From nobody Sun Dec 7 11:28:30 2025 X-Original-To: freebsd-security@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4dPNCn1wl1z6KHQc for ; Sun, 07 Dec 2025 11:28:37 +0000 (UTC) (envelope-from hello@bacula-web.org) Received: from mail-106117.protonmail.ch (mail-106117.protonmail.ch [79.135.106.117]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "protonmail.com", Issuer "R13" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4dPNCl4QcYz3DrX for ; Sun, 07 Dec 2025 11:28:35 +0000 (UTC) (envelope-from hello@bacula-web.org) Authentication-Results: mx1.freebsd.org; dkim=pass header.d=bacula-web.org header.s=protonmail header.b=IYO2a16i; dmarc=pass (policy=none) header.from=bacula-web.org; spf=pass (mx1.freebsd.org: domain of hello@bacula-web.org designates 79.135.106.117 as permitted sender) smtp.mailfrom=hello@bacula-web.org DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=bacula-web.org; s=protonmail; t=1765106912; x=1765366112; bh=4xEHN53vJD9N6Zj+V6UPrKj10Uvpm2hqj2Jn1WegdbY=; h=Date:To:From:Subject:Message-ID:Feedback-ID:From:To:Cc:Date: Subject:Reply-To:Feedback-ID:Message-ID:BIMI-Selector; b=IYO2a16ifbgztKCQonV+00zHrgR1JKaNTgR7IqCDsVvNJ1jfL5usIqQgJK2VrOys3 7ZXdWwaNXbDatvsn3joMn7Xeu/gUGA8w9/VlwEtPYLgYAhAv30znDjC6PuZpkoXjcW bS6bYrsN4Vwo/8314WYdp2tnCb/7/F6ehGZBLjx4cxnsZab6/csqA4V3fQrWAAChtE 1wAe4IdUND8Xg9T7M8ytcZjlglxfUi/GrYeTFKqyBmZnNiEqvWIybkLvvSEi5nFuM1 Tc3HxDgM89PMIeduxTE0ByGfDg/u7jGdV2xY8dSKgf0hVhFkc7kYqx6EgcOBmrvsIN 59s9HyOpxyYbQ== Date: Sun, 07 Dec 2025 11:28:30 +0000 To: "freebsd-security@FreeBSD.org" From: Bacula-Web project maintainer Subject: Guidance on how to handle FreeBSD port vulnerability Message-ID: Feedback-ID: 62987555:user:proton X-Pm-Message-ID: 327d13e7972f25f9b2a3525597396d96513abfd0 List-Id: Security issues List-Archive: https://lists.freebsd.org/archives/freebsd-security List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: freebsd-security@freebsd.org Sender: owner-freebsd-security@FreeBSD.org MIME-Version: 1.0 Content-Type: multipart/alternative; boundary="b1=_uTbZXVIEYfOu9uDkwHob2tWV6oO942NZN1ElC45cvo" X-Spamd-Bar: -- X-Spamd-Result: default: False [-2.35 / 15.00]; MIME_BASE64_TEXT_BOGUS(1.00)[]; NEURAL_HAM_LONG(-1.00)[-1.000]; NEURAL_HAM_MEDIUM(-1.00)[-1.000]; DMARC_POLICY_ALLOW(-0.50)[bacula-web.org,none]; NEURAL_HAM_SHORT(-0.45)[-0.453]; R_DKIM_ALLOW(-0.20)[bacula-web.org:s=protonmail]; R_SPF_ALLOW(-0.20)[+ip4:79.135.106.0/24]; MIME_BASE64_TEXT(0.10)[]; MIME_GOOD(-0.10)[multipart/alternative,text/plain]; TO_DN_EQ_ADDR_ALL(0.00)[]; FROM_HAS_DN(0.00)[]; RCPT_COUNT_ONE(0.00)[1]; TO_MATCH_ENVRCPT_ALL(0.00)[]; DKIM_TRACE(0.00)[bacula-web.org:+]; MISSING_XM_UA(0.00)[]; ASN(0.00)[asn:62371, ipnet:79.135.106.0/24, country:CH]; MLMMJ_DEST(0.00)[freebsd-security@FreeBSD.org]; FROM_EQ_ENVFROM(0.00)[]; ARC_NA(0.00)[]; MID_RHS_MATCH_FROM(0.00)[]; BLOCKLISTDE_FAIL(0.00)[79.135.106.117:server fail]; RCVD_COUNT_ZERO(0.00)[0]; MIME_TRACE(0.00)[0:+,1:+,2:~] X-Rspamd-Queue-Id: 4dPNCl4QcYz3DrX --b1=_uTbZXVIEYfOu9uDkwHob2tWV6oO942NZN1ElC45cvo Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: base64 SGVsbG8gdGhlcmUsCgpJJ2QgbmVlZCBzb21lIGhlbHAgdG8gdGFja2xlIGEga25vd24gRnJlZUJT RCBwb3J0IHZ1bG5lcmFiaWxpdHkgd2hpY2ggZG9lc24ndCBzZWVtIHRvIGJlIHJlZmVyZW5jZWQg b24gRnJlc2hQb3J0Lm9yZy4KClRoZSBhZmZlY3RlZCBwb3J0IGlzIGh0dHBzOi8vd3d3LmZyZXNo cG9ydHMub3JnL3d3dy9iYWN1bGEtd2ViLy4KCkFsc28sIEknZCBsaWtlIHRvIHB1dCBzb21lIGVm Zm9ydHMgdG8ga2VlcCB1cGRhdGVkIGFib3ZlIHBvcnRzIGFzIGl0IGRlc2VydmUgc29tZSBtb3Jl ICJsb3ZlIi4KCkFuIGhpbnRzIC8gbGluayB0byBkb2N1bWVudGVkIHByb2Nlc3Mgd291bGQgYmUg bmljZS4KClRoYW5rcwoKQmVzdCwKCkRhdmlkZQ== --b1=_uTbZXVIEYfOu9uDkwHob2tWV6oO942NZN1ElC45cvo Content-Type: text/html; charset=utf-8 Content-Transfer-Encoding: base64 PGRpdiBzdHlsZT0iZm9udC1mYW1pbHk6IEFyaWFsLCBzYW5zLXNlcmlmOyBmb250LXNpemU6IDE0 cHg7Ij5IZWxsbyB0aGVyZSw8L2Rpdj48ZGl2IHN0eWxlPSJmb250LWZhbWlseTogQXJpYWwsIHNh bnMtc2VyaWY7IGZvbnQtc2l6ZTogMTRweDsiPjxicj48L2Rpdj48ZGl2IHN0eWxlPSJmb250LWZh bWlseTogQXJpYWwsIHNhbnMtc2VyaWY7IGZvbnQtc2l6ZTogMTRweDsiPkknZCBuZWVkIHNvbWUg aGVscCB0byB0YWNrbGUgYSBrbm93biBGcmVlQlNEIHBvcnQgdnVsbmVyYWJpbGl0eSB3aGljaCBk b2Vzbid0IHNlZW0gdG8gYmUgcmVmZXJlbmNlZCBvbiBGcmVzaFBvcnQub3JnLjwvZGl2PjxkaXYg c3R5bGU9ImZvbnQtZmFtaWx5OiBBcmlhbCwgc2Fucy1zZXJpZjsgZm9udC1zaXplOiAxNHB4OyI+ PGJyPjwvZGl2PjxkaXYgc3R5bGU9ImZvbnQtZmFtaWx5OiBBcmlhbCwgc2Fucy1zZXJpZjsgZm9u dC1zaXplOiAxNHB4OyI+VGhlIGFmZmVjdGVkIHBvcnQgaXMmbmJzcDs8c3Bhbj48YSB0YXJnZXQ9 Il9ibGFuayIgcmVsPSJub3JlZmVycmVyIG5vZm9sbG93IG5vb3BlbmVyIiBocmVmPSJodHRwczov L3d3dy5mcmVzaHBvcnRzLm9yZy93d3cvYmFjdWxhLXdlYi8iPmh0dHBzOi8vd3d3LmZyZXNocG9y dHMub3JnL3d3dy9iYWN1bGEtd2ViLzwvYT4uPC9zcGFuPjwvZGl2PjxkaXYgc3R5bGU9ImZvbnQt ZmFtaWx5OiBBcmlhbCwgc2Fucy1zZXJpZjsgZm9udC1zaXplOiAxNHB4OyI+PGJyPjwvZGl2Pjxk aXYgc3R5bGU9ImZvbnQtZmFtaWx5OiBBcmlhbCwgc2Fucy1zZXJpZjsgZm9udC1zaXplOiAxNHB4 OyI+QWxzbywgSSdkIGxpa2UgdG8gcHV0IHNvbWUgZWZmb3J0cyB0byBrZWVwIHVwZGF0ZWQgYWJv dmUgcG9ydHMgYXMgaXQgZGVzZXJ2ZSBzb21lIG1vcmUgImxvdmUiLjwvZGl2PjxkaXYgc3R5bGU9 ImZvbnQtZmFtaWx5OiBBcmlhbCwgc2Fucy1zZXJpZjsgZm9udC1zaXplOiAxNHB4OyI+PGJyPjwv ZGl2PjxkaXYgc3R5bGU9ImZvbnQtZmFtaWx5OiBBcmlhbCwgc2Fucy1zZXJpZjsgZm9udC1zaXpl OiAxNHB4OyI+QW4gaGludHMgLyBsaW5rIHRvIGRvY3VtZW50ZWQgcHJvY2VzcyB3b3VsZCBiZSBu aWNlLjwvZGl2PjxkaXYgc3R5bGU9ImZvbnQtZmFtaWx5OiBBcmlhbCwgc2Fucy1zZXJpZjsgZm9u dC1zaXplOiAxNHB4OyI+PGJyPjwvZGl2PjxkaXYgc3R5bGU9ImZvbnQtZmFtaWx5OiBBcmlhbCwg c2Fucy1zZXJpZjsgZm9udC1zaXplOiAxNHB4OyI+VGhhbmtzPC9kaXY+PGRpdiBzdHlsZT0iZm9u dC1mYW1pbHk6IEFyaWFsLCBzYW5zLXNlcmlmOyBmb250LXNpemU6IDE0cHg7Ij48YnI+PC9kaXY+ PGRpdiBzdHlsZT0iZm9udC1mYW1pbHk6IEFyaWFsLCBzYW5zLXNlcmlmOyBmb250LXNpemU6IDE0 cHg7Ij5CZXN0LDwvZGl2PjxkaXYgc3R5bGU9ImZvbnQtZmFtaWx5OiBBcmlhbCwgc2Fucy1zZXJp ZjsgZm9udC1zaXplOiAxNHB4OyI+PGJyPjwvZGl2PjxkaXYgc3R5bGU9ImZvbnQtZmFtaWx5OiBB cmlhbCwgc2Fucy1zZXJpZjsgZm9udC1zaXplOiAxNHB4OyI+RGF2aWRlPC9kaXY+DQo= --b1=_uTbZXVIEYfOu9uDkwHob2tWV6oO942NZN1ElC45cvo--