From nobody Fri Nov 01 00:44:14 2024 X-Original-To: dev-commits-ports-main@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4XfhvL2T9mz5bFd1; Fri, 01 Nov 2024 00:44:14 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R10" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4XfhvL1PZhz4G4S; Fri, 1 Nov 2024 00:44:14 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1730421854; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=Gaq395ykWV/ascG3Rfe4LF158oJQN4+8BWaS4u+ZYys=; b=kT1Ne5Sf+LKyaMA7bcNOMXkWmTlW2f/8ajqgg/dTERdm+imDOvtQ+AUrC82pe7TL7Lb+sQ kLee4BGtn+zHnnH0VuRPUg0ZF3vOPOcfhyRvEfCF9dReHbJ+VQuQFkgqezpzNhkVHYB6hj jpS9Ji/kQ82dEBGsx4JIz79FwACjXoLhBDO1l7w9+gt4xL1kLwJ+Ht4vELq9WT7FiKNUwy Ay7ADuw4dinIp/2slcH2b75oaSYyczjOVYTw31Xf2255YJ8Rx+mQqtuJQr2toJG6zHOSli ShLWLE/qGx2hVpB1UpmqrnQI/RFgNpHcD5mOTlhILC6EFqNisq7SKmxapLVcsQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1730421854; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=Gaq395ykWV/ascG3Rfe4LF158oJQN4+8BWaS4u+ZYys=; b=gAox1wZAozTaxjU+lzb/uhPbKmuSeoXdJ4jWam5kPN8eseRJHIBqcANlnnII81aFOiby0g Ag6aTDndoXPTfCpFa7zZoT8QKP3FCNcoqOI5JZ6yKvjhPHoi6DtmNYfBmW1502DYtT9DF4 o73xLlIC1NJGyvQHKNFtCZ07XhP+vXbMTMuUDUX1Z/to1Z+mmLget4DLNAtPklYdwB2E/j 56IKP2/BmmLnqhHnAgFnVGKxPPm3RpCzL/jwheXxqzcbf4AW6hYJuW8vcpiVQ9EgYSWq7M aQMl1gukrAt7zyDDIcEPPIHPWhDsE8eOycElEtokHR37nTR2TZISrf8uHaKDSQ== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1730421854; a=rsa-sha256; cv=none; b=v1/HFvW0WqbKfezdfFqcZwHJHJZU5EMcg6hC19xYZNsxRrvdPbngM/lJTEC2JKepmPJrAN zModRrucj3d9Rje/jrfFZTkjrj/U5wpVZhs/ggPmo3stQF/H7RLzrzIi0gXhzxmE4bCgA3 N4F+MDs6m573i7CF2jYhZVQ9c6LCHlQhGKdk4YmOetTBEHNBAdlTQ2PmSb4HqzCFhGJI9b XE+4swOZQuKDpGa4984GjfeTf5Qwoa26Ken7gMmonnkCMcE/LiKKkOl1P4d0oj80p1GmBA xPXim4CRhIoMoO//eEvVs+FPCwhedMtZumZI1vfVR7yqA3WzBbGTYf2gps4rEw== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4XfhvL10QFzyRF; Fri, 1 Nov 2024 00:44:14 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.18.1/8.18.1) with ESMTP id 4A10iEjc052659; Fri, 1 Nov 2024 00:44:14 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.18.1/8.18.1/Submit) id 4A10iEiK052656; Fri, 1 Nov 2024 00:44:14 GMT (envelope-from git) Date: Fri, 1 Nov 2024 00:44:14 GMT Message-Id: <202411010044.4A10iEiK052656@gitrepo.freebsd.org> To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-main@FreeBSD.org From: "Jason E. Hale" Subject: git: 6892e780d7d0 - main - security/vuxml: Add www/qt5-webengine < 5.15.18p2 List-Id: Commits to the main branch of the FreeBSD ports repository List-Archive: https://lists.freebsd.org/archives/dev-commits-ports-main List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-ports-main@freebsd.org Sender: owner-dev-commits-ports-main@FreeBSD.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: jhale X-Git-Repository: ports X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: 6892e780d7d0e0840ce737cbe41589f2468bc2a2 Auto-Submitted: auto-generated The branch main has been updated by jhale: URL: https://cgit.FreeBSD.org/ports/commit/?id=6892e780d7d0e0840ce737cbe41589f2468bc2a2 commit 6892e780d7d0e0840ce737cbe41589f2468bc2a2 Author: Jason E. Hale AuthorDate: 2024-11-01 00:41:09 +0000 Commit: Jason E. Hale CommitDate: 2024-11-01 00:41:09 +0000 security/vuxml: Add www/qt5-webengine < 5.15.18p2 Fix indentation issues caught by `make validate` for previous entry. --- security/vuxml/vuln/2024.xml | 78 +++++++++++++++++++++++++++++++++++++------- 1 file changed, 67 insertions(+), 11 deletions(-) diff --git a/security/vuxml/vuln/2024.xml b/security/vuxml/vuln/2024.xml index b3bbd1b07135..a74986da6255 100644 --- a/security/vuxml/vuln/2024.xml +++ b/security/vuxml/vuln/2024.xml @@ -1,22 +1,78 @@ + + qt5-webengine -- Multiple vulnerabilities + + + qt5-webengine + 5.15.18p2 + + + + +
+

Backports for 15 security bugs in Chromium:

+
    +
  • CVE-2024-4761: Out of bounds write in V8
  • +
  • CVE-2024-5158: Type confusion in V8
  • +
  • CVE-2024-7532: Out of bounds memory access in ANGLE
  • +
  • CVE-2024-7965: Inappropriate implementation in V8
  • +
  • CVE-2024-7967: Heap buffer overflow in Fonts
  • +
  • CVE-2024-7971: Type confusion in V8
  • +
  • CVE-2024-8198: Heap buffer overflow in Skia
  • +
  • CVE-2024-8636: Heap buffer overflow in Skia
  • +
  • CVE-2024-9123: Integer overflow in Skia
  • +
  • CVE-2024-9602: Type confusion in V8
  • +
  • CVE-2024-9603: Type confusion in V8
  • +
  • CVE-2024-10229: Inappropriate implementation in Extensions
  • +
  • CVE-2024-45490: Negative length in libexpat
  • +
  • CVE-2024-45491: Integer overflow in libexpat
  • +
  • CVE-2024-45492: Integer overflow in libexpat
  • +
+
+ +
+ + CVE-2024-4761 + CVE-2024-5158 + CVE-2024-7532 + CVE-2024-7965 + CVE-2024-7967 + CVE-2024-7971 + CVE-2024-8198 + CVE-2024-8636 + CVE-2024-9123 + CVE-2024-9602 + CVE-2024-9603 + CVE-2024-10229 + CVE-2024-45490 + CVE-2024-45491 + CVE-2024-45492 + https://code.qt.io/cgit/qt/qtwebengine-chromium.git/log/?h=87-based + + + 2024-09-18 + 2024-10-31 + +
+ keycloak -- Missing server identity checks when sending mails via SMTPS - keycloak - 26.0.4 + keycloak + 26.0.4 -

Red Hat reports:

-
-

A vulnerability was found in Apache Sling Commons Messaging - Mail(angus-mail), which provides a simple interface for sending - emails via SMTPS in OSGi, does not offer an option to enable - server identity checks, leaving connections vulnerable to - "man-in-the-middle" attacks and can allow insecure email - communication.

-
+

Red Hat reports:

+
+

A vulnerability was found in Apache Sling Commons Messaging + Mail(angus-mail), which provides a simple interface for sending + emails via SMTPS in OSGi, does not offer an option to enable + server identity checks, leaving connections vulnerable to + "man-in-the-middle" attacks and can allow insecure email + communication.

+