pkgsrc-Changes archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

CVS commit: pkgsrc/doc



Module Name:    pkgsrc
Committed By:   leot
Date:           Wed Dec 24 21:19:05 UTC 2025

Modified Files:
        pkgsrc/doc: pkg-vulnerabilities

Log Message:
pkg-vulnerabilities: add last days CVEs

+ direwolf (fixed in HEAD, latest 1.8.1 release affected),
  fluidsynth, gimp, mariadb-client, net-snmp,
  netcdf (probably not fixed),
  openexr,
  ruby-httparty (fixed upstream, latest 0.23.2 release affected),


To generate a diff of this commit:
cvs rdiff -u -r1.687 -r1.688 pkgsrc/doc/pkg-vulnerabilities

Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.

Modified files:

Index: pkgsrc/doc/pkg-vulnerabilities
diff -u pkgsrc/doc/pkg-vulnerabilities:1.687 pkgsrc/doc/pkg-vulnerabilities:1.688
--- pkgsrc/doc/pkg-vulnerabilities:1.687        Tue Dec 23 19:19:18 2025
+++ pkgsrc/doc/pkg-vulnerabilities      Wed Dec 24 21:19:05 2025
@@ -1,4 +1,4 @@
-# $NetBSD: pkg-vulnerabilities,v 1.687 2025/12/23 19:19:18 bsiegert Exp $
+# $NetBSD: pkg-vulnerabilities,v 1.688 2025/12/24 21:19:05 leot Exp $
 #
 #FORMAT 1.0.0
 #
@@ -29136,3 +29136,24 @@ ruby{32,33,34}-aws-sdk-s3<1.208.0      weak-c
 thunderbird<146                multiple-vulnerabilities        https://www.mozilla.org/en-US/security/advisories/mfsa2025-95/
 thunderbird140<140.6   multiple-vulnerabilities        https://www.mozilla.org/en-US/security/advisories/mfsa2025-96/
 firefox<146.0.1                multiple-vulnerabilities        https://www.mozilla.org/en-US/security/advisories/mfsa2025-98/
+direwolf-[0-9]*                denial-of-service       https://nvd.nist.gov/vuln/detail/CVE-2025-34457
+direwolf-[0-9]*                denial-of-service       https://nvd.nist.gov/vuln/detail/CVE-2025-34458
+fluidsynth<2.5.2       use-after-free          https://nvd.nist.gov/vuln/detail/CVE-2025-68617
+gimp<3.2.0     integer-overflow        https://nvd.nist.gov/vuln/detail/CVE-2025-14422
+gimp<3.2.0     stack-overflow          https://nvd.nist.gov/vuln/detail/CVE-2025-14423
+gimp<3.2.0     use-after-free          https://nvd.nist.gov/vuln/detail/CVE-2025-14424
+gimp<3.2.0     heap-overflow           https://nvd.nist.gov/vuln/detail/CVE-2025-14425
+mariadb-client<10.6.24         directory-traversal     https://nvd.nist.gov/vuln/detail/CVE-2025-13699
+mariadb-client>=10.11<10.11.15 directory-traversal     https://nvd.nist.gov/vuln/detail/CVE-2025-13699
+mariadb-client>=11.4<11.4.9    directory-traversal     https://nvd.nist.gov/vuln/detail/CVE-2025-13699
+mariadb-client>=11.8<11.8.4    directory-traversal     https://nvd.nist.gov/vuln/detail/CVE-2025-13699
+net-snmp<5.9.5 denial-of-service       https://nvd.nist.gov/vuln/detail/CVE-2025-68615
+netcdf-[0-9]*  stack-overflow          https://nvd.nist.gov/vuln/detail/CVE-2025-14932
+netcdf-[0-9]*  integer-overflow        https://nvd.nist.gov/vuln/detail/CVE-2025-14933
+netcdf-[0-9]*  stack-overflow          https://nvd.nist.gov/vuln/detail/CVE-2025-14934
+netcdf-[0-9]*  heap-overflow           https://nvd.nist.gov/vuln/detail/CVE-2025-14935
+netcdf-[0-9]*  stack-overflow          https://nvd.nist.gov/vuln/detail/CVE-2025-14936
+openexr<3.4.3  heap-overflow   https://nvd.nist.gov/vuln/detail/CVE-2025-12495
+openexr<3.4.3  heap-overflow   https://nvd.nist.gov/vuln/detail/CVE-2025-12839
+openexr<3.4.3  heap-overflow   https://nvd.nist.gov/vuln/detail/CVE-2025-12840
+ruby{32,33,34}-httparty-[0-9]* server-side-request-forgery     https://nvd.nist.gov/vuln/detail/CVE-2025-68696



Home | Main Index | Thread Index | Old Index