notbugAs an Amazon Associate I earn from qualifying purchases.
Want a good read? Try FreeBSD Mastery: Jails (IT Mastery Book 15)
Want a good monitor light? See my photosAll times are UTC
Ukraine
non port: security/vuxml/vuln.xml

Number of commits found: 6273 (showing only 100 on this page)

[First Page]  «  4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14  »  [Last Page]

Wednesday, 3 Apr 2019
17:22 romain search for other commits by this committer
Update sysutils/puppetserver5 entry

Puppetlabs released version 5.3.8 of Puppet Server which address the issue:
https://puppet.com/docs/puppetserver/5.3/release_notes.html#puppet-server-538

With hat:	puppet
Original commitRevision:497737 
Tuesday, 2 Apr 2019
20:48 mfechner search for other commits by this committer
Documented gitlab vulnerability.
Original commitRevision:497587 
07:58 brnrd search for other commits by this committer
security/vuxml: Document Apache httpd vulnerabilities
Original commitRevision:497553 
Monday, 1 Apr 2019
19:29 danilo search for other commits by this committer
- Document sysutils/kubectl CVE-2019-1002101
Original commitRevision:497507 
Sunday, 31 Mar 2019
13:50 dbaio search for other commits by this committer
security/vuxml: Document irc/znc issue

Security:	CVE-2019-9917
Original commitRevision:497423 
Friday, 29 Mar 2019
16:36 sunpoet search for other commits by this committer
Document py-notebook vulnerability
Original commitRevision:497167 
14:17 sunpoet search for other commits by this committer
Update openjpeg status
Original commitRevision:497140 
Thursday, 28 Mar 2019
12:21 ler search for other commits by this committer
vuxml: Document mail/dovecot buffer overflow.
Original commitRevision:497014 
08:26 joneum search for other commits by this committer
Add modified line for drupal after r496987

Sponsored by:	Netzkommune GmbH
Original commitRevision:497005 
Wednesday, 27 Mar 2019
21:51 acm search for other commits by this committer
- Update 94d63fd7-508b-11e9-9ba0-4c72b94353b5 entry
Original commitRevision:496987 
19:23 sunpoet search for other commits by this committer
Update Python vulnerability (d74371d2-4fee-11e9-a5cd-1df8a848de3d)
Original commitRevision:496976 
17:44 joneum search for other commits by this committer
Add entry for www/drupal7

Sponsored by:	Netzkommune GmbH
Original commitRevision:496953 
Tuesday, 26 Mar 2019
18:12 sunpoet search for other commits by this committer
Document Python vulnerability
Original commitRevision:496919 
Friday, 22 Mar 2019
04:08 zeising search for other commits by this committer
Update the libXdmcp entry to make it clearer.
Original commitRevision:496547 
Thursday, 21 Mar 2019
09:36 joneum search for other commits by this committer
Add entry for wordpress

Sponsored by:	Netzkommune GmbH
Original commitRevision:496435 
08:15 mfechner search for other commits by this committer
Documented gitlab vulnerability.
Original commitRevision:496430 
02:03 zeising search for other commits by this committer
Add entry for x11/libXdmcp vulnerabilty.

Add entry for x11/libXdmcp vulnerabilty, insufficient entripy generating
session keys.  It is unknown if this actually affects FreeBSD.

Security:	CVE-2017-2625
Original commitRevision:496407 
Wednesday, 20 Mar 2019
14:04 mfechner search for other commits by this committer
Documented security vulnerability for gitlab < 11.8.2.
Original commitRevision:496343 
11:30 joneum search for other commits by this committer
Add entry for www/gitea

PR:		236563
Original commitRevision:496333 
Tuesday, 19 Mar 2019
20:22 jbeich search for other commits by this committer
security/vuxml: mark firefox < 66 as vulnerable
Original commitRevision:496292 
14:51 swills search for other commits by this committer
Document PowerDNS issue

PR:		236634
Reported by:	Dani <i.dani@outlook.com>
Original commitRevision:496262 
Monday, 18 Mar 2019
18:25 sunpoet search for other commits by this committer
Document Rails vulnerability
Original commitRevision:496197 
Sunday, 17 Mar 2019
14:16 mandree search for other commits by this committer
Record PuTTY security vulnerabilities in versions before 0.71.
Original commitRevision:496062 
Saturday, 16 Mar 2019
23:23 sunpoet search for other commits by this committer
Document py-notebook vulnerability
Original commitRevision:495996 
Friday, 15 Mar 2019
21:42 sunpoet search for other commits by this committer
Document ruby-gems vulnerability
Original commitRevision:495829 
Tuesday, 12 Mar 2019
06:14 riggs search for other commits by this committer
Document CVE fixes in libsndfile-1.0.28_2

PR:		227669
Reported by:	p5B2E9A8F@t-online.de
Original commitRevision:495442 
Friday, 8 Mar 2019
02:26 cy search for other commits by this committer
Fill in the actual URL for March 2019 ntp-4.2.8p13 NTP Release and
Security Vulnerability Announcement
Original commitRevision:495009 
Thursday, 7 Mar 2019
19:33 brnrd search for other commits by this committer
security/vuxml: Document OpenSSL 1.1.1 vulnerability
Original commitRevision:494994 
13:32 cy search for other commits by this committer
Document crafted ull dereference ntp attack.

Security:	CVE-2019-8936
Obtained from:	nwtime.org
Original commitRevision:494940 
Wednesday, 6 Mar 2019
19:56 kai search for other commits by this committer
security/vuxml: Document shells/rssh < 2.3.4_2 vulnerabilities

PR:		235121
Approved by:	tcberner (mentor)
Differential Revision:	https://reviews.freebsd.org/D19473
Original commitRevision:494835 
07:31 matthew search for other commits by this committer
Document a jQuery related XSS security fix in rt4.4.4 and rt4.2.16

Note: the release notes also mention 3 other security issues in perl
modules depended on by these packages.  Of those, vulnerabilities in
the Email::Address and Email::Address::List perl modules have already
been addressed in their respective ports, while the third: HTML::Gumbo
is not currently in the ports at all.
Original commitRevision:494780 
Tuesday, 5 Mar 2019
15:00 0mp search for other commits by this committer
Document a slixmpp < 1.4.1 vulnerability

Reviewed by:	krion, mat
Approved by:	krion (mentor), mat (mentor)
MFH:		2019Q1
Original commitRevision:494705 
10:23 mfechner search for other commits by this committer
Doucumented several www/gitlab-ce security vulnerabilities.
Original commitRevision:494691 
06:20 tobik search for other commits by this committer
Document www/py-gunicorn vulnerability
Original commitRevision:494678 
Monday, 4 Mar 2019
10:54 joneum search for other commits by this committer
Update mybb entry

Sponsored by:	Netzkommune GmbH
Original commitRevision:494582 
Sunday, 3 Mar 2019
00:03 bhughes search for other commits by this committer
security/vuxml: document Node.js February 2019 Security Releases

https://nodejs.org/en/blog/vulnerability/february-2019-security-releases/

Sponsored by:	Miles AS
Original commitRevision:494469 
Saturday, 2 Mar 2019
10:29 joneum search for other commits by this committer
Document vulnerability in www/mybb

Sponsored by:	Netzkommune GmbH
Original commitRevision:494381 
Friday, 1 Mar 2019
08:57 madpilot search for other commits by this committer
Document new asterisk vulnerability.

Security:	CVE-2019-7251
Original commitRevision:494243 
Wednesday, 27 Feb 2019
07:33 brnrd search for other commits by this committer
security/vuxml: Update OpenSSL 1.0.2r entry
Original commitRevision:494030 
Sunday, 24 Feb 2019
19:59 kwm search for other commits by this committer
Document webkit-gtk CVE's

Security:	CVE-2019-6212, CVE-2019-6215, CVE-2019-6216, CVE-2019-6217, \
		CVE-2019-6226, CVE-2019-6227, CVE-2019-6229, CVE-2019-6233, \
		CVE-2019-6234.
Original commitRevision:493804 
Friday, 22 Feb 2019
17:58 pi search for other commits by this committer
security/vuxml: dokument rdesktop < 1.8.4 vulnerabilities

PR:		235885, 229029
Original commitRevision:493578 
Thursday, 21 Feb 2019
19:49 romain search for other commits by this committer
Document sysutils/puppetserver* vulnerabilities.

PuppetServer bundles Bouncy Castle, so add affected ports to the Bouncy Castle
entry.

sysutils/puppetserver is EOL and will likely never get a fix;
sysutils/puppetserver5 may get fixed in a future release of the 5.x branch;
sysutils/puppetserver6 was fixed in the latest release.

With hat:	puppet
Original commitRevision:493527 
14:45 acm search for other commits by this committer
- Add drupal8 vulnerability entry
Original commitRevision:493506 
Wednesday, 20 Feb 2019
10:13 brnrd search for other commits by this committer
security/vuxml: Document announced OpenSSL vulnerability

 - To be updated with more specifics on 2019-02-26
Original commitRevision:493418 
Friday, 15 Feb 2019
15:06 novel search for other commits by this committer
Document mail/msmtp certificate verification issue
Original commitRevision:493001 
Wednesday, 13 Feb 2019
11:27 cmt search for other commits by this committer
fix firefox-esr PORTEPOCH in latest entry

Submitted by:	jbeich
Original commitRevision:492852 
11:09 cmt search for other commits by this committer
add more mozilla products to latest entry

https://www.mozilla.org/en-US/security/advisories/mfsa2019-05/
(same CVEs as mfsa2019-04, so not creating another entry)
Original commitRevision:492847 
09:57 cmt search for other commits by this committer
document firefox vulnerabilities

https://www.mozilla.org/en-US/security/advisories/mfsa2019-04/
Original commitRevision:492841 
Tuesday, 12 Feb 2019
15:39 jkim search for other commits by this committer
Document the latest Flash Player vulnerability.

https://helpx.adobe.com/security/products/flash-player/apsb19-06.html
Original commitRevision:492788 
Monday, 11 Feb 2019
19:11 sunpoet search for other commits by this committer
Fix r492723 for the name of NVD report
Original commitRevision:492731 
18:59 sunpoet search for other commits by this committer
Update openjpeg status

There were 5 vulnerabilities in openjpeg and 4 of them are fixed.
The current status  is described in [1] as follows:
- CVE-2017-17479 and CVE-2017-17480 were fixed in r477112.
- CVE-2018-5785 was fixed in r480624.
- CVE-2018-6616 was fixed in r489415.
- CVE-2018-5727 is not fixed yet.

Though I keep committing fixes and updating the status, it does not show in the
"pkg audit" result. Users have to follow the link but apparently few people
would do that. Therefore, I got mails asking if the CVEs are fixed, etc.

I don't know if there's a better way to handle this condition (partly fixed over
several months). Instead of removing fixed CVEs from vuln.xml, I decided to add
a new entry (5efd7a93-2dfb-11e9-9549-e980e869c2e9) which is split from the old
entry (11dc3890-0e64-11e8-99b0-d017c2987f9a). It should be clearer for users if
they only read the "pkg audit" result.

[1] https://www.vuxml.org/freebsd/11dc3890-0e64-11e8-99b0-d017c2987f9a.html
Original commitRevision:492723 
00:11 feld search for other commits by this committer
Document FreeBSD-SA-19:02.fd
Original commitRevision:492661 
00:10 feld search for other commits by this committer
Document FreeBSD-SA-19:01.syscall
Original commitRevision:492660 
Sunday, 10 Feb 2019
18:02 tcberner search for other commits by this committer
Document kf5-kauth vulnerability.
Original commitRevision:492622 
Friday, 8 Feb 2019
01:12 osa search for other commits by this committer
Update versions range for recent unit vulnerability.
Original commitRevision:492404 
01:04 osa search for other commits by this committer
Document unit vulnerability.
Original commitRevision:492402 
Thursday, 7 Feb 2019
23:14 sunpoet search for other commits by this committer
Document curl vulnerability
Original commitRevision:492400 
Wednesday, 6 Feb 2019
09:10 mfechner search for other commits by this committer
Document gitlab-ce vulnerability.
Original commitRevision:492295 
Tuesday, 5 Feb 2019
14:52 ler search for other commits by this committer
mail/dovecot: update reporter for latest vuln
Original commitRevision:492246 
14:39 ler search for other commits by this committer
mail/dovecot: Suitable client certificate can be used to login as other user

update vuxml
Original commitRevision:492242 
Saturday, 2 Feb 2019
21:55 sunpoet search for other commits by this committer
Document typo3 vulnerability

PR:		235187, 235188
Original commitRevision:492007 
01:26 jrm search for other commits by this committer
security/vuxml: Document Gitea < 1.7.1 vulnerabilities

PR:		235399
Submitted by:	stb@lassitu.de (www/gitea maintainer)
Original commitRevision:491910 
Thursday, 31 Jan 2019
19:36 matthew search for other commits by this committer
Document vulnerability addressed by release 0.06 of p5-Email-Address-List

Unfortunately there is very little real description of the
vulnerability available, other than what is in the changelog.  Even
the CVE number only leads to a page saying the number is reserved.
Original commitRevision:491756 
17:42 mfechner search for other commits by this committer
Documented multiple vulnerabilities for www/gitlab-ce.
Original commitRevision:491741 
Wednesday, 30 Jan 2019
11:37 bhughes search for other commits by this committer
security/vuxml: document vulnerabilities in net/turnserver

Sponsored by:	Miles AS
Original commitRevision:491623 
Tuesday, 29 Jan 2019
17:18 jbeich search for other commits by this committer
security/vuxml: mark firefox < 65 as vulnerable
Original commitRevision:491586 
Monday, 28 Jan 2019
16:53 swills search for other commits by this committer
Document powerdns-recursor issue

PR:		235113
Submitted by:	Ralf van der Enden <tremere@cainites.net>
Original commitRevision:491493 
Sunday, 27 Jan 2019
19:58 sunpoet search for other commits by this committer
Update py-requests entry

Reference:	https://lists.freebsd.org/pipermail/svn-ports-head/2019-January/198601.html
Original commitRevision:491395 
15:14 brnrd search for other commits by this committer
security/vuxml: Document recent MySQL vulnerabilities

 - 5.5 branch see https://mariadb.com/kb/en/library/mariadb-5563-release-notes/
Original commitRevision:491356 
09:58 tcberner search for other commits by this committer
security/vuxml: Document security/botan2 vulnerability

PR:		234938
Submitted by:	Ralf van der Enden <tremere@cainites.net> (maintainer)
Original commitRevision:491336 
09:19 matthew search for other commits by this committer
Document PMASA-2019-1 and PMSA-2019-2 security advisories: Arbitrary
file disclosure and SQL injection attacks.
Original commitRevision:491330 
Saturday, 26 Jan 2019
10:54 joneum search for other commits by this committer
Add entry for www/gitea

PR:		235140
Sponsored by:	Netzkommune GmbH
Original commitRevision:491264 
09:49 koobs search for other commits by this committer
security/vuxml: Add libzmq4 -- Remote Code Execution Vulnerability

PR:	230575
Original commitRevision:491255 
Wednesday, 23 Jan 2019
15:10 zi search for other commits by this committer
Fix invalid package name in previous commit for
4af3241d-1f0c-11e9-b4bd-d43d7eed0ce2
Original commitRevision:491044 
14:37 joneum search for other commits by this committer
Add entry for www/apache24

Sponsored by:	Netzkommune GmbH
Original commitRevision:491040 
12:48 lev search for other commits by this committer
 Add CVE-2018-11803 for www/mod_dav_svn.
Original commitRevision:491034 
Tuesday, 22 Jan 2019
12:32 gjb search for other commits by this committer
Attempt to fix vuxml build.

Sponsored by:	The FreeBSD Foundation
Original commitRevision:490941 
10:44 koobs search for other commits by this committer
security/vuxml: Add www/py-requests: Information disclosure vulnerability
Original commitRevision:490936 
Sunday, 20 Jan 2019
01:05 ler search for other commits by this committer
security/vuxml: Document joomla 3 vulnerabilities.
Original commitRevision:490767 
Saturday, 19 Jan 2019
20:37 acm search for other commits by this committer
- Add drupal7 and drupal8 vulnerability entry
Original commitRevision:490737 
Friday, 18 Jan 2019
22:39 danilo search for other commits by this committer
Document helm security advisory
Original commitRevision:490676 
Thursday, 17 Jan 2019
00:14 mfechner search for other commits by this committer
Documented gitlab security vulnerability.
Original commitRevision:490522 
Wednesday, 16 Jan 2019
17:43 lwhsu search for other commits by this committer
Document Jenkins Security Advisory 2019-01-16

Sponsored by:	The FreeBSD Foundation
Original commitRevision:490495 
Tuesday, 15 Jan 2019
12:20 swills search for other commits by this committer
Document py-matrix-synapse issue

PR:		234828
Submitted by:	Sascha Biberhofer <ports@skyforge.at> (with slight editing)
Original commitRevision:490365 
Thursday, 10 Jan 2019
18:59 dbaio search for other commits by this committer
security/vuxml: Document irc/irssi issue

Security:	CVE-2019-5882

PR:		234798
Original commitRevision:489887 
Sunday, 6 Jan 2019
19:30 riggs search for other commits by this committer
Document out-of-bounds vulnerability in net/uriparser < 0.9.1

Reported by:	sebastian@pipping.org (via e-mail)
Original commitRevision:489524 
16:55 swills search for other commits by this committer
Document gitea issue

PR:		234659
Submitted by:	stb@lassitu.de
Original commitRevision:489511 
Saturday, 5 Jan 2019
23:00 sunpoet search for other commits by this committer
Update openjpeg status
Original commitRevision:489417 
13:20 cpm search for other commits by this committer
Document new vulnerability in www/chromium < 71.0.3578.98

Obtained
from:	https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop_12.html
Original commitRevision:489333 
13:10 cpm search for other commits by this committer
Document new vulnerabilities in www/chromium < 71.0.3578.80

Obtained
from:	https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html
Original commitRevision:489329 
08:09 wen search for other commits by this committer
- Documented security vulnerability of Django
Original commitRevision:489303 
Wednesday, 2 Jan 2019
09:03 mfechner search for other commits by this committer
Documented several gitlab-ce security vulnerabilities.

Approved by:	mentors (implicit)
Original commitRevision:489066 
Wednesday, 26 Dec 2018
21:05 swills search for other commits by this committer
Document gitea issue
Original commitRevision:488443 
16:09 rodrigo search for other commits by this committer
Add entry for archivers/rpm4 security isssue on 4.14.2
Original commitRevision:488403 
16:04 tijl search for other commits by this committer
Update handbrake entries now that 1.2.0 has been released.

PR:		234322
Submitted by:	Nei Teng  You Yi Lang  <naito.yuichiro@gmail.com> (maintainer)
Original commitRevision:488402 
Saturday, 22 Dec 2018
07:42 mfechner search for other commits by this committer
Documented security vulnerability for gitlab-ce.

Approved by:	mentors (implicit)
Original commitRevision:488071 
Thursday, 20 Dec 2018
14:50 girgen search for other commits by this committer
Add vuxml entry for shibboleth-sp
Original commitRevision:487884 
09:38 dch search for other commits by this committer
Document databases/couchdb2 and databases/couchdb vulnerability

Approved by:	jrm (mentor)
Security:	CVE-2018-17188
Security:	see http://docs.couchdb.org/en/stable/cve/2018-17188.html
Differential Revision:	https://reviews.freebsd.org/D18498
Original commitRevision:487870 
01:15 leres search for other commits by this committer
Mark bro < 2.6.1 as vulnerable as per:

    https://www.bro.org/download/NEWS.bro.html

The issue is a remote code execution vulnerability in the bundled
sqlite ("Magellan").

Reviewed by:	ler (mentor)
Approved by:	ler (mentor)
Differential Revision:	https://reviews.freebsd.org/D18615
Original commitRevision:487821 
Wednesday, 19 Dec 2018
21:15 feld search for other commits by this committer
Document FreeBSD-SA-18:15.bootpd
Original commitRevision:487817 

Number of commits found: 6273 (showing only 100 on this page)

[First Page]  «  4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14  »  [Last Page]