pkgsrc-Changes archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]
CVS commit: pkgsrc/doc
Module Name: pkgsrc
Committed By: leot
Date: Fri Jan 30 11:05:48 UTC 2026
Modified Files:
pkgsrc/doc: pkg-vulnerabilities
Log Message:
pkg-vulnerabilities: restrict CVE-2021-39246 to older tor
This was fixed in tor-0.4.6.10 and should be no longer a problem given that v2
onion addresses should be no longer around and supported.
To generate a diff of this commit:
cvs rdiff -u -r1.723 -r1.724 pkgsrc/doc/pkg-vulnerabilities
Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.
Modified files:
Index: pkgsrc/doc/pkg-vulnerabilities
diff -u pkgsrc/doc/pkg-vulnerabilities:1.723 pkgsrc/doc/pkg-vulnerabilities:1.724
--- pkgsrc/doc/pkg-vulnerabilities:1.723 Thu Jan 29 11:48:49 2026
+++ pkgsrc/doc/pkg-vulnerabilities Fri Jan 30 11:05:48 2026
@@ -1,4 +1,4 @@
-# $NetBSD: pkg-vulnerabilities,v 1.723 2026/01/29 11:48:49 leot Exp $
+# $NetBSD: pkg-vulnerabilities,v 1.724 2026/01/30 11:05:48 leot Exp $
#
#FORMAT 1.0.0
#
@@ -22194,7 +22194,7 @@ ansible-base<2.12.0nb1 code-injection ht
curl>=7.73.0<7.79.0 double-free https://nvd.nist.gov/vuln/detail/CVE-2021-22945
libressl-[0-9]* buffer-overflow https://nvd.nist.gov/vuln/detail/CVE-2021-41581
#tor-browser-[0-9]* excessive-logging https://nvd.nist.gov/vuln/detail/CVE-2021-39246 The logging is by tor, not tor-browser
-tor-[0-9]* excessive-logging https://nvd.nist.gov/vuln/detail/CVE-2021-39246
+tor<0.4.6.10 excessive-logging https://nvd.nist.gov/vuln/detail/CVE-2021-39246
openssh>=6.2<8.8 privilege-escalation https://nvd.nist.gov/vuln/detail/CVE-2021-41617
apache>=2.4.49<2.4.50 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2021-41524
apache>=2.4.49<2.4.50 directory-traversal https://nvd.nist.gov/vuln/detail/CVE-2021-41773
Home |
Main Index |
Thread Index |
Old Index