pkgsrc-Changes archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]
CVS commit: pkgsrc/doc
Module Name: pkgsrc
Committed By: leot
Date: Wed Dec 24 21:19:05 UTC 2025
Modified Files:
pkgsrc/doc: pkg-vulnerabilities
Log Message:
pkg-vulnerabilities: add last days CVEs
+ direwolf (fixed in HEAD, latest 1.8.1 release affected),
fluidsynth, gimp, mariadb-client, net-snmp,
netcdf (probably not fixed),
openexr,
ruby-httparty (fixed upstream, latest 0.23.2 release affected),
To generate a diff of this commit:
cvs rdiff -u -r1.687 -r1.688 pkgsrc/doc/pkg-vulnerabilities
Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.
Modified files:
Index: pkgsrc/doc/pkg-vulnerabilities
diff -u pkgsrc/doc/pkg-vulnerabilities:1.687 pkgsrc/doc/pkg-vulnerabilities:1.688
--- pkgsrc/doc/pkg-vulnerabilities:1.687 Tue Dec 23 19:19:18 2025
+++ pkgsrc/doc/pkg-vulnerabilities Wed Dec 24 21:19:05 2025
@@ -1,4 +1,4 @@
-# $NetBSD: pkg-vulnerabilities,v 1.687 2025/12/23 19:19:18 bsiegert Exp $
+# $NetBSD: pkg-vulnerabilities,v 1.688 2025/12/24 21:19:05 leot Exp $
#
#FORMAT 1.0.0
#
@@ -29136,3 +29136,24 @@ ruby{32,33,34}-aws-sdk-s3<1.208.0 weak-c
thunderbird<146 multiple-vulnerabilities https://www.mozilla.org/en-US/security/advisories/mfsa2025-95/
thunderbird140<140.6 multiple-vulnerabilities https://www.mozilla.org/en-US/security/advisories/mfsa2025-96/
firefox<146.0.1 multiple-vulnerabilities https://www.mozilla.org/en-US/security/advisories/mfsa2025-98/
+direwolf-[0-9]* denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-34457
+direwolf-[0-9]* denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-34458
+fluidsynth<2.5.2 use-after-free https://nvd.nist.gov/vuln/detail/CVE-2025-68617
+gimp<3.2.0 integer-overflow https://nvd.nist.gov/vuln/detail/CVE-2025-14422
+gimp<3.2.0 stack-overflow https://nvd.nist.gov/vuln/detail/CVE-2025-14423
+gimp<3.2.0 use-after-free https://nvd.nist.gov/vuln/detail/CVE-2025-14424
+gimp<3.2.0 heap-overflow https://nvd.nist.gov/vuln/detail/CVE-2025-14425
+mariadb-client<10.6.24 directory-traversal https://nvd.nist.gov/vuln/detail/CVE-2025-13699
+mariadb-client>=10.11<10.11.15 directory-traversal https://nvd.nist.gov/vuln/detail/CVE-2025-13699
+mariadb-client>=11.4<11.4.9 directory-traversal https://nvd.nist.gov/vuln/detail/CVE-2025-13699
+mariadb-client>=11.8<11.8.4 directory-traversal https://nvd.nist.gov/vuln/detail/CVE-2025-13699
+net-snmp<5.9.5 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-68615
+netcdf-[0-9]* stack-overflow https://nvd.nist.gov/vuln/detail/CVE-2025-14932
+netcdf-[0-9]* integer-overflow https://nvd.nist.gov/vuln/detail/CVE-2025-14933
+netcdf-[0-9]* stack-overflow https://nvd.nist.gov/vuln/detail/CVE-2025-14934
+netcdf-[0-9]* heap-overflow https://nvd.nist.gov/vuln/detail/CVE-2025-14935
+netcdf-[0-9]* stack-overflow https://nvd.nist.gov/vuln/detail/CVE-2025-14936
+openexr<3.4.3 heap-overflow https://nvd.nist.gov/vuln/detail/CVE-2025-12495
+openexr<3.4.3 heap-overflow https://nvd.nist.gov/vuln/detail/CVE-2025-12839
+openexr<3.4.3 heap-overflow https://nvd.nist.gov/vuln/detail/CVE-2025-12840
+ruby{32,33,34}-httparty-[0-9]* server-side-request-forgery https://nvd.nist.gov/vuln/detail/CVE-2025-68696
Home |
Main Index |
Thread Index |
Old Index