From nobody Wed Sep 20 12:27:00 2023 X-Original-To: ports-bugs@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4RrHpX6Sknz4tbqQ for ; Wed, 20 Sep 2023 12:27:00 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4RrHpX5RgTz3L06 for ; Wed, 20 Sep 2023 12:27:00 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1695212820; a=rsa-sha256; cv=none; b=a89djAP40Pr5df1h8hJOH04/3cnBK4Ug0BgNNqZ3FQCFwOIDbbgWBRTEN9hgOUh3ex6paf DtfzXDgKTGHHu2X0pVpKCz4FqBMt4mmHh4KC6muLD07udZ9Squ27i9eK1o+NpONmmT3bI8 /PlX4vzEgihfHMg0gaLB+q9t2QSbFPmozRXCZLys6pMeynPoeqnvi9AT07EMKir+nm1Y51 s+VYR/fLiv0iOsjkNB84J+Nl9mJwl6WPIijujrHLm2x1odf9WEBI9yT8ft6oo0lNhyQpGS 6rGzCpDSOzs0avvqCOap9/TKWdilvw0TyA3fEVgkeXm6vAbAuFWsB5W9BRTjMA== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1695212820; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=39hr76kHRWiSG+xvLKEzjAqSSIeG0rJIZRKKswle2IY=; b=Q0k9ZelG1R5EaJUYrEDXBYigNztr/Oe8/Ex46A81JowdyKjE6z/W8AsilOfthwHKSNQRvI s4WzELYVVy2xH3dlbYeyNu+tu7WVku94fRCLf3hCRCc03d9bWb0jXUQ8zUnn0KA2AyKVST S59D3pOvF5hEokTmyIS9oqjGP4b5bomNvrp2kKQZd8CN5uE5mHokeEFNxQDAI1td2Ejy8C lM7ZaV1cpYzUDnCJBlSas8j5Bu4HutkgSyOJuQBjNDktzyONWrdlu9uWYyPWFCOjfWxHNY SUhgNovVTBxI2FXPzEoFkUNhDKF0w4zrzL/SybPk4qKxQkwiPNpxnsJzX+o5lQ== Received: from kenobi.freebsd.org (kenobi.freebsd.org [IPv6:2610:1c1:1:606c::50:1d]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4RrHpX4WtFzvs1 for ; Wed, 20 Sep 2023 12:27:00 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from kenobi.freebsd.org ([127.0.1.5]) by kenobi.freebsd.org (8.15.2/8.15.2) with ESMTP id 38KCR0HL021140 for ; Wed, 20 Sep 2023 12:27:00 GMT (envelope-from bugzilla-noreply@freebsd.org) Received: (from bugzilla@localhost) by kenobi.freebsd.org (8.15.2/8.15.2/Submit) id 38KCR0hI021139 for ports-bugs@FreeBSD.org; Wed, 20 Sep 2023 12:27:00 GMT (envelope-from bugzilla-noreply@freebsd.org) X-Authentication-Warning: kenobi.freebsd.org: bugzilla set sender to bugzilla-noreply@freebsd.org using -f From: bugzilla-noreply@freebsd.org To: ports-bugs@FreeBSD.org Subject: [Bug 273416] www/tor-browser: Update to 12.0.7 or upgrade to 12.5.2 Date: Wed, 20 Sep 2023 12:27:00 +0000 X-Bugzilla-Reason: AssignedTo X-Bugzilla-Type: changed X-Bugzilla-Watch-Reason: None X-Bugzilla-Product: Ports & Packages X-Bugzilla-Component: Individual Port(s) X-Bugzilla-Version: Latest X-Bugzilla-Keywords: needs-patch X-Bugzilla-Severity: Affects Many People X-Bugzilla-Who: commit-hook@FreeBSD.org X-Bugzilla-Status: Open X-Bugzilla-Resolution: X-Bugzilla-Priority: --- X-Bugzilla-Assigned-To: ports-bugs@FreeBSD.org X-Bugzilla-Flags: maintainer-feedback? X-Bugzilla-Changed-Fields: Message-ID: In-Reply-To: References: Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable X-Bugzilla-URL: https://bugs.freebsd.org/bugzilla/ Auto-Submitted: auto-generated List-Id: Ports bug reports List-Archive: https://lists.freebsd.org/archives/freebsd-ports-bugs List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-freebsd-ports-bugs@freebsd.org X-BeenThere: freebsd-ports-bugs@freebsd.org MIME-Version: 1.0 https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D273416 --- Comment #2 from commit-hook@FreeBSD.org --- A commit in branch main references this bug: URL: https://cgit.FreeBSD.org/ports/commit/?id=3D2e8c97b9bc3f7c6c14c30676f3c32f3= 2c464e97b commit 2e8c97b9bc3f7c6c14c30676f3c32f32c464e97b Author: Fernando Apestegu=C3=ADa AuthorDate: 2023-09-20 12:21:30 +0000 Commit: Fernando Apestegu=C3=ADa CommitDate: 2023-09-20 12:21:30 +0000 security/vuxml: Add Tor browser libwebp vulnerability CVE-2023-4863 Base Score: 8.8 HIGH Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H PR: 273416 Reported by: kaltheat Security: CVE-2023-4863 security/vuxml/vuln/2023.xml | 31 +++++++++++++++++++++++++++++++ 1 file changed, 31 insertions(+) --=20 You are receiving this mail because: You are the assignee for the bug.=