From nobody Thu Sep 05 02:26:52 2024 X-Original-To: freebsd-security@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4WzjtL3Vb8z5WVSB for ; Thu, 05 Sep 2024 02:27:06 +0000 (UTC) (envelope-from crispy.james.watt@gmail.com) Received: from mail-wm1-x32c.google.com (mail-wm1-x32c.google.com [IPv6:2a00:1450:4864:20::32c]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (2048 bits) client-digest SHA256) (Client CN "smtp.gmail.com", Issuer "WR4" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4WzjtK5V9Rz4fb9 for ; Thu, 5 Sep 2024 02:27:05 +0000 (UTC) (envelope-from crispy.james.watt@gmail.com) Authentication-Results: mx1.freebsd.org; dkim=pass header.d=gmail.com header.s=20230601 header.b="CD5iE6/4"; dmarc=pass (policy=none) header.from=gmail.com; spf=pass (mx1.freebsd.org: domain of crispy.james.watt@gmail.com designates 2a00:1450:4864:20::32c as permitted sender) smtp.mailfrom=crispy.james.watt@gmail.com Received: by mail-wm1-x32c.google.com with SMTP id 5b1f17b1804b1-428e0d184b4so1093255e9.2 for ; Wed, 04 Sep 2024 19:27:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1725503224; x=1726108024; darn=freebsd.org; h=to:subject:message-id:date:from:mime-version:from:to:cc:subject :date:message-id:reply-to; bh=xakDfVNdOiJG87BJ3SvmsjWP/lIb8ATFd8C/NpNF734=; b=CD5iE6/4grNP3K2NJ8YjZ/BMfVeGQSR+WaAoj9HQznxZY5hjwHHGMWSKlF/Ku8XmJ3 WLAlV73LHwi4hVb0ixIkvup5JVaRnOzTyp1mbi6brgceqsWAfO6tdAW/7hQa7MxeGeuR Gmh/CTNDbNHdp0Oj86HonOtw0Ls0WHkByBVnYJGlfVK8Eb1K9UNG4LZV755YhJOnN8Nv LPdJ4hWystrj6B5Endm4QDLegVbrc5QCKJCJFZfEuwVMRLDhIxiGBCS+rqWXD6mLsLSl Ps6681oaatalSn2M5BAdgBi5FqfMZQyPe61yaMFBEEgXiJOYwqfTDSzF5i9Xuah7QZxR CZNQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1725503224; x=1726108024; h=to:subject:message-id:date:from:mime-version:x-gm-message-state :from:to:cc:subject:date:message-id:reply-to; bh=xakDfVNdOiJG87BJ3SvmsjWP/lIb8ATFd8C/NpNF734=; b=nTCXI5ptZifkP1r3cIFlEQE51ylynIGyzDFOONzJRajx/N9q5SImDTE29rDZcaL9O0 nYUSrE1ydsLr8UV9wvlsE6OfOvq91wxNB0c/dtjiNaitKjiJqWQOC0ZnrtoGbD0wMCK9 t2Qq8lsx9PD6a+WD6bSkSolog6fVbeFC3o2KZXVcPhLq2nujhGUqAYuknHC/T6lEPec4 m5ha8JZJ34JV2BSQt0bM24GIOxqa7YdcUDFdnA11awKk+rK3gGH1AIlYNakj76D/qPCC i8i0KCGONxAtdam++zPPNH7mBIBpBTPCcsUlYJkWPQA+/myM5T0usWOjlQiGRIG+i3sp U+Sw== X-Gm-Message-State: AOJu0YxeJmpYJbXjHjoYpVjanRv894S0TE2slITu6y0uRwZHmbuI9YaO svIBLG9M5GF/9UgE7KkRKYUlga8czbu3rDd25saPLkZ8y+iQFgKFLa5OKLtuaCJQhQNy2pytNXY gcY0ZQ53KH9aI2TLm8M8GlGkaCPtM6QV4 X-Google-Smtp-Source: AGHT+IHzH22Y00031Z4930et6SYkQgM6P1sMUmwIyzwKk+C/Mk6VBnRfDQm5s36bv5EofO0tly2HnzeLED8jHB0lVlo= X-Received: by 2002:a05:600c:4f4b:b0:426:629f:1556 with SMTP id 5b1f17b1804b1-42c7b5f0cf8mr99250565e9.31.1725503223002; Wed, 04 Sep 2024 19:27:03 -0700 (PDT) List-Id: Security issues List-Archive: https://lists.freebsd.org/archives/freebsd-security List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: freebsd-security@freebsd.org Sender: owner-freebsd-security@FreeBSD.org MIME-Version: 1.0 From: James Watt Date: Thu, 5 Sep 2024 10:26:52 +0800 Message-ID: Subject: =?UTF-8?Q?Security_vulnerability=E2=80=94_action_required=EF=BC=9Aplease_u?= =?UTF-8?Q?pdate_openssh_in_you_project_of_releng=2F14=2E0_to_9=2E6p1_like_br?= =?UTF-8?Q?anch_master?= To: freebsd-security@freebsd.org Content-Type: multipart/alternative; boundary="000000000000aa7d58062156069d" X-Spamd-Bar: -- X-Spamd-Result: default: False [-3.00 / 15.00]; NEURAL_HAM_MEDIUM(-1.00)[-1.000]; URI_COUNT_ODD(1.00)[1]; NEURAL_HAM_LONG(-1.00)[-1.000]; NEURAL_HAM_SHORT(-1.00)[-0.999]; DMARC_POLICY_ALLOW(-0.50)[gmail.com,none]; R_DKIM_ALLOW(-0.20)[gmail.com:s=20230601]; R_SPF_ALLOW(-0.20)[+ip6:2a00:1450:4000::/36:c]; MIME_GOOD(-0.10)[multipart/alternative,text/plain]; RCVD_TLS_LAST(0.00)[]; TO_MATCH_ENVRCPT_ALL(0.00)[]; FROM_HAS_DN(0.00)[]; ARC_NA(0.00)[]; FREEMAIL_ENVFROM(0.00)[gmail.com]; RCPT_COUNT_ONE(0.00)[1]; FREEMAIL_FROM(0.00)[gmail.com]; MIME_TRACE(0.00)[0:+,1:+,2:~]; TAGGED_FROM(0.00)[]; MISSING_XM_UA(0.00)[]; DWL_DNSWL_NONE(0.00)[gmail.com:dkim]; PREVIOUSLY_DELIVERED(0.00)[freebsd-security@freebsd.org]; TO_DN_NONE(0.00)[]; FROM_EQ_ENVFROM(0.00)[]; DKIM_TRACE(0.00)[gmail.com:+]; MID_RHS_MATCH_FROMTLD(0.00)[]; ASN(0.00)[asn:15169, ipnet:2a00:1450::/32, country:US]; MLMMJ_DEST(0.00)[freebsd-security@freebsd.org]; RCVD_COUNT_ONE(0.00)[1]; RCVD_IN_DNSWL_NONE(0.00)[2a00:1450:4864:20::32c:from] X-Rspamd-Queue-Id: 4WzjtK5V9Rz4fb9 --000000000000aa7d58062156069d Content-Type: text/plain; charset="UTF-8" Hi, we have detected that your project of release/14.0 is vulnerable to the CVE-2023-51384 which is caused by the lower version of openssh, maybe you need to update it? Best regards, James --000000000000aa7d58062156069d Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable
Hi,
=C2=A0 we have detected that your project of relea= se/14.0 is vulnerable to the=C2=A0 CVE-2023-51384 which is caused by the lower version of openssh, maybe you n= eed to update it?

Best regards,
James3D""
--000000000000aa7d58062156069d--