Commit History - (may be incomplete: for full details, see links to repositories near top of page) |
Commit | Credits | Log message |
1.1_6 14 Jul 2025 18:44:35
    |
Bernard Spil (brnrd)  |
security/vuxml: Document liboqs vulnerability |
1.1_6 14 Jul 2025 09:49:43
    |
Tijl Coosemans (tijl)  |
security/vuxml: Document GnuTLS SA 2025-07-08 |
1.1_6 12 Jul 2025 09:40:26
    |
Matthias Andree (mandree)  |
security/vuxml: extend libxml2/libxslt vuln to linux-* ports |
1.1_6 12 Jul 2025 09:13:36
    |
Matthias Andree (mandree)  |
textproc/libxml2, textproc/libxslt: vulnerable
Note that libxslt is vulnerable, unfixed, and without maintainer.
Two of four vulnerabilities have been fixed.
Note that libxml2 in our ports is vulnerable and there is no upstream
release fixing these bugs, they need cherry-picks.
Deprecate textproc/xmlto and textproc/minixmlto,
which both depend on the unmaintained and vulnerable libxslt.
I have filed https://pagure.io/xmlto/issue/15 to ask the xmlto
upstream to switch to different XML/XSLT libraries.
Two issues are undisclosed and do not seem to have a CVE assigned yet.
(Only the first 15 lines of the commit message are shown above ) |
1.1_6 11 Jul 2025 21:35:16
    |
Bernard Spil (brnrd)  |
security/vuxml: Document mod_http2 vulnerabilities |
1.1_6 11 Jul 2025 21:15:09
    |
Bernard Spil (brnrd)  |
security/vuxml: Document Apache httpd vulnerabilities |
1.1_6 10 Jul 2025 21:24:29
    |
Sergey A. Osokin (osa)  |
security/vuxml: document tomcat vulnerabilities |
1.1_6 10 Jul 2025 04:28:58
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulnerabilities |
1.1_6 08 Jul 2025 17:19:09
    |
Renato Botelho (garga)  |
security/vuxml: Add multiple git vulnerabilities
* CVE-2025-27613
* CVE-2025-27614
* CVE-2025-46835
* CVE-2025-48384
* CVE-2025-48385
* CVE-2025-48386
Sponsored by: Rubicon Communications, LLC ("Netgate") |
1.1_6 08 Jul 2025 16:10:55
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Fix mongodb entry
Remove mongodb80 entry since it is not affected.
Reported by: ronald-lists@klop.ws
Fixes: fbefcec73997 |
1.1_6 08 Jul 2025 15:46:14
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add mongodb* vulnerabilities
* CVE-2025-6711
* CVE-2025-6712
* CVE-2025-6713
* CVE-2025-6714
* CVE-2025-7259 |
1.1_6 08 Jul 2025 06:30:12
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add ModSecurity vulnerability
* CVE-2025-52891 |
1.1_6 07 Jul 2025 19:22:05
    |
Yasuhiro Kimura (yasu)  |
security/vuxml: Document multiple vlunerabilities in redis and valky |
1.1_6 06 Jul 2025 23:24:53
    |
Philip Paeps (philip)  |
security/vuxml: add FreeBSD SA issued on 2025-07-02
FreeBSD-SA-25:06.xz affects FreeBSD 13.5 and FreeBSD 14.2 |
1.1_6 06 Jul 2025 08:47:37
    |
Jason E. Hale (jhale)  |
security/vuxml: Document multimedia/gstreamer1-plugins-bad < 1.26.3 |
1.1_6 04 Jul 2025 12:24:40
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add Mozilla vulnerabilities
* CVE-2025-6425
* CVE-2025-6427
* CVE-2025-6429
* CVE-2025-6430
* CVE-2025-6432
* CVE-2025-6433
* CVE-2025-6434
* CVE-2025-6435
* CVE-2025-6436 |
1.1_6 03 Jul 2025 18:40:24
    |
Muhammad Moinur Rahman (bofh)  |
security/vuxml: Add CVE for php8* |
1.1_6 03 Jul 2025 17:13:35
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add Mozilla vulnerability |
1.1_6 02 Jul 2025 12:53:24
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 138.0.7204.96
Obtained
from: https://chromereleases.googleblog.com/2025/06/stable-channel-update-for-desktop_30.html
Obtained
from: https://chromereleases.googleblog.com/2025/06/stable-channel-update-for-desktop_24.html |
1.1_6 01 Jul 2025 17:45:51
    |
Matthias Andree (mandree)  |
security/vuxml: sudo<1.9.17p1 privilege escalation
PR: 287938
Security: 24f4b495-56a1-11f0-9621-93abbef07693
Security: CVE-2025-32462
Security: CVE-2025-32463 |
1.1_6 01 Jul 2025 10:18:18
    |
Emmanuel Vadot (manu)  |
security/vuxml: Add entries for xorg/xwayland latest vulnerabilities |
1.1_6 30 Jun 2025 13:18:09
    |
Sergey A. Osokin (osa)  |
security/vuxml: document sysutils/podman vulnerability |
1.1_6 26 Jun 2025 16:39:18
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add mongodb vulnerabilities
* CVE-2025-6706
* CVE-2025-6707
* CVE-2025-6709
* CVE-2025-6710 |
1.1_6 26 Jun 2025 08:31:15
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add kanboard vulnerability
* CVE-2025-52560
* CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N |
1.1_6 26 Jun 2025 02:16:19
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulnerabilities |
1.1_6 24 Jun 2025 08:46:58
    |
Koichiro Iwao (meta)  Author: Tom Hukins |
security/vuxml: fix spelling mistakes
Fixes: 986be61969
Pull Request: https://github.com/freebsd/freebsd-ports/pull/396 |
1.1_6 22 Jun 2025 20:45:11
    |
Daniel Engberg (diizzy)  |
security/vuxml: Add openh264 vulnerability
Document CVE-2025-27091 |
1.1_6 21 Jun 2025 18:38:59
    |
Charlie Li (vishwin)  |
security/vuxml: adjust affected textproc/libxml2 versions
Account for all branches' minor versions with fixes and local
backports to 2.11.
PR: 287391 |
1.1_6 20 Jun 2025 15:34:44
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add clamav vulnerabilities
* CVE-2025-20234
* CVE-2025-20260
PR: 287672
Reported by: Christos Chatzaras <chris@cretaforce.gr> |
1.1_6 20 Jun 2025 09:54:30
    |
Don Lewis (truckman)  Author: Olivier Duchateau |
x11/yelp: update to 42.3
Update to 42.3 and fix CVE-2025-3155 vulnerability
PR: 287543
MFH: 2025Q2
Security: 0e200a73-289a-489e-b405-40b997911036 |
1.1_6 20 Jun 2025 09:54:30
    |
Don Lewis (truckman)  Author: Olivier Duchateau |
textproc/yelp-xsl: Upgrade to 42.4
Upgrade yelp-xsl to 42.4 and fix CVE-2025-3155 vulnerability.
PR: 287542
MFH: 2025Q2
Security: 9449f018-84a3-490d-959f-38c05fbc77a7 |
1.1_6 19 Jun 2025 07:25:13
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 137.0.7151.119
Obtained
from: https://chromereleases.googleblog.com/2025/06/stable-channel-update-for-desktop_17.html |
1.1_6 18 Jun 2025 20:42:53
    |
Kevin Bowling (kbowling)  |
security/vuxml: Add multimedia/navidrome CVE-2025-48949 |
1.1_6 18 Jun 2025 17:45:19
    |
Fernando Apesteguía (fernape)  Author: Boris Korzun |
security/vuxml: Add grafana vulnerability
While here, correct versions for a previous grafana entry.
PR: 287634
Reported by: Boris Korzun <drtr0jan@yandex.ru> |
1.1_6 17 Jun 2025 15:38:39
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add firefox vulnerabilities
* CVE-2025-49709
* CVE-2025-49710 |
1.1_6 17 Jun 2025 07:01:26
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 137.0.7151.103
Obtained
from: https://chromereleases.googleblog.com/2025/06/stable-channel-update-for-desktop_10.html
Obtained
from: https://chromereleases.googleblog.com/2025/06/stable-channel-update-for-desktop.html |
1.1_6 15 Jun 2025 16:05:45
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Fix file validation
Reformat a couple of entries |
1.1_6 15 Jun 2025 15:57:44
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add Mozilla vulnerabilities
* CVE-2025-2817 |
1.1_6 15 Jun 2025 11:26:55
    |
Jimmy Olgeni (olgeni)  |
security/vuxml: Document CVE-2024-12828 (CGI Command Injection RCE in webmin) |
1.1_6 13 Jun 2025 15:28:49
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Fix make validate
After a clean.
PR: 287479
Reported by: dvl@ lwhsu@
Fixes: 3c9a11c9111b |
1.1_6 13 Jun 2025 13:28:04
    |
Li-Wen Hsu (lwhsu)  |
security/vuxml: Fix syntax of entry 2a220a73-4759-11f0-a44a-6cc21735f730
Fixes: 47f0fcd2cc49 security/vulxml: Add entry for PostgreSQL JDBC Driver
Sponsored by: The FreeBSD Foundation |
1.1_6 12 Jun 2025 07:36:13
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulnerabilities |
1.1_6 12 Jun 2025 06:55:28
    |
Palle Girgensohn (girgen)  |
security/vulxml: Add entry for PostgreSQL JDBC Driver |
1.1_6 06 Jun 2025 18:01:08
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add mod_security vulnerabilities
* CVE-2025-47947
* CVE-2025-48866 |
1.1_6 05 Jun 2025 16:00:03
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Correct roundcube entry
Flavored ports should include all package names in the VuXML entry.
PR: 287306
Reported by: Tomáš Čiernik <tomas@ciernik.sk> |
1.1_6 05 Jun 2025 15:45:59
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add Mozilla vulnerabilities
* CVE-2025-5267
* CVE-2025-5266
* CVE-2025-5264
* CVE-2025-5263 |
1.1_6 04 Jun 2025 12:33:23
    |
Hiroki Tagato (tagattie)  |
security/vuxml: add electron{34,36} out of bounds read and write in V8 |
1.1_6 04 Jun 2025 06:15:29
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add Chromium vulnerability
* CVE-2025-5419 |
1.1_6 04 Jun 2025 06:07:07
    |
Hiroki Tagato (tagattie)  |
security/vuxml: document electron35 out of bounds read and write in V8
Obtained from: https://github.com/electron/electron/releases/tag/v35.5.1 |
1.1_6 03 Jun 2025 16:16:08
    |
Alex Dupre (ale)  |
security/vuxml: add entry for roundcube.
PR: 287208
Submitted by: Christos Chatzaras <chris@cretaforce.gr> |
1.1_6 02 Jun 2025 16:10:41
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Fix make vuln-flat.xml
According to the documentation, we should be able to type:
make vuln-flat.xml
(https://docs.freebsd.org/en/books/porters-handbook/book/#security-notify-vuxml-testing)
But after 87748de634d7b the target name includes the PKGDIR which is not right.
Fixes: 87748de634d7b |
1.1_6 02 Jun 2025 15:59:34
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add Gimp vulnerabilities
* CVE-2025-2760
* CVE-2025-2761 |
1.1_6 02 Jun 2025 15:51:45
    |
Fernando Apesteguía (fernape)  Author: Christos Chatzaras |
security/vuxml: Add entry for ftp/curl
* CVE-2025-4947
* CVE-2025-5025
PR: 287219
Reported by: chris@cretaforce.gr |
1.1_6 31 May 2025 17:34:06
    |
Daniel Engberg (diizzy)  |
security/vuxml: Fix libxml2 CVE-2025-32414 entry
xmlsoft is the vendor name, replace it with libxml2
For some reason it go picked up while adding the this entry
Reported by: fernape |
1.1_6 31 May 2025 17:17:49
    |
Daniel Engberg (diizzy)  |
security/vuxml: Document libxml2 vulnerabilities
Document CVE-2024-56171, CVE-2025-24928 and CVE-2025-32414 |
1.1_6 31 May 2025 12:20:52
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Fix librewolf entries
librewolf does not have PORTEPOCH.
PR: 286455
Reported by: ax61@disroot.org |
1.1_6 31 May 2025 05:20:05
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 137.0.7151.55
Obtained
from: https://chromereleases.googleblog.com/2025/05/stable-channel-update-for-desktop_27.html |
1.1_6 30 May 2025 18:05:05
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add chromium vulnerability
* CVE-2025-5063 |
1.1_6 30 May 2025 17:44:19
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add Mozilla vulnerabilities
* CVE-2025-5268
* CVE-2025-5269
* CVE-2025-5270
* CVE-2025-5271
* CVE-2025-5272 |
1.1_6 30 May 2025 12:30:14
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add mod_security DoS vulnerability
* CVE-2025-47947
PR: 278180 |
1.1_6 30 May 2025 02:42:16
    |
Li-Wen Hsu (lwhsu)  |
security/vuxml: Fix entry 34744aab-3bf7-11f0-b81c-001b217e4ee5
Block-level elements such as <ul> are not allowed as children of <p>.
Fixes: 26d54384e9ef (security/vuxml: document kea vulnerabilities)
Sponsored by: The FreeBSD Foundation |
1.1_6 29 May 2025 22:46:18
    |
Thomas Zander (riggs)  |
security/vuxml: Document vulnerability in net/traefik |
1.1_6 29 May 2025 15:51:25
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add glpi vulnerabilities
* CVE-2024-11955
* CVE-2025-21619
* CVE-2025-21626
* CVE-2025-21627
* CVE-2025-23024
* CVE-2025-23046
* CVE-2025-24799
* CVE-2025-24801
* CVE-2025-25192 |
1.1_6 29 May 2025 15:08:48
    |
Brad Davis (brd)  |
security/vuxml: document kea vulnerabilities |
1.1_6 29 May 2025 05:36:05
    |
Hiroki Tagato (tagattie)  |
security/vuxml: document electron{34,35} multiple vulnerabilities
Obtained from: https://github.com/electron/electron/releases/tag/v34.5.7,
https://github.com/electron/electron/releases/tag/v35.5.0 |
1.1_6 28 May 2025 06:21:40
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Ammend entry for asterisk18
An extra 0 was in the version number.
Reported by: Sulev-Madis Silber |
1.1_6 27 May 2025 19:27:35
    |
Charlie Li (vishwin)  |
security/vuxml: adjust lang/python3 versions for CVE-2025-4516
PORTREVISIONs are bumped for each port containing the respective
upstream commit that is not included in any release yet.
PR: 287009 |
1.1_6 27 May 2025 15:58:22
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add grafana vulnerability
* CVE-2025-4123 |
1.1_6 24 May 2025 15:33:50
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add python3 vulnerability
* CVE-2025-4516
PR: 287009
Reported by: ngie@ |
1.1_6 23 May 2025 15:58:53
    |
Bernard Spil (brnrd)  |
security/vuxml: Document OpenSSL 3.5 vulnerability |
1.1_6 23 May 2025 12:28:26
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add Firefox vulnerability
* CVE-2025-3608 |
1.1_6 23 May 2025 06:08:51
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulnerabilities |
1.1_6 22 May 2025 18:51:40
    |
Brad Davis (brd)  |
security/vuxml: Document screen vulnerabilities |
1.1_6 19 May 2025 16:17:26
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add firefox{-esr} vulnerabilities
* CVE-2025-4918
* CVE-2025-4919 |
1.1_6 17 May 2025 08:20:54
    |
Bernard Spil (brnrd)  |
security/vuxml: Document WeeChat vulnerabilities |
1.1_6 15 May 2025 08:29:57
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 136.0.7103.113
Obtained
from: https://chromereleases.googleblog.com/2025/05/stable-channel-update-for-desktop_14.html |
1.1_6 14 May 2025 15:28:05
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add Mozilla vulnerabilities
* CVE-2025-4091
* CVE-2025-4093 |
1.1_6 14 May 2025 15:22:13
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Fix 2025.xml
Please, remember to always run "make validate" before committing.
fernape@ with ports-secteam@ hat on.
Fixes: 7e75a5ba66e3a |
1.1_6 14 May 2025 12:25:35
    |
Hiroki Tagato (tagattie)  |
security/vuxml: document vscode security feature bypass vulnerability
Obtained
from: https://github.com/microsoft/vscode/security/advisories/GHSA-742r-ggwg-vqxm |
1.1_6 13 May 2025 22:30:00
    |
Charlie Li (vishwin)  |
security/vuxml: add textproc/libxslt
PR: 286782 |
1.1_6 12 May 2025 23:07:46
    |
Danilo G. Baio (dbaio)  |
security/vuxml: Add Varnish Cache vulnerability |
1.1_6 11 May 2025 16:48:21
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add Mozilla vulnerabilities
* CVE-2025-4083
* CVE-2025-4085
* CVE-2025-4087
* CVE-2025-4088
* CVE-2025-4089
* CVE-2025-4092 |
1.1_6 10 May 2025 04:19:58
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulnerabilities |
1.1_6 08 May 2025 20:00:15
    |
Palle Girgensohn (girgen)  |
security/vuxml: Add information about PostgreSQL overflow issue |
1.1_6 07 May 2025 06:40:58
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 136.0.7103.92
Obtained
from: https://chromereleases.googleblog.com/2025/05/stable-channel-update-for-desktop.html |
1.1_6 06 May 2025 06:37:48
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 136.0.7103.59
Obtained
from: https://chromereleases.googleblog.com/2025/04/stable-channel-update-for-desktop_29.html |
1.1_6 05 May 2025 16:03:39
    |
Fernando Apesteguía (fernape)  Author: Christos Chatzaras |
security/vuxml: Add entry for fcgi < 2.4.5
PR: 286590
Reported by: chris@cretaforce.gr |
1.1_6 04 May 2025 16:08:21
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add dnsdist vulnerability
* CVE-2025-30194
PR: 286282 |
1.1_6 04 May 2025 03:04:21
    |
Philip Paeps (philip)  |
security/vuxml: libspf2 >= 1.2.11_1 not vulnerable
Fix the version range for libspf2 CVE-2023-42118.
libspf2 was patched in commit bbdef08a89c2124b0c149597f23d67c39cf3a522
to address CVE-2023-42118. PORTREVISION was bumped but vuxml was never
updated.
PR: 274215
Reported by: JC Burger <Jc.Burger@nttdata.com>
Security: CVE-2023-42118 |
1.1_6 01 May 2025 04:52:08
    |
Kurt Jaeger (pi)  Author: Ralf van der Enden |
security/vuxml: add VuXML entry for CVE-2025-30195 for dns/powerdns-recursor
PR: 286139
Reported-by: Jordan Ostreff <jordan@ostreff.info> |
1.1_6 01 May 2025 00:26:39
    |
Koichiro Iwao (meta)  Author: Tom Hukins |
security/vuxml: fix clumsy whitespace use
This text was added in 72eea8b with words split in half.
Pull Request: https://github.com/freebsd/freebsd-ports/pull/385 |
1.1_6 30 Apr 2025 17:18:21
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add sqlite vulnerability
* CVE-2025-29087 |
1.1_6 30 Apr 2025 12:58:58
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Fix entry range
PR: 286470
Reported by: Einar Bjarni Halldórsson <einar@isnic.is>
Fixes: 86c0781ad496e |
1.1_6 29 Apr 2025 19:55:55
    |
Kevin Bowling (kbowling)  |
security/vuxml: Fix navidrome range statement |
1.1_6 29 Apr 2025 13:10:08
    |
Muhammad Moinur Rahman (bofh)  |
net/py-h11: Update version 0.14.0=>0.16.0
- This addresses fix for CVE-2025-43859 — a critical vulnerability
affecting HTTP/1.1 connection handling.
- This update may break ports that depend on older h11 APIs, as some
interfaces and behaviors have changed in the new release.
Ports known or suspected to be affected should be tested carefully and
updated accordingly. A heads-up will also be sent to ports@.
Quarterly merge should take place after all the downstream ports have
been fixed for building.
Security: CVE-2025-43859
Changelog: https://github.com/python-hyper/h11/releases/tag/v0.16.0
MFH: 2025Q2 |
1.1_6 25 Apr 2025 06:25:12
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add grafana vulnerabilities
* CVE-2025-2703 - DOM XSS vulnerability (Medium)
* CVE-2025-3260 - Bypass Viewer and Editor permission (High)
* CVE-2025-3454 - Authorization bypass in data source proxy API (Medium)
PR: 286323
Reported by: Boris Korzun <drtr0jan@yandex.ru |
1.1_6 24 Apr 2025 08:20:30
    |
Yasuhiro Kimura (yasu)  |
security/vuxml: Document DoS vulnerability in redis and valkey |
1.1_6 24 Apr 2025 03:18:06
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulnerabilities |
1.1_6 23 Apr 2025 04:49:55
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 135.0.7049.114
Obtained
from: https://chromereleases.googleblog.com/2025/04/stable-channel-update-for-desktop_22.html |
1.1_6 22 Apr 2025 02:56:39
    |
Kevin Bowling (kbowling)  |
security/vuxml: Add multimedia/navidrome CVE-2025-27112 |