FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The VUXML data was last processed by FreshPorts on 2025-06-26 16:42:54 UTC

List all Vulnerabilities, by package

List all Vulnerabilities, by date

k68

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
c6f4177c-8e29-11ef-98e7-84a93843eb75OpenSSL -- OOB memory access vulnerability

The OpenSSL project reports:

Low-level invalid GF(2^m) parameters lead to OOB memory access (CVE-2024-9143) (Low)

Use of the low-level GF(2^m) elliptic curve APIs with untrusted explicit values for the field polynomial can lead to out-of-bounds memory reads or writes.


Discovery 2024-10-16
Entry 2024-10-19
openssl
< 3.0.15_1,1

openssl31
< 3.1.7_1

openssl32
< 3.2.3_1

openssl33
< 3.3.2_1

openssl-quictls
< 3.0.15_1,1

openssl31-quictls
< 3.1.7_1

CVE-2024-9143
https://openssl-library.org/news/secadv/20241016.txt
a64761a1-e895-11ef-873e-8447094a420fOpenSSL -- Man-in-the-Middle vulnerability

The OpenSSL project reports:

RFC7250 handshakes with unauthenticated servers don't abort as expected (High). Clients using RFC7250 Raw Public Keys (RPKs) to authenticate a server may fail to notice that the server was not authenticated, because handshakes don't abort as expected when the SSL_VERIFY_PEER verification mode is set.


Discovery 2025-02-11
Entry 2025-02-11
openssl32
< 3.2.4

openssl33
< 3.3.2

openssl34
< 3.4.1

CVE-2024-12797
https://openssl-library.org/news/secadv/20250211.txt