Commit History - (may be incomplete: for full details, see links to repositories near top of page) |
Commit | Credits | Log message |
1.1_6 23 Feb 2024 23:15:13
    |
Li-Wen Hsu (lwhsu)  Author: Boris Korzun |
security/vuxml: Document CVE-2023-6152 for www/grafana*
PR: 277184 |
1.1_6 23 Feb 2024 22:51:42
    |
Rodrigo Osorio (rodrigo)  |
security/vuxml: Record dns/c-ares vulnerability |
1.1_6 23 Feb 2024 19:06:32
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Record security/suricata multiple vulnerabilities
No details for this CVEs yet.
CVE-2024-23839 – Critical severity
CVE-2024-23836 – Critical severity
CVE-2024-23835 – High severity
CVE-2024-24568 – Moderate severity
CVE-2024-23837 – Critical severity
PR: 277025
Reported by: franco@opnsense.org
MFH: 2024Q1 (security fixes) |
1.1_6 23 Feb 2024 04:48:56
    |
Hiroki Tagato (tagattie)  |
security/vuxml: document electron27 multiple vulnerabilities
Obtained from: https://github.com/electron/electron/releases/tag/v27.3.3 |
1.1_6 22 Feb 2024 05:48:55
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulnerabilities |
1.1_6 16 Feb 2024 14:54:20
    |
Ryan Steinmetz (zi)  |
security/vuxml: Add lower bound on new www/nginx-devel vuln |
1.1_6 16 Feb 2024 08:58:21
    |
Fernando Apesteguía (fernape)  |
security/vuxml: document dns/powerdns-recursor vulnerabilities
* CVE-2023-50387
* CVE-2023-50868
PR: 277048
Reported by: Ralf van der Enden <tremere@cainites.net> |
1.1_6 16 Feb 2024 08:48:14
    |
Fernando Apesteguía (fernape)  |
security/vuxml: document www/gitea vulnerability
Prevent anonymous container access if RequireSignInView is enabled
PR: 277066 |
1.1_6 15 Feb 2024 17:27:39
    |
Ryan Steinmetz (zi)  |
security/vuxml: Document www/nginx-devel vulns: CVE-2024-24989, CVE-2024-24990 |
1.1_6 14 Feb 2024 19:50:37
    |
Gabriel M. Dutra (dutra)  |
security/vuxml: Add sysutils/eza vulnerability
Include eza port in the Libgit2 entry.
Approved by: dbaio (mentor), garga (mentor)
Differential Revision: https://reviews.freebsd.org/D43868 |
1.1_6 14 Feb 2024 14:48:43
    |
Philip Paeps (philip)  |
security/vuxml: add FreeBSD SAs released on 2024-02-14
FreeBSD-SA-24:01.bhyveload affects all supported releases of FreeBSD.
FreeBSD-SA-24:02.tty affects all supported releases of FreeBSD. |
1.1_6 14 Feb 2024 07:45:33
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 121.0.6167.184
Obtained
from: https://chromereleases.googleblog.com/2024/02/stable-channel-update-for-desktop_13.html |
1.1_6 13 Feb 2024 23:13:16
    |
Matthias Andree (mandree)  |
security/vuxml: document dnssec validating resolver DoS vuln...
for Bind9, dnsmasq, PowerDNS, Unbound.
Security: 21a854cc-cac1-11ee-b7a7-353f1e043d9a
Security: CVE-2023-50387
Security: CVE-2023-50868 |
1.1_6 13 Feb 2024 20:00:16
    |
Florian Smeets (flo)  |
security/vuxml: add phpmyfaq < 3.2.5 |
1.1_6 12 Feb 2024 17:10:26
    |
Matthias Andree (mandree)  |
security/vuxml: fix NS tag on body of Gitlab vuln entry
This fixes a vxquery warning (line number may vary):
| Parsing failed @ line 4442:
| Expected element in XHTML namespace.
Security: 6e0ebb4a-5e75-11ee-a365-001b217b3468 |
1.1_6 12 Feb 2024 15:50:59
    |
Matthias Andree (mandree)  |
security/vuxml: Add openexr<3.2.2 (<3.1.12) heap overflow
Security: CVE-2023-5841
Security: f161a5ad-c9bd-11ee-b7a7-353f1e043d9a |
1.1_6 12 Feb 2024 00:55:07
    |
Jason E. Hale (jhale)  |
security/vuxml: Document vulnerability in readstat |
1.1_6 11 Feb 2024 19:03:15
    |
Rodrigo Osorio (rodrigo)  |
security/vuxml: add vulnerability for p5-Spreadsheet-ParseExcel
https://nvd.nist.gov/vuln/detail/CVE-2023-7101 |
1.1_6 10 Feb 2024 20:15:08
    |
Jason E. Hale (jhale)  |
security/vuxml: Add qt[56]-webengine
qt5-webengine and qt6-webengine are also vulnerable to:
dc9e5237-c197-11ee-86bb-a8a1599412c6
19047673-c680-11ee-86bb-a8a1599412c6
qt5-webengine is also vulnerable to:
bbcb1584-c068-11ee-bdd6-4ccc6adda413 |
1.1_6 09 Feb 2024 17:19:42
    |
Baptiste Daroussin (bapt)  |
vuxml: fix cve name for postgres
This was breaking the build of the vuxml website |
1.1_6 08 Feb 2024 21:28:35
    |
Palle Girgensohn (girgen)  |
security/vuxml: add issue for PostgreSQL
https://www.postgresql.org/support/security/CVE-2024-0985/ |
1.1_6 08 Feb 2024 17:22:12
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulnerabilities |
1.1_6 08 Feb 2024 14:36:42
    |
Guido Falsi (madpilot)  |
security/vuxml: Add new php-composer vulnerability. |
1.1_6 08 Feb 2024 13:16:43
    |
Matthias Fechner (mfechner)  |
security/vuxml: document a libgit2 vulnerability |
1.1_6 08 Feb 2024 12:52:56
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 121.0.6167.160
Obtained
from: https://chromereleases.googleblog.com/2024/02/stable-channel-update-for-desktop.html |
1.1_6 08 Feb 2024 05:18:12
    |
Yasuhiro Kimura (yasu)  |
security/vuxml: Document multiple vulnerabilities in clamav |
1.1_6 07 Feb 2024 10:04:13
    |
Wen Heping (wen)  |
security/vuxml: Document django multiple vulnerabilities |
1.1_6 02 Feb 2024 06:59:01
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 121.0.6167.{85,139}
Obtained
from: https://chromereleases.googleblog.com/2024/01/stable-channel-update-for-desktop_23.html
Obtained
from: https://chromereleases.googleblog.com/2024/01/stable-channel-update-for-desktop_30.html |
1.1_6 01 Feb 2024 08:17:02
    |
Hiroki Tagato (tagattie)  |
security/vuxml: document electron{26,27,28} use after free in Web Audio
Obtained from: https://github.com/electron/electron/releases/tag/v26.6.8,
https://github.com/electron/electron/releases/tag/v27.3.1,
https://github.com/electron/electron/releases/tag/v28.2.1 |
1.1_6 31 Jan 2024 20:07:14
    |
Jason E. Hale (jhale)  |
security/vuxml: Document qt6-webengine vulnerabilities |
1.1_6 31 Jan 2024 18:57:37
    |
Bernard Spil (brnrd)  |
security/vuxml: Register OpenSSL vulnerabilities |
1.1_6 31 Jan 2024 07:43:35
    |
Hiroki Tagato (tagattie)  |
security/vuxml: document lizard memory corruption
Obtained from: https://nvd.nist.gov/vuln/detail/CVE-2018-11498 |
1.1_6 30 Jan 2024 00:41:36
    |
Jason E. Hale (jhale)  |
security/vuxml: Document qt(5|6)-webengine vulnerabilities |
1.1_6 29 Jan 2024 22:52:31
    |
Cy Schubert (cy)  |
security/vuxml: Fix krb5-devel version number |
1.1_6 26 Jan 2024 13:53:08
    |
Fernando Apesteguía (fernape)  |
security/vuxml: document rclone vulnerabilities
CVE-2023-48795: Base Score: 5.9 MEDIUM
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
CVE-2023-45286: Base Score: 5.9 MEDIUM
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
PR: 276515 |
1.1_6 26 Jan 2024 09:41:32
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulnerabilities |
1.1_6 24 Jan 2024 18:00:43
    |
Li-Wen Hsu (lwhsu)  |
security/vuxml: Document Jenkins Security Advisory 2024-01-24
Sponsored by: The FreeBSD Foundation |
1.1_6 23 Jan 2024 14:42:22
    |
Bernard Spil (brnrd)  |
security/vuxml: Document TinyMCE vulnerability
* Note that www/tinymce is not affected
* Document supply-chain vuln in Roundcube |
1.1_6 22 Jan 2024 17:47:35
    |
Craig Leres (leres)  |
security/vuxml: Mark zeek < 6.0.3 as vulnerable as per:
https://github.com/zeek/zeek/releases/tag/v6.0.3
This release fixes the following potential DoS vulnerability:
- A specially-crafted series of packets containing nested MIME
entities can cause Zeek to spend large amounts of time parsing
the entities.
Reported by: Tim Wojtulewicz |
1.1_6 19 Jan 2024 06:16:21
    |
Hiroki Tagato (tagattie)  |
security/vuxml: document electron26 uut of bounds memory access in V8
Obtained from: https://github.com/electron/electron/releases/tag/v26.6.7 |
1.1_6 18 Jan 2024 08:04:04
    |
Hiroki Tagato (tagattie)  |
security/vuxml: mark electron26 < 26.6.6, electron27 < 27.2.4 as vulnerable
Obtained from: https://github.com/electron/electron/releases/tag/v26.6.6,
https://github.com/electron/electron/releases/tag/v27.2.4 |
1.1_6 17 Jan 2024 11:18:52
    |
Hiroki Tagato (tagattie)  |
security/vuxml: document electron27 multiple vulnerabilities
Obtained from: https://github.com/electron/electron/releases/tag/v27.2.3 |
1.1_6 17 Jan 2024 08:44:32
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 120.0.6099.224
Obtained
from: https://chromereleases.googleblog.com/2024/01/stable-channel-update-for-desktop_16.html
(cherry picked from commit 105eebecb78a6fcd68b0477fb8ec502a9df29ef2) |
1.1_6 16 Jan 2024 17:24:08
    |
Jan Beich (jbeich)  |
security/vuxml: add xwayland-devel to 62bb32d7090f list |
1.1_6 16 Jan 2024 17:09:39
    |
Emmanuel Vadot (manu)  |
security/vuxml: Document xorg-server and xwayland recent vulnerabilities
Sponsored by: Beckhoff Automation GmbH & Co. KG |
1.1_6 12 Jan 2024 08:50:16
    |
Hiroki Tagato (tagattie)  |
security/vuxml: document electron{26,27} multiple vulnerabilities
Obtained from: https://github.com/electron/electron/releases/tag/v26.6.5,
https://github.com/electron/electron/releases/tag/v27.2.2 |
1.1_6 12 Jan 2024 08:05:31
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulnerabilities |
1.1_6 11 Jan 2024 12:28:25
    |
Bernard Spil (brnrd)  |
security/vuxml: Document OpenSSL ppc vulnerability |
1.1_6 10 Jan 2024 15:39:25
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 120.0.6099.216
Obtained
from: https://chromereleases.googleblog.com/2024/01/stable-channel-update-for-desktop_9.html |
1.1_6 07 Jan 2024 22:19:22
    |
Jason E. Hale (jhale)  |
security/vuxml: Fix copypasta typo |
1.1_6 07 Jan 2024 22:01:55
    |
Jason E. Hale (jhale)  |
security/vuxml: Document QtNetwork buffer overflow
An issue was discovered in the HTTP2 implementation in Qt before 5.15.17,
6.x before 6.2.11, 6.3.x through 6.5.x before 6.5.4, and 6.6.x before
6.6.2. network/access/http2/hpacktable.cpp has an incorrect HPack integer
overflow check.
Base Score: 9.8 CRITICAL
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
1.1_6 06 Jan 2024 16:44:06
    |
Dan Langille (dvl)  |
security/vuxml: add databases/mantis-php* < 2.25.8
Obtained from https://mantisbt.org/bugs/changelog_page.php?version_id=370
PR: 276146 |
1.1_6 04 Jan 2024 07:42:11
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 120.0.6099.199
Obtained
from: https://chromereleases.googleblog.com/2024/01/stable-channel-update-for-desktop.html |
1.1_6 04 Jan 2024 05:56:13
    |
Hiroki Tagato (tagattie)  |
security/vuxml: document electron27 multiple vulnerabilities
Obtained from: https://github.com/electron/electron/releases/tag/v27.2.1 |
1.1_6 04 Jan 2024 05:56:12
    |
Hiroki Tagato (tagattie)  |
security/vuxml: document electron26 multiple vulnerabilities
Obtained from: https://github.com/electron/electron/releases/tag/v26.6.4 |
1.1_6 02 Jan 2024 06:11:10
    |
Philip Paeps (philip)  |
security/vuxml: add FreeBSD SA released on 2023-12-19
FreeBSD-SA-23:19.openssl affects all supported releases of FreeBSD.
FreeBSD 12.4 reached its end of life at the end of December 2023. Users
are encouraged to either implement the documented workaround or leverage
an up to date version of OpenSSH from the ports/pkg collection. |
1.1_6 02 Jan 2024 06:11:09
    |
Philip Paeps (philip)  |
security/vuxml: add 2024 entity |
1.1_6 31 Dec 2023 06:26:05
    |
Matthias Andree (mandree)  |
security/vuxml: unexpand spaces for gitea 482bb980-99a3-11ee-b5f7-6bd56600d90c |
1.1_6 31 Dec 2023 06:23:12
    |
Matthias Andree (mandree)  |
security/vuxml: extend openvpn vuln entry to openvpn-devel < g20231109,1
Security: 2fe004f5-83fd-11ee-9f5d-31909fb2f495
Security: CVE-2023-46849
Security: CVE-2023-46850 |
1.1_6 31 Dec 2023 05:57:51
    |
Jason E. Hale (jhale)  |
security/vuxml: Add www/qt5-webengine
qt5-webengine < 5.15.16.p5_2 is also affected by the following VuXML
IDs:
- 8cdd38c7-8ebb-11ee-86bb-a8a1599412c6
- 4405e9ad-97fe-11ee-86bb-a8a1599412c6 |
1.1_6 30 Dec 2023 23:24:05
    |
Jason E. Hale (jhale)  |
security/vuxml: Add www/qt6-webengine
qt6-webengine < 6.6.1_1 is also affected by the following VuXML IDs:
- 8cdd38c7-8ebb-11ee-86bb-a8a1599412c6
- 4405e9ad-97fe-11ee-86bb-a8a1599412c6 |
1.1_6 29 Dec 2023 18:24:40
    |
Muhammad Moinur Rahman (bofh)  Author: Dmitry Wagin |
devel/zookeeper: Update version 3.8.1=>3.8.3
- Fixes critical security vulnerability
- Return to pool
- Add entry in vuxml
PR: 275999
Approved by: submitter is maintainer |
1.1_6 22 Dec 2023 05:23:10
    |
Hiroki Tagato (tagattie)  |
security/vuxml: document electron multiple vulnerabilities
Obtained from: https://github.com/electron/electron/releases/tag/v26.6.3,
https://github.com/electron/electron/releases/tag/v27.2.0 |
1.1_6 22 Dec 2023 01:24:35
    |
Muhammad Moinur Rahman (bofh)  Author: Stefan Bethke |
www/gitea: Update version 1.21.0=>1.21.3
- Add relevant vuxml entry
- Move pkg-message to SUB_FILES as we are using PREFIX
Changelog: https://blog.gitea.com/release-of-1.21.3/
PR: 275742
Approved by: submitter is maintainer |
1.1_6 21 Dec 2023 09:45:29
    |
Ashish SHUKLA (ashish)  |
security/vuxml: document nebula vulnerability |
1.1_6 21 Dec 2023 07:49:30
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 120.0.6099.129
Obtained
from: https://chromereleases.googleblog.com/2023/12/stable-channel-update-for-desktop_20.html |
1.1_6 19 Dec 2023 22:21:58
    |
Matthias Andree (mandree)  |
security/vuxml: add security/putty[-nogtk] < 0.80 'Terrapin' vulnerability
Security: 91955195-9ebb-11ee-bc14-a703705db3a6
Security: CVE-2023-48795 |
1.1_6 19 Dec 2023 18:06:12
    |
Thierry Thomas (thierry)  |
security/vuxml: add an entry for slurm-wlm |
1.1_6 17 Dec 2023 10:29:43
    |
Dave Cottlehuber (dch)  |
security/vuxml: add CouchDB CVE details
Security: CVE-2023-26268
Sponsored by: SkunkWerks, GmbH |
1.1_6 14 Dec 2023 05:03:50
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulnerabilities |
1.1_6 14 Dec 2023 02:10:59
    |
Philip Paeps (philip)  |
security/vuxml: adjust 12.4 range of FreeBSD SA-23:17.pf
Similar to what I did in 4826396e5d1555b9eebf58cac290490b24bf1243,
adjust the 12.4 releases affected by FreeBSD SA-23:17.pf.
There is no 100% correct way to encode this issue in vuxml. Since the
issue only affects pf.ko, freebsd-update does not rebuild the kernel.
PR: 275743
Reported by: martin@lispworks.com |
1.1_6 13 Dec 2023 12:33:43
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 120.0.6099.109
Obtained
from: https://chromereleases.googleblog.com/2023/12/stable-channel-update-for-desktop_12.html |
1.1_6 13 Dec 2023 06:23:15
    |
Philip Paeps (philip)  |
security/vuxml: add FreeBSD SA released on 2023-12-12
FreeBSD-SA-23:18.nfsclient affects FreeBSD 14.0 and 13.2. |
1.1_6 13 Dec 2023 03:39:47
    |
Jan Beich (jbeich)  |
security/vuxml: mark xorg-server < 21.1.10,1 as vulnerable |
1.1_6 11 Dec 2023 08:23:11
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 120.0.6099.62
Obtained
from: https://chromereleases.googleblog.com/2023/12/stable-channel-update-for-desktop.html |
1.1_6 11 Dec 2023 07:38:52
    |
Fernando Apesteguía (fernape)  |
secuirty/vuxml: Remove duplicate entry
A previous entry for CVE-2023-41913 was added in
8c6ee1a1c2df0d7a769c1fd50f0366ded3798e86
PR: 275620
Reported by: eugen@
Fixes: eea55ca7b5c621fd4f032b1f256b8472fbae2b15 |
1.1_6 10 Dec 2023 17:07:55
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Record kafka vulnerability
Authorization Bypass Through User-Controlled Key vulnerability in Apache
ZooKeeper.
Note that this only affects SASL Quorum Peer authentication which is
not enabled by default.
Base Score: 9.1 CRITICAL
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
PR: 275611 |
1.1_6 10 Dec 2023 16:57:47
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Record strongswan buffer overflow
strongSwan before 5.9.12 has a buffer overflow and possible unauthenticated
remote code execution via a DH public value that exceeds the internal buffer in
charon-tkm's DH proxy. The earliest affected version is 5.3.0. An attack can
occur via a crafted IKE_SA_INIT message.
NVD score not yet provided.
PR: 275620 |
1.1_6 07 Dec 2023 08:54:15
    |
Hiroki Tagato (tagattie)  |
security/vuxml: document electron25 multiple vulnerabilities
Obtained from: https://github.com/electron/electron/releases/tag/v25.9.8 |
1.1_6 07 Dec 2023 04:49:28
    |
Philip Paeps (philip)  |
security/vuxml: correct last SA's affected range
FreeBSD-SA-23:17.pf only affects the kernel, not userland. The first
patch level of the kernel without the vulnerability is 13.2_4, not
13.2_7.
Reported by: dvl |
1.1_6 05 Dec 2023 23:01:20
    |
Philip Paeps (philip)  |
security/vuxml: add FreeBSD SA released on 2023-12-05
FreeBSD-SA-23:17.pf affects all supported releases (12.4, 13.2, 14.0). |
1.1_6 02 Dec 2023 18:42:34
    |
Danilo G. Baio (dbaio)  |
security/vuxml: Add Varnish Cache vulnerability |
1.1_6 01 Dec 2023 18:12:59
    |
Jason E. Hale (jhale)  |
security/vuxml: Add www/qt6-webengine
qt6-webengine < 6.6.1 is also affected by the following VuXML IDs:
- 6d9c6aae-5eb1-11ee-8290-a8a1599412c6
- 07ee8c14-68f1-11ee-8290-a8a1599412c6
- a1e27775-7a61-11ee-8290-a8a1599412c6
- 0da4db89-84bf-11ee-8290-a8a1599412c6 |
1.1_6 01 Dec 2023 06:45:57
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulnerabilities |
1.1_6 01 Dec 2023 05:19:49
    |
Hiroki Tagato (tagattie)  |
security/vuxml: document electron multiple vulnerabilities
Obtained from: https://github.com/electron/electron/releases/tag/v25.9.7,
https://github.com/electron/electron/releases/tag/v26.6.2 |
1.1_6 29 Nov 2023 13:35:20
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 119.0.6045.199
Obtained
from: https://chromereleases.googleblog.com/2023/11/stable-channel-update-for-desktop_28.html |
1.1_6 27 Nov 2023 01:22:00
    |
Jason E. Hale (jhale)  |
security/vuxml: Add devel/cmake-core
VuXML ID d6c19e8c-6806-11ee-9464-b42e991fc52e also affects the bundled
libcurl in devel/cmake-core < 3.27.8. |
1.1_6 26 Nov 2023 17:28:38
    |
Bernard Spil (brnrd)  |
security/vuxml: Document MariaDB vulnerability |
1.1_6 26 Nov 2023 12:53:20
    |
Jason E. Hale (jhale)  |
security/vuxml: Add www/qt5-webengine
VuXML ID 0da4db89-84bf-11ee-8290-a8a1599412c6 also affects
www/qt5-webengine < 5.15.16.p5 |
1.1_6 24 Nov 2023 08:32:26
    |
Eugene Grosbein (eugen)  |
security/vuxml: document strongSwan vulnerability CVE-2023-41913
Security: a62c0c50-8aa0-11ee-ac0d-00e0670f2660
Security: CVE-2023-41913 |
1.1_6 22 Nov 2023 22:49:01
    |
Hiroki Tagato (tagattie)  |
security/vuxml: document electron use after free in Garbage Collection
Obtained from: https://github.com/electron/electron/releases/tag/v25.9.6,
https://github.com/electron/electron/releases/tag/v26.6.1 |
1.1_6 16 Nov 2023 20:33:48
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 119.0.6045.159
Obtained
from: https://chromereleases.googleblog.com/2023/11/stable-channel-update-for-desktop_14.html |
1.1_6 16 Nov 2023 09:02:23
    |
Hiroki Tagato (tagattie)  |
security/vuxml: document electron use after free in WebAudio
Obtained from: https://github.com/electron/electron/releases/tag/v25.9.5,
https://github.com/electron/electron/releases/tag/v26.6.0 |
1.1_6 15 Nov 2023 21:49:26
    |
Matthias Andree (mandree)  |
security/vuxml: 2.6.0 <= openvpn < 2.6.7 vulnerabilities
Related to:
PR: 275055
Security: 2fe004f5-83fd-11ee-9f5d-31909fb2f495
Security: CVE-2023-46849
Security: CVE-2023-46850
This specifically documents < 2.6.7_1 in order to collect the
regression fix for https://github.com/OpenVPN/openvpn/issues/449
which was a bug newly introduced into 2.6.7. |
1.1_6 15 Nov 2023 14:44:30
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Record typo3-1{12} vulnerabilities
PR: 275073 275074 |
1.1_6 09 Nov 2023 15:07:59
    |
Palle Girgensohn (girgen)  |
security/vuxml: add issues for PostgreSQL
https://www.postgresql.org/about/news/postgresql-161-155-1410-1313-1217-and-1122-released-2749/ |
1.1_6 09 Nov 2023 06:27:00
    |
Hiroki Tagato (tagattie)  |
security/vuxml: document electron multiple vulnerabilities
Obtained from: https://github.com/electron/electron/releases/tag/v25.9.4,
https://github.com/electron/electron/releases/tag/v26.5.0 |
1.1_6 08 Nov 2023 22:29:20
    |
Daniel Engberg (diizzy)  |
security/vuxml: Document libsndfile vulnerability
https://nvd.nist.gov/vuln/detail/CVE-2022-33065 |
1.1_6 08 Nov 2023 18:21:31
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 119.0.6045.123
Obtained
from: https://chromereleases.googleblog.com/2023/11/stable-channel-update-for-desktop.html |
1.1_6 08 Nov 2023 16:13:42
    |
Bernard Spil (brnrd)  |
security/vuxml: Document OpenSSL vulnerability |