pkgsrc-Bugs archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]
Re: pkg/60609: doc/pkg-vulnerabilities: fix patterns that cannot match any PKGBASE
The following reply was made to PR pkg/60609; it has been noted by GNATS.
From: Showta Ishizaki <zakinko%snowrabbit.org@localhost>
To: gnats-bugs%NetBSD.org@localhost
Cc:
Subject: Re: pkg/60609: doc/pkg-vulnerabilities: fix patterns that cannot match any PKGBASE
Date: Mon, 17 Aug 2026 17:10:58 +0900 (JST)
While preparing the previous patch I noticed one more entry of the
same family that should be fixed together:
gstreamer1<1.222.4 integer-overflow .../CVE-2023-37327
"1.222.4" is a typo for "1.22.4" (the fixed version per GStreamer
SA-2023-0002). In dewey terms 1.222 sorts above 1.26, so as written
the entry currently flags every gstreamer1 version, including current
1.26.x, as vulnerable to this 2023 issue -- a permanent false
positive. Supplementary patch below (applies on top of the previous
one, or independently against rev 1.779).
--- pkg-vulnerabilities.1779.deadfix 2026-08-17 17:03:55
+++ pkg-vulnerabilities.1779.deadfix2 2026-08-17 17:09:52
@@ -28820,7 +28820,7 @@
# Gstreamer Installer, not used by pkgsrc
#gstreamer1-[0-9]* privilege-escalation https://nvd.nist.gov/vuln/detail/CVE-2025-2759
gstreamer1<1.26.1 stack-overflow https://nvd.nist.gov/vuln/detail/CVE-2025-3887
-gstreamer1<1.222.4 integer-overflow https://nvd.nist.gov/vuln/detail/CVE-2023-37327
+gstreamer1<1.22.4 integer-overflow https://nvd.nist.gov/vuln/detail/CVE-2023-37327
gstreamer1<1.22.5 integer-overflow https://nvd.nist.gov/vuln/detail/CVE-2023-38103
gstreamer1<1.22.5 integer-overflow https://nvd.nist.gov/vuln/detail/CVE-2023-38104
gstreamer1<1.22.8 stack-overflow https://nvd.nist.gov/vuln/detail/CVE-2023-50186
Home |
Main Index |
Thread Index |
Old Index