pkgsrc-Bugs archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: pkg/60616: doc/pkg-vulnerabilities: fix entries applying CVEs to the wrong product



The following reply was made to PR pkg/60616; it has been noted by GNATS.

From: Showta Ishizaki <zakinko%snowrabbit.org@localhost>
To: gnats-bugs%NetBSD.org@localhost
Cc: 
Subject: Re: pkg/60616: doc/pkg-vulnerabilities: fix entries applying CVEs to the wrong product
Date: Tue, 18 Aug 2026 07:23:36 +0900 (JST)

 A correction and additions for the icinga entries.  The attached
 patch is self-contained for everything icinga-related and
 SUPERSEDES the icinga-base portion of my previous patch (the
 phppgadmin / php / go123 / blosc / py-installer portions of that
 patch are unaffected):
 
 1. The previous patch proposed "icingaweb2<2.6.2" as the
    replacement entry for CVE-2018-18248; that upper bound is
    wrong.  Unlike its four sibling CVEs from the usd-2018-0028
    batch (CVE-2018-18246/18247/18249/18250, all fixed in Icinga
    Web 2 2.6.2 per the companion advisories and NVD), 18248 was
    never fixed: the advisory records "Vendor Status: won't fix"
    (2018-11-08), the 2.6.2 changelog and git range v2.6.1..v2.6.2
    contain no corresponding change, NVD pins 2.6.1 with no
    end-of-range, and the vulnerable dir-parameter handling in
    library/Icinga/Web/Widget/SortBox.php is logically unchanged
    through the latest 2.12.x.  The patch therefore adds an
    UNBOUNDED entry: icingaweb2-[0-9]*.  (pkgsrc's icingaweb2
    2.8.2 is still affected and is flagged correctly by it.)
 
 2. Five more entries of the same family, Icinga Web 2 / Icinga 2
    CVEs written against icinga-base (which packages Icinga 1.x,
    frozen at 1.9.4 -- Icinga 1.x never reached version 2, so
    these can never match):
 
    - icinga-base>=2<2.6.2 x4 -> icingaweb2>=2<2.6.2
      (CVE-2018-18246/18247/18249/18250)
    - icinga-base>=2<2.12.3 -> icinga2>=2.8<2.11.8 plus
      icinga2>=2.12<2.12.3 (CVE-2020-29663: the fix commits are in
      2.11.8 and 2.12.3; 2.12.0/2.12.1 are affected as well -- the
      vulnerable source files are byte-identical across
      2.12.0/2.12.1/2.12.2, so the CVE's "v2.12.2" is branch
      shorthand and NVD's CPE exempting 2.12.0/2.12.1 is an
      encoding artifact.  net/icinga2 has PKGBASE icinga2.)
 
 Thanks as always for the prompt handling of these reports.
 
 Patch against rev 1.779:
 
 --- pkg-vulnerabilities.cvshead	2026-08-17 16:35:32
 +++ pkg-vulnerabilities.1779.icingaA	2026-08-18 07:18:45
 @@ -16401,11 +16401,11 @@
  sqlite3<3.25.3	remote-code-execution		https://nvd.nist.gov/vuln/detail/CVE-2018-20346
  couchdb<2.3.0	remote-privilege-escalation	https://nvd.nist.gov/vuln/detail/CVE-2018-17188
  nagios-base<4.4.3	cross-site-scripting	https://nvd.nist.gov/vuln/detail/CVE-2018-18245
 -icinga-base>=2<2.6.2	cross-site-request-forgery		https://nvd.nist.gov/vuln/detail/CVE-2018-18246
 -icinga-base>=2<2.6.2	cross-site-scripting			https://nvd.nist.gov/vuln/detail/CVE-2018-18247
 -icinga-base>=2		cross-site-scripting			https://nvd.nist.gov/vuln/detail/CVE-2018-18248
 -icinga-base>=2<2.6.2	code-injection				https://nvd.nist.gov/vuln/detail/CVE-2018-18249
 -icinga-base>=2<2.6.2	sensitive-information-disclosure	https://nvd.nist.gov/vuln/detail/CVE-2018-18250
 +icingaweb2>=2<2.6.2	cross-site-request-forgery		https://nvd.nist.gov/vuln/detail/CVE-2018-18246
 +icingaweb2>=2<2.6.2	cross-site-scripting			https://nvd.nist.gov/vuln/detail/CVE-2018-18247
 +#icinga-base>=2		cross-site-scripting			https://nvd.nist.gov/vuln/detail/CVE-2018-18248	# CVE is for Icinga Web 2, not Icinga 1.x; corrected entry added at end of file
 +icingaweb2>=2<2.6.2	code-injection				https://nvd.nist.gov/vuln/detail/CVE-2018-18249
 +icingaweb2>=2<2.6.2	sensitive-information-disclosure	https://nvd.nist.gov/vuln/detail/CVE-2018-18250
  yara-[0-9]*	arbitrary-code-execution	https://nvd.nist.gov/vuln/detail/CVE-2018-19974
  yara-[0-9]*	arbitrary-code-execution	https://nvd.nist.gov/vuln/detail/CVE-2018-19975
  yara-[0-9]*	arbitrary-code-execution	https://nvd.nist.gov/vuln/detail/CVE-2018-19976
 @@ -20424,7 +20424,8 @@
  gdm<3.38.2.1	authentication-bypass	https://nvd.nist.gov/vuln/detail/CVE-2020-27837
  go-text-[0-9]*	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2020-28851
  go-text-[0-9]*	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2020-28852
 -icinga-base>=2<2.12.3	improper-certificate-validation	https://nvd.nist.gov/vuln/detail/CVE-2020-29663
 +icinga2>=2.8<2.11.8	improper-certificate-validation	https://nvd.nist.gov/vuln/detail/CVE-2020-29663
 +icinga2>=2.12<2.12.3	improper-certificate-validation	https://nvd.nist.gov/vuln/detail/CVE-2020-29663
  mantis<2.24.4	sql-injection				https://nvd.nist.gov/vuln/detail/CVE-2020-28413
  mantis<2.24.4	sensitive-information-disclosure	https://nvd.nist.gov/vuln/detail/CVE-2020-35849
  mediawiki<1.35.1	cross-site-scripting			https://nvd.nist.gov/vuln/detail/CVE-2020-35474
 @@ -30424,3 +30425,4 @@
  nginx{,-devel}>=1.31.0<1.31.3	sensitive-information-disclosure	https://nvd.nist.gov/vuln/detail/CVE-2026-60005
  nginx{,-devel}>=0.9.6<1.30.4	heap-overflow	https://nvd.nist.gov/vuln/detail/CVE-2026-42533
  nginx{,-devel}>=1.31.0<1.31.3	heap-overflow	https://nvd.nist.gov/vuln/detail/CVE-2026-42533
 +icingaweb2-[0-9]*	cross-site-scripting	https://nvd.nist.gov/vuln/detail/CVE-2018-18248
 



Home | Main Index | Thread Index | Old Index