From owner-freebsd-security@freebsd.org Tue Apr 13 04:03:13 2021 Return-Path: Delivered-To: freebsd-security@mailman.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.nyi.freebsd.org (Postfix) with ESMTP id EA82E5D0A9B for ; Tue, 13 Apr 2021 04:03:13 +0000 (UTC) (envelope-from gordon@tetlows.org) Received: from mail-pf1-x431.google.com (mail-pf1-x431.google.com [IPv6:2607:f8b0:4864:20::431]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (2048 bits) client-digest SHA256) (Client CN "smtp.gmail.com", Issuer "GTS CA 1O1" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4FKBm06wLPz3lhm for ; Tue, 13 Apr 2021 04:03:12 +0000 (UTC) (envelope-from gordon@tetlows.org) Received: by mail-pf1-x431.google.com with SMTP id o123so10576741pfb.4 for ; Mon, 12 Apr 2021 21:03:12 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:content-transfer-encoding:from:mime-version :subject:date:message-id:references:cc:in-reply-to:to; bh=t0AUtgIAqqWyOngGIG7GBZ/XgtrBn94eQXyYDnjTVz0=; b=r2LooPETXlELoX1rDwQTjof9KywjUWW/OrPNnBe6Q64ddlfnOW4Rx6L5NbXqHEcM2W a/XOR/g1jXSTed2RpkJlUEcDgD0eVT02TmYgrxMuiCIsJO5vZ5RUUfuNY1T6XC4YTwqp aP2SspIbK12peR4Q61+pCujj2yb2btAsd1EhYBW5DKffmJt1Vh2lFspcLwuLa/DJcr72 iwVuRsXNuQ6SYNFwLcZbNiUdV0OuMJjvUmeDoyLYQY2axzlAkLKqozL86Uwz1C+yWw4R WNBELLKDwsJQMbb/TnU94/o1EWB9LBIo//cKOat35lAoAr/u6KrzNk+OyQqOWFxE53lZ zjCA== X-Gm-Message-State: AOAM532Ert6Yd0iM/J5gSwBmznnqngBsPHE18Eg4kkCfNF6rak48BUlf K9hKh5ftc4sivAlLELDPdpOfhfpWpnj1 X-Google-Smtp-Source: ABdhPJw1l4u7PWgkNtOxNM5dWimGOl/3RofG4qp2XDN9auLYs4a6DPgOqC+VyeE3dgRqRl9RC2y5QQ== X-Received: by 2002:aa7:8a47:0:b029:24e:22de:de6a with SMTP id n7-20020aa78a470000b029024e22dede6amr5976717pfa.20.1618286590541; Mon, 12 Apr 2021 21:03:10 -0700 (PDT) Received: from ?IPv6:2603:8000:7a00:d288:9dfe:fb02:daf3:71d7? (2603-8000-7a00-d288-9dfe-fb02-daf3-71d7.res6.spectrum.com. [2603:8000:7a00:d288:9dfe:fb02:daf3:71d7]) by smtp.gmail.com with ESMTPSA id z10sm5144201pfe.218.2021.04.12.21.03.09 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Mon, 12 Apr 2021 21:03:10 -0700 (PDT) Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable From: Gordon Tetlow Mime-Version: 1.0 (1.0) Subject: Re: FreeBSD Security Advisory FreeBSD-SA-21:08.vm missing in vuxml Date: Mon, 12 Apr 2021 21:03:08 -0700 Message-Id: <9695BE88-A3E7-498D-8A5A-92BCB2E79DBD@tetlows.org> References: Cc: Gian Piero Carrubba , freebsd-security@freebsd.org In-Reply-To: To: Miroslav Lachman <000.fbsd@quip.cz> X-Mailer: iPad Mail (18D70) X-Rspamd-Queue-Id: 4FKBm06wLPz3lhm X-Spamd-Bar: / X-Spamd-Result: default: False [0.47 / 15.00]; RCVD_VIA_SMTP_AUTH(0.00)[]; TO_DN_SOME(0.00)[]; MV_CASE(0.50)[]; R_SPF_ALLOW(-0.20)[+ip6:2607:f8b0:4000::/36]; RCVD_COUNT_THREE(0.00)[3]; DKIM_TRACE(0.00)[tetlows.org:+]; DMARC_POLICY_ALLOW(-0.50)[tetlows.org,quarantine]; FROM_EQ_ENVFROM(0.00)[]; MIME_TRACE(0.00)[0:+]; RBL_DBL_DONT_QUERY_IPS(0.00)[2607:f8b0:4864:20::431:from]; ASN(0.00)[asn:15169, ipnet:2607:f8b0::/32, country:US]; MID_RHS_MATCH_FROM(0.00)[]; ARC_NA(0.00)[]; NEURAL_HAM_MEDIUM(-1.00)[-1.000]; R_DKIM_ALLOW(-0.20)[tetlows.org:s=google]; FREEFALL_USER(0.00)[gordon]; FROM_HAS_DN(0.00)[]; RCPT_COUNT_THREE(0.00)[3]; NEURAL_SPAM_SHORT(0.97)[0.966]; MIME_GOOD(-0.10)[text/plain]; PREVIOUSLY_DELIVERED(0.00)[freebsd-security@freebsd.org]; SPAMHAUS_ZRD(0.00)[2607:f8b0:4864:20::431:from:127.0.2.255]; TO_MATCH_ENVRCPT_SOME(0.00)[]; NEURAL_SPAM_LONG(1.00)[1.000]; RCVD_IN_DNSWL_NONE(0.00)[2607:f8b0:4864:20::431:from]; RCVD_TLS_ALL(0.00)[]; MAILMAN_DEST(0.00)[freebsd-security] X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 13 Apr 2021 04:03:14 -0000 > On Apr 12, 2021, at 03:21, Miroslav Lachman <000.fbsd@quip.cz> wrote: >=20 > =EF=BB=BFOn 11/04/2021 21:49, Gian Piero Carrubba wrote: >> * [Sun, Apr 11, 2021 at 09:36:05PM +0200] Miroslav Lachman: >>>> On 11/04/2021 21:21, Gian Piero Carrubba wrote: >>>>> CCing ports-secteam@ as it seems a more appropriate recipient. >>>=20 >>> Vulnerabilities in base should be handled by core secteam, not ports sec= team. >> The maintainer address for vuxml is ports-secteam@, so my impression is t= hat entries in vuxml, regardless if they affect base or ports, are managed b= y them. Am I wrong? >=20 > Because there are entries mainly for ports and vuxml is port too. But the r= esponsible side for vulnerabilities in base is Security Officer Team. They a= re publishing SAs, they should create and submit entries to vuxml. They are a= lmost always lacking behind, sometimes for months. I tried created patches w= ith entries in the past because I am the author of base-audit script and mai= ntainer of the port but then it was waiting for a long time to have it confi= rmed by Security Officer Team. >=20 > I fought with this many times. Hi there! Secteam has been pretty faithfully putting base issues into vuxml for the pa= st year at least, thanks to the tireless work by Philip. The current issues w= ere committed to vuxml 6 days ago. Apparently, the backend that serves the v= uxml for clients hasn=E2=80=99t been updated for the ports git transition. T= here is a pr for that already and hopefully it will be sorted soon. Regards, Gordon=