notbugAs an Amazon Associate I earn from qualifying purchases.
Want a good read? Try FreeBSD Mastery: Jails (IT Mastery Book 15)
Want a good monitor light? See my photosAll times are UTC
Ukraine
non port: security/vuxml/vuln.xml

Number of commits found: 6273 (showing only 100 on this page)

[First Page]  «  1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11  »  [Last Page]

Sunday, 7 Jun 2020
02:20 dbaio search for other commits by this committer
security/vuxml: Update CVE-2019-18348 and CVE-2020-8492 entries

CVE-2019-18348:	Add missing Python packages range
CVE-2020-8492:	Fix Python 3.7 entrie, it's currently affected.

After committing fixes, we'll need to change ranges again.

PR:		246984
Original commitRevision:538142 
Friday, 5 Jun 2020
10:51 rene search for other commits by this committer
Document new vulnerabilities in www/chromium < 83.0.4103.97

Obtained
from:	https://chromereleases.googleblog.com/2020/06/stable-channel-update-for-desktop.html
Original commitRevision:538006 
Thursday, 4 Jun 2020
23:43 wen search for other commits by this committer
- Fix the name of py-django30 in my previous commit

Spotted by:	dan@langille.org
Original commitRevision:537980 
23:31 gjb search for other commits by this committer
Attempt to fix build.

Sponsored by:	Rubicon Communications, LLC (netgate.com)
Original commitRevision:537978 
22:49 acm search for other commits by this committer
- Update c5ec57a9-9c2b-11ea-82b8-4c72b94353b5 entry. Add drupal 8.8.6
Original commitRevision:537973 
17:51 mfechner search for other commits by this committer
Document gitlab-ce vulnerabilities.
Original commitRevision:537913 
14:25 wen search for other commits by this committer
- Document Django multiple vulnerabilities
Original commitRevision:537897 
12:41 garga search for other commits by this committer
vuxml: Document git vulnerability CVE-2020-5260

PR:		245821
Submitted by:	rob2g2 <spam123@bitbert.com>
Sponsored by:	Rubicon Communications, LLC (Netgate)
Original commitRevision:537893 
12:37 garga search for other commits by this committer
vuxml: Document git vulnerability CVE-2020-11008

PR:		245822
Submitted by:	rob2g2 <spam123@bitbert.com>
Sponsored by:	Rubicon Communications, LLC (Netgate)
Original commitRevision:537891 
12:14 tijl search for other commits by this committer
Add entry for GNUTLS-SA-2020-06-03 (flaw in TLS).
Add CVE reference to previous GnuTLS entry.
Original commitRevision:537888 
Wednesday, 3 Jun 2020
16:46 sunpoet search for other commits by this committer
Document rubygem-websocket-extensions vulnerability
Original commitRevision:537620 
16:44 sunpoet search for other commits by this committer
Document nghttp2 vulnerability
Original commitRevision:537619 
Sunday, 31 May 2020
10:53 adamw search for other commits by this committer
VuXML: Add entry for gitea < 1.11.6

PR:		246892
Submitted by:	maintainer
Original commitRevision:537150 
Friday, 29 May 2020
06:51 tagattie search for other commits by this committer
Correct vulnerable version range of powerdns-recursor

PR:		246655
Submitted by:	Ralf van der Enden <tremere@cainites.net>
Approved by:	ehaupt (mentor)
Original commitRevision:536950 
02:07 sunpoet search for other commits by this committer
Fix r536871
Original commitRevision:536876 
01:59 sunpoet search for other commits by this committer
Document rubygem-kaminari-core vulnerability
Original commitRevision:536871 
Thursday, 28 May 2020
10:20 cmt search for other commits by this committer
document sane-backend vulnerabilities

CVE-2020-12861, CVE-2020-12862, CVE-2020-12863, CVE-2020-12864,
CVE-2020-12865, CVE-2020-12866, CVE-2020-12867

PR:		246803
Original commitRevision:536757 
06:19 mfechner search for other commits by this committer
Document gitlab-ce vulnerabilities.
Original commitRevision:536740 
Wednesday, 27 May 2020
16:20 pi search for other commits by this committer
security/vuxml: add two entries for mail/sympa

PR:		246701
Submitted by:	Geoffroy Desvernay <dgeo@centrale-marseille.fr>
Original commitRevision:536701 
12:08 tagattie search for other commits by this committer
Document powerdns-recursor vulnerabilities

PR:		246655
Submitted by:	Ralf van der Enden <tremere@cainites.net>
Approved by:	ehaupt (mentor)
Original commitRevision:536689 
Monday, 25 May 2020
18:04 pi search for other commits by this committer
security/vuxml: add three CVEs for qmail

PR:		245010
Submitted by:	erdgeist@erdgeist.org
Original commitRevision:536490 
Sunday, 24 May 2020
18:55 rene search for other commits by this committer
Document new vulnerabilities in www/chromium 83.0.4103.61.

The website is somewhat crippled and does not show the full text.
Original commitRevision:536418 
Saturday, 23 May 2020
12:31 joneum search for other commits by this committer
Add entry for piwigo

PR:		245153
Sponsored by:	Netzkommune GmbH
Original commitRevision:536295 
09:22 joneum search for other commits by this committer
Add entry for tomcat

PR:		246657
Sponsored by:	Netzkommune GmbH
Original commitRevision:536276 
Friday, 22 May 2020
22:20 delphij search for other commits by this committer
Document unbound multiple vulnerabilities.
Original commitRevision:536247 
13:07 joneum search for other commits by this committer
Add entry for drual7

Sponsored by:	Netzkommune GmbH
Original commitRevision:536198 
Wednesday, 20 May 2020
11:41 dbaio search for other commits by this committer
security/vuxml: Document net-mgmt/zabbix3 issue

Security:	CVE-2020-11800
Original commitRevision:535992 
Tuesday, 19 May 2020
23:35 sunpoet search for other commits by this committer
Document rails vulnerability
Original commitRevision:535958 
14:18 wen search for other commits by this committer
- Document CVE-2019-18348, CVE-2020-8492 for python38
Original commitRevision:535860 
Monday, 18 May 2020
19:00 ler search for other commits by this committer
security/vuxml: Report multiple dovecot vulnerabilities.
Original commitRevision:535775 
Sunday, 17 May 2020
20:42 zi search for other commits by this committer
- Document security/clamav vulnerabilities
Original commitRevision:535678 
20:18 sunpoet search for other commits by this committer
Update json-c vulnerability

- While I'm here, fix format

json-c 0.14 will land the ports tree along with the fix, thus I change it to
0.14.

PR:		246389
Original commitRevision:535672 
18:33 sunpoet search for other commits by this committer
Document rails vulnerability
Original commitRevision:535637 
Saturday, 16 May 2020
09:17 brnrd search for other commits by this committer
security/vuxml: MariaDB vulnerabilities
Original commitRevision:535368 
06:45 woodsb02 search for other commits by this committer
Add new sysutils/py-salt vulnerabilities

PR:		246061
Reported by:	Christer Edwards <christer.edwards@gmail.com>
Security:	CVE-2020-11651
Security:	CVE-2020-11652
Original commitRevision:535356 
Thursday, 14 May 2020
11:29 mandree search for other commits by this committer
devel/json-c: CVE-2020-12762 integer overflow, out of bounds write

Reported by:	Daniel Engberg
Security:	abc3ef37-95d4-11ea-9004-25fadb81abf4
Security:	CVE-2020-12762
Original commitRevision:535226 
Wednesday, 13 May 2020
20:44 sunpoet search for other commits by this committer
Document typo3 vulnerability
Original commitRevision:535178 
Tuesday, 12 May 2020
18:37 gordon search for other commits by this committer
Add data for today's SA batch.

Approved by:	so
Original commitRevision:535002 
Saturday, 9 May 2020
16:02 novel search for other commits by this committer
security/vuxml: log www/qutebrowser CVE-2020-11054
Original commitRevision:534787 
10:08 wen search for other commits by this committer
- Document python27 CVE-2019-18348
Original commitRevision:534730 
08:23 joneum search for other commits by this committer
add entry for www/glpi

PR:		244971
Sponsored by:	Netzkommune GmbH
Original commitRevision:534722 
Thursday, 7 May 2020
19:56 mandree search for other commits by this committer
mail/mailman: extend content injection vuln via private archive login

This led up to mailman 2.1.33 today.
https://bugs.launchpad.net/mailman/+bug/1877379
https://launchpadlibrarian.net/478684932/private.diff
https://mail.python.org/archives/list/mailman-developers@python.org/thread/SYBIZ3MNSQZLKN6PVKO7ZKR7QMOBMS45/

Approved by:	ports-secteam@ (blanket for security fixes)
Security:	88760f4d-8ef7-11ea-a66d-4b2ef158be83
Original commitRevision:534283 
Wednesday, 6 May 2020
23:26 leres search for other commits by this committer
security/vuxml: Mark zeek < 3.0.6 as vulnerable as per:

    https://raw.githubusercontent.com/zeek/zeek/v3.0.6/NEWS

Various issues including buffer over-reads, uninitialized field
access, memory leak, and stack overflows.
Original commitRevision:534209 
15:02 salvadore search for other commits by this committer
security/vuxml: Update discovery date for CVE-2020-1730

Update discovery date for CVE-2020-1730 based on information obtained from
the libssh team.

Approved by:	gerald (mentor)
Original commitRevision:534178 
05:14 sunpoet search for other commits by this committer
Document wagtail vulnerability
Original commitRevision:534144 
Tuesday, 5 May 2020
22:55 mandree search for other commits by this committer
Permit mail/mailman vulnerability to be fixed in 2.1.30_3 already

...not in 2.1.31 only. We can't just easily backport 2.1.31 to 2020Q2.

Security:	88760f4d-8ef7-11ea-a66d-4b2ef158be83
Original commitRevision:534107 
17:51 mandree search for other commits by this committer
new mailman < 2.1.31 content injection vulnerability

similar to CVE-2018-13796 (not sure if they'll reuse that no. so
not including in Security: tags below)

https://bugs.launchpad.net/mailman/+bug/1873722

Security:	88760f4d-8ef7-11ea-a66d-4b2ef158be83
Original commitRevision:534100 
05:32 fjoe search for other commits by this committer
Fix version range for 97fcc60a-6ec0-11ea-a84a-4c72b94353b5:
phpMyAdmin 4.9.5 is not vulnerable

PR:		245096
Original commitRevision:534026 
Monday, 4 May 2020
23:23 dbaio search for other commits by this committer
security/vuxml: Document net-mgmt/cacti issue

PR:		246164
Submitted by:	Michael Muenz <m.muenz@gmail.com>
Security:	CVE-2020-7106
Original commitRevision:533995 
Sunday, 3 May 2020
21:28 pi search for other commits by this committer
security/vuxml: add squid 4.10 CVEs

PR:		245433
Submitted by:	Michael Muenz <m.muenz@gmail.com>
Original commitRevision:533883 
07:46 tcberner search for other commits by this committer
Document audio/taglib vulnerability
Original commitRevision:533756 
Friday, 1 May 2020
09:44 mfechner search for other commits by this committer
Documented gitlab vulnerabilities.
Original commitRevision:533532 
Wednesday, 29 Apr 2020
22:31 dbaio search for other commits by this committer
security/vuxml: Add other flavors of py-yaml
Original commitRevision:533400 
18:48 tcberner search for other commits by this committer
Document multimedia/vlc vulnerabilities

Security:	CVE-2019-19721 CVE-2020-6071 CVE-2020-6072 CVE-2020-6073 CVE-2020-6077
CVE-2020-6078 CVE-2020-6079
Original commitRevision:533382 
15:03 timur search for other commits by this committer
Add an entry about CVE-2020-10700, CVE-2020-10704 in samba410 and 411.

Security:	CVE-2020-10700
		CVE-2020-10704
Original commitRevision:533343 
06:08 fluffy search for other commits by this committer
net/ceph14: document CVE-2020-1759, CVE-2020-1760
Original commitRevision:533316 
01:35 delphij search for other commits by this committer
Document OpenLDAP CVE-2020-12243.

PR:		213895
Submitted by:	rob2g2 <spam123 bitbert com>
Original commitRevision:533305 
Monday, 27 Apr 2020
19:47 jpaetzel search for other commits by this committer
Add entry for py-yaml vulnerability
Original commitRevision:533163 
Sunday, 26 Apr 2020
17:39 dbaio search for other commits by this committer
security/vuxml: Document www/py-bleach issue

PR:		245943
Security:	CVE-2020-6817
Original commitRevision:533080 
Thursday, 23 Apr 2020
12:25 brnrd search for other commits by this committer
security/vuxml: MySQL Server 2020Q2 vulnerabilities
Original commitRevision:532677 
12:23 brnrd search for other commits by this committer
security/vuxml: MySQL client 2020Q2 vulnerabilities
Original commitRevision:532676 
11:48 brnrd search for other commits by this committer
security/vuxml: Register Nextcloud vulnerabilities
Original commitRevision:532672 
01:17 dbaio search for other commits by this committer
security/vuxml: Document lang/python issue

PR:		245819
Security:	CVE-2020-8492
Original commitRevision:532610 
Wednesday, 22 Apr 2020
21:33 sunpoet search for other commits by this committer
Document wagtail vulnerability
Original commitRevision:532599 
20:29 gordon search for other commits by this committer
11.3 isn't vulenrable to the recent OpenSSL vulnerability.

Approved by:	so
X-Pointy-Hat to: gordon
Original commitRevision:532512 
20:02 leres search for other commits by this committer
security/vuxml: Restore openssl port version range to the 2020-04-21 entry

I tested that this passes "make validate" and correctly flags
openssl-1.1.1f,1 as vulnerable.

Approved by:	gjb
Original commitRevision:532511 
11:11 gjb search for other commits by this committer
Revert r532466, adding back 'FreeBSD' to the topic.

Sponsored by:	Rubicon Communications, LLC (netgate.com)
Original commitRevision:532469 
11:09 gjb search for other commits by this committer
The vuxml build is now fixed.  Remove the 'ignore' block and its
contents.

Sponsored by:	Rubicon Communications, LLC (netgate.com)
Original commitRevision:532468 
11:07 gjb search for other commits by this committer
Comment the second name tag, which I believe is what is causing the
vuxml build to fail.  If I am wrong, I will revert this commit.

Sponsored by:	Rubicon Communications, LLC (netgate.com)
Original commitRevision:532467 
11:03 gjb search for other commits by this committer
Um, ok.  Third attempt to try to fix the vuxml build.

Sponsored by:	Rubicon Communications, LLC (netgate.com)
Original commitRevision:532466 
10:44 gjb search for other commits by this committer
Attempt number 2 to fix the vuxml build.

Sponsored by:	Rubicon Communications, LLC (netgate.com)
Original commitRevision:532463 
10:36 gjb search for other commits by this committer
Fix vuxml build.

Sponsored by:	Rubicon Communications, LLC (netgate.com)
Original commitRevision:532462 
09:38 brnrd search for other commits by this committer
security/vuxml: Fix OpenSSL port commit
Original commitRevision:532458 
08:20 brnrd search for other commits by this committer
security/vuxml: Mark OpenSSL 1.1.1f from ports vulnerable too
Original commitRevision:532451 
Tuesday, 21 Apr 2020
19:48 sunpoet search for other commits by this committer
Document libntlm vulnerability
Original commitRevision:532399 
18:29 gordon search for other commits by this committer
Add new entries for SA-20:10 and SA-20:11.
Original commitRevision:532291 
12:25 dbaio search for other commits by this committer
security/vuxml: Document devel/py-twisted vulnerabilities

PR:		245252
Submitted by:	Sascha Biberhofer <ports@skyforge.at>
Reported by:	contact@evilham.com
Original commitRevision:532266 
Sunday, 19 Apr 2020
12:58 salvadore search for other commits by this committer
security/vuxml: Add CVE-2020-1730 affecting security/libssh

Approved by:	gerald (mentor)
Differential Revision:	https://reviews.freebsd.org/D24377
Original commitRevision:532108 
Saturday, 18 Apr 2020
11:35 kwm search for other commits by this committer
Document webkit2-gtk3 vulnability
Original commitRevision:532023 
04:13 acm search for other commits by this committer
- Add www/drupal8 entry
Original commitRevision:531995 
Friday, 17 Apr 2020
22:29 bofh search for other commits by this committer
sysutils/ansible*: Add multiple Vulnerabilities

- Add vuxml entry for CVE-2020-1737, CVE-2020-1739 and CVE-2020-1740

Security:       CVE-2020-1737
Security:       CVE-2020-1739
Security:       CVE-2020-1740
Original commitRevision:531977 
Thursday, 16 Apr 2020
16:16 rene search for other commits by this committer
Document new vulnerabilities in www/chromium < 81.0.4044.113

Obtained from:	Google Chrome Releases
Original commitRevision:531859 
09:32 mandree search for other commits by this committer
document security/openvpn{,-mbedtls,-devel} illegal client float DoS

URL:		https://community.openvpn.net/openvpn/ticket/1272

Reported by:	Lev Stipakov
Security:	CVE-2020-11810
Security:	8604121c-7fc2-11ea-bcac-7781e90b0c8f
Original commitRevision:531833 
Wednesday, 15 Apr 2020
13:30 tijl search for other commits by this committer
Document Mbed TLS CVE-2020-10932.

Security:	https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security-advisory-2020-04
Original commitRevision:531767 
06:21 mfechner search for other commits by this committer
Document gitlab vulnerabilities.
Original commitRevision:531745 
Tuesday, 14 Apr 2020
20:53 leres search for other commits by this committer
security/vuxml: Mark zeek < 3.0.4 as vulnerable as per:

   
https://github.com/zeek/zeek/blob/e059d4ec2e689b3c8942f4aa08b272f24ed3f612/NEWS

An attacker can crash Zeek remotely via crafted packet sequence via
a stack overflow in POP3 analyzer.
Original commitRevision:531728 
Sunday, 12 Apr 2020
10:06 rene search for other commits by this committer
Document new vulnerabilities in www/chromium < 81.0.4044.92
Original commitRevision:531501 
Thursday, 2 Apr 2020
19:32 rene search for other commits by this committer
Document partial new vulnerabilities in www/chromium < 80.0.3987.162
Original commitRevision:530403 
18:12 flo search for other commits by this committer
Add an entry for the HAproxy vulnerability announced today. The ports have
already been fixed.

PR:		245282
Discussed with:	demon
Original commitRevision:530396 
12:21 sunpoet search for other commits by this committer
Fix rubygem-json entry (40194e1c-6d89-11ea-8082-80ee73419af3)

rubygem-json 2.3.0 was erroneously marked as vulnerable.

% cd /usr/ports/devel/rubygem-json
% make fetch
===>  rubygem-json-2.3.0 has known vulnerabilities:
rubygem-json-2.3.0 is vulnerable:
rubygem-json -- Unsafe Objection Creation Vulnerability in JSON (Additional fix)
CVE: CVE-2020-10663
WWW: https://vuxml.FreeBSD.org/freebsd/40194e1c-6d89-11ea-8082-80ee73419af3.html

1 problem(s) in 1 installed package(s) found.
=> Please update your ports tree and try again.
=> Note: Vulnerable ports are marked as such even if there is no update
available.
=> If you wish to ignore this vulnerability rebuild with 'make
DISABLE_VULNERABILITIES=yes'
*** Error code 1

Stop.
make: stopped in /usr/ports/devel/rubygem-json
Original commitRevision:530364 
07:23 joneum search for other commits by this committer
Add entry for Apache 2.4

Sponsored by:	Netzkommune GmbH
Original commitRevision:530262 
Wednesday, 1 Apr 2020
22:06 woodsb02 search for other commits by this committer
Document multiple vulnerabilities in net-mgmt/cacti < 1.2.10

PR:		245205
Submitted by:	Michael Muenz <m.muenz@gmail.com>
Original commitRevision:530246 
Tuesday, 31 Mar 2020
15:52 tijl search for other commits by this committer
Add entry for GNUTLS-SA-2020-03-31 (flaw in DTLS).

Security:	https://gnutls.org/security-new.html#GNUTLS-SA-2020-03-31
Original commitRevision:529982 
Sunday, 29 Mar 2020
19:50 girgen search for other commits by this committer
Fix validation error
Original commitRevision:529829 
19:46 girgen search for other commits by this committer
Add vuxml entry for CVE-2020-1720
Original commitRevision:529828 
Friday, 27 Mar 2020
13:48 wen search for other commits by this committer
- Document mediawiki's multiple vulnerabilities
Original commitRevision:529248 
Thursday, 26 Mar 2020
20:43 gjb search for other commits by this committer
Fix vuxml build.

Sponsored by:	Rubicon Communications, LLC (netgate.com)
Original commitRevision:529216 
20:27 mfechner search for other commits by this committer
Document gitlab vulnerabilities.
Original commitRevision:529214 
04:40 meta search for other commits by this committer
security/vuxml: Document CVE-2020-10663 (devel/rubygem-json)

PR:		245023
Original commitRevision:529161 
Wednesday, 25 Mar 2020
18:25 lwhsu search for other commits by this committer
Document Jenkins Security Advisory 2020-03-25

Sponsored by:	The FreeBSD Foundation
Original commitRevision:529115 

Number of commits found: 6273 (showing only 100 on this page)

[First Page]  «  1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11  »  [Last Page]