From nobody Fri Jul 19 08:17:38 2024 X-Original-To: dev-commits-ports-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4WQMwy3HlSz5RCmw; Fri, 19 Jul 2024 08:17:38 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R11" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4WQMwy2fQwz4D8y; Fri, 19 Jul 2024 08:17:38 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1721377058; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=/Z9SyJXuN+cxr5ihzyBDC8DcA3IxAMqLUC0FZ4RabE8=; b=gDLhE/3Z82s2HYZs92EXDA1IbMEUYjDKIUNduDhFHoo8PkjBBZQ8BZ/t54B398fRzVLgxg TSuVrethiUHwqEcNfKu+stvTKQUE2cKSUwPUPybIsGN/h1HgpFCdtsGVU1et+oG1vfmXtb MWhE6hU3CaasyLY4DPjCwCpOc9bf4QTXHFIqjReP6/6hbz7nLuU1KIiGeYeVSKO+KU0kDK 3CjSXQQPmRuPME9y1rnXNj2mwbd4OHWY2l54173FVgBZO/F0d9DFfMpfq2d4wuLAtH3UGS oUV/E811KMzKM1u3BFz/rD0HLjA+BKO4kE7FNaG34ILPd408t6ohPOiPXjU/PQ== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1721377058; a=rsa-sha256; cv=none; b=flfDCwcg+L6H88dJ+t8GslDXmz2rGWdB+kEJ/NiOomPLLv5Ez40nE76c12dG4HRqJ8GduY vCFHzFJ2TSWdQuBo8QwEbW1u4rWXSoF15z0nJ+z1DWlTixjoAEVZ5Qe9ZyxZ359vm69fFW LRooFEO5ti4v0ALICeBXx3Ndx+3bbcXB7TJqwdZACYGuP9E+RoofsHeBur3gAyLedut6uc /PnR+IvsPGYYIABQoa4mt/3cM1hEIa9/jDaFTXy7v6tl7Wc5DkOJ+HMNYX9LAb35LybpS1 7JNaVT/N7HU87QG1/OGsOBpsANlXvv7Do6LKmbxZ7VN9qSHtGzthziOWQJM63A== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1721377058; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=/Z9SyJXuN+cxr5ihzyBDC8DcA3IxAMqLUC0FZ4RabE8=; b=fu/+aaYb1PS2UPs8/MhrT/Mjq5R9f3+uVB8LgEhKsXvjB+zr45ZmR/2HOWmCSeAqrkl+xN trMQ8s/ZqoY6cD3BLDi99cVM+POGbrqOJbgbkcugda5hV8bsA7B+ifH/EQ5PLQ8JALXSH0 08gtUXWD4TfojaBI7aefpgaJT03JR0WABIfQQ/IEKalC5nflUmTKg86tSU8FYpoJnQ4phr HgwNaMXWGavP/f+fR1NaPnJKJOAhUX9i/mFnwEl/GjxuNylbbNGof34OQxebveBuV6utgQ 9UwREUakOalgPFK+WDodIICgtZ6VDLNvwqOjs0dmluqRASU/SrXfkUThP4XKbw== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4WQMwy2FxrzPPX; Fri, 19 Jul 2024 08:17:38 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.18.1/8.18.1) with ESMTP id 46J8HcQZ030457; Fri, 19 Jul 2024 08:17:38 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.18.1/8.18.1/Submit) id 46J8Hcfk030454; Fri, 19 Jul 2024 08:17:38 GMT (envelope-from git) Date: Fri, 19 Jul 2024 08:17:38 GMT Message-Id: <202407190817.46J8Hcfk030454@gitrepo.freebsd.org> To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-main@FreeBSD.org From: Hiroki Tagato Subject: git: ce84c5afb89b - main - security/vuxml: document electron29 multiple vulnerabilities List-Id: Commit messages for all branches of the ports repository List-Archive: https://lists.freebsd.org/archives/dev-commits-ports-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-ports-all@freebsd.org Sender: owner-dev-commits-ports-all@FreeBSD.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: tagattie X-Git-Repository: ports X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: ce84c5afb89b497aecf69abaf2b7ae34f7ad380c Auto-Submitted: auto-generated The branch main has been updated by tagattie: URL: https://cgit.FreeBSD.org/ports/commit/?id=ce84c5afb89b497aecf69abaf2b7ae34f7ad380c commit ce84c5afb89b497aecf69abaf2b7ae34f7ad380c Author: Hiroki Tagato AuthorDate: 2024-07-19 08:16:29 +0000 Commit: Hiroki Tagato CommitDate: 2024-07-19 08:17:20 +0000 security/vuxml: document electron29 multiple vulnerabilities Obtained from: https://github.com/electron/electron/releases/tag/v29.4.5 --- security/vuxml/vuln/2024.xml | 38 ++++++++++++++++++++++++++++++++++++++ 1 file changed, 38 insertions(+) diff --git a/security/vuxml/vuln/2024.xml b/security/vuxml/vuln/2024.xml index 1e31f47a5cf4..59130ea70611 100644 --- a/security/vuxml/vuln/2024.xml +++ b/security/vuxml/vuln/2024.xml @@ -1,3 +1,41 @@ + + electron29 -- multiple vulnerabilities + + + electron29 + 29.4.5 + + + + +

Electron developers report:

+
+

This update fixes the following vulnerabilities:

+
    +
  • Security: backported fix for CVE-2024-6291.
  • +
  • Security: backported fix for CVE-2024-6293.
  • +
  • Security: backported fix for CVE-2024-6290.
  • +
  • Security: backported fix for CVE-2024-6292.
  • +
+
+ +
+ + CVE-2024-6291 + https://github.com/advisories/GHSA-rpvg-h6p6-42qj + CVE-2024-6293 + https://github.com/advisories/GHSA-9f8f-453p-rg87 + CVE-2024-6290 + https://github.com/advisories/GHSA-r5mh-qgc2-26p2 + CVE-2024-6292 + https://github.com/advisories/GHSA-m848-8f5r-6j4g + + + 2024-07-17 + 2024-07-19 + +
+ Apache httpd -- Source code disclosure with handlers configured via AddType