pkgsrc-Bugs archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]
Re: pkg/60610: doc/pkg-vulnerabilities: add missing upper bounds to open-ended entries
The following reply was made to PR pkg/60610; it has been noted by GNATS.
From: Thomas Klausner <wiz%netbsd.org@localhost>
To: NetBSD bugtracking <gnats-bugs%netbsd.org@localhost>
Cc:
Subject: Re: pkg/60610: doc/pkg-vulnerabilities: add missing upper bounds to
open-ended entries
Date: Fri, 28 Aug 2026 12:19:17 +0200
On Mon, Aug 17, 2026 at 08:25:00AM +0100, Showta Ishizaki via gnats wrote:
> --- pkg-vulnerabilities.cvshead 2026-08-17 16:35:32
> +++ pkg-vulnerabilities.1779.bounds 2026-08-17 17:20:39
> @@ -3829,7 +3829,7 @@
> ap{2,22}-perl<2.0.4nb5 cross-site-scripting https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0796
> unrealircd<3.2.7nb2 denial-of-service http://forums.unrealircd.com/viewtopic.php?t=6204
> ntp<4.2.4p7 arbitrary-code-execution https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0159
> -pptp>1.7.2 information-disclosure https://bugzilla.redhat.com/show_bug.cgi?id=492090
> +pptp<=1.7.2 information-disclosure https://bugzilla.redhat.com/show_bug.cgi?id=492090
> geeklog<1.5.2.2 sql-injection http://www.geeklog.net/article.php/geeklog-1.5.2sr2
> geeklog<1.5.2.3 sql-injection http://www.geeklog.net/article.php/webservices-exploit
> ghostscript<8.64 arbitrary-code-execution https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-6679
Reading the ticket, it seems that 1.7.2-3 was affected and it was only
fixed in 1.7.2-5 in Fedora, so I think the upper bound is wrong.
on the other hand, it talks about file permissions for a config file
which pkgsrc does not install, so I'll comment it out.
> - libbpg>=0.9.5<0.9.8: CVE-2016-5637 affects "0.9.5 through
> 0.9.7". (pkgsrc libbpg has been 0.9.2 since its 2014 import,
> so this entry has never matched anything; bounded for
> correctness.)
CVEs often have this wording - but it doesn't mean it's fixed in newer
versions, it's just that the submitter only tested these versions.
These are the commits for the 0.9.8 release:
https://github.com/mirrorer/libbpg/commit/0e2aadbe40fd8b962440caa51a52c558ccdbc791
so I'm not quite convinced this is fixed, the function restore_tqb_pixels is not
changed, so I'd tend to leave this alone for now.
Except for these, I've applied the diff - thank you very much for
digging into this!
I've replaced a couple SA link with CVE links.
Thomas
Home |
Main Index |
Thread Index |
Old Index