non port: security/vuxml/vuln.xml |
SVNWeb
|
Number of commits found XX: 6166 (showing only 100 on this page) 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 » [Last Page] |
Sun, 28 Mar 2021
|
[ 21:37 mandree ] 
569416 security/vuxml/vuln.xml
security/linux-c7-nettle: mark vulnerable, too
See https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=254355#c14
PR: 254355
Reported by: Graham Perrin <grahamperrin@gmail.com>
|
[ 03:20 timur ] 
569371 security/vuxml/vuln.xml
Add entry about recent Samba4* vulnerabilities:
CVE-2020-27840: An anonymous attacker can crash the Samba AD DC LDAP server by
sending easily crafted DNs as part of a bind request. More serious heap
corruption is likely also possible.
CVE-2021-20277: User-controlled LDAP filter strings against the AD DC LDAP
server may crash the LDAP server.
Security: CVE-2020-27840
CVE-2021-20277
|
Sat, 27 Mar 2021
|
[ 11:12 mandree ] 
569321 security/vuxml/vuln.xml
vuln.xml: mention nettle < 3.7.2 ECDSA verify bugs
Security: 80f9dbd3-8eec-11eb-b9e8-3525f51429a0
|
Fri, 26 Mar 2021
|
[ 08:09 brnrd ] 
569246 security/vuxml/vuln.xml
security/vuxml: Document High OpenSSL vulnerabilities
* While here, fix incorrect year in ec04f3d0-8cd9-11eb-bb9f-206a8a720317
|
Wed, 24 Mar 2021
|
[ 20:02 cy ] 
569157 security/vuxml/vuln.xml
security/vuxml: Document spamassassin CVE-2020-1946
PR: 254526
Security: https://s.apache.org/ng9u9
https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-1946
|
[ 03:15 adamw ] 
569083 security/vuxml/vuln.xml
security/vuxml: Add entry for gitea < 1.13.6
PR: 254515
Submitted by: maintainer
|
Sun, 21 Mar 2021
|
[ 18:30 adamw ] 
568929 security/vuxml/vuln.xml
security/vuxml: Add entry for gitea < 1.13.5
PR: 254468
Submitted by: maintainer
|
Thu, 18 Mar 2021
|
[ 20:52 bdrewery ] 
568762 security/vuxml/vuln.xml
OpenSSH CVE-2021-28041 fixed in 8.4.p1_4,1.
Also add flavored package names.
|
[ 19:30 bdrewery ] 
568757 security/vuxml/vuln.xml
Document OpenSSH CVE-2021-28041
PR: 254258
Submitted by: Yasuhiro Kimura
|
[ 14:05 mfechner ] 
568741 security/vuxml/vuln.xml
Document gitlab vulnerability.
|
[ 00:27 mandree ] 
568705 security/vuxml/vuln.xml
fixup PORTEPOCH for dnsmasq-devel
which used to be at 3 already earlier. Adjust vuxml entry accordingly.
Security: CVE-2021-3448
Security: 5b72b1ff-877c-11eb-bd4f-2f1d57dafe46
|
[ 00:23 mandree ] 
568704 security/vuxml/vuln.xml
fixup version range for dnsmasq[-devel] to 2.85.r1,1 not 2.85r1,1
Security: 5b72b1ff-877c-11eb-bd4f-2f1d57dafe46
Security: CVE-2021-3448
|
[ 00:09 mandree ] 
568701 security/vuxml/vuln.xml
vuxml: Add dnsmasq < 2.85 cache poisoning vulnerability.
This affects only certain dnsmasq configurations,
and use of dnsmasq with NetworkManager.
Security: CVE-2021-3448
|
Wed, 17 Mar 2021
|
[ 13:04 swills ] 
568653 security/vuxml/vuln.xml
Document minio issue
|
Tue, 16 Mar 2021
|
[ 15:42 brnrd ] 
568571 security/vuxml/vuln.xml
security/vuxml: Document LibreSSL potential use-after-free
|
[ 08:50 rene ] 
568546 security/vuxml/vuln.xml
Document new vulnerabilities in www/chromium < 89.0.4389.90
Obtained
from: https://chromereleases.googleblog.com/2021/03/stable-channel-update-for-desktop_12.html
|
Mon, 15 Mar 2021
|
[ 20:16 crees ] 
568503 security/vuxml/vuln.xml
Document CVE-2015-4645 in sysutils/squashfs-tools
Security: CVE-2015-4645
|
Thu, 11 Mar 2021
|
[ 14:01 fernape ] 
568095 security/vuxml/vuln.xml
security/vuxml: Fix www/gitea entry.
s/1.13.24/1.13.4
PR: 254130
Reported by: clubok@gmx.net
|
Wed, 10 Mar 2021
|
[ 23:37 dmgk ] 
568051 security/vuxml/vuln.xml
security/vuxml: Document lang/go vulnerabilities
|
[ 18:45 nc ] 
568030 security/vuxml/vuln.xml
Document vulnerabilities in www/gitea < 1.13.4
PR: 254130
Submitted by: stb AT lassitu DOT de (maintainer)
|
[ 14:03 lwhsu ] 
568002 security/vuxml/vuln.xml
Document vulnerabilities in databases/mantis <2.24.4
PR: 252612
Submitted by: Zoltan ALEXANDERSON BESSE <zab@zltech.eu>
|
Tue, 9 Mar 2021
|
[ 06:26 bhughes ] 
567892 security/vuxml/vuln.xml
security/vuxml: document Node.js February 2021 Security Releases
https://nodejs.org/en/blog/vulnerability/february-2021-security-releases/
Sponsored by: Miles AS
|
Fri, 5 Mar 2021
|
[ 21:18 mfechner ] 
567419 security/vuxml/vuln.xml
Document gitlab vulnerabilities.
|
Thu, 4 Mar 2021
|
[ 19:48 madpilot ] 
567337 security/vuxml/vuln.xml
Report new asterisk vulnerability.
|
[ 09:51 rene ] 
567296 security/vuxml/vuln.xml
Document new vulnerabilities in www/chromium < 89.0.4389.72
Obtained
from: https://chromereleases.googleblog.com/2021/03/stable-channel-update-for-desktop.html
|
Wed, 3 Mar 2021
|
[ 18:18 sunpoet ] 
567244 security/vuxml/vuln.xml
Document jasper vulnerability
|
[ 06:41 ohauer ] 
567027 security/vuxml/vuln.xml
- add CVE entries for saltstack
|
Tue, 2 Mar 2021
|
[ 15:17 osa ] 
566966 security/vuxml/vuln.xml
Fix the redis5 affected versions.
|
Sat, 27 Feb 2021
|
[ 01:49 swills ] 
566651 security/vuxml/vuln.xml
Document vault issue
|
Thu, 25 Feb 2021
|
[ 02:33 philip ] 
566520 security/vuxml/vuln.xml
security/vuxml: add FreeBSD SA-21:04.jail_remove
|
[ 02:33 philip ] 
566519 security/vuxml/vuln.xml
security/vuxml: add FreeBSD SA-21:06.xen
|
[ 02:33 philip ] 
566518 security/vuxml/vuln.xml
security/vuxml: add FreeBSD SA-21:05.jail_chdir
|
[ 02:33 philip ] 
566517 security/vuxml/vuln.xml
security/vuxml: add FreeBSD SA-21:03.pam_login_access
|
Tue, 23 Feb 2021
|
[ 13:57 osa ] 
566398 security/vuxml/vuln.xml
Document integer overflow on 32-bit systems (CVE-2021-21309):
o) databases/redis5
o) databases/redis
o) databases/redis-devel
|
[ 01:04 leres ] 
566361 security/vuxml/vuln.xml
security/vuxml: Mark zeek < 3.0.13 as vulnerable as per:
https://github.com/zeek/zeek/releases/tag/v3.0.13
Fix ASCII Input reader's treatment of input files containing
null-bytes. An input file containing null-bytes could lead to a
buffer-over-read, crash Zeek, and be exploited to cause Denial of
Service.
|
Sat, 20 Feb 2021
|
[ 16:38 adridg ] 
566165 security/vuxml/vuln.xml
Add vuxml entry for textproc/raptor2 CVE
PR: 251102
|
[ 02:36 lwhsu ] 
566136 security/vuxml/vuln.xml
Connect vuln-2020.xml (2/2)
|
[ 02:20 lwhsu ] 
566132 security/vuxml/vuln.xml
Document Jenkins Security Advisory 2021-02-19
Sponsored by: The FreeBSD Foundation
|
Thu, 18 Feb 2021
|
[ 20:41 madpilot ] 
565978 security/vuxml/vuln.xml
Report new asterisk vulnerabilities.
|
[ 18:18 brnrd ] 
565962 security/vuxml/vuln.xml
security/openssl-devel: Mark vulnerable CVE-2021-23841
MFH: 2021Q1
Security: 96a21236-707b-11eb-96d8-d4c9ef517024
|
Wed, 17 Feb 2021
|
[ 18:30 sunpoet ] 
565782 security/vuxml/vuln.xml
Document rails vulnerability
|
[ 12:47 rene ] 
565499 security/vuxml/vuln.xml
Document new vulnerabilities in www/chromium < 88.0.4324.182
Obtained
from: https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop_16.html
|
Tue, 16 Feb 2021
|
[ 17:35 brnrd ] 
565421 security/vuxml/vuln.xml
security/vuxml: Document OpenSSL 1.1.1i vulnerabilities
|
Fri, 12 Feb 2021
|
[ 20:44 mandree ] 
565063 security/vuxml/vuln.xml
openexr/ilmbase < v2.5.5 security vulnerabilities
https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v2.5.5
Security: 98044aba-6d72-11eb-aed7-1b1b8a70cc8b
|
[ 13:28 mfechner ] 
565016 security/vuxml/vuln.xml
Document gitlab vulnerabilities.
|
[ 04:47 nc ] 
564994 security/vuxml/vuln.xml
Add security/vuxml entry for CVE-2021-21291 affecting www/oauth2-proxy < 7.0.0.
While I'm here, fix formatting for mod_dav_svn CVE-2020-17525 vuxml entry,
MFH: 2021Q1
|
Wed, 10 Feb 2021
|
[ 17:45 gjb ] 
564888 security/vuxml/vuln.xml
Fix build.
Sponsored by: Rubicon Communications, LLC ("Netgate")
|
[ 17:09 lev ] 
564881 security/vuxml/vuln.xml
Document https://subversion.apache.org/security/CVE-2020-17525-advisory.txt.
|
Sun, 7 Feb 2021
|
[ 02:54 adamw ] 
564589 security/vuxml/vuln.xml
security/vuxml: Add entry for gitea < 1.13.2
PR: 253295
Submitted by: maintainer
|
Sat, 6 Feb 2021
|
[ 00:05 rene ] 
564167 security/vuxml/vuln.xml
Document new vulnerability in www/chromium < 88.0.4324.150
Obtained
from: https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop_4.html
|
Wed, 3 Feb 2021
|
[ 20:06 rene ] 
563959 security/vuxml/vuln.xml
Document new vulnerabilities in www/chromium < 88.0.4324.146
Obtained
from: https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop.html
|
Tue, 2 Feb 2021
|
[ 07:50 mfechner ] 
563788 security/vuxml/vuln.xml
Document gitlab-ce vulnerabilities.
|
Sun, 31 Jan 2021
|
[ 21:55 swills ] 
563534 security/vuxml/vuln.xml
Document minio issue
|
Fri, 29 Jan 2021
|
[ 06:47 philip ] 
563173 security/vuxml/vuln.xml
security/vuxml: add FreeBSD SA-21:02.xenoom
|
[ 06:47 philip ] 
563172 security/vuxml/vuln.xml
security/vuxml: add FreeBSD SA-21:01.fsdisclosure
|
Thu, 28 Jan 2021
|
[ 12:51 lcook ] 
563133 security/vuxml/vuln.xml
security/vuxml: Document graphics/pngcheck vulnerability
PR: 253019
Approved by: fernape (mentor)
Differential Revision: https://reviews.freebsd.org/D28308
|
Tue, 26 Jan 2021
|
[ 20:28 cy ] 
562998 security/vuxml/vuln.xml
Document sudo CVE-2021-3156.
* When invoked as sudoedit, the same set of command line options
are now accepted as for "sudo -e". The -H and -P options are
now rejected for sudoedit and "sudo -e" which matches the sudo
1.7 behavior. This is part of the fix for CVE-2021-3156.
* Fixed a potential buffer overflow when unescaping backslashes
in the command's arguments. Normally, sudo escapes special
characters when running a command via a shell (sudo -s or sudo
-i). However, it was also possible to run sudoedit with the -s
or -i flags in which case no escaping had actually been done,
making a buffer overflow possible. This fixes CVE-2021-3156.
PR: 253034
Reported by: "Todd C. Miller" <Todd.Miller@sudo.ws> via mailing list
emaste
Obtained from: sudo
|
[ 17:56 sunpoet ] 
562967 security/vuxml/vuln.xml
Document py-pysaml2 vulnerability
|
[ 13:21 lwhsu ] 
562658 security/vuxml/vuln.xml
Document Jenkins Security Advisory 2021-01-26
Sponsored by: The FreeBSD Foundation
|
Mon, 25 Jan 2021
|
[ 17:16 bapt ] 
562586 security/vuxml/vuln.xml
Rework the entity declaration
when expanded they will look better (as when the file was not split)
While here cleanup some indentation
|
Sat, 23 Jan 2021
|
[ 18:19 otis ] 
562408 security/vuxml/vuln.xml
security/vuxml: Document mail/mutt vulnerability
Document mail/mutt vulnerability CVE-2021-3181
PR: 252931
Submitted by: Derek Schrock <dereks@lifeofadishwasher.com>
Reported by: Derek Schrock <dereks@lifeofadishwasher.com>
Reviewed by: osa (mentor)
Approved by: osa (mentor)
Differential Revision: https://reviews.freebsd.org/D28308
|
[ 17:46 gjb ] 
562406 security/vuxml/vuln.xml
Fix build.
Sponsored by: Rubicon Communications, LLC ("Netgate")
|
[ 14:46 brnrd ] 
562396 security/vuxml/vuln.xml
security/vuxml: Add new MySQL vulnerabilities
|
Fri, 22 Jan 2021
|
[ 20:37 rene ] 
562336 security/vuxml/vuln.xml
Document new vulnerabilities in www/chromium < 88.0.4324.96
Obtained
from: https://chromereleases.googleblog.com/2021/01/stable-channel-update-for-desktop_19.html
|
[ 09:33 jhale ] 
562282 security/vuxml/vuln.xml
Document CVE-2020-15983 for games/chocolate-doom and games/crispy-doom
|
[ 00:22 mfechner ] 
562266 security/vuxml/vuln.xml
Made clear how to test now entries against the newly formatted file.
|
[ 00:13 gjb ] 
562265 security/vuxml/vuln.xml
Fix build.
Yes, please do FIXME.
Sponsored by: Rubicon Communications, LLC ("Netgate")
|
[ 00:09 mfechner ] 
562264 security/vuxml/vuln.xml
Added security vulnerability for rubygem-nokogiri.
|
Thu, 21 Jan 2021
|
[ 13:19 bapt ] 
562204 security/vuxml/vuln.xml
Split vuln.xml file [2/2]
The vuln.xml file has grown a lot since 2003. To avoid having to unlock
the svn size limitation, the file is now split into 1 file per year up
to the current year + previous one. The split is made based on the date
when the entry has been added.
In order to achieve the split without breaking any consumer we use a standard
XML mechanism via the definition of entities.
While here add a new target make vuln-flat.xml which will expand the entities
in order to be able to regenerate a one uniq file if needed. This useful to for
example allow to test with pkg audit directly given the XML parser used in pkg
does not support custom entities.
The vuxml web site generator has been modified to ensure the vuln.xml file it
provides is the expanded version, so for consumers it is still only one single
file to download.
|
Wed, 20 Jan 2021
|
[ 19:25 mandree ] 
562156 security/vuxml/vuln.xml
dns/dnsmasq-devel: mark stale name vulnerable, too
dnsmasq-devel isn't currently in ports, but if someone never
switched to dnsmasq, we should also flag the older dnsmasq-devel
vulnerable.
Security: 5b5cf6e5-5b51-11eb-95ac-7f9491278677
|
[ 19:11 mandree ] 
562153 security/vuxml/vuln.xml
dns/dnsmasq < 2.83 vulnerabilities (buffer overflow, DNS cache poisoning)
Security: 5b5cf6e5-5b51-11eb-95ac-7f9491278677
Security: CVE-2020-25684
Security: CVE-2020-25685
Security: CVE-2020-25686
Security: CVE-2020-25681
Security: CVE-2020-25682
Security: CVE-2020-25683
Security: CVE-2020-25687
|
[ 00:25 dmgk ] 
562103 security/vuxml/vuln.xml
security/vuxml: Document lang/go vulnerabilities
|
Tue, 19 Jan 2021
|
[ 21:12 jrm ] 
562089 security/vuxml/vuln.xml
security/vuxml: Fix range of affected cloud-init versions
|
[ 20:47 jrm ] 
562084 security/vuxml/vuln.xml
security/vuxml: Document vulnerability in cloud-init version 20.4
https://bugs.launchpad.net/cloud-init/+bug/1911680
Reported by: Mina Galic <me@igalic.co>
|
Mon, 18 Jan 2021
|
[ 08:21 lwhsu ] 
561901 security/vuxml/vuln.xml
Document CVE-2020-25074 and CVE-2020-15275 for www/moinmoin
|
Sun, 17 Jan 2021
|
[ 22:23 0mp ] 
561880 security/vuxml/vuln.xml
Document ghostscript9-agpl-base vulnerability committed in r544907
PR: 248580
Requested by: joneum (ports-secteam)
Reported by: VVD <vvd@unislabs.com>
MFH: 2021Q1
Security: CVE-2020-15900
|
Thu, 14 Jan 2021
|
[ 20:37 bhughes ] 
561590 security/vuxml/vuln.xml
security/vuxml: document Node.js January 2021 Security Releases
https://nodejs.org/en/blog/vulnerability/january-2021-security-releases/
Sponsored by: Miles AS
|
[ 12:03 mfechner ] 
561551 security/vuxml/vuln.xml
Document gitlab vulnerability.
|
[ 07:30 riggs ] 
561541 security/vuxml/vuln.xml
Document integer overflow in wavpack (CVE-2020-35738).
|
Wed, 13 Jan 2021
|
[ 17:32 lwhsu ] 
561491 security/vuxml/vuln.xml
Document Jenkins Security Advisory 2021-01-13
Sponsored by: The FreeBSD Foundation
|
Tue, 12 Jan 2021
|
[ 21:20 flo ] 
561382 security/vuxml/vuln.xml
Document phpmyfaq vulnerability
|
[ 04:27 cy ] 
561298 security/vuxml/vuln.xml
Document sudo CVE-2021-23239.
|
Sun, 10 Jan 2021
|
[ 08:26 sunpoet ] 
561020 security/vuxml/vuln.xml
Document cairosvg vulnerability
|
Sat, 9 Jan 2021
|
[ 20:06 mfechner ] 
560889 security/vuxml/vuln.xml
Document gitlab vulnerabilities.
|
Thu, 7 Jan 2021
|
[ 15:09 rene ] 
560715 security/vuxml/vuln.xml
Document new vulnerabilities in www/chromium < 87.0.4280.141
Obtained
from: https://chromereleases.googleblog.com/2021/01/stable-channel-update-for-desktop.html
|
Wed, 6 Jan 2021
|
[ 14:11 pi ] 
560521 security/vuxml/vuln.xml
security/vuxml: add dovecot CVE-2020-24386
PR: 252415
Submitted by: Evilham <contact@evilham.com>
Relnotes: https://dovecot.org/pipermail/dovecot-news/2021-January/000448.html
|
Fri, 1 Jan 2021
|
[ 16:05 adamw ] 
559841 security/vuxml/vuln.xml
security/vuxml: Add entry for gitea < 1.13.1
PR: 252310
Submitted by: maintainer
|
[ 04:31 jrm ] 
559800 security/vuxml/vuln.xml
Document inspircd vulnerabilitiy
PR: 252291
Reported by: Sadie Powell <sadie@witchery.services>
|
Mon, 28 Dec 2020
|
[ 13:15 riggs ] 
559468 security/vuxml/vuln.xml
Document CVE-2020-0543 for Intel CPUs.
PR: 247197
Submitted by: spam123@bitbert.com
|
Tue, 22 Dec 2020
|
[ 22:44 madpilot ] 
558949 security/vuxml/vuln.xml
Document new asterisk vulnerabilities.
|
[ 14:16 otis ] 
558911 security/vuxml/vuln.xml
Document vulns for powerdns and postsrsd
Reviewed by: osa (mentor)
Approved by: osa (mentor)
Differential Revision: https://reviews.freebsd.org/D27706
|
Sat, 19 Dec 2020
|
[ 13:16 riggs ] 
558451 security/vuxml/vuln.xml
Correct entries for mantis and libX11 (missing PORTEPOCH in package string).
PR: 251168
Submitted by: zab@zltech.eu
|
Thu, 17 Dec 2020
|
[ 21:09 swills ] 
558329 security/vuxml/vuln.xml
Document vault issue
|
Tue, 15 Dec 2020
|
[ 01:32 philip ] 
558123 security/vuxml/vuln.xml
security/vuxml: Note FreeBSD 11.4 fix for CVE-2020-1971
|
Sun, 13 Dec 2020
|
[ 14:49 sunpoet ] 
557986 security/vuxml/vuln.xml
Document jasper vulnerability
|
[ 00:28 dbaio ] 
557876 security/vuxml/vuln.xml
security/vuxml: Document net-im/py-matrix-synapse issue
PR: 251768
Submitted by: contact@evilham.com
Security: CVE-2020-26257
|
Sat, 12 Dec 2020
|
[ 18:37 brnrd ] 
557848 security/vuxml/vuln.xml
security/vuxml: Document p11-kit vulnerabilities
|
[ 16:23 brnrd ] 
557834 security/vuxml/vuln.xml
security/vuxml: Document Unbound/NSD vuln
|
[ 15:38 brnrd ] 
557831 security/vuxml/vuln.xml
security/vuxml: Update LibreSSL vuln
* for 2020Q4 branch which is on 3.1
|
Fri, 11 Dec 2020
|
[ 10:38 brnrd ] 
557712 security/vuxml/vuln.xml
security/vuxml: Document LibreSSL vulnerability
|
Number of commits found XX: 6166 (showing only 100 on this page) 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 » [Last Page] |