| Commit History - (may be incomplete: for full details, see links to repositories near top of page) |
| Commit | Credits | Log message |
1.1_3 14 Nov 2018 17:54:24
  |
madpilot  |
Document recent asterisk vulneraability. |
1.1_3 13 Nov 2018 23:12:10
  |
jkim  |
Document the latest Flash Player vulnerability.
https://helpx.adobe.com/security/products/flash-player/apsb18-39.html |
1.1_3 12 Nov 2018 20:18:10
  |
brnrd  |
security/vuxml: Document openssl vulnerability |
1.1_3 12 Nov 2018 19:03:48
  |
tcberner  |
security/vuxml: Add entry for devel/kio-extras <= 18.08.3_1
https://www.kde.org/info/security/advisory-20181012-1.txt
Security: CVE-2018-19120 |
1.1_3 11 Nov 2018 18:24:46
  |
sunpoet  |
Update openjpeg status |
1.1_3 11 Nov 2018 18:03:48
  |
jbeich  |
security/vuxml: list CVE numbers forgotten in r484705 |
1.1_3 11 Nov 2018 17:53:32
  |
jbeich  |
security/vuxml: mark patch < 2.7.7 as vulnerable
Another copypasta because pkg-audit(8) doesn't grok CPE e.g.,
https://nvd.nist.gov/vuln/search/results?form_type=Advanced&cves=on&cpe_version=cpe:2.3:a:gnu:patch:2.7.6 |
1.1_3 10 Nov 2018 14:02:00
  |
brnrd  |
security/vuxml: Update latest openssl entry
- LibreSSL prior to 2.8 not vulnerable
- LibreSSL likely not vulnerable to CVE-2018-0735
PR: 233109
Submitted by: Franco Fichtner <franco opnsense org> |
1.1_3 09 Nov 2018 10:54:54
  |
dinoex  |
- lighttpd - use-after-free vulnerabilities
PR: 232278 |
1.1_3 08 Nov 2018 23:08:55
  |
girgen  |
Add info about security vulnerability in PostgreSQL
Security: CVE-2018-16850 |
1.1_3 08 Nov 2018 17:29:07
  |
brnrd  |
security/vuxml: Mark MariaDB 10.3.10 vulnerable
- From MariaDB release notes (not released yet)
See: https://mariadb.com/kb/en/library/mariadb-10311-release-notes/
PR: 233068 |
1.1_3 06 Nov 2018 17:24:51
  |
joneum  |
Add modified entrey for drupal after changes in r484148
Sponsored by: Netzkommune GmbH |
1.1_3 06 Nov 2018 16:34:09
  |
joneum  |
Add entry for nginx and nginx-devel
Sponsored by: Netzkommune GmbH |
1.1_3 04 Nov 2018 21:16:14
  |
acm  |
- Add www/drupal8 entry |
1.1_3 01 Nov 2018 22:00:16
  |
flo  |
Document gitea vulnerability
PR: 232897
Submitted by: stb@lassitu.de (maintainer) |
1.1_3 01 Nov 2018 19:20:06
  |
sunpoet  |
Document curl vulnerability |
1.1_3 01 Nov 2018 19:06:56
  |
mfechner  |
Document gilab-ce vulnerability.
Approved by: mentors (implicit) |
1.1_3 01 Nov 2018 14:05:12
  |
sunpoet  |
Document rubygem-loofah vulnerability |
1.1_3 01 Nov 2018 12:16:17
  |
brnrd  |
security/vuxml: Update latest OpenSSL entry
- As per a LibreSSL dev, also vulnerable |
1.1_3 29 Oct 2018 18:33:06
  |
mfechner  |
Documented several security issues with www/gitlab-ce.
Approved by: mentors (implicit) |
1.1_3 29 Oct 2018 17:51:00
  |
brnrd  |
security/vuxml: Document OpenSSL 1.1.x vulnerabilities |
1.1_3 28 Oct 2018 16:26:42
  |
riggs  |
Document potential remote code execution in net/liveMedia (CVE-2018-4013) |
1.1_3 27 Oct 2018 17:04:57
  |
leres  |
Mark mini_httpd < 1.30 as vulnerable as per:
http://acme.com/updates/archive/211.html
The issue is arbitrary file disclosure in some circumstances.
Reviewed by: matthew (mentor)
Approved by: matthew (mentor)
Differential Revision: https://reviews.freebsd.org/D17718 |
1.1_3 27 Oct 2018 08:06:03
  |
woodsb02  |
Add entry for sysutils/py-salt
PR: 232663
Reported by: Christer Edwards <christer.edwards@gmail.com>
Security: https://www.vuxml.org/freebsd/4f7c6af3-6a2c-4ead-8453-04e509688d45.html |
1.1_3 23 Oct 2018 17:32:42
  |
jbeich  |
security/vuxml: mark firefox < 63 as vulnerable |
1.1_3 22 Oct 2018 16:21:18
  |
joneum  |
Add entry for www/drupal7
Sponsored by: Netzkommune GmbH |
1.1_3 20 Oct 2018 14:57:17
  |
sunpoet  |
Document ruby vulnerability
PR: 232427 (based on)
Submitted by: Yasuhiro KIMURA <yasu@utahime.org> |
1.1_3 20 Oct 2018 07:58:43
  |
brnrd  |
security/vuxml: Document 2018-10 MySQL vulnerabilities |
1.1_3 19 Oct 2018 16:06:30
  |
joneum  |
Add entry for www/matomo
Sponsored by: Netzkommune GmbH |
1.1_3 17 Oct 2018 15:54:16
  |
feld  |
Document libssh vulnerability
PR: 232344
Security: CVE-2018-10933 |
1.1_3 15 Oct 2018 11:29:07
  |
mfechner  |
Document security vulnerability with devel/libgit2 < 0.27.5.
Approved by: mentors (implicit) |
1.1_3 11 Oct 2018 19:54:18
  |
thierry  |
Add an entry for a memory leak bug in net-im/tox < v0.2.8. |
1.1_3 11 Oct 2018 15:28:08
  |
joneum  |
Add entry for www/gitea
PR: 232123
Reported by: maintainer
Sponsored by: Netzkommune GmbH |
1.1_3 11 Oct 2018 13:42:28
  |
lwhsu  |
Document Jenkins Security Advisory 2018-10-10
Sponsored by: The FreeBSD Foundation |
1.1_3 09 Oct 2018 21:13:59
  |
dinoex  |
- add entry for tinc and tinc-devel |
1.1_3 05 Oct 2018 22:06:20
  |
mfechner  |
Document several vulnerabilities for gitlab-ce.
Approved by: mentors (implicit) |
1.1_3 04 Oct 2018 01:32:18
  |
ler  |
security/vuxml: add multiple vulnerabilities in security/clamav.
PR: 231924
Submitted by: yasu@utahime.org |
1.1_3 03 Oct 2018 13:46:36
  |
wen  |
- Document django21 vulnerability |
1.1_3 03 Oct 2018 01:01:23
  |
jbeich  |
security/vuxml: mark firefox < 62.0.3 as vulnerable |
1.1_3 01 Oct 2018 19:02:32
  |
mfechner  |
Document several vulnerabilities for gitlab-ce.
Approved by: mentors (implicit) |
1.1_3 01 Oct 2018 14:53:24
  |
swills  |
Document pango DoS |
1.1_3 30 Sep 2018 06:48:23
  |
joneum  |
Add entry for www/serendipity
Sponsored by: Netzkommune GmbH |
1.1_3 29 Sep 2018 23:26:59
  |
kbowling  |
security/vuxml: Add entry for net-p2p/bitcoin CVE-2018-17144
Add VuXML for r480928
Approved by: timur (mentor)
Differential Revision: https://reviews.freebsd.org/D17360 |
1.1_3 26 Sep 2018 18:09:07
  |
zeising  |
Document spamassassin - multiple vulnerabilities
Document spamassassin vulnerabilities, as found in this announcement:
https://seclists.org/oss-sec/2018/q3/242 |
1.1_3 26 Sep 2018 13:07:50
  |
lme  |
security/vuxml:
Document wesnoth vulnerability |
1.1_3 26 Sep 2018 12:49:24
  |
brnrd  |
security/vuxml: Add Apache 2.4 vulnerability |
1.1_3 25 Sep 2018 16:09:40
  |
sunpoet  |
Update OpenJPEG vulnerability
CVE-2018-5785 was fixed in r480624. |
1.1_3 25 Sep 2018 14:07:08
  |
tobik  |
Document mantis vulnerability |
1.1_3 22 Sep 2018 16:50:19
  |
sunpoet  |
Document rubygem-smart_proxy_dynflow vulnerability |
1.1_3 22 Sep 2018 14:05:45
  |
wen  |
- Document mediawiki's multiple vulnerabilities |
1.1_3 21 Sep 2018 23:03:37
  |
jbeich  |
security/vuxml: mark firefox < 62.0.2 as vulnerable |
1.1_3 21 Sep 2018 08:17:45
  |
madpilot  |
Document new asterisk vulnerability. |
1.1_3 18 Sep 2018 10:48:27
  |
wen  |
- Document moodle multiple vulnerabilities |
1.1_3 15 Sep 2018 23:40:15
  |
ler  |
security/vuxml: add Joomla3 Vulnerabilities |
1.1_3 15 Sep 2018 08:54:58
  |
jbeich  |
security/vuxml: mark waterfox < 56.2.3 as vulnerable |
1.1_3 13 Sep 2018 21:56:23
  |
sunpoet  |
Update OpenJPEG vulnerability
Only CVE-2017-17479 and CVE-2017-17480 were fixed in r477112.
Notified by: tijl |
1.1_3 13 Sep 2018 19:08:11
  |
joneum  |
Document vulnerability in www/mybb
Sponsored by: Netzkommune GmbH |
1.1_3 12 Sep 2018 13:57:04
  |
feld  |
Document FreeBSD-SA-18:12.elf |
1.1_3 11 Sep 2018 20:36:44
  |
yuri  |
Add VuXML vulnerability CVE-2018-15598 for traefik.
Port update is already MFHed. |
1.1_3 11 Sep 2018 18:43:42
  |
jkim  |
Document the latest Flash Player vulnerability.
https://helpx.adobe.com/security/products/flash-player/apsb18-31.html |
1.1_3 11 Sep 2018 16:13:58
  |
feld  |
Improve formatting
Also add plexmediaserver-plexpass package as vulnerable |
1.1_3 11 Sep 2018 16:10:31
  |
feld  |
Document Plex vulnerability
Security: CVE-2018-13415 |
1.1_3 11 Sep 2018 10:39:06
  |
adridg  |
The 0.18 release of x11/sddm contains a fix for a security error
that allows unlocking a session without a password, if the
ReuseSession configuration option is set to true. The default
configuration sets it to false.
I'm setting the version to < 0.17.0_1 here, because I'm going
to update 0.17 with backports rather than pull in 0.18 (there's
a lot more work in that update, because of reorganisation upstream
and none of our patches apply anymore).
PR: 230029
Reported by: doctorwhoguy@gmail.com |
1.1_3 11 Sep 2018 09:53:49
  |
joneum  |
Document vulnerability in www/mybb
Sponsored by: Netzkommune GmbH |
1.1_3 09 Sep 2018 17:46:23
  |
flo  |
Document gitea vulnerability.
PR: 231180
Submitted by: stb@lassitu.de
Security: 7c750960-b129-11e8-9fcd-080027f43a02 |
1.1_3 07 Sep 2018 03:49:46
  |
cy  |
Remove duplicate entry for WPA EAPOL vulnerability. Use r477829 instead
as its version range is more complete.
PR: 231054
Reported by: 000.fbsd@quip.cz |
1.1_3 06 Sep 2018 06:53:44
  |
yuri  |
Add VuXML entry for the fixed CVE-2017-11114 in www/links
PR: 230849
Submitted by: Dmitri Goutnik <dg@syrec.org> |
1.1_3 05 Sep 2018 23:30:17
  |
sunpoet  |
Document curl vulnerability |
1.1_3 05 Sep 2018 20:39:51
  |
jbeich  |
security/vuxml: mark firefox < 62 as vulnerable |
1.1_3 04 Sep 2018 12:47:08
  |
tijl  |
Document Ghostscript -dSAFER sandbox bypass vulnerabilities.
PR: 231148
Security: https://www.kb.cert.org/vuls/id/332928 |
1.1_3 31 Aug 2018 23:47:50
  |
swills  |
Document grafana issues
PR: 231019
PR: 231020
PR: 231021
PR: 231022 |
1.1_3 30 Aug 2018 20:47:55
  |
mfechner  |
Document several vulnerabilities for gitlab-ce.
Approved by: mentors (implicit) |
1.1_3 30 Aug 2018 06:33:34
  |
tota  |
- Fix range for ja-mailman in CVE-2018-13796 |
1.1_3 30 Aug 2018 00:09:58
  |
leres  |
Mark bro < 2.5.5 as vulnerable as per:
https://www.bro.org/download/NEWS.bro.html
Reviewed by: ler (mentor)
Approved by: ler (mentor)
Differential Revision: https://reviews.freebsd.org/D16948 |
1.1_3 27 Aug 2018 11:19:03
  |
bhughes  |
security/vuxml: document Node.js vulnerabilities
https://nodejs.org/en/blog/vulnerability/august-2018-security-releases/
Sponsored by: Miles AS |
1.1_3 24 Aug 2018 10:34:46
  |
tobik  |
Fix databases/mantis entry after r477954 |
1.1_3 23 Aug 2018 05:34:56
  |
matthew  |
Apparently you can have more than on <name></name> item inside a
<package></packge> group. Also, re-add plain 'phpMyAdmin' without a
flavour suffix as a possible package name -- it's only been a few
months since flavourization, and there may well be some older installs
still out there. (Although those should already be flagging for the
previous PMASA)
Reported by: mat |
1.1_3 22 Aug 2018 21:58:04
  |
matthew  |
Third time's the charm. Now capitalize the package names correctly. |
1.1_3 22 Aug 2018 21:40:11
  |
matthew  |
phpMyAdmin is flavoured now: use the correct package names. |
1.1_3 22 Aug 2018 21:28:45
  |
feld  |
Document FreeBSD-SA-18:11.hostapd |
1.1_3 22 Aug 2018 21:28:04
  |
feld  |
Document FreeBSD-SA-18:10.ip |
1.1_3 22 Aug 2018 21:27:36
  |
feld  |
Document FreeBSD-SA-18:09.l1tf |
1.1_3 22 Aug 2018 21:03:21
  |
swills  |
Document gogs open redirect issue
PR: 230800
Submitted by: Dmitri Goutnik <dg@syrec.org> |
1.1_3 22 Aug 2018 20:32:50
  |
matthew  |
Document the latest phpMyAdmin security advisory PMASA-2018-5 |
1.1_3 22 Aug 2018 19:28:01
  |
zeising  |
Document libX11 vulnerabilities.
CVE-2018-14598
CVE-2018-14599
CVE-2018-14600
https://lists.x.org/archives/xorg-announce/2018-August/002915.html |
1.1_3 21 Aug 2018 17:53:08
  |
dch  |
security/vuxml: add CVE-2018-11769 for databases/couchdb versions < 2.2.0
Reported by: Apache CouchDB PMC
Approved by: jrm
Security: CVE-2018-11769
Security: https://lists.apache.org/thread.html/1052ad7a1b32b9756df4f7860f5cb5a96b739f444117325a19a4bf75@%3Cdev.couchdb.apache.org%3E
Differential Revision: https://reviews.freebsd.org/D16820 |
1.1_3 17 Aug 2018 21:07:32
  |
swills  |
Document issue in security/botan2
PR: 230666 |
1.1_3 15 Aug 2018 21:01:23
  |
lwhsu  |
Document Jenkins Security Advisory 2018-08-15
Sponsored by: The FreeBSD Foundation |
1.1_3 14 Aug 2018 20:21:53
  |
cy  |
Document WPA unauthenticated encrypted EAPOL-Key data vunlerability.
Security: CVE-2018-14526 |
1.1_3 14 Aug 2018 19:08:38
  |
jkim  |
Document the latest Flash Player vulnerabilities.
https://helpx.adobe.com/security/products/flash-player/apsb18-25.html |
1.1_3 14 Aug 2018 13:37:35
  |
timur  |
Add an entry about multiple Samba vulnerabilities:
* CVE-2018-1139 (Weak authentication protocol allowed.)
* CVE-2018-1140 (Denial of Service Attack on DNS and LDAP server.)
* CVE-2018-10858 (Insufficient input validation on client directory
listing in libsmbclient.)
* CVE-2018-10918 (Denial of Service Attack on AD DC DRSUAPI server.)
* CVE-2018-10919 (Confidential attribute disclosure from the AD LDAP
server.)
Security: CVE-2018-1139
CVE-2018-1140
CVE-2018-10858
CVE-2018-10918
CVE-2018-10919
Sponsored by: iXsystems Inc. |
1.1_3 12 Aug 2018 17:35:08
  |
sunpoet  |
Document GraphicsMagick vulnerability |
1.1_3 12 Aug 2018 13:44:39
  |
tobik  |
Document lang/chicken vulerabilities |
1.1_3 12 Aug 2018 07:55:09
  |
flo  |
Document www/gitea vulnerability, with the scarce details provided by Gitea
PR: 230512 |
1.1_3 10 Aug 2018 14:35:45
  |
tijl  |
Document mbed TLS Security Advisory 2018-02.
Security: https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security-advisory-2018-02 |
1.1_3 10 Aug 2018 08:56:53
  |
girgen  |
Add entry about postgresql vulnerabilites |
1.1_3 08 Aug 2018 19:07:31
  |
brnrd  |
security/vuxml: Document Oracle's Crititcal Patch Update |
1.1_3 07 Aug 2018 13:18:03
  |
girgen  |
Add vulnerability information about apache-xml-security-c |
1.1_3 06 Aug 2018 21:26:20
  |
feld  |
Document FreeBSD-SA-18:08.tcp |
1.1_3 06 Aug 2018 03:23:23
  |
koobs  |
security/py-cryptography: Add tag forgery vulnerability
PR: 226906 |