notbugAs an Amazon Associate I earn from qualifying purchases.
Want a good read? Try FreeBSD Mastery: Jails (IT Mastery Book 15)
Want a good monitor light? See my photosAll times are UTC
Ukraine
This referral link gives you 10% off a Fastmail.com account and gives me a discount on my Fastmail account.

Get notified when packages are built

A new feature has been added. FreshPorts already tracks package built by the FreeBSD project. This information is displayed on each port page. You can now get an email when FreshPorts notices a new package is available for something on one of your watch lists. However, you must opt into that. Click on Report Subscriptions on the right, and New Package Notification box, and click on Update.

Finally, under Watch Lists, click on ABI Package Subscriptions to select your ABI (e.g. FreeBSD:14:amd64) & package set (latest/quarterly) combination for a given watch list. This is what FreshPorts will look for.

non port: security/vuxml/vuln.xml

Number of commits found: 6271 (showing only 100 on this page)

[First Page]  «  1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11  »  [Last Page]

Thursday, 19 Mar 2020
18:00 gordon search for other commits by this committer
Add details for today's SAs.

Approved by:	so
Original commitRevision:528737 
Wednesday, 18 Mar 2020
07:23 koobs search for other commits by this committer
security/vuxml: Add www/py-bleach entry
Original commitRevision:528629 
Sunday, 15 Mar 2020
22:31 leres search for other commits by this committer
security/vuxml: Mark zeek < 3.0.3 as vulnerable as per:

   
https://raw.githubusercontent.com/zeek/zeek/9dda3602a760f00d9532c6314ea79108106033fa/NEWS

There are a number of potential denial of service issues due to
memory leaks, buffer overflows, and a null pointer dereference.

Approved by:	matthew (mentor, implicit)
Original commitRevision:528507 
Friday, 13 Mar 2020
05:48 tcberner search for other commits by this committer
scurity/vuxml: fix range
Original commitRevision:528332 
05:39 tcberner search for other commits by this committer
Document security issue in graphics/okular

https://kde.org/info/security/advisory-20200312-1.txt:

Overview
========
Okular can be tricked into executing local binaries via specially crafted
PDF files.

This binary execution can require almost no user interaction.

No parameters can be passed to those local binaries.

We have not been able to identify any binary that will cause actual damage,
be it in the hardware or software level, when run without parameters.

We remain relatively confident that for this issue to do any actual damage,
it has to run a binary specially crafted. That binary must have been deployed
to the user system via another method, be it the user downloading it directly
as an email attachment, webpage download, etc. or by the system being already
compromised.

Solution
========
- Update to Okular >= 1.10.0
- or apply the following patch:
https://invent.kde.org/kde/okular/-/commit/6a93a033b4f9248b3cd4d04689b8391df754e244

Workaround
==========
There's no real workaround other than not opening PDF files from untrusted
sources.

Credits
=======
Thanks to Mickael Karatekin from Sysdream Labs for the discovery and to
Albert Astals Cid for the fix.
Original commitRevision:528330 
Thursday, 12 Mar 2020
10:05 mfechner search for other commits by this committer
Document gitlab-ce vulnerability.
Original commitRevision:528282 
01:31 wen search for other commits by this committer
- Document django's potential SQL injection vulnerability
Original commitRevision:528265 
Wednesday, 11 Mar 2020
10:58 decke search for other commits by this committer
Document py-matrix-synapse vulnerabilities

PR:		244279
Submitted by:	Sascha Biberhofer <ports@skyforge.at>
Original commitRevision:528227 
Monday, 9 Mar 2020
21:54 bhughes search for other commits by this committer
security/vuxml: document recent Node.js vulnerabilities

https://nodejs.org/en/blog/vulnerability/february-2020-security-releases/

While here, fix errors from `make validate` for the preceeding gitea
vulnerabilities.

Sponsored by:	Miles AS
Original commitRevision:528135 
Saturday, 7 Mar 2020
20:25 adamw search for other commits by this committer
Fix closing tag

Reported by:	joneum
Original commitRevision:527976 
18:31 adamw search for other commits by this committer
Add entry for www/gitea

PR:		244025
Submitted by:	maintainer
Original commitRevision:527959 
00:41 woodsb02 search for other commits by this committer
Document vulnerability in sysutils/py-salt

PR:		243908
Reported by:	Christer Edwards <christer.edwards@gmail.com>
Security:	CVE-2019-17361
Original commitRevision:527909 
Friday, 6 Mar 2020
07:25 mfechner search for other commits by this committer
Documment gitlab vulnerabilities.
Original commitRevision:527861 
Wednesday, 4 Mar 2020
15:23 cy search for other commits by this committer
Document the latest nwtime.org ntp security advisory found at:
http://support.ntp.org/bin/view/Main/SecurityNotice#\
March_2020_ntp_4_2_8p14_NTP_Rele

No CVEs have been documented yet.

Security:	http://support.ntp.org/bin/view/Main/NtpBug3610
		http://support.ntp.org/bin/view/Main/NtpBug3596
		http://support.ntp.org/bin/view/Main/NtpBug3592
Original commitRevision:527761 
Monday, 2 Mar 2020
18:32 kwm search for other commits by this committer
Document librsvg2 vulnabilities.

Security:	CVE-2019-20446
Original commitRevision:527647 
08:56 0mp search for other commits by this committer
Document some audio/timidity++* vulnerabilities

PR:		244429
Reported by:	pi
Security:	CVE-2017-11546
Security:	CVE-2017-11547
Security:	CVE-2017-11549
Original commitRevision:527617 
Saturday, 29 Feb 2020
09:59 mfechner search for other commits by this committer
Document apache-solr vulnerabilities.
Original commitRevision:527403 
Thursday, 27 Feb 2020
10:23 fluffy search for other commits by this committer
security/vuxml: fix vuxml entries for OpenSMTPd, remove duplicates with wrong
version and missed description

Approved by:	ports-secteam (miwi)
Original commitRevision:527243 
Tuesday, 25 Feb 2020
03:07 fluffy search for other commits by this committer
Document OpenSMTPd vulnerability

LPE and RCE in OpenSMTPD's default install

Security:	CVE-2020-8793, CVE-2020-8794
Original commitRevision:527060 
Monday, 24 Feb 2020
21:15 cs search for other commits by this committer
CVE-2020-8794

Security:	CVE-2020-8794
Original commitRevision:527050 
21:11 cs search for other commits by this committer
CVE-2020-8793

Security:	CVE-2020-8793
Original commitRevision:527049 
17:21 tijl search for other commits by this committer
Document Mbed TLS vulnerabilities 2019-12 and 2020-02.

Security:	https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security-advisory-2019-12
Security:	https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security-advisory-2020-02
Original commitRevision:527003 
Sunday, 23 Feb 2020
08:58 tcberner search for other commits by this committer
vuxml: correct range for avidemux2

- avidemux2 version 2.6.12 switched to ffmpeg 2.7.6
Original commitRevision:526906 
05:02 cy search for other commits by this committer
Post 93v ksh is only affected by the code injection vulnerability.
Original commitRevision:526875 
Friday, 21 Feb 2020
18:46 brnrd search for other commits by this committer
security/vuxml: Document latest WeeChat vulns
Original commitRevision:526641 
Wednesday, 19 Feb 2020
18:06 kwm search for other commits by this committer
Document webkit2-gtk3 vulnabilities
Original commitRevision:526521 
Friday, 14 Feb 2020
01:16 philip search for other commits by this committer
security/vuxml: Add January FreeBSD SAs

SA-20:01.libfetch
SA-20:02.ipsec
SA-20:03.thrmisc

PR:		243702
Submitted by:	Miroslav Lachman <000.fbsd@quip.cz>
Original commitRevision:526079 
Thursday, 13 Feb 2020
21:41 mfechner search for other commits by this committer
Document gitlab vulnerability.
Original commitRevision:526066 
00:18 ler search for other commits by this committer
security/vuxml: dovecot vulnerabilities
Original commitRevision:525986 
Wednesday, 12 Feb 2020
16:18 cem search for other commits by this committer
security/vuxml: Document sysutils/grub2-bhyve escalations

Mitigated in r525916.

admbugs:	948
Reported by:	Reno Robert <renorobert AT gmail.com>
Approved by:	bapt
MFH:		2020Q1 (bapt)
Original commitRevision:525917 
00:19 dbaio search for other commits by this committer
security/vuxml: Document graphics/libexif issue

PR:		244060
Reported by:	tj@mrsk.me (email)
Security:	CVE-2019-9278
Original commitRevision:525894 
Tuesday, 11 Feb 2020
15:13 jkim search for other commits by this committer
Document the latest Flash Player vulnerability.

https://helpx.adobe.com/security/products/flash-player/apsb20-06.html
Original commitRevision:525831 
08:53 joneum search for other commits by this committer
Fix entry for NGINX

Sponsored by:	Netzkommune GmbH
Original commitRevision:525797 
Monday, 10 Feb 2020
17:42 joneum search for other commits by this committer
Fix NGINX entry

Sponsored by:	Netzkommune GmbH
Original commitRevision:525726 
Sunday, 9 Feb 2020
11:10 joneum search for other commits by this committer
Add entry for nginx

PR:		243952
Sponsored by:	Netzkommune GmbH
Original commitRevision:525646 
Friday, 7 Feb 2020
19:38 cy search for other commits by this committer
Document ksh93 CVE-2019-14868: certain environment variables interpreted
as arithmetic expressions on startup, leading to code injection.

Reported by:   Siteshwar Vashisht <svashisht@redhat.com>
MFH:		2020Q1
Security:	CVE-2019-14868
		https://bugzilla.redhat.com/show_bug.cgi?id=1757324
		https://access.redhat.com/security/cve/CVE-2019-14868
Original commitRevision:525501 
Thursday, 6 Feb 2020
21:02 pi search for other commits by this committer
security/vuxml: Document Denial-of-Service vulnerability in ClamAV

- CVE-2020-3123

PR:		243913
Submitted by:	Yasuhiro KIMURA <yasu@utahime.org>
Original commitRevision:525451 
Tuesday, 4 Feb 2020
18:17 sunpoet search for other commits by this committer
Document Django vulnerability
Original commitRevision:525230 
Sunday, 2 Feb 2020
20:14 brnrd search for other commits by this committer
security/vuxml: Properly document MariaDB vuln

PR:		243660
Reported by:	<ari ish com au>
Original commitRevision:525001 
07:20 woodsb02 search for other commits by this committer
Fix typo in SpamAssassin vuxml entry from 2020-01-31
Original commitRevision:524815 
07:15 woodsb02 search for other commits by this committer
vuxml: Add entry for libssh CVE-2019-14889

Security:	CVE-2019-14889
Original commitRevision:524814 
Friday, 31 Jan 2020
20:22 cy search for other commits by this committer
Remove my older entry for CVE-2020-1931. The subequent entry by
zeising@ is better.

Whitespace adjustment.
Original commitRevision:524742 
16:02 zeising search for other commits by this committer
vuxml: Add entries for spamassasin vulnerabilities.
Original commitRevision:524719 
14:00 cy search for other commits by this committer
Document sudo CVE-2019-18634:

Buffer overflow when pwfeedback is set in sudoers.

Security:	CVE-2019-18634
Original commitRevision:524708 
10:09 mfechner search for other commits by this committer
Document gitlab vulnerabilities.
Original commitRevision:524689 
Thursday, 30 Jan 2020
13:51 cy search for other commits by this committer
Document:

[CVE-2020-1931] Apache SpamAssassin Nefarious rule configuration
(.cf) files can be configured to run system commands with warnings

Security:	CVE-2020-1931
Security:	https://svn.apache.org/repos/asf/spamassassin/branches/3.4/\
			build/announcements/3.4.4.txt
Security:	https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-1931
Original commitRevision:524641 
06:25 fluffy search for other commits by this committer
Document mail/opensmtpd LPE and RCE vulnerabilities

PR:		243686
Security:	CVE-2020-7247
Original commitRevision:524633 
Wednesday, 29 Jan 2020
15:29 lwhsu search for other commits by this committer
Document Jenkins Security Advisory 2020-01-29

Sponsored by:	The FreeBSD Foundation
Original commitRevision:524553 
13:23 bapt search for other commits by this committer
Document libfetch vulnerability which affects pkg.
Original commitRevision:524546 
Monday, 27 Jan 2020
01:38 timur search for other commits by this committer
Add an entry about CVE-2019-14902, CVE-2019-14907, CVE-2019-19344
vulnerabilities in the Samba 4.1[01] versions.

Security:	CVE-2019-14902
		CVE-2019-14907
		CVE-2019-19344
Original commitRevision:524234 
Sunday, 26 Jan 2020
17:51 kwm search for other commits by this committer
Document webkit-gtk3 vulnabilities.
Original commitRevision:524225 
Friday, 24 Jan 2020
22:20 kai search for other commits by this committer
security/vuxml: Document graphics/py-pillow issues

PR:		243336
Security:	CVE-2019-19911
		CVE-2020-5310
		CVE-2020-5311
		CVE-2020-5312
		CVE-2020-5313
Original commitRevision:523993 
Monday, 20 Jan 2020
11:07 joneum search for other commits by this committer
Add entry for www/gitea

PR:		243437
Reported by:	stb@lassitu.de
Sponsored by:	Netzkommune GmbH
Original commitRevision:523613 
Wednesday, 15 Jan 2020
20:23 brnrd search for other commits by this committer
security/vuxml: Document 2020Q1 Oracle MySQL Vulns
Original commitRevision:523158 
13:54 zeising search for other commits by this committer
vuxml: Document recent intel GPU vulnerability
Original commitRevision:523111 
Tuesday, 14 Jan 2020
13:57 adamw search for other commits by this committer
VuXML: Add entry for p5-Template-Toolkit directory traversal bug
Original commitRevision:523015 
07:28 mfechner search for other commits by this committer
Document gitlab vulnerability.
Original commitRevision:522991 
Saturday, 11 Jan 2020
18:32 mandree search for other commits by this committer
mark e2fsprogs vulnerable, CVE-2019-5188

Security:	8b61308b-322a-11ea-b34b-1de6fb24355d
Security:	CVE-2019-5188
Original commitRevision:522701 
08:19 mfechner search for other commits by this committer
Document phpMyAdmin vulnerability.
Original commitRevision:522636 
Monday, 6 Jan 2020
17:27 kai search for other commits by this committer
security/vuxml: Document net-mgmt/cacti issues

PR:		242834
Submitted by:	Michael Muenz <m.muenz@gmail.com> (based on)
Security:	CVE-2019-17357
                CVE-2019-17358
Original commitRevision:522265 
Friday, 3 Jan 2020
09:18 mfechner search for other commits by this committer
Document gitlab vulnerabilities.
Original commitRevision:521915 
Sunday, 29 Dec 2019
12:58 sunpoet search for other commits by this committer
Document rubygem-rack vulnerability
Original commitRevision:521360 
12:11 mandree search for other commits by this committer
Document graphics/ilmbase graphics/openexr vulnerabilities.

Security:	e4d9dffb-2a32-11ea-9693-e1b3f6feec79
Security:	CVE-2018-18443
Security:	CVE-2018-18444
Original commitRevision:521274 
Thursday, 26 Dec 2019
10:03 joneum search for other commits by this committer
Add entry for wordpress

Sponsored by:	Netzkommune GmbH
Original commitRevision:520901 
Wednesday, 25 Dec 2019
12:25 joneum search for other commits by this committer
Add entry for typo3

PR:		242707 242708
Sponsored by:	Netzkommune GmbH
Original commitRevision:520853 
Saturday, 21 Dec 2019
11:04 mandree search for other commits by this committer
Add vulnerability of e2fsprogs quota code < 1.45.4

Security:	ad3451b9-23e0-11ea-8b36-f1925a339a82
Security:	CVE-2019-5094
Original commitRevision:520554 
02:36 acm search for other commits by this committer
- Re-add py-matrix-synapse entry
Original commitRevision:520542 
02:28 acm search for other commits by this committer
- Add drupal[78] entry
Original commitRevision:520540 
Friday, 20 Dec 2019
21:05 decke search for other commits by this committer
Document py-matrix-synapse vulnerabilities

PR:		242702
Submitted by:	Sascha Biberhofer <ports@skyforge.at>
Original commitRevision:520526 
15:04 brnrd search for other commits by this committer
security/vuxml: Document OpenSSL 1.0.2 vuln
Original commitRevision:520513 
Friday, 13 Dec 2019
20:34 swills search for other commits by this committer
Fix typo

PR:		242627
Submitted by:	lightside <lightside@gmx.com>
Original commitRevision:520069 
20:03 cy search for other commits by this committer
Document two new spamassassin 3.4.2 vulnerabilities.

    CVE-2019-12420 for Multipart Denial of Service Vulnerability
    CVE-2018-11805 for nefarious CF files can be configured to run system
                   commands without any output or errors.
Original commitRevision:520066 
16:11 timur search for other commits by this committer
Add entry for Samba4 CVE-2019-14861 and CVE-2019-14870

Security:	CVE-2019-14861
		CVE-2019-14870
Original commitRevision:520049 
14:40 ler search for other commits by this committer
security/vuxml: dovecot vulnerability
Original commitRevision:520039 
Tuesday, 10 Dec 2019
21:06 mfechner search for other commits by this committer
Document gitlab vulnerabilities.
Original commitRevision:519779 
17:16 sunpoet search for other commits by this committer
Update libidn2 vulnerability

Reported by:	Stephen Wall <stephen.wall@redcom.com>, jkim
Original commitRevision:519761 
Monday, 9 Dec 2019
20:54 tijl search for other commits by this committer
Document Ghostscript vulnerabilities.

Security:	CVE-2019-14811, CVE-2019-14812, CVE-2019-14813, CVE-2019-14817
Original commitRevision:519632 
Friday, 6 Dec 2019
20:22 joneum search for other commits by this committer
Add entry for phpmyadmin

Sponsored by:	Netzkommune GmbH
Original commitRevision:519163 
Wednesday, 4 Dec 2019
20:32 zeising search for other commits by this committer
vuxml: Add drm-fbsd11.2-kmod to drm vulnerability

Add drm-fbsd11.2-kmod to the list of packages vulnerable to the
drm graphics drivers -- Local privilege escalation and denial of serivce
entry.
Original commitRevision:519048 
Tuesday, 3 Dec 2019
03:04 wen search for other commits by this committer
- Document Django multiple vulnerabilities
Original commitRevision:518903 
Thursday, 28 Nov 2019
15:44 decke search for other commits by this committer
Document net-im/py-matrix-synapse vulnerabilities

PR:		241574
Submitted by:	Sascha Biberhofer <ports@skyforge.at>
Original commitRevision:518587 
07:02 mfechner search for other commits by this committer
Document gitlab-ce vulnerability.
Original commitRevision:518563 
Wednesday, 27 Nov 2019
19:04 mfechner search for other commits by this committer
Document www/gitlab-ce vulnerabilities.
Original commitRevision:518519 
16:32 kwm search for other commits by this committer
Document webkit2-gtk3 vulnabilities
Original commitRevision:518507 
Tuesday, 26 Nov 2019
11:51 kai search for other commits by this committer
security/vuxml: Document net/py-urllib3 issues

PR:		229322
Security:	CVE-2018-20060
		CVE-2019-11236
		CVE-2019-11324
Original commitRevision:518463 
Monday, 25 Nov 2019
21:45 dch search for other commits by this committer
security/vuxml: add FreeBSD kernel entries for recent Intel CVEs

PR:		241931
Submitted by:	Miroslav Lachman <000.fbsd@quip.cz>
Reviewed by:	dch
Approved by:	joneum (ports-secteam)
Security:	CVE-2019-11135
Security:	CVE-2019-11139
Security:	CVE-2018-12126
Security:	CVE-2018-12127
Security:	CVE-2018-12130
Security:	CVE-2018-11091
Security:	CVE-2017-5715
Security:	CVE-2018-12207
Sponsored by:	SkunkWerks, GmbH
Original commitRevision:518430 
09:18 joneum search for other commits by this committer
Add entry for security/clamav

PR:		242118
Sponsored by:	Netzkommune GmbH
Original commitRevision:518386 
Saturday, 23 Nov 2019
12:50 joneum search for other commits by this committer
Add entry for dns/unbound

PR:		242075
Sponsored by:	Netzkommune GmbH
Original commitRevision:518226 
Friday, 22 Nov 2019
11:15 kai search for other commits by this committer
security/vuxml: Document www/gitea issues

PR:		241981
Submitted by:	Nils Johannsen <nilsjohannsen@gmx.de> (based on)
Approved by:	stb@lassitu.de (maintainer)
Original commitRevision:518141 
09:03 madpilot search for other commits by this committer
Document asterisk vulnerabilities.
Original commitRevision:518130 
09:01 madpilot search for other commits by this committer
Remove extra whitespace.
Original commitRevision:518129 
Wednesday, 20 Nov 2019
10:57 zeising search for other commits by this committer
Document intel drm driver vulnerabilities

Document intel drm driver vulnerabilities related to Intel 2019.2 IPU [1].

[1]
https://blogs.intel.com/technology/2019/11/ipas-november-2019-intel-platform-update-ipu
Original commitRevision:518000 
Tuesday, 19 Nov 2019
08:25 joneum search for other commits by this committer
Add entry for www/squid

PR:		241976
Sponsored by:	Netzkommune GmbH
Original commitRevision:517944 
Monday, 18 Nov 2019
18:13 sunpoet search for other commits by this committer
Document libidn2 vulnerability
Original commitRevision:517921 
Friday, 15 Nov 2019
22:46 naddy search for other commits by this committer
Document vulnerabilities in GNU cpio < 2.13.
Original commitRevision:517704 
Wednesday, 13 Nov 2019
23:45 sunpoet search for other commits by this committer
Document libmad vulnerability
Original commitRevision:517534 
Tuesday, 12 Nov 2019
21:38 gjb search for other commits by this committer
Fix build.

Sponsored by:	Rubicon Communications, LLC (netgate.com)
Original commitRevision:517352 
21:01 rene search for other commits by this committer
Document new vulnerability in www/chromium < 78.0.3904.97
Original commitRevision:517348 
08:16 joneum search for other commits by this committer
fix typo

Sponsored by:	Netzkommune GmbH
Original commitRevision:517316 
07:42 joneum search for other commits by this committer
Add entry for wordpress

Sponsored by:	Netzkommune GmbH
Original commitRevision:517309 

Number of commits found: 6271 (showing only 100 on this page)

[First Page]  «  1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11  »  [Last Page]