From nobody Mon Jul 01 16:46:59 2024 X-Original-To: dev-commits-ports-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4WCX551RPkz5PxQJ; Mon, 01 Jul 2024 16:47:05 +0000 (UTC) (envelope-from leres@freebsd.org) Received: from smtp.freebsd.org (smtp.freebsd.org [96.47.72.83]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "smtp.freebsd.org", Issuer "R10" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4WCX550h4qz4NB3; Mon, 1 Jul 2024 16:47:05 +0000 (UTC) (envelope-from leres@freebsd.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1719852425; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=wrT4I07V0eP0QX7Xh8skmRMbirIcbDcMTNYFo4wLjwg=; b=ilX6dqLSxYuUd0mz00LudkMU5rvWjnA+4YPgAGsEX3jgrHmUAua9pr6Cmya82hgv97XUoR zneWUak0cpbeIZsHXE7vf3ptpOAa1boVfBJUXso+MtoI6u3JkTDG4kXpIDdbHL3NEBBdRU P+7VyYSokGa2f7CVcx8erjRsIBlxR6fN9U6GzoPvSKThbQefq5/QtQgH1G5f9Ll2i0+tAL m8eYhuhCRfEmuQuixzLpztHr9OKmdliolw8J7OKtL4eHEeSb4T9q6/CilFbjQBveWThReS rKL7PHZRjL2jlAZipn3+QnFaxlAZnBmMHRCx9CShm9Qh8k2oBboBv6m+RIOuPw== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1719852425; a=rsa-sha256; cv=none; b=DQpqMB3Yj3J/C3ThZgwlTRu5iRkYpv3yLLa0yw0Cj79XnIziZwSd1ALT2NU8iATvpHF1xW R8NoI5cH69MA+lOCZq8vdhzkShEawvxKfLRm2D3Z4VkeHDeEHClQ5PzXuJWHjxgtzbjAKi XMyGoGbPpvM5Kvg9vk9ZoYaxeYLXVaKj+63OVImBFutjehxt+HGbZC64aTMOmTBZcMWqEN JURJYIq9ex8id3jJK4UnRxmfYfRc+mtfoZa7xCnrAgE1MCjPTwESQ0vlyUyK5VPjMF/m5/ kbJmpQmLT4Ik0B8umzemtwnWcUCj67R5FXWjjWkqzO/Xc4i3qzSwJTfx3BnoRA== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1719852425; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=wrT4I07V0eP0QX7Xh8skmRMbirIcbDcMTNYFo4wLjwg=; b=JYF4+o+yJB8kBMIEFXslV8Tnd+LRVmivH2rjVSxyxIAsRCL0OYgTvRj3OeYGeTweTGiYR5 Sx5tjD95xjN7Zmhj7byIlYT8kAXIXY7850HiZWPiWjXC0mTU7aSSh6AlfrkN/SQLCQiDvn wK1vZopQDxG0mbFfx2SYIoleM7Q6gRh4i8Z3lFcWHNw+yZZO4EGTN2GKzJ8niUxn4EsDPd waJwFzt4bWJfU3YFgCChwOzXIf0drud3HgQXx3at732fRGbsnzFP3Nb5PibzUAaX0wPcET lwsL285Dh8v254YWs4M9o8utIkSu9kY+KFfbP6bEwoDpE9SLYLcLrC59RoYdqw== Received: from [IPV6:fd:1965::2] (unknown [IPv6:2600:1700:ab1b:6800:2e0:edff:fece:8f27]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) (Authenticated sender: leres) by smtp.freebsd.org (Postfix) with ESMTPSA id 4WCX544lVfzRGN; Mon, 1 Jul 2024 16:47:04 +0000 (UTC) (envelope-from leres@freebsd.org) Message-ID: <2892d574-1d19-43e4-8981-f2b8dcd6ad97@freebsd.org> Date: Mon, 1 Jul 2024 09:46:59 -0700 List-Id: Commit messages for all branches of the ports repository List-Archive: https://lists.freebsd.org/archives/dev-commits-ports-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-ports-all@freebsd.org Sender: owner-dev-commits-ports-all@FreeBSD.org MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: git: 66a620a734b4 - main - security/vuxml: Document OpenSSH vulnerability To: Bernard Spil , ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-main@FreeBSD.org References: <202407011055.461AtaUt039539@gitrepo.freebsd.org> From: Craig Leres Content-Language: en-US In-Reply-To: <202407011055.461AtaUt039539@gitrepo.freebsd.org> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit On 7/1/24 03:55, Bernard Spil wrote: > The branch main has been updated by brnrd: > > URL: https://cgit.FreeBSD.org/ports/commit/?id=66a620a734b489596452f342224330207c6e23b1 > > commit 66a620a734b489596452f342224330207c6e23b1 > Author: Bernard Spil > AuthorDate: 2024-07-01 10:55:32 +0000 > Commit: Bernard Spil > CommitDate: 2024-07-01 10:55:32 +0000 > > security/vuxml: Document OpenSSH vulnerability > --- > security/openssh-portable/Makefile | 13 +++++--- > .../openssh-portable/files/patch-CVE-2024-6387 | 36 ++++++++++++++++++++++ > security/vuxml/vuln/2024.xml | 26 ++++++++++++++++ > 3 files changed, 71 insertions(+), 4 deletions(-) > > + openssh-portable > + 9.7_1,1 I think should be 9.7.p1_1,1 (my systems still report as vulnerable after installing) Craig fun 28 # pkg info | fgrep openssh openssh-portable-9.7.p1_1,1 The portable version of OpenBSD's OpenSSH fun 29 # pkg audit -qF -f /var/db/pkg/vuln.xml openssh-portable-9.7.p1_1,1