pkgsrc-Bugs archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

pkg/60609: doc/pkg-vulnerabilities: fix patterns that cannot match any PKGBASE



>Number:         60609
>Category:       pkg
>Synopsis:       doc/pkg-vulnerabilities: fix patterns that cannot match any PKGBASE
>Confidential:   no
>Severity:       non-critical
>Priority:       medium
>Responsible:    pkg-manager
>State:          open
>Class:          doc-bug
>Submitter-Id:   net
>Arrival-Date:   Mon Aug 17 08:10:00 +0000 2026
>Originator:     Showta Ishizaki
>Release:        NetBSD 10.1 / pkgsrc doc/pkg-vulnerabilities rev 1.779
>Organization:
>Environment:
System: NetBSD bambi.snowrabbit.org 10.1 NetBSD 10.1 (GENERIC) #0: Mon Dec 16 13:08:11 UTC 2024 mkrepro%mkrepro.NetBSD.org@localhost:/usr/src/sys/arch/i386/compile/GENERIC i386
Architecture: i386
Machine: i386
>Description:
	Dewey-style patterns in pkg-vulnerabilities are matched against
	the exact PKGBASE, so an entry written against a package name
	that does not exist can never fire and "pkg_admin audit" users
	are silently never warned.  An audit against rev 1.779 found 92
	such active entries:

	- 80 postgresql-server / postgresql-client entries added since
	  2022 (CVE-2022-1552, CVE-2022-2625, CVE-2024-0985,
	  CVE-2025-1094, CVE-2025-4207, CVE-2025-8713..8715,
	  CVE-2025-12817/12818, CVE-2026-2003..2007, and two eol
	  entries).  The unversioned postgresql packages were removed
	  in 2004 at version 7.4; the real packages are
	  postgresqlNN-server / postgresqlNN-client.  Note the file
	  itself used the correct form for the 2020 CVEs, e.g.
	  "postgresql13-server<13.1" (CVE-2020-25694..25696), so this
	  is a regression in newer entries.  This block also contains
	  5 accidental byte-identical duplicate lines (4x CVE-2026-2004,
	  1x CVE-2026-2005).

	- 12 other entries: djvulibre (3 entries; the packages are
	  djvulibre-lib / djvulibre-tools, all sibling entries already
	  use djvulibre-lib), "qimp" (typo for gimp, CVE-2023-44442),
	  gstreamer (2 entries; the 1.x framework is gstreamer1 /
	  gst-plugins1-*, the 0.8-era "gstreamer" package was removed
	  in 2006), c-ares (the package is libcares; the other 14
	  entries for this library already say libcares; bound also
	  corrected to the actual fix 1.17.1), commonmarker (the gem is
	  rubyNN-commonmarker), yubico-c-client (the package is
	  ykclient), py{NN}-mysql (PyMySQL is packaged as
	  py{NN}-pymysql; bound also corrected to <1.1.1, the actual
	  fixed version of CVE-2024-36039), "php-8.1<8.2" eol entry
	  (the PHP base PKGBASE is "php"; cf. the correct "php>=7.4<8.0"
	  form four lines above), and the
	  p5-Apache-Session-Generate-[0-9]* glob (the affected module
	  Apache::Session::Generate::MD5 ships in the Apache-Session
	  distribution, packaged as p5-Apache-Session; the glob
	  requires a digit after "Generate-" and matches nothing).

	The patch:

	- corrects 85 entries in place where the old pattern never
	  matched any package that ever existed;

	- comments out 7 entries whose pattern DID match a historic
	  package (the pre-2004 unversioned postgresql at <13.23 /
	  <14.21 without a lower bound, and 0.8-era gstreamer at
	  <1.26.3) and adds 7 corrected replacement entries at the end
	  of the file, so behavior for museum systems is preserved in
	  the comment trail;

	- comments out the 5 accidental duplicate lines.

	Thanks as always for the prompt handling of these reports.
>How-To-Repeat:
	pkg_info -e 'postgresql16-server>=0' vs the patterns above;
	grep '^postgresql-server' pkg-vulnerabilities and compare with
	databases/postgresql16-server/Makefile (PKGNAME=
	${DISTNAME:S/-/16-server-/}).
>Fix:
	Apply the following patch (against rev 1.779):

--- pkg-vulnerabilities.cvshead	2026-08-17 16:35:32
+++ pkg-vulnerabilities.1779.deadfix	2026-08-17 17:03:55
@@ -24998,16 +24998,16 @@
 amanda-client<3.3.9nb7	sensitive-information-disclosure	https://nvd.nist.gov/vuln/detail/CVE-2022-37703
 GraphicsMagick<1.3.38	heap-based-buffer-overflow	https://nvd.nist.gov/vuln/detail/CVE-2022-1270
 ap{22,24}-auth-openidc<2.4.12.2	open-redirect	https://nvd.nist.gov/vuln/detail/CVE-2022-23527
-postgresql-server>=10<10.22	arbitrary-command-execution	https://nvd.nist.gov/vuln/detail/CVE-2022-2625
-postgresql-server>=11<11.17	arbitrary-command-execution	https://nvd.nist.gov/vuln/detail/CVE-2022-2625
-postgresql-server>=12<12.12	arbitrary-command-execution	https://nvd.nist.gov/vuln/detail/CVE-2022-2625
-postgresql-server>=13<13.8	arbitrary-command-execution	https://nvd.nist.gov/vuln/detail/CVE-2022-2625
-postgresql-server>=14<14.5	arbitrary-command-execution	https://nvd.nist.gov/vuln/detail/CVE-2022-2625
-postgresql-server>=10<10.21	arbitrary-command-execution	https://nvd.nist.gov/vuln/detail/CVE-2022-1552
-postgresql-server>=11<11.16	arbitrary-command-execution	https://nvd.nist.gov/vuln/detail/CVE-2022-1552
-postgresql-server>=12<12.11	arbitrary-command-execution	https://nvd.nist.gov/vuln/detail/CVE-2022-1552
-postgresql-server>=13<13.7	arbitrary-command-execution	https://nvd.nist.gov/vuln/detail/CVE-2022-1552
-postgresql-server>=14<14.3	arbitrary-command-execution	https://nvd.nist.gov/vuln/detail/CVE-2022-1552
+postgresql10-server<10.22	arbitrary-command-execution	https://nvd.nist.gov/vuln/detail/CVE-2022-2625
+postgresql11-server<11.17	arbitrary-command-execution	https://nvd.nist.gov/vuln/detail/CVE-2022-2625
+postgresql12-server<12.12	arbitrary-command-execution	https://nvd.nist.gov/vuln/detail/CVE-2022-2625
+postgresql13-server<13.8	arbitrary-command-execution	https://nvd.nist.gov/vuln/detail/CVE-2022-2625
+postgresql14-server<14.5	arbitrary-command-execution	https://nvd.nist.gov/vuln/detail/CVE-2022-2625
+postgresql10-server<10.21	arbitrary-command-execution	https://nvd.nist.gov/vuln/detail/CVE-2022-1552
+postgresql11-server<11.16	arbitrary-command-execution	https://nvd.nist.gov/vuln/detail/CVE-2022-1552
+postgresql12-server<12.11	arbitrary-command-execution	https://nvd.nist.gov/vuln/detail/CVE-2022-1552
+postgresql13-server<13.7	arbitrary-command-execution	https://nvd.nist.gov/vuln/detail/CVE-2022-1552
+postgresql14-server<14.3	arbitrary-command-execution	https://nvd.nist.gov/vuln/detail/CVE-2022-1552
 asterisk>=16<16.16.2	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2021-46837
 asterisk>=17<17.9.3	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2021-46837
 asterisk>=18<18.2.2	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2021-46837
@@ -25086,7 +25086,7 @@
 nodejs>=19<19.6.1	security-restrictions-bypass	https://nvd.nist.gov/vuln/detail/CVE-2023-23918
 apache<2.4.56	http-response-splitting	https://nvd.nist.gov/vuln/detail/CVE-2023-27522
 apache<2.4.56	http-response-splitting	https://nvd.nist.gov/vuln/detail/CVE-2023-25690
-yubico-c-client-[0-9]*	eol	https://ftp.NetBSD.org/pub/NetBSD/packages/vulns/eol-packages
+ykclient-[0-9]*	eol	https://ftp.NetBSD.org/pub/NetBSD/packages/vulns/eol-packages
 curl>=7.7<8.00	command-injection	https://nvd.nist.gov/vuln/detail/CVE-2023-27533
 curl>=7.18<8.00	improper-path-limitation	https://nvd.nist.gov/vuln/detail/CVE-2023-27534
 curl>=7.13<8.00	authentication-bypass	https://nvd.nist.gov/vuln/detail/CVE-2023-27535
@@ -25473,8 +25473,8 @@
 libcue<2.2.1nb1	memory-corruption	https://nvd.nist.gov/vuln/detail/CVE-2023-43641
 mutt<2.2.12	null-pointer-dereference	https://nvd.nist.gov/vuln/detail/CVE-2023-4874
 mutt<2.2.12	null-pointer-dereference	https://nvd.nist.gov/vuln/detail/CVE-2023-4875
-djvulibre-[0-9]*	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2021-46312
-djvulibre-[0-9]*	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2021-46310
+djvulibre-lib-[0-9]*	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2021-46312
+djvulibre-lib-[0-9]*	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2021-46310
 grpc<1.53.0	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2023-32732
 grpc>=1.53.0<1.55.0	expected-behavior-violation	https://nvd.nist.gov/vuln/detail/CVE-2023-32731
 grpc>=1.51.0<1.53.0	expected-behavior-violation	https://nvd.nist.gov/vuln/detail/CVE-2023-1428
@@ -25726,7 +25726,7 @@
 exiv2>=0.28<0.28.1	out-of-bounds-write	https://nvd.nist.gov/vuln/detail/CVE-2023-44398
 ltm<1.2.1	integer-overflow	https://nvd.nist.gov/vuln/detail/CVE-2023-36328
 gimp<2.10.36	remote-code-execution	https://nvd.nist.gov/vuln/detail/CVE-2023-44441
-qimp<2.10.36	remote-code-execution	https://nvd.nist.gov/vuln/detail/CVE-2023-44442
+gimp<2.10.36	remote-code-execution	https://nvd.nist.gov/vuln/detail/CVE-2023-44442
 gimp<2.10.36	remote-code-execution	https://nvd.nist.gov/vuln/detail/CVE-2023-44443
 gimp<2.10.36	remote-code-execution	https://nvd.nist.gov/vuln/detail/CVE-2023-44444
 tor<0.4.8.8	unknown-impact	https://gitlab.torproject.org/tpo/core/team/-/wikis/NetworkTeam/TROVE
@@ -25824,7 +25824,7 @@
 coreutils<9.4		heap-overflow	https://nvd.nist.gov/vuln/detail/CVE-2024-0684
 gnutls<3.8.3	timing-side-channel	https://nvd.nist.gov/vuln/detail/CVE-2023-0553
 py{27,38,39,310,311,312}-Pillow<10.2.0	arbitrary-code-execution	https://nvd.nist.gov/vuln/detail/CVE-2023-50447
-postgresql-server>=11<12	eol	https://ftp.NetBSD.org/pub/NetBSD/packages/vulns/eol-packages
+postgresql11-*	eol	https://ftp.NetBSD.org/pub/NetBSD/packages/vulns/eol-packages
 nodejs>=16<18	eol	https://ftp.NetBSD.org/pub/NetBSD/packages/vulns/eol-packages
 py{27,37,38,39,310,311,312}-aiohttp<3.9.2	directory-traversal	https://nvd.nist.gov/vuln/detail/CVE-2024-23334
 py{27,37,38,39,310,311,312}-aiohttp<3.9.2	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2024-23829
@@ -25845,11 +25845,11 @@
 py{37,38,39,310,311,312}-django>=4.1<4.2	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2024-24680
 py{37,38,39,310,311,312}-django>=4.2<4.2.10	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2024-24680
 libuv>=1.24.0<1.48	address-check-bypass	https://nvd.nist.gov/vuln/detail/CVE-2024-24806
-postgresql-server>=12<12.18	arbitrary-command-execution	https://nvd.nist.gov/vuln/detail/CVE-2024-0985
-postgresql-server>=13<13.14	arbitrary-command-execution	https://nvd.nist.gov/vuln/detail/CVE-2024-0985
-postgresql-server>=14<14.11	arbitrary-command-execution	https://nvd.nist.gov/vuln/detail/CVE-2024-0985
-postgresql-server>=15<15.6	arbitrary-command-execution	https://nvd.nist.gov/vuln/detail/CVE-2024-0985
-postgresql-server>=16<16.2	arbitrary-command-execution	https://nvd.nist.gov/vuln/detail/CVE-2024-0985
+postgresql12-server<12.18	arbitrary-command-execution	https://nvd.nist.gov/vuln/detail/CVE-2024-0985
+postgresql13-server<13.14	arbitrary-command-execution	https://nvd.nist.gov/vuln/detail/CVE-2024-0985
+postgresql14-server<14.11	arbitrary-command-execution	https://nvd.nist.gov/vuln/detail/CVE-2024-0985
+postgresql15-server<15.6	arbitrary-command-execution	https://nvd.nist.gov/vuln/detail/CVE-2024-0985
+postgresql16-server<16.2	arbitrary-command-execution	https://nvd.nist.gov/vuln/detail/CVE-2024-0985
 asterisk-13.*		eol		https://ftp.NetBSD.org/pub/NetBSD/packages/vulns/eol-packages
 unbound<1.19.1	denial-of-service	https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-50387
 unbound<1.19.1	denial-of-service	https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-50868
@@ -25973,7 +25973,7 @@
 keepassxc-[0-9]*	sensitive-information-disclosure	https://nvd.nist.gov/vuln/detail/CVE-2024-33900
 keepassxc-[0-9]*	sensitive-information-disclosure	https://nvd.nist.gov/vuln/detail/CVE-2024-33901
 py{27,37,38,39,310,311,312}-requests<2.32.0	sensitive-information-disclosure	https://nvd.nist.gov/vuln/detail/CVE-2024-35195
-py{37,38,39,310,311,312}-mysql<1.1.0	sql-injection	https://nvd.nist.gov/vuln/detail/CVE-2024-36039
+py{37,38,39,310,311,312}-pymysql<1.1.1	sql-injection	https://nvd.nist.gov/vuln/detail/CVE-2024-36039
 gst-plugins1-base<1.24.3	integer-overflow	https://nvd.nist.gov/vuln/detail/CVE-2024-4453
 lighttpd-[0-9]*	sensitive-information-disclosure	https://nvd.nist.gov/vuln/detail/CVE-2024-3708
 libarchive<3.7.4	out-of-bounds-access	https://nvd.nist.gov/vuln/detail/CVE-2024-26256
@@ -26102,13 +26102,13 @@
 openafs>=1.7<1.8.13	denial-of-service	http://openafs.org/pages/security/OPENAFS-SA-2024-002.txt
 openafs<1.6.25		buffer-overflow		http://openafs.org/pages/security/OPENAFS-SA-2024-003.txt
 openafs>=1.7<1.8.13	buffer-overflow		http://openafs.org/pages/security/OPENAFS-SA-2024-003.txt
-postgresql-server>=12<13	eol	https://ftp.NetBSD.org/pub/NetBSD/packages/vulns/eol-packages
+postgresql12-*	eol	https://ftp.NetBSD.org/pub/NetBSD/packages/vulns/eol-packages
 wget<1.25.0	sensitive-information-disclosure	https://nvd.nist.gov/vuln/detail/CVE-2024-10524
 webkit-gtk<2.46.4	remote-code-execution	https://nvd.nist.gov/vuln/detail/CVE-2024-44308
 py{38,39,310,311,312}-django>=4<4.2.17	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2024-53907
 py{38,39,310,311,312}-django>=5<5.1.4	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2024-53907
 curl<8.11.1	credential-leak	https://nvd.nist.gov/vuln/detail/CVE-2024-11053
-gstreamer-1.24.10	multiple-vulnerabilities	https://discourse.gstreamer.org/t/gstreamer-1-24-10-stable-bug-fix-release/3683
+gstreamer1<1.24.10	multiple-vulnerabilities	https://discourse.gstreamer.org/t/gstreamer-1-24-10-stable-bug-fix-release/3683
 firefox<131.0.2			remote-code-execution		https://nvd.nist.gov/vuln/detail/CVE-2024-9680
 firefox128<128.3.1		remote-code-execution		https://nvd.nist.gov/vuln/detail/CVE-2024-9680
 firefox115<115.16.1		remote-code-execution		https://nvd.nist.gov/vuln/detail/CVE-2024-9680
@@ -26126,11 +26126,11 @@
 libtasn1<4.20.0	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2024-12133
 openssl>=3.3<3.3.3	man-in-the-middle	https://nvd.nist.gov/vuln/detail/CVE-2024-12797
 openssl>=3.4<3.4.1	man-in-the-middle	https://nvd.nist.gov/vuln/detail/CVE-2024-12797
-postgresql-server>=13<13.19	sql-injection	https://nvd.nist.gov/vuln/detail/CVE-2025-1094
-postgresql-server>=14<14.16	sql-injection	https://nvd.nist.gov/vuln/detail/CVE-2025-1094
-postgresql-server>=15<15.11	sql-injection	https://nvd.nist.gov/vuln/detail/CVE-2025-1094
-postgresql-server>=16<16.7	sql-injection	https://nvd.nist.gov/vuln/detail/CVE-2025-1094
-postgresql-server>=17<17.3	sql-injection	https://nvd.nist.gov/vuln/detail/CVE-2025-1094
+postgresql13-server<13.19	sql-injection	https://nvd.nist.gov/vuln/detail/CVE-2025-1094
+postgresql14-server<14.16	sql-injection	https://nvd.nist.gov/vuln/detail/CVE-2025-1094
+postgresql15-server<15.11	sql-injection	https://nvd.nist.gov/vuln/detail/CVE-2025-1094
+postgresql16-server<16.7	sql-injection	https://nvd.nist.gov/vuln/detail/CVE-2025-1094
+postgresql17-server<17.3	sql-injection	https://nvd.nist.gov/vuln/detail/CVE-2025-1094
 vim<9.1.1115			use-after-free	https://github.com/vim/vim/security/advisories/GHSA-63p5-mwg2-787v
 libxml2<2.12.10	stack-buffer-overflow		https://nvd.nist.gov/vuln/detail/CVE-2025-24928
 libxml2<2.12.10	use-after-free		https://nvd.nist.gov/vuln/detail/CVE-2024-56171
@@ -26184,11 +26184,11 @@
 liboqs<0.13.0	information-disclosure	https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/Wiu4ZQo3fP8
 py{39,310,311,312,313}-django<4.2.21	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-32873
 py{39,310,311,312,313}-django>=5<5.2.1	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-32873
-postgresql-server>=13<13.21	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-4207
-postgresql-server>=14<14.18	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-4207
-postgresql-server>=15<15.13	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-4207
-postgresql-server>=16<16.9	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-4207
-postgresql-server>=17<17.5	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-4207
+postgresql13-server<13.21	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-4207
+postgresql14-server<14.18	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-4207
+postgresql15-server<15.13	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-4207
+postgresql16-server<16.9	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-4207
+postgresql17-server<17.5	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-4207
 dropbear<2025.88	command-injection	https://nvd.nist.gov/vuln/detail/CVE-2025-47203
 screen<4.9.1nb2	multiple-vulnerabilities	https://security.opensuse.org/2025/05/12/screen-security-issues.html
 screen>=5<5.0.0nb3	multiple-vulnerabilities	https://security.opensuse.org/2025/05/12/screen-security-issues.html
@@ -27118,7 +27118,7 @@
 chromium<138.0.7204.96	sensitive-information-disclosure	https://nvd.nist.gov/vuln/detail/CVE-2025-6554
 cpp-httplib<0.20.1	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-53628
 cpp-httplib<0.20.1	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-53629
-djvulibre<3.5.29	out-of-bounds-read	https://nvd.nist.gov/vuln/detail/CVE-2025-53367
+djvulibre-lib<3.5.29	out-of-bounds-read	https://nvd.nist.gov/vuln/detail/CVE-2025-53367
 dpkg<1.22.21		denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-6297
 gdk-pixbuf2<2.42.12nb3	out-of-bounds-read	https://nvd.nist.gov/vuln/detail/CVE-2025-7345
 git-base>=2.50<2.50.1		buffer-overflow		https://nvd.nist.gov/vuln/detail/CVE-2025-48386
@@ -27132,7 +27132,7 @@
 gnutls<3.8.10		sensitive-information-disclosure	https://nvd.nist.gov/vuln/detail/CVE-2025-32989
 gnutls<3.8.10		denial-of-service			https://nvd.nist.gov/vuln/detail/CVE-2025-32990
 gnutls<3.8.10		denial-of-service			https://nvd.nist.gov/vuln/detail/CVE-2025-6395
-gstreamer<1.26.3	stack-overflow		https://nvd.nist.gov/vuln/detail/CVE-2025-6663
+#gstreamer<1.26.3	stack-overflow		https://nvd.nist.gov/vuln/detail/CVE-2025-6663	# wrong PKGBASE; corrected entry added at end of file
 gtar-[0-9]*		directory-traversal	https://nvd.nist.gov/vuln/detail/CVE-2025-45582
 guacamole-server<1.6.0	arbitrary-code-execution	https://nvd.nist.gov/vuln/detail/CVE-2024-35164
 hdf5-[0-9]*	heap-overflow	https://nvd.nist.gov/vuln/detail/CVE-2025-7067
@@ -27392,21 +27392,21 @@
 libsixel<1.8.7		stack-overflow				https://nvd.nist.gov/vuln/detail/CVE-2025-9300
 libsndfile-[0-9]*	buffer-overflow				https://nvd.nist.gov/vuln/detail/CVE-2025-52194
 libssh<0.112		integer-overflow			https://nvd.nist.gov/vuln/detail/CVE-2025-4877
-postgresql-server>=13<13.22	information-disclosure	https://nvd.nist.gov/vuln/detail/CVE-2025-8713
-postgresql-server>=14<14.19	information-disclosure	https://nvd.nist.gov/vuln/detail/CVE-2025-8713
-postgresql-server>=15<15.14	information-disclosure	https://nvd.nist.gov/vuln/detail/CVE-2025-8713
-postgresql-server>=16<16.10	information-disclosure	https://nvd.nist.gov/vuln/detail/CVE-2025-8713
-postgresql-server>=17<17.6	information-disclosure	https://nvd.nist.gov/vuln/detail/CVE-2025-8713
-postgresql-server>=13<13.22	code-injection		https://nvd.nist.gov/vuln/detail/CVE-2025-8714
-postgresql-server>=14<14.19	code-injection		https://nvd.nist.gov/vuln/detail/CVE-2025-8714
-postgresql-server>=15<15.14	code-injection		https://nvd.nist.gov/vuln/detail/CVE-2025-8714
-postgresql-server>=16<16.10	code-injection		https://nvd.nist.gov/vuln/detail/CVE-2025-8714
-postgresql-server>=17<17.6	code-injection		https://nvd.nist.gov/vuln/detail/CVE-2025-8714
-postgresql-server>=13<13.22	code-injection		https://nvd.nist.gov/vuln/detail/CVE-2025-8715
-postgresql-server>=14<14.19	code-injection		https://nvd.nist.gov/vuln/detail/CVE-2025-8715
-postgresql-server>=15<15.14	code-injection		https://nvd.nist.gov/vuln/detail/CVE-2025-8715
-postgresql-server>=16<16.10	code-injection		https://nvd.nist.gov/vuln/detail/CVE-2025-8715
-postgresql-server>=17<17.6	code-injection		https://nvd.nist.gov/vuln/detail/CVE-2025-8715
+postgresql13-server<13.22	information-disclosure	https://nvd.nist.gov/vuln/detail/CVE-2025-8713
+postgresql14-server<14.19	information-disclosure	https://nvd.nist.gov/vuln/detail/CVE-2025-8713
+postgresql15-server<15.14	information-disclosure	https://nvd.nist.gov/vuln/detail/CVE-2025-8713
+postgresql16-server<16.10	information-disclosure	https://nvd.nist.gov/vuln/detail/CVE-2025-8713
+postgresql17-server<17.6	information-disclosure	https://nvd.nist.gov/vuln/detail/CVE-2025-8713
+postgresql13-server<13.22	code-injection		https://nvd.nist.gov/vuln/detail/CVE-2025-8714
+postgresql14-server<14.19	code-injection		https://nvd.nist.gov/vuln/detail/CVE-2025-8714
+postgresql15-server<15.14	code-injection		https://nvd.nist.gov/vuln/detail/CVE-2025-8714
+postgresql16-server<16.10	code-injection		https://nvd.nist.gov/vuln/detail/CVE-2025-8714
+postgresql17-server<17.6	code-injection		https://nvd.nist.gov/vuln/detail/CVE-2025-8714
+postgresql13-server<13.22	code-injection		https://nvd.nist.gov/vuln/detail/CVE-2025-8715
+postgresql14-server<14.19	code-injection		https://nvd.nist.gov/vuln/detail/CVE-2025-8715
+postgresql15-server<15.14	code-injection		https://nvd.nist.gov/vuln/detail/CVE-2025-8715
+postgresql16-server<16.10	code-injection		https://nvd.nist.gov/vuln/detail/CVE-2025-8715
+postgresql17-server<17.6	code-injection		https://nvd.nist.gov/vuln/detail/CVE-2025-8715
 proftpd<1.3.3d			backdoor		https://nvd.nist.gov/vuln/detail/CVE-2010-20103
 # disputed, this is how Python's import works
 #py{27,39,310,311,312,313}-future-[0-9]*	arbitrary-code-execution	https://nvd.nist.gov/vuln/detail/CVE-2025-50817
@@ -28040,7 +28040,7 @@
 botan>=3<3.5.0	improper-certificate-validation	https://nvd.nist.gov/vuln/detail/CVE-2024-39312
 botan<3.6.0	unspecified			https://nvd.nist.gov/vuln/detail/CVE-2024-50382
 botan<3.6.0	unspecified			https://nvd.nist.gov/vuln/detail/CVE-2024-50383
-c-ares<1.17.0	buffer-overflow		https://nvd.nist.gov/vuln/detail/CVE-2020-22217
+libcares<1.17.1	buffer-overflow		https://nvd.nist.gov/vuln/detail/CVE-2020-22217
 cJSON<1.7.17	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2023-50471
 cJSON<1.7.17	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2023-50472
 cJSON<1.7.18	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2024-31755
@@ -28092,7 +28092,7 @@
 clamav<1.4.2	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-20128
 clojure<1.9.0	arbitrary-code-execution	https://nvd.nist.gov/vuln/detail/CVE-2017-20189
 clojure<1.12.0	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2024-22871
-commonmarker<0.23.4	integer-overflow	https://nvd.nist.gov/vuln/detail/CVE-2024-22051
+ruby{26,27,30,31,32,33,34}-commonmarker<0.23.4	integer-overflow	https://nvd.nist.gov/vuln/detail/CVE-2024-22051
 consul<1.20.1	path-traversal	https://nvd.nist.gov/vuln/detail/CVE-2024-10005
 consul<1.20.1	security-bypass	https://nvd.nist.gov/vuln/detail/CVE-2024-10006
 consul<1.20.0	cross-site-scripting	https://nvd.nist.gov/vuln/detail/CVE-2024-10086
@@ -28916,18 +28916,18 @@
 php{56,74,81,82,83,84}-phppgadmin<9.10	command-injection		https://nvd.nist.gov/vuln/detail/CVE-2025-12763
 php{56,74,81,82,83,84}-phppgadmin<9.10	denial-of-service		https://nvd.nist.gov/vuln/detail/CVE-2025-12764
 php{56,74,81,82,83,84}-phppgadmin<9.10	improper-certificate-validation	https://nvd.nist.gov/vuln/detail/CVE-2025-12765
-postgresql-client<13.23	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-12818
-postgresql-client>=14<14.20	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-12818
-postgresql-client>=15<15.15	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-12818
-postgresql-client>=16<16.11	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-12818
-postgresql-client>=17<17.7	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-12818
-postgresql-client>=18<18.1	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-12818
-postgresql-server<13.23		denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-12817
-postgresql-server>=14<14.20	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-12817
-postgresql-server>=15<15.15	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-12817
-postgresql-server>=16<16.11	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-12817
-postgresql-server>=17<17.7	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-12817
-postgresql-server>=18<18.1	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-12817
+#postgresql-client<13.23	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-12818	# wrong PKGBASE; corrected entry added at end of file
+postgresql14-client<14.20	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-12818
+postgresql15-client<15.15	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-12818
+postgresql16-client<16.11	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-12818
+postgresql17-client<17.7	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-12818
+postgresql18-client<18.1	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-12818
+#postgresql-server<13.23		denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-12817	# wrong PKGBASE; corrected entry added at end of file
+postgresql14-server<14.20	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-12817
+postgresql15-server<15.15	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-12817
+postgresql16-server<16.11	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-12817
+postgresql17-server<17.7	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-12817
+postgresql18-server<18.1	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-12817
 radare2<6.0.5	null-pointer-dereference	https://nvd.nist.gov/vuln/detail/CVE-2025-63744
 radare2<6.0.5	null-pointer-dereference	https://nvd.nist.gov/vuln/detail/CVE-2025-63745
 qjson-[0-9]*	eol		https://ftp.NetBSD.org/pub/NetBSD/packages/vulns/eol-packages
@@ -29326,7 +29326,7 @@
 iperf3<3.14	integer-overflow	https://nvd.nist.gov/vuln/detail/CVE-2023-38403
 iperf3<3.17	timing-side-channel	https://nvd.nist.gov/vuln/detail/CVE-2024-26306
 iperf3<3.18	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2024-53580
-php-8.1<8.2	eol	https://ftp.NetBSD.org/pub/NetBSD/packages/vulns/eol-packages
+php>=8.1<8.2	eol	https://ftp.NetBSD.org/pub/NetBSD/packages/vulns/eol-packages
 php81-*		eol	https://ftp.NetBSD.org/pub/NetBSD/packages/vulns/eol-packages
 chromium<143.0.7499.192 	code-injection	https://nvd.nist.gov/vuln/detail/CVE-2026-0628
 libtasn1<4.21.0	stack-overflow		https://nvd.nist.gov/vuln/detail/CVE-2025-13151
@@ -29906,32 +29906,32 @@
 php{56,74,81,82,83,84}-owncloud-[0-9]*	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2019-25337
 php{56,74,81,82,83,84}-piwigo<15.0.0	insufficiently-random-numbers	https://nvd.nist.gov/vuln/detail/CVE-2024-48928
 php{56,74,81,82,83,84}-piwigo-[0-9]*	information-disclosure	https://nvd.nist.gov/vuln/detail/CVE-2025-62512
-postgresql-server<14.21		input-validation	https://nvd.nist.gov/vuln/detail/CVE-2026-2003
-postgresql-server>=15<15.16	input-validation	https://nvd.nist.gov/vuln/detail/CVE-2026-2003
-postgresql-server>=16<16.12	input-validation	https://nvd.nist.gov/vuln/detail/CVE-2026-2003
-postgresql-server>=17<17.8	input-validation	https://nvd.nist.gov/vuln/detail/CVE-2026-2003
-postgresql-server>=18<18.2	input-validation	https://nvd.nist.gov/vuln/detail/CVE-2026-2003
-postgresql-server<14.21		input-validation	https://nvd.nist.gov/vuln/detail/CVE-2026-2004
-postgresql-server>=15<15.16	input-validation	https://nvd.nist.gov/vuln/detail/CVE-2026-2004
-postgresql-server>=15<15.16	input-validation	https://nvd.nist.gov/vuln/detail/CVE-2026-2004
-postgresql-server>=15<15.16	input-validation	https://nvd.nist.gov/vuln/detail/CVE-2026-2004
-postgresql-server>=15<15.16	input-validation	https://nvd.nist.gov/vuln/detail/CVE-2026-2004
-postgresql-server>=15<15.16	input-validation	https://nvd.nist.gov/vuln/detail/CVE-2026-2004
-postgresql-server>=16<16.12	input-validation	https://nvd.nist.gov/vuln/detail/CVE-2026-2004
-postgresql-server>=17<17.8	input-validation	https://nvd.nist.gov/vuln/detail/CVE-2026-2004
-postgresql-server>=18<18.2	input-validation	https://nvd.nist.gov/vuln/detail/CVE-2026-2004
-postgresql-server<14.21		heap-overflow	https://nvd.nist.gov/vuln/detail/CVE-2026-2005
-postgresql-server>=15<15.16	heap-overflow	https://nvd.nist.gov/vuln/detail/CVE-2026-2005
-postgresql-server>=16<16.12	heap-overflow	https://nvd.nist.gov/vuln/detail/CVE-2026-2005
-postgresql-server>=17<17.8	heap-overflow	https://nvd.nist.gov/vuln/detail/CVE-2026-2005
-postgresql-server>=17<17.8	heap-overflow	https://nvd.nist.gov/vuln/detail/CVE-2026-2005
-postgresql-server>=18<18.2	heap-overflow	https://nvd.nist.gov/vuln/detail/CVE-2026-2005
-postgresql-server<14.21		arbitrary-code-execution	https://nvd.nist.gov/vuln/detail/CVE-2026-2006
-postgresql-server>=15<15.16	arbitrary-code-execution	https://nvd.nist.gov/vuln/detail/CVE-2026-2006
-postgresql-server>=16<16.12	arbitrary-code-execution	https://nvd.nist.gov/vuln/detail/CVE-2026-2006
-postgresql-server>=17<17.8	arbitrary-code-execution	https://nvd.nist.gov/vuln/detail/CVE-2026-2006
-postgresql-server>=18<18.2	arbitrary-code-execution	https://nvd.nist.gov/vuln/detail/CVE-2026-2006
-postgresql-server>=18<18.2	heap-overflow	https://nvd.nist.gov/vuln/detail/CVE-2026-2007
+#postgresql-server<14.21		input-validation	https://nvd.nist.gov/vuln/detail/CVE-2026-2003	# wrong PKGBASE; corrected entry added at end of file
+postgresql15-server<15.16	input-validation	https://nvd.nist.gov/vuln/detail/CVE-2026-2003
+postgresql16-server<16.12	input-validation	https://nvd.nist.gov/vuln/detail/CVE-2026-2003
+postgresql17-server<17.8	input-validation	https://nvd.nist.gov/vuln/detail/CVE-2026-2003
+postgresql18-server<18.2	input-validation	https://nvd.nist.gov/vuln/detail/CVE-2026-2003
+#postgresql-server<14.21		input-validation	https://nvd.nist.gov/vuln/detail/CVE-2026-2004	# wrong PKGBASE; corrected entry added at end of file
+postgresql15-server<15.16	input-validation	https://nvd.nist.gov/vuln/detail/CVE-2026-2004
+#postgresql15-server<15.16	input-validation	https://nvd.nist.gov/vuln/detail/CVE-2026-2004	# accidental duplicate of the previous line
+#postgresql15-server<15.16	input-validation	https://nvd.nist.gov/vuln/detail/CVE-2026-2004	# accidental duplicate of the previous line
+#postgresql15-server<15.16	input-validation	https://nvd.nist.gov/vuln/detail/CVE-2026-2004	# accidental duplicate of the previous line
+#postgresql15-server<15.16	input-validation	https://nvd.nist.gov/vuln/detail/CVE-2026-2004	# accidental duplicate of the previous line
+postgresql16-server<16.12	input-validation	https://nvd.nist.gov/vuln/detail/CVE-2026-2004
+postgresql17-server<17.8	input-validation	https://nvd.nist.gov/vuln/detail/CVE-2026-2004
+postgresql18-server<18.2	input-validation	https://nvd.nist.gov/vuln/detail/CVE-2026-2004
+#postgresql-server<14.21		heap-overflow	https://nvd.nist.gov/vuln/detail/CVE-2026-2005	# wrong PKGBASE; corrected entry added at end of file
+postgresql15-server<15.16	heap-overflow	https://nvd.nist.gov/vuln/detail/CVE-2026-2005
+postgresql16-server<16.12	heap-overflow	https://nvd.nist.gov/vuln/detail/CVE-2026-2005
+postgresql17-server<17.8	heap-overflow	https://nvd.nist.gov/vuln/detail/CVE-2026-2005
+#postgresql17-server<17.8	heap-overflow	https://nvd.nist.gov/vuln/detail/CVE-2026-2005	# accidental duplicate of the previous line
+postgresql18-server<18.2	heap-overflow	https://nvd.nist.gov/vuln/detail/CVE-2026-2005
+#postgresql-server<14.21		arbitrary-code-execution	https://nvd.nist.gov/vuln/detail/CVE-2026-2006	# wrong PKGBASE; corrected entry added at end of file
+postgresql15-server<15.16	arbitrary-code-execution	https://nvd.nist.gov/vuln/detail/CVE-2026-2006
+postgresql16-server<16.12	arbitrary-code-execution	https://nvd.nist.gov/vuln/detail/CVE-2026-2006
+postgresql17-server<17.8	arbitrary-code-execution	https://nvd.nist.gov/vuln/detail/CVE-2026-2006
+postgresql18-server<18.2	arbitrary-code-execution	https://nvd.nist.gov/vuln/detail/CVE-2026-2006
+postgresql18-server<18.2	heap-overflow	https://nvd.nist.gov/vuln/detail/CVE-2026-2007
 py{27,310,311,312,313,314}-Pillow<12.1.1	out-of-bounds-write	https://nvd.nist.gov/vuln/detail/CVE-2026-25990
 py{27,310,311,312,313,314}-flask<3.1.3	sensitive-information-disclosure	https://nvd.nist.gov/vuln/detail/CVE-2026-27205
 py{27,310,311,312,313,314}-nltk<3.9.3	arbitrary-code-execution	https://nvd.nist.gov/vuln/detail/CVE-2025-14009
@@ -30145,7 +30145,7 @@
 mold-[0-9]*	heap-overflow	https://nvd.nist.gov/vuln/detail/CVE-2026-3994
 openexr<3.4.6	out-of-bounds-write	https://nvd.nist.gov/vuln/detail/CVE-2026-27622
 openssl<3.6.2	security-bypass	https://nvd.nist.gov/vuln/detail/CVE-2026-2673
-p5-Apache-Session-Generate-[0-9]*	weak-cryptography	https://nvd.nist.gov/vuln/detail/CVE-2025-40931
+p5-Apache-Session-[0-9]*	weak-cryptography	https://nvd.nist.gov/vuln/detail/CVE-2025-40931
 php{56,74,81,82,83,84}-concrete-cms<9.4.8	cross-site-request-forgery	https://nvd.nist.gov/vuln/detail/CVE-2026-2994
 php{56,74,81,82,83,84}-concrete-cms<9.4.8	cross-site-scripting	https://nvd.nist.gov/vuln/detail/CVE-2026-3240
 php{56,74,81,82,83,84}-concrete-cms<9.4.8	cross-site-scripting	https://nvd.nist.gov/vuln/detail/CVE-2026-3241
@@ -30424,3 +30424,10 @@
 nginx{,-devel}>=1.31.0<1.31.3	sensitive-information-disclosure	https://nvd.nist.gov/vuln/detail/CVE-2026-60005
 nginx{,-devel}>=0.9.6<1.30.4	heap-overflow	https://nvd.nist.gov/vuln/detail/CVE-2026-42533
 nginx{,-devel}>=1.31.0<1.31.3	heap-overflow	https://nvd.nist.gov/vuln/detail/CVE-2026-42533
+gst-plugins1-bad<1.26.3	stack-overflow		https://nvd.nist.gov/vuln/detail/CVE-2025-6663
+postgresql13-client<13.23	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-12818
+postgresql13-server<13.23	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-12817
+postgresql14-server<14.21	input-validation	https://nvd.nist.gov/vuln/detail/CVE-2026-2003
+postgresql14-server<14.21	input-validation	https://nvd.nist.gov/vuln/detail/CVE-2026-2004
+postgresql14-server<14.21	heap-overflow	https://nvd.nist.gov/vuln/detail/CVE-2026-2005
+postgresql14-server<14.21	arbitrary-code-execution	https://nvd.nist.gov/vuln/detail/CVE-2026-2006




Home | Main Index | Thread Index | Old Index