ntlmbuf.patch</a></td></tr>
+  <tr><td>Advisories</td><td><a href="adv_20051013.html">Project cURL Security Advisory</a>,  <a
   href="http://www.idefense.com/application/poi/display?id=322&type=vulnerabilities">iDEFENSE's
-  advisory</a>
+  advisory</a></td></tr>
+</table>
 <p>
  libcurl's NTLM function can overflow a stack-based buffer if given a too long
  user name or domain name. This would happen if you enable NTLM authentication
@@ -63,14 +67,15 @@
   The <a
   href="http://article.gmane.org/gmane.comp.web.wget.general/5064">notification
   mail</a> to us about this flaw was also sent to a public wget mailing list
-  and thus became official immediately.
+  and thus became public immediately.
 
-<a name="BID12616"></a>
+<a name="BID12616"></a><a name="CAN-2005-0490"></a>
 SUBTITLE(Kerberos Authentication Buffer Overflow)
 <p>
-  February 21, 2005 <a href="http://www.securityfocus.com/bid/12616">BID
+  Date: February 21, 2005<br>
+  ID: <a href="http://www.securityfocus.com/bid/12616">BID
   12616</a> <a
-  href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0490">CAN-2005-0490</a> <br>
+  href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0490">CAN-2005-0490</a> <small><a href="#BID12616">(permalink)</a></small> <br>
   Affected versions: 7.3 to and including 7.13.0<br>
   Not affected versions: 7.13.1 and later
 <p>
@@ -85,9 +90,10 @@
 <a name="BID12615"></a>
 SUBTITLE(NTLM Authentication Buffer Overflow)
 <p>
-  February 21, 2005 <a href="http://www.securityfocus.com/bid/12615">BID
+  Date: February 21, 2005<br>
+  ID: <a href="http://www.securityfocus.com/bid/12615">BID
   12615</a> <a
-  href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0490">CAN-2005-0490</a><br>
+  href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0490">CAN-2005-0490</a>  <small><a href="#BID12615">(permalink)</a></small><br>
   Affected versions: 7.10.6 to and including 7.13.0<br>
   Not affected versions: 7.13.1 and later
  <p>
@@ -100,7 +106,8 @@
 <a name="BID8432"></a>
 SUBTITLE(Proxy Authentication Header Information Leakage)
 <p>
-  August 3, 2003 <a href="http://www.securityfocus.com/bid/8432">BID 8432</a><br>
+  Date: August 3, 2003<br>
+  ID: <a href="http://www.securityfocus.com/bid/8432">BID 8432</a>  <small><a href="#BID8432">(permalink)</a></small><br>
   Affected versions: 7.1 to and including 7.10.6<br>
   Not affected versions: 7.10.7 and later
 <p>
@@ -111,9 +118,10 @@
 <a name="BID1804"></a>
 SUBTITLE(FTP Server Response Buffer Overflow)
 <o>
-  October 13, 2000 <a href="http://www.securityfocus.com/bid/1804">BID
+  Date: October 13, 2000<br>
+  ID: <a href="http://www.securityfocus.com/bid/1804">BID
   1804</a> <a
-  href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0973">CVE-2000-0973</a> <br>
+  href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0973">CVE-2000-0973</a>  <small><a href="#BID1804">(permalink)</a></small><br>
   Affected versions: 6.0 (and possibly earlier) to and including 7.4<br>
   Not affected versions: 7.4.1 and later
 <p>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.