pkgsrc-Changes archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

CVS commit: pkgsrc/doc



Module Name:    pkgsrc
Committed By:   leot
Date:           Tue Jun 17 13:44:43 UTC 2025

Modified Files:
        pkgsrc/doc: pkg-vulnerabilities

Log Message:
pkg-vulnerabilities: Add recent CVEs

+ gimp, glib2, kafka, konsole, libarchive, libtpms, metabase,
  ncurses (fixed on 20250329 devel version, latest 6.5 affected),
  openssl, p5-CryptX,
  pspp (probably not fixed, no feedbacks from upstream in the bug report),
  py-octoprint, py-protobuf


To generate a diff of this commit:
cvs rdiff -u -r1.424 -r1.425 pkgsrc/doc/pkg-vulnerabilities

Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.

Modified files:

Index: pkgsrc/doc/pkg-vulnerabilities
diff -u pkgsrc/doc/pkg-vulnerabilities:1.424 pkgsrc/doc/pkg-vulnerabilities:1.425
--- pkgsrc/doc/pkg-vulnerabilities:1.424        Tue Jun 17 10:44:12 2025
+++ pkgsrc/doc/pkg-vulnerabilities      Tue Jun 17 13:44:43 2025
@@ -1,4 +1,4 @@
-# $NetBSD: pkg-vulnerabilities,v 1.424 2025/06/17 10:44:12 leot Exp $
+# $NetBSD: pkg-vulnerabilities,v 1.425 2025/06/17 13:44:43 leot Exp $
 #
 #FORMAT 1.0.0
 #
@@ -26385,3 +26385,24 @@ chromium<137.0.7151.103        use-after-free          
 chromium<137.0.7151.103        arbitrary-code-execution        https://nvd.nist.gov/vuln/detail/CVE-2025-5959
 firefox<139.0.4                multiple-vulnerabilities        https://www.mozilla.org/en-US/security/advisories/mfsa2025-47/
 thunderbird<139.0.2            multiple-vulnerabilities        https://www.mozilla.org/en-US/security/advisories/mfsa2025-50/
+gimp<3.0.4     integer-overflow        https://nvd.nist.gov/vuln/detail/CVE-2025-6035
+glib2<2.84.3   memory-corruption       https://nvd.nist.gov/vuln/detail/CVE-2025-6052
+kafka<3.9.1    server-side-request-forgery     https://nvd.nist.gov/vuln/detail/CVE-2025-27817
+kafka<3.9.1    remote-code-execution           https://nvd.nist.gov/vuln/detail/CVE-2025-27818
+kafka<3.9.1    remote-code-execution           https://nvd.nist.gov/vuln/detail/CVE-2025-27819
+konsole<25.04.2        remote-code-execution           https://nvd.nist.gov/vuln/detail/CVE-2025-49091
+libarchive<3.8.0       double-free             https://nvd.nist.gov/vuln/detail/CVE-2025-5914
+libarchive<3.8.0       out-of-bounds-read      https://nvd.nist.gov/vuln/detail/CVE-2025-5915
+libarchive<3.8.0       integer-overflow        https://nvd.nist.gov/vuln/detail/CVE-2025-5916
+libarchive<3.8.0       out-of-bounds-write     https://nvd.nist.gov/vuln/detail/CVE-2025-5917
+libarchive<3.8.0       out-of-bounds-read      https://nvd.nist.gov/vuln/detail/CVE-2025-5918
+libtpms<0.10.1         out-of-bounds-read      https://nvd.nist.gov/vuln/detail/CVE-2025-49133
+metabase<0.54.5                denial-of-service       https://nvd.nist.gov/vuln/detail/CVE-2025-5895
+ncurses-[0-9]*         stack-overflow          https://nvd.nist.gov/vuln/detail/CVE-2025-6141
+openssl<3.5.0          side-channel            https://nvd.nist.gov/vuln/detail/CVE-2025-27587
+p5-CryptX<0.065                denial-of-service       https://nvd.nist.gov/vuln/detail/CVE-2025-40912
+pspp-[0-9]*            out-of-bounds-write     https://nvd.nist.gov/vuln/detail/CVE-2025-5898
+pspp-[0-9]*            denial-of-service       https://nvd.nist.gov/vuln/detail/CVE-2025-5899
+py{39,310,311,312,313}-octoprint<1.11.2        path-traversal          https://nvd.nist.gov/vuln/detail/CVE-2025-48067
+py{39,310,311,312,313}-octoprint<1.11.2        denial-of-service       https://nvd.nist.gov/vuln/detail/CVE-2025-48879
+py{39,310,311,312,313}-protobuf<6.31.1 denial-of-service       https://nvd.nist.gov/vuln/detail/CVE-2025-4565



Home | Main Index | Thread Index | Old Index