From nobody Mon Aug 3 10:49:23 2026 X-Original-To: dev-commits-ports-main@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4hDD2K008fz6n68T for ; Mon, 03 Aug 2026 10:49:29 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR1" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4hDD2J6Xckz3GwT for ; Mon, 03 Aug 2026 10:49:28 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1785754168; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=Sch/O0xW4eZ+2sJevseu8FlSIgVb2C686Hr8OtC/l1Y=; b=FDCGPTJERuYX2BLNX2jVDgqZWzFlWeTTfDgei0WB7pYjnooyWTFGNF3BSxT5zt6gGZcsMJ avwEvDtjQvbPA8f2sMhWAfIhv6RRabrk1D+8WG0APY+M6pF5ItdzDMaXiCJU/vdgZBgpHj 6QRZ869iZB5SS+fS04hUARtP9YVazGErlIToRu/5xG+RCCYhZRiYlwm3cdSgWHxhn8e79q 0Wfmn8/5oCWoj3WUFiT2m8QbiOsSCVmA1xdK05y1uzH8yjYBIZ5GOzd7ltjLcAeEf4ScMq IKgezOZtAmjXQ4z+fKWuA+AwE3BDa+RPxLIq37XECWcuQp6PP/sJHUgkA4ktnw== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1785754168; a=rsa-sha256; cv=none; b=Rk/vKpGbuh9IuU2JHThPX7KYzPuhPrEJX+ldTYU6dR52UfAd2ox7RoTX0qanLFfmHxVgA3 l1CBFZ8ZyPrv+yMbzQkTFwmtD+EkCeFvS3DIEnoaDDPC1R4XZYoabPh1X6kUhqQVKBD1oB Gj+BQhQl/USAesVQ/d/kHq5BLyHCcmQpbzV+o7Daca4DyXpU+X85Eryxpkj6xXYdpsVCpO Y7ZFHABraqzIu8O+2pcftg4iXPB7IB7XHTCmFh4/2tyOm0A8Tc+pusxOvZT71Bf2G8mVPx o+c3gzDwqPYzWK7tJ32CcPK4tHd6ubZoWQRsP390/7rOABD1/rG0ixFR72GVyQ== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1785754168; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=Sch/O0xW4eZ+2sJevseu8FlSIgVb2C686Hr8OtC/l1Y=; b=Y2pGlda+d0dAAUL145Tfh175YbLtHhJ00fqixc3SgH7ArM9hQMNmcOpmYgfD4AGa5XOmja /S1tk3VvJk3hKsq5dav8otJe2j6Cnn7NarksDbUvlz9FltIB0t6A+M7T271xnFBSAF+TC/ s+YQbvpDndq5PC9o7kHJABxTuUJW3yTG8pzJqo3zuICsNuG8yWdqcMvOlF/lX9nWl2cspm Lus9mGAi5noq4PNf4pO4HwgxD2H8hQxTtVw4Yzrr1iIEBlQpNKUTU0b9n4PNtzduQLENH0 cM9WZlW3EqT7Fl/+35Z92Il7t/un3ESM1dgC6Sa30fRiSP5A0PzZn6ZwXAv06A== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4hDD2J4lcnzxS9 for ; Mon, 03 Aug 2026 10:49:28 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 45d6c by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Mon, 03 Aug 2026 10:49:23 +0000 To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-main@FreeBSD.org From: Bernard Spil Subject: git: e8cf3cddb951 - main - security/vuxml: Remove spurious file List-Id: Commits to the main branch of the FreeBSD ports repository List-Archive: https://lists.freebsd.org/archives/dev-commits-ports-main List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-ports-main@freebsd.org Sender: owner-dev-commits-ports-main@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: brnrd X-Git-Repository: ports X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: e8cf3cddb951062975d21b8f48e00ff679985b33 Auto-Submitted: auto-generated Date: Mon, 03 Aug 2026 10:49:23 +0000 Message-Id: <6a707233.45d6c.738fcfd5@gitrepo.freebsd.org> The branch main has been updated by brnrd: URL: https://cgit.FreeBSD.org/ports/commit/?id=e8cf3cddb951062975d21b8f48e00ff679985b33 commit e8cf3cddb951062975d21b8f48e00ff679985b33 Author: Bernard Spil AuthorDate: 2026-08-03 10:48:57 +0000 Commit: Bernard Spil CommitDate: 2026-08-03 10:49:18 +0000 security/vuxml: Remove spurious file --- security/vuxml/myvuln | 50 -------------------------------------------------- 1 file changed, 50 deletions(-) diff --git a/security/vuxml/myvuln b/security/vuxml/myvuln deleted file mode 100644 index 2765beda1b1c..000000000000 --- a/security/vuxml/myvuln +++ /dev/null @@ -1,50 +0,0 @@ - - Weechat -- Multiple vulnerabilities - - - weechat - 4.10.0 - - - - -

The Weechat project reports:

-
-
    -
  • core: fix buffer overflow in display of time in chat area with a custom time format
  • -
  • core: fix integer overflow in size calculation when evaluating "${hide:...}" and "${base_encode:...}"
  • -
  • core: fix possible buffer overflow in command /color alias
  • -
  • core: fix possible buffer overflow in list of commands displayed by /help
  • -
  • irc: fix heap use-after-free when a batched message causes a disconnection from the server (GHSA-rfmh-3r7f-jpx5)
  • -
  • irc: fix stack buffer overflow when splitting a JOIN message with a large list of channels and keys (GHSA-q2xg-9ggx-77mr)
  • -
  • irc: limit size of data received from the server to prevent memory exhaustion
  • -
  • irc: fix out-of-bounds read on incoming DCC command with a quoted filename ending the message
  • -
  • logger: fix path traversal in log file name when a buffer local variable contains the char used internally to protect directory separators
  • -
  • relay: fix use-after-free and double free on remote buffer (GHSA-hx59-4hq9-6vmw)
  • -
  • relay: fix authentication bypass with the "plain" password hash algorithm (GHSA-68ff-gq39-pqjm)
  • -
  • relay: limit size of decompressed websocket frame with permessage-deflate to prevent memory exhaustion (GHSA-v2v4-45wm-5cr3, CVE-2026-53524) -
  • relay: limit size of received websocket frame and HTTP body to prevent memory exhaustion
  • -
  • relay: limit size of partial message received while reading an HTTP request to prevent memory exhaustion
  • -
  • relay: fix timing attack on password authentication (GHSA-vhv8-g2r9-cwcc, CVE-2026-53525)
  • -
  • relay: fix out-of-bounds read in dump of data
  • -
  • relay/api: fix memory leak in resources "handshake", "input" and "completion" (GHSA-wmpc-m6g9-fwj8)
  • -
  • relay: fix read of uncompressed websocket frame
  • -
  • api, relay: fix timing attack on TOTP validation (GHSA-vhv8-g2r9-cwcc, CVE-2026-53525)
  • -
  • xfer: replace directory separator in remote nick by underscore in download filename to prevent writing the file outside the download directory
  • -
  • xfer: fix out-of-bounds read when receiving empty line in DCC chat
  • -
  • xfer: fix out-of-bounds write in xfer file transfer resume
  • -
-
- -
- - CVE-2026-53524 - CVE-2026-53525 - https://github.com/weechat/weechat/releases/tag/v4.10.0 - - - 2026-08-02 - 2026-08-02 - -
-