[Bug 280103] www/yt-dlp: update to 2024.07.01 to solve 2 vulnerabilities
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Wed, 03 Jul 2024 01:44:10 UTC
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=280103 Bug ID: 280103 Summary: www/yt-dlp: update to 2024.07.01 to solve 2 vulnerabilities Product: Ports & Packages Version: Latest Hardware: Any OS: Any Status: New Severity: Affects Some People Priority: --- Component: Individual Port(s) Assignee: yuri@freebsd.org Reporter: diario202@outlook.com Flags: maintainer-feedback?(yuri@freebsd.org) Assignee: yuri@freebsd.org I suggest an exp-run, since yt-dlp 2024.07.01 fixes 2 CVEs: Properly sanitize file-extension to prevent file system modification and RCE: https://github.com/yt-dlp/yt-dlp/security/advisories/GHSA-79w7-vh3h-8g4j https://nvd.nist.gov/vuln/detail/CVE-2024-10123 Disallow unsafe extensions: CVE-2024-38519 https://github.com/yt-dlp/yt-dlp/commit/5ce582448ececb8d 9c30c8c31f58330090ced03a -- You are receiving this mail because: You are the assignee for the bug.