Commit History - (may be incomplete: for full details, see links to repositories near top of page) |
Commit | Credits | Log message |
1.1_6 29 Aug 2025 03:22:52
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulnerabilities |
1.1_6 28 Aug 2025 19:42:05
    |
Renato Botelho (garga)  |
security/vuxml: Adjust affected kea versions
CVE-2025-40779 doesn't affect Kea 2.6.x, which is the version present on
quarterly branch. On net/kea, it only affects 3.0.0 while it affects
3.1.0 and 2.7.x on net/kea-devel. |
1.1_6 28 Aug 2025 19:32:40
    |
Renato Botelho (garga)  Author: Andrey Pevnev |
security/vuxml: Add net/kea vulnerability
* CVE-2025-40779 |
1.1_6 28 Aug 2025 05:06:27
    |
Jason E. Hale (jhale)  |
security/vuxml: Add devel/qt6-base < 6.9.2 |
1.1_6 28 Aug 2025 05:06:26
    |
Jason E. Hale (jhale)  |
security/vuxml: Add www/qt6-webengine < 6.9.2 |
1.1_6 27 Aug 2025 17:02:53
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Fix entry
Fixes: 35f7214f7a9ec |
1.1_6 27 Aug 2025 17:00:06
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add SQLite vulnerability
* CVE-2025-29088 |
1.1_6 24 Aug 2025 11:42:50
    |
Rodrigo Osorio (rodrigo)  |
security/vuxml: add p5-Catalyst-Authentication-Credential-HTTP |
1.1_6 22 Aug 2025 15:28:41
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add Mozilla vulnerabilities
* CVE-2025-9187
* CVE-2025-9184
* CVE-2025-9185
* CVE-2025-9183
* CVE-2025-9182
* CVE-2025-9181
* CVE-2025-9180
* CVE-2025-9179 |
1.1_6 15 Aug 2025 16:10:38
    |
Sergey A. Osokin (osa)  |
security/vuxml: add www/nginx-devel < 1.29.1
Obtained from: https://my.f5.com/manage/s/article/K000152786 |
1.1_6 14 Aug 2025 19:16:40
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 139.0.7258.127
Obtained
from: https://chromereleases.googleblog.com/2025/08/stable-channel-update-for-desktop_12.html |
1.1_6 14 Aug 2025 14:10:16
    |
Palle Girgensohn (girgen)  |
security/vuxml: Add vulnerabilities for PostgreSQL |
1.1_6 14 Aug 2025 03:41:47
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulnerabilities |
1.1_6 13 Aug 2025 15:41:08
    |
Ryan Steinmetz (zi)  |
security/vuxml: Document www/varnish7 DoS condition |
1.1_6 13 Aug 2025 09:19:28
    |
Rodrigo Osorio (rodrigo)  |
security/vuxml: add security/p5-Authen-SASL |
1.1_6 11 Aug 2025 08:10:50
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 139.0.7258.66
Obtained
from: https://chromereleases.googleblog.com/2025/08/stable-channel-update-for-desktop.html |
1.1_6 09 Aug 2025 14:19:07
    |
Bernard Spil (brnrd)  |
security/vuxml: Document Apache httpd vulnerability |
1.1_6 08 Aug 2025 01:20:58
    |
Philip Paeps (philip)  |
security/vuxml: add FreeBSD SA issued on 2025-08-08
FreeBSD-SA-25:07.libarchive affects all supported versions of FreeBSD. |
1.1_6 02 Aug 2025 16:57:24
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add Sqlite vulnerability
* CVE-2025-3277 |
1.1_6 01 Aug 2025 09:51:05
    |
Matthias Andree (mandree)  |
security/vuxml: navidrome < 0.56.0 CVE-2025-48948
This wasn't mentioned along with the other navidrome < 0.56
vuln and also has a wider affected version range.
Security: CVE-2025-48948
Security: 95480188-6ebc-11f0-8a78-bf201f293bce |
1.1_6 01 Aug 2025 09:45:34
    |
Matthias Andree (mandree)  |
security/vuxml: fixup linux_base -> linux_base-rl9 |
1.1_6 01 Aug 2025 09:41:36
    |
Matthias Andree (mandree)  |
security/vuxml: clean up sqlite3 version range mess
Several sqlite3 entries mentioned wrong version ranges
with respect to PORTEPOCH and/or forgot the linux-*-sqlite
or, more recently, linux_base port.
While auditing this, I saw several implausible tags that used <gt>
(greater-than) in ranges where I believe that <ge> (greater-or-equal)
would be more adequate.
Add relevant reminders to vuxml's Makefile.
Fix up sqlite3's 2025 entries.
linux_base-rl9 currently ships 3.34.1-7.el9_3, see
emulators/linux_base-rl9/Makefile.version - I don't know if that's
vulnerable or was patched inside Rocky Linux, but let's err on the safe side.
I'll leave it up to emulation@ to clean up this particular entry. |
1.1_6 01 Aug 2025 08:52:38
    |
Matthias Andree (mandree)  |
security/vuxml: fix up range for sqlite3's CVE-2025-7458
Security: f51077bd-6dd7-11f0-9d62-b42e991fc52e
Security: CVE-2025-7458 |
1.1_6 31 Jul 2025 06:40:27
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add Sqlite vulnerability
CVE_ID=CVE-2025-7458 |
1.1_6 29 Jul 2025 20:22:43
    |
Rodrigo Osorio (rodrigo)  |
security/vuxml: Use of Cryptographically Weak Pseudo-Random Number Generator in
p5-Crypt-CBC
Also, fix typo missing space in previous report. |
1.1_6 27 Jul 2025 12:31:03
    |
Dan Langille (dvl)  |
security/vuxml: Add devel/viewvc-devel entry |
1.1_6 25 Jul 2025 21:59:11
    |
Yasuhiro Kimura (yasu)  |
security/vuxml: Document possible DoS valnerability in rubygem-resolv |
1.1_6 24 Jul 2025 16:09:03
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add Mozilla vulnerabilities
* CVE-2025-8027
* CVE-2025-8028
* CVE-2025-8029
* CVE-2025-8030
* CVE-2025-8031
* CVE-2025-8032
* CVE-2025-8033
* CVE-2025-8034
* CVE-2025-8035
* CVE-2025-8036
* CVE-2025-8037
* CVE-2025-8038
* CVE-2025-8039
* CVE-2025-8040
* CVE-2025-8043
* CVE-2025-8044 |
1.1_6 24 Jul 2025 16:04:14
    |
Sergey A. Osokin (osa)  |
security/vuxml: document gdk-pixbuf2 vulnerability |
1.1_6 24 Jul 2025 13:08:36
    |
Hiroki Tagato (tagattie)  Author: Ralf van der Enden |
security/vuxml: add dns/powerdns-recursor entry for CVE-2025-30192
PR: 288384
Reported by: Ralf van der Enden <tremere@cainites.net>
Obtained from: https://blog.powerdns.com/powerdns-security-advisory-2025-04 |
1.1_6 24 Jul 2025 03:27:52
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulnerabilities |
1.1_6 23 Jul 2025 19:29:20
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add sqlite3 vulnerability
CVE-2025-6965 |
1.1_6 22 Jul 2025 18:33:02
    |
Max Brazhnikov (makc)  |
security/vuxml: Document 7-zip vulnerability
Prompted by: asomers@ |
1.1_6 21 Jul 2025 20:44:53
    |
Daniel Engberg (diizzy)  |
security/vuxml: Adjust affected versions for openh264 (CVE-2025-27091)
Adjust range to since port uses PORTEPOCH
Fixes: 13dd451 |
1.1_6 20 Jul 2025 04:32:53
    |
Sergey A. Osokin (osa)  |
security/vuxml: document libwasmtime vulnerability |
1.1_6 18 Jul 2025 21:03:08
    |
Hiroki Tagato (tagattie)  Author: Jaap Akkerhuis |
security/vuxml: document unbound cache poisoning via the ECS-enabled rebirthday
attack
PR: 288276
Reported by: Jaap Akkerhuis <jaap@NLnetLabs.nl> |
1.1_6 16 Jul 2025 20:06:13
    |
Michael Osipov (michaelo)  |
security/vuxml: Fix ranges for Tomcat vulnerabilities
Approved by: otis (mentor), jbeich, vvd (maintainer)
Differential Revision: https://reviews.freebsd.org/D51323 |
1.1_6 15 Jul 2025 18:37:23
    |
Matthias Andree (mandree)  |
security/vuxml: libxml2 fixed version is 2.14.5.
Security: abbc8912-5efa-11f0-ae84-99047d0a6bcc |
1.1_6 14 Jul 2025 18:44:35
    |
Bernard Spil (brnrd)  |
security/vuxml: Document liboqs vulnerability |
1.1_6 14 Jul 2025 09:49:43
    |
Tijl Coosemans (tijl)  |
security/vuxml: Document GnuTLS SA 2025-07-08 |
1.1_6 12 Jul 2025 09:40:26
    |
Matthias Andree (mandree)  |
security/vuxml: extend libxml2/libxslt vuln to linux-* ports |
1.1_6 12 Jul 2025 09:13:36
    |
Matthias Andree (mandree)  |
textproc/libxml2, textproc/libxslt: vulnerable
Note that libxslt is vulnerable, unfixed, and without maintainer.
Two of four vulnerabilities have been fixed.
Note that libxml2 in our ports is vulnerable and there is no upstream
release fixing these bugs, they need cherry-picks.
Deprecate textproc/xmlto and textproc/minixmlto,
which both depend on the unmaintained and vulnerable libxslt.
I have filed https://pagure.io/xmlto/issue/15 to ask the xmlto
upstream to switch to different XML/XSLT libraries.
Two issues are undisclosed and do not seem to have a CVE assigned yet.
(Only the first 15 lines of the commit message are shown above ) |
1.1_6 11 Jul 2025 21:35:16
    |
Bernard Spil (brnrd)  |
security/vuxml: Document mod_http2 vulnerabilities |
1.1_6 11 Jul 2025 21:15:09
    |
Bernard Spil (brnrd)  |
security/vuxml: Document Apache httpd vulnerabilities |
1.1_6 10 Jul 2025 21:24:29
    |
Sergey A. Osokin (osa)  |
security/vuxml: document tomcat vulnerabilities |
1.1_6 10 Jul 2025 04:28:58
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulnerabilities |
1.1_6 08 Jul 2025 17:19:09
    |
Renato Botelho (garga)  |
security/vuxml: Add multiple git vulnerabilities
* CVE-2025-27613
* CVE-2025-27614
* CVE-2025-46835
* CVE-2025-48384
* CVE-2025-48385
* CVE-2025-48386
Sponsored by: Rubicon Communications, LLC ("Netgate") |
1.1_6 08 Jul 2025 16:10:55
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Fix mongodb entry
Remove mongodb80 entry since it is not affected.
Reported by: ronald-lists@klop.ws
Fixes: fbefcec73997 |
1.1_6 08 Jul 2025 15:46:14
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add mongodb* vulnerabilities
* CVE-2025-6711
* CVE-2025-6712
* CVE-2025-6713
* CVE-2025-6714
* CVE-2025-7259 |
1.1_6 08 Jul 2025 06:30:12
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add ModSecurity vulnerability
* CVE-2025-52891 |
1.1_6 07 Jul 2025 19:22:05
    |
Yasuhiro Kimura (yasu)  |
security/vuxml: Document multiple vlunerabilities in redis and valky |
1.1_6 06 Jul 2025 23:24:53
    |
Philip Paeps (philip)  |
security/vuxml: add FreeBSD SA issued on 2025-07-02
FreeBSD-SA-25:06.xz affects FreeBSD 13.5 and FreeBSD 14.2 |
1.1_6 06 Jul 2025 08:47:37
    |
Jason E. Hale (jhale)  |
security/vuxml: Document multimedia/gstreamer1-plugins-bad < 1.26.3 |
1.1_6 04 Jul 2025 12:24:40
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add Mozilla vulnerabilities
* CVE-2025-6425
* CVE-2025-6427
* CVE-2025-6429
* CVE-2025-6430
* CVE-2025-6432
* CVE-2025-6433
* CVE-2025-6434
* CVE-2025-6435
* CVE-2025-6436 |
1.1_6 03 Jul 2025 18:40:24
    |
Muhammad Moinur Rahman (bofh)  |
security/vuxml: Add CVE for php8* |
1.1_6 03 Jul 2025 17:13:35
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add Mozilla vulnerability |
1.1_6 02 Jul 2025 12:53:24
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 138.0.7204.96
Obtained
from: https://chromereleases.googleblog.com/2025/06/stable-channel-update-for-desktop_30.html
Obtained
from: https://chromereleases.googleblog.com/2025/06/stable-channel-update-for-desktop_24.html |
1.1_6 01 Jul 2025 17:45:51
    |
Matthias Andree (mandree)  |
security/vuxml: sudo<1.9.17p1 privilege escalation
PR: 287938
Security: 24f4b495-56a1-11f0-9621-93abbef07693
Security: CVE-2025-32462
Security: CVE-2025-32463 |
1.1_6 01 Jul 2025 10:18:18
    |
Emmanuel Vadot (manu)  |
security/vuxml: Add entries for xorg/xwayland latest vulnerabilities |
1.1_6 30 Jun 2025 13:18:09
    |
Sergey A. Osokin (osa)  |
security/vuxml: document sysutils/podman vulnerability |
1.1_6 26 Jun 2025 16:39:18
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add mongodb vulnerabilities
* CVE-2025-6706
* CVE-2025-6707
* CVE-2025-6709
* CVE-2025-6710 |
1.1_6 26 Jun 2025 08:31:15
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add kanboard vulnerability
* CVE-2025-52560
* CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N |
1.1_6 26 Jun 2025 02:16:19
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulnerabilities |
1.1_6 24 Jun 2025 08:46:58
    |
Koichiro Iwao (meta)  Author: Tom Hukins |
security/vuxml: fix spelling mistakes
Fixes: 986be61969
Pull Request: https://github.com/freebsd/freebsd-ports/pull/396 |
1.1_6 22 Jun 2025 20:45:11
    |
Daniel Engberg (diizzy)  |
security/vuxml: Add openh264 vulnerability
Document CVE-2025-27091 |
1.1_6 21 Jun 2025 18:38:59
    |
Charlie Li (vishwin)  |
security/vuxml: adjust affected textproc/libxml2 versions
Account for all branches' minor versions with fixes and local
backports to 2.11.
PR: 287391 |
1.1_6 20 Jun 2025 15:34:44
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add clamav vulnerabilities
* CVE-2025-20234
* CVE-2025-20260
PR: 287672
Reported by: Christos Chatzaras <chris@cretaforce.gr> |
1.1_6 20 Jun 2025 09:54:30
    |
Don Lewis (truckman)  Author: Olivier Duchateau |
x11/yelp: update to 42.3
Update to 42.3 and fix CVE-2025-3155 vulnerability
PR: 287543
MFH: 2025Q2
Security: 0e200a73-289a-489e-b405-40b997911036 |
1.1_6 20 Jun 2025 09:54:30
    |
Don Lewis (truckman)  Author: Olivier Duchateau |
textproc/yelp-xsl: Upgrade to 42.4
Upgrade yelp-xsl to 42.4 and fix CVE-2025-3155 vulnerability.
PR: 287542
MFH: 2025Q2
Security: 9449f018-84a3-490d-959f-38c05fbc77a7 |
1.1_6 19 Jun 2025 07:25:13
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 137.0.7151.119
Obtained
from: https://chromereleases.googleblog.com/2025/06/stable-channel-update-for-desktop_17.html |
1.1_6 18 Jun 2025 20:42:53
    |
Kevin Bowling (kbowling)  |
security/vuxml: Add multimedia/navidrome CVE-2025-48949 |
1.1_6 18 Jun 2025 17:45:19
    |
Fernando Apesteguía (fernape)  Author: Boris Korzun |
security/vuxml: Add grafana vulnerability
While here, correct versions for a previous grafana entry.
PR: 287634
Reported by: Boris Korzun <drtr0jan@yandex.ru> |
1.1_6 17 Jun 2025 15:38:39
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add firefox vulnerabilities
* CVE-2025-49709
* CVE-2025-49710 |
1.1_6 17 Jun 2025 07:01:26
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 137.0.7151.103
Obtained
from: https://chromereleases.googleblog.com/2025/06/stable-channel-update-for-desktop_10.html
Obtained
from: https://chromereleases.googleblog.com/2025/06/stable-channel-update-for-desktop.html |
1.1_6 15 Jun 2025 16:05:45
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Fix file validation
Reformat a couple of entries |
1.1_6 15 Jun 2025 15:57:44
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add Mozilla vulnerabilities
* CVE-2025-2817 |
1.1_6 15 Jun 2025 11:26:55
    |
Jimmy Olgeni (olgeni)  |
security/vuxml: Document CVE-2024-12828 (CGI Command Injection RCE in webmin) |
1.1_6 13 Jun 2025 15:28:49
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Fix make validate
After a clean.
PR: 287479
Reported by: dvl@ lwhsu@
Fixes: 3c9a11c9111b |
1.1_6 13 Jun 2025 13:28:04
    |
Li-Wen Hsu (lwhsu)  |
security/vuxml: Fix syntax of entry 2a220a73-4759-11f0-a44a-6cc21735f730
Fixes: 47f0fcd2cc49 security/vulxml: Add entry for PostgreSQL JDBC Driver
Sponsored by: The FreeBSD Foundation |
1.1_6 12 Jun 2025 07:36:13
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulnerabilities |
1.1_6 12 Jun 2025 06:55:28
    |
Palle Girgensohn (girgen)  |
security/vulxml: Add entry for PostgreSQL JDBC Driver |
1.1_6 06 Jun 2025 18:01:08
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add mod_security vulnerabilities
* CVE-2025-47947
* CVE-2025-48866 |
1.1_6 05 Jun 2025 16:00:03
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Correct roundcube entry
Flavored ports should include all package names in the VuXML entry.
PR: 287306
Reported by: Tomáš Čiernik <tomas@ciernik.sk> |
1.1_6 05 Jun 2025 15:45:59
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add Mozilla vulnerabilities
* CVE-2025-5267
* CVE-2025-5266
* CVE-2025-5264
* CVE-2025-5263 |
1.1_6 04 Jun 2025 12:33:23
    |
Hiroki Tagato (tagattie)  |
security/vuxml: add electron{34,36} out of bounds read and write in V8 |
1.1_6 04 Jun 2025 06:15:29
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add Chromium vulnerability
* CVE-2025-5419 |
1.1_6 04 Jun 2025 06:07:07
    |
Hiroki Tagato (tagattie)  |
security/vuxml: document electron35 out of bounds read and write in V8
Obtained from: https://github.com/electron/electron/releases/tag/v35.5.1 |
1.1_6 03 Jun 2025 16:16:08
    |
Alex Dupre (ale)  |
security/vuxml: add entry for roundcube.
PR: 287208
Submitted by: Christos Chatzaras <chris@cretaforce.gr> |
1.1_6 02 Jun 2025 16:10:41
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Fix make vuln-flat.xml
According to the documentation, we should be able to type:
make vuln-flat.xml
(https://docs.freebsd.org/en/books/porters-handbook/book/#security-notify-vuxml-testing)
But after 87748de634d7b the target name includes the PKGDIR which is not right.
Fixes: 87748de634d7b |
1.1_6 02 Jun 2025 15:59:34
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add Gimp vulnerabilities
* CVE-2025-2760
* CVE-2025-2761 |
1.1_6 02 Jun 2025 15:51:45
    |
Fernando Apesteguía (fernape)  Author: Christos Chatzaras |
security/vuxml: Add entry for ftp/curl
* CVE-2025-4947
* CVE-2025-5025
PR: 287219
Reported by: chris@cretaforce.gr |
1.1_6 31 May 2025 17:34:06
    |
Daniel Engberg (diizzy)  |
security/vuxml: Fix libxml2 CVE-2025-32414 entry
xmlsoft is the vendor name, replace it with libxml2
For some reason it go picked up while adding the this entry
Reported by: fernape |
1.1_6 31 May 2025 17:17:49
    |
Daniel Engberg (diizzy)  |
security/vuxml: Document libxml2 vulnerabilities
Document CVE-2024-56171, CVE-2025-24928 and CVE-2025-32414 |
1.1_6 31 May 2025 12:20:52
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Fix librewolf entries
librewolf does not have PORTEPOCH.
PR: 286455
Reported by: ax61@disroot.org |
1.1_6 31 May 2025 05:20:05
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 137.0.7151.55
Obtained
from: https://chromereleases.googleblog.com/2025/05/stable-channel-update-for-desktop_27.html |
1.1_6 30 May 2025 18:05:05
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add chromium vulnerability
* CVE-2025-5063 |
1.1_6 30 May 2025 17:44:19
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add Mozilla vulnerabilities
* CVE-2025-5268
* CVE-2025-5269
* CVE-2025-5270
* CVE-2025-5271
* CVE-2025-5272 |
1.1_6 30 May 2025 12:30:14
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add mod_security DoS vulnerability
* CVE-2025-47947
PR: 278180 |
1.1_6 30 May 2025 02:42:16
    |
Li-Wen Hsu (lwhsu)  |
security/vuxml: Fix entry 34744aab-3bf7-11f0-b81c-001b217e4ee5
Block-level elements such as <ul> are not allowed as children of <p>.
Fixes: 26d54384e9ef (security/vuxml: document kea vulnerabilities)
Sponsored by: The FreeBSD Foundation |
1.1_6 29 May 2025 22:46:18
    |
Thomas Zander (riggs)  |
security/vuxml: Document vulnerability in net/traefik |