FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The VUXML data was last processed by FreshPorts on 2025-03-28 12:03:43 UTC

List all Vulnerabilities, by package

List all Vulnerabilities, by date

k68

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
fe5c1e7a-7eed-11ef-9533-f875a43e1796php -- Multiple vulnerabilities

php.net reports:

  • CVE-2024-8926: CGI: Fixed bug GHSA-9pqp-7h25-4f32 (Bypass of CVE-2024-4577, Parameter Injection Vulnerability).
  • CVE-2024-8927: CGI: Fixed bug GHSA-94p6-54jq-9mwp (cgi.force_redirect configuration is bypassable due to the environment variable collision).
  • CVE-2024-9026: FPM: Fixed bug GHSA-865w-9rf3-2wh5 (Logs from childrens may be altered).
  • CVE-2024-8925: SAPI: Fixed bug GHSA-9pqp-7h25-4f32 (Erroneous parsing of multipart form data).

Discovery 2024-09-26
Entry 2024-09-30
php81
< 8.1.30

php82
< 8.2.24

php83
< 8.3.12

CVE-2024-8926
CVE-2024-8927
CVE-2024-9026
CVE-2024-8925
https://www.php.net/ChangeLog-8.php
2ac2ddc2-0051-11f0-8673-f02f7432cf97php -- Multiple vulnerabilities

php.net reports:

  • CVE-2024-11235: Core: Fixed GHSA-rwp7-7vc6-8477 (Reference counting in php_request_shutdown causes Use-After-Free).
  • CVE-2025-1219: LibXML: Fixed GHSA-p3x9-6h7p-cgfc (libxml streams use wrong `content-type` header when requesting a redirected resource).
  • CVE-2025-1736: Streams: Fixed GHSA-hgf5-96fm-v528 (Stream HTTP wrapper header check might omit basic auth header).
  • CVE-2025-1861: Streams: Fixed GHSA-52jp-hrpf-2jff (Stream HTTP wrapper truncate redirect location to 1024 bytes).
  • CVE-2025-1734: Streams: Fixed GHSA-pcmh-g36c-qc44 (Streams HTTP wrapper does not fail for headers without colon).
  • CVE-2025-1217: Streams: Fixed GHSA-v8xr-gpvj-cx9g (Header parser of `http` stream wrapper does not handle folded headers).

Discovery 2025-03-13
Entry 2025-03-13
php81
< 8.1.32

php82
< 8.2.28

php83
< 8.3.19

php84
< 8.4.5

CVE-2024-11235
CVE-2025-1219
CVE-2025-1736
CVE-2025-1861
CVE-2025-1734
CVE-2025-1217
https://www.php.net/ChangeLog-8.php