From nobody Fri Aug 30 06:34:35 2024 X-Original-To: dev-commits-ports-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4Ww7g12Xwmz5T9Z5; Fri, 30 Aug 2024 06:34:53 +0000 (UTC) (envelope-from fernando.apesteguia@gmail.com) Received: from mail-lf1-f51.google.com (mail-lf1-f51.google.com [209.85.167.51]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (2048 bits) client-digest SHA256) (Client CN "smtp.gmail.com", Issuer "WR4" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4Ww7g10VBhz4GkY; Fri, 30 Aug 2024 06:34:53 +0000 (UTC) (envelope-from fernando.apesteguia@gmail.com) Authentication-Results: mx1.freebsd.org; none Received: by mail-lf1-f51.google.com with SMTP id 2adb3069b0e04-53345604960so1466145e87.3; Thu, 29 Aug 2024 23:34:53 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1724999690; x=1725604490; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=BbAt4i3AkAmbpAkWTfhJ9s2oIvrh3wqz1La3yC0ZJW8=; b=e0FKvDM0jPz4cqCd9bHpvt22hJwYrFSZ0xtKcEoHevzecOKegyImMY10hqVk9xSwgD VC7i4VarX3Nod+IKlmvk4FtoESLjVFc0n/owqp02MCOYUn1N2kQQARqSURp1UMaSOk50 aZRvyTPhWI5KgLHGSee0rHdIJ2an+DdENyGYDIICnEKALUsgwyWS7l28pLhXbZSzxi5q OWKh+5P4+nhMYP6Wy6ZAiFLTAiw/6dwbFd8jrzl3CiJN9RAbejxlsrdf3k8iS6Hh7Mpg 4cQlCB5ilLN9UnwRx55GpeZzo5HbRSIZKjr2A0OjSkVJOtCmodQBgfyehPHYH9+RYmqX QnUQ== X-Forwarded-Encrypted: i=1; AJvYcCU10RqxJshg+jzlTZ0k0qwuWrYrJRZIIhnlv1vZnWjvCJ2oJ8I3rTHIRA8d3a0UDj0fURynxFaK11RxdADpqEul58DDnaxkrw==@freebsd.org, AJvYcCWVxzGNdw4VjuRPY1pYTtkEZm0z0+J/hJZe1B3dBBjGHaxAjIeICGXRfcZeMHBuWjNVS96bzDgG1ePnr3Qblm3PSsJC36o=@freebsd.org X-Gm-Message-State: AOJu0YwfxPxsQS1bvxkX3i3e7ui7gkvU2+ogklbG8CcI4fwMdIzeasun BUVJVLyAniOcKQDacmEu7SLFTW8K/kBlANuwQ5wOuimvo4MxWyRg3O6XGkF0 X-Google-Smtp-Source: AGHT+IHpoR+7I5SNfVIjmYH41j7KhKuz68nCM0BeAkWNqcXywwfYSv4z9qJeewdFOp88VHuHROHxJA== X-Received: by 2002:a05:6512:3d24:b0:52e:a68a:6076 with SMTP id 2adb3069b0e04-53546bb4d0fmr717823e87.49.1724999689736; Thu, 29 Aug 2024 23:34:49 -0700 (PDT) Received: from mail-lf1-f41.google.com (mail-lf1-f41.google.com. [209.85.167.41]) by smtp.gmail.com with ESMTPSA id 2adb3069b0e04-53540840e76sm447411e87.191.2024.08.29.23.34.48 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Thu, 29 Aug 2024 23:34:48 -0700 (PDT) Received: by mail-lf1-f41.google.com with SMTP id 2adb3069b0e04-53345604960so1466110e87.3; Thu, 29 Aug 2024 23:34:48 -0700 (PDT) X-Forwarded-Encrypted: i=1; AJvYcCWNFH8boXX9WD0kP5inwK+heFj3Zfm5vG9PzMCEPU3mcXwyHlnvu5SqpSJPdMIFJdBr+PWWwWJlxWgURK0XVk8fc+c7+wU=@freebsd.org, AJvYcCXtJr27hF0tRQm77+yKAQx4LuR4EEvIo8EFGw7UhBUvThgd77/1SkUM/djJjKmEuUXhEkc/qL1YN/bWr81BJ/hN4e+DzPWaLQ==@freebsd.org X-Received: by 2002:ac2:4c4e:0:b0:52c:9f9e:d8e3 with SMTP id 2adb3069b0e04-53546b40c79mr678156e87.31.1724999688361; Thu, 29 Aug 2024 23:34:48 -0700 (PDT) List-Id: Commit messages for all branches of the ports repository List-Archive: https://lists.freebsd.org/archives/dev-commits-ports-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-ports-all@freebsd.org Sender: owner-dev-commits-ports-all@FreeBSD.org MIME-Version: 1.0 References: <202408291747.47THltnT050010@gitrepo.freebsd.org> <1673063164.6537.1724964124887@localhost> In-Reply-To: <1673063164.6537.1724964124887@localhost> From: =?UTF-8?Q?Fernando_Apestegu=C3=ADa?= Date: Fri, 30 Aug 2024 08:34:35 +0200 X-Gmail-Original-Message-ID: Message-ID: Subject: Re: git: 4453cf7eef05 - main - security/vuxml: Record firefox multiple vulnerabilites To: Ronald Klop Cc: ports-committers@freebsd.org, dev-commits-ports-main@freebsd.org, dev-commits-ports-all@freebsd.org Content-Type: multipart/alternative; boundary="000000000000a9a84f0620e0c93b" X-Spamd-Bar: ---- X-Rspamd-Pre-Result: action=no action; module=replies; Message is reply to one we originated X-Spamd-Result: default: False [-4.00 / 15.00]; REPLY(-4.00)[]; TAGGED_FROM(0.00)[]; ASN(0.00)[asn:15169, ipnet:209.85.128.0/17, country:US] X-Rspamd-Queue-Id: 4Ww7g10VBhz4GkY --000000000000a9a84f0620e0c93b Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable On Thu, Aug 29, 2024 at 10:42=E2=80=AFPM Ronald Klop = wrote: > Hi, > > When I read the CVE documents they mention that these are about Firefox > for iOS. > The advisory page of Mozilla also talks about Firefox for iOS. > https://www.mozilla.org/en-US/security/advisories/mfsa2024-36/ > > So I doubt that this is applicable to the FreeBSD package. But you might > know things I don't know. > You're right, it seems those are only for iOS. They should have been discarded along CVE-2024-7523... I'll revert the commit and commit the pending CVEs: CVE-2024-0745 CVE-2024-6608 CVE-2024-6609 CVE-2024-6610 CVE-2024-7524 Thanks for the heads up. > > Regards, > Ronald. > > > > *Van:* "Fernando Apestegu=C3=ADa" > *Datum:* donderdag, 29 augustus 2024 19:47 > *Aan:* ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, > dev-commits-ports-main@FreeBSD.org > *Onderwerp:* git: 4453cf7eef05 - main - security/vuxml: Record firefox > multiple vulnerabilites > > The branch main has been updated by fernape: > > URL: > https://cgit.FreeBSD.org/ports/commit/?id=3D4453cf7eef05f9ac2b27bda7a87af= b7da713f1c4 > > commit 4453cf7eef05f9ac2b27bda7a87afb7da713f1c4 > Author: Fernando Apestegu=C3=ADa > AuthorDate: 2024-08-29 17:43:33 +0000 > Commit: Fernando Apestegu=C3=ADa > CommitDate: 2024-08-29 17:47:42 +0000 > > security/vuxml: Record firefox multiple vulnerabilites > > CVE-2024-43111 > * Base Score: 6.1 MEDIUM > * Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N > > CVE-2024-43112 > * Base Score: 6.1 MEDIUM > * Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N > > CVE-2024-43113 > * Base Score: 6.1 MEDIUM > * Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N > --- > security/vuxml/vuln/2024.xml | 39 ++++++++++++++++++++++++++++++++++++++= + > 1 file changed, 39 insertions(+) > > diff --git a/security/vuxml/vuln/2024.xml b/security/vuxml/vuln/2024.xml > index 7dd64a18968f..e9606c88bfca 100644 > --- a/security/vuxml/vuln/2024.xml > +++ b/security/vuxml/vuln/2024.xml > @@ -1,3 +1,42 @@ > + > + firefox -- multiple vulnerabilities > + > + > + firefox > + 129 > + > + > + > + http://www.w3.org/1999/xhtml"> > +

security@mozilla.org reports:

> +
"> > +

This update includes 3 CVEs:

> +
    > +
  • The contextual menu for links could provide an > + opportunity for cross-site scripting attacks.
  • > +
  • Long pressing on a download link could potentially > + provide a means for cross-site scripting.
  • > +
  • Long pressing on a download link could potentially > + allow Javascript commands to be executed within the > + browser.
  • > +
> +
> + > +
> + > + CVE-2024-43113 > + https://nvd.nist.gov/vuln/detail/CVE-2024-43113 > + CVE-2024-43112 > + https://nvd.nist.gov/vuln/detail/CVE-2024-43112 > + CVE-2024-43111 > + https://nvd.nist.gov/vuln/detail/CVE-2024-43111 > + > + > + 2024-08-06 > + 2024-08-29 > + > +
> + > > chromium -- multiple security fixes > > ------------------------------ > > > > --000000000000a9a84f0620e0c93b Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable


=
On Thu, Aug 29, 2024 at 10:42=E2=80= =AFPM Ronald Klop <ronald-lists@= klop.ws> wrote:
Hi,

When I read the CVE documents they mention that these are about Firefox for= iOS.
The advisory page of Mozilla also talks about Firefox for iOS.
https://www.mozilla.org/en-US/security/advisories/mfsa202= 4-36/

So I doubt that this is applicable to the FreeBSD package. But you might kn= ow things I don't know.

You&#= 39;re right, it seems those are only for iOS.
They should have be= en discarded along CVE-2024-7523...

I'll rever= t the commit and commit the pending CVEs:
CVE-2024-0745
CVE-2024-6608
CVE-2024-6609
CVE-2024-6610
CV= E-2024-7524
=C2=A0
Thanks for the heads up.

Regards,
Ronald.

=C2=A0

Van: "Fernando Apestegu=C3=ADa" <fernape@FreeBSD.org= >
Datum: donderdag, 29 augustus 2024 19:47
Aan: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org= , dev-commits-ports-main@FreeBSD.org
Onderwerp: git: 4453cf7eef05 - main - security/vuxml: Record firefox= multiple vulnerabilites

The branch main has been updated by fe= rnape:

URL: https://cgit.FreeBSD.org/ports= /commit/?id=3D4453cf7eef05f9ac2b27bda7a87afb7da713f1c4

commit 4453cf7eef05f9ac2b27bda7a87afb7da713f1c4
Author: =C2=A0=C2=A0=C2=A0=C2=A0Fernando Apestegu=C3=ADa <fernape@FreeBS= D.org>
AuthorDate: 2024-08-29 17:43:33 +0000
Commit: =C2=A0=C2=A0=C2=A0=C2=A0Fernando Apestegu=C3=ADa <fernape@FreeBS= D.org>
CommitDate: 2024-08-29 17:47:42 +0000

=C2=A0=C2=A0=C2=A0=C2=A0security/vuxml: Record firefox multiple vulnerabili= tes
=C2=A0=C2=A0=C2=A0=C2=A0
=C2=A0=C2=A0=C2=A0=C2=A0CVE-2024-43111
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0* Base Score: =C2=A06.1 MEDIUM
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0* Vector: =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0CVSS:= 3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
=C2=A0=C2=A0=C2=A0=C2=A0
=C2=A0=C2=A0=C2=A0=C2=A0CVE-2024-43112
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0* Base Score: =C2=A06.1 MEDIUM
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0* Vector: =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0CVSS:= 3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
=C2=A0=C2=A0=C2=A0=C2=A0
=C2=A0=C2=A0=C2=A0=C2=A0CVE-2024-43113
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0* Base Score: =C2=A06.1 MEDIUM
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0* Vector: =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0CVSS:= 3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
---
=C2=A0security/vuxml/vuln/2024.xml | 39 +++++++++++++++++++++++++++++++++++= ++++
=C2=A01 file changed, 39 insertions(+)

diff --git a/security/vuxml/vuln/2024.xml b/security/vuxml/vuln/2024.xml index 7dd64a18968f..e9606c88bfca 100644
--- a/security/vuxml/vuln/2024.xml
+++ b/security/vuxml/vuln/2024.xml
@@ -1,3 +1,42 @@
+ =C2=A0<vuln vid=3D"44de1b82-662d-11ef-a51b-b42e991fc52e">=
+ =C2=A0=C2=A0=C2=A0<topic>firefox -- multiple vulnerabilities</to= pic>
+ =C2=A0=C2=A0=C2=A0<affects>
+ =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0<package>
+ =C2=A0=C2=A0<name>firefox</name>
+ =C2=A0=C2=A0<range><lt>129</lt></range>
+ =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0</package>
+ =C2=A0=C2=A0=C2=A0</affects>
+ =C2=A0=C2=A0=C2=A0<description>
+ =C2=A0=C2=A0<bodyhttp://www.w3.org/1999/xhtml">http://www.w3.org/1999/xhtml"><= br> + =C2=A0=C2=A0<p>security@mozilla.org reports:</p>
+ =C2=A0=C2=A0<blockquote cite=3D"https://bugzilla.mozill= a.org/show_bug.cgi?id=3D1874964">
+ =C2=A0=C2=A0=C2=A0=C2=A0<p>This update includes 3 CVEs:</p> + =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0<ul>
+ =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0<li>The contextual = menu for links could provide an
+ =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0opportunity for cross-site scripting = attacks.</li>
+ =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0<li>Long pressing o= n a download link could potentially
+ =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0provide a means for cross-site script= ing.</li>
+ =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0<li>Long pressing o= n a download link could potentially
+ =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0allow Javascript commands to be execu= ted within the
+ =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0browser.</li>
+ =C2=A0=C2=A0</ul>
+ =C2=A0=C2=A0</blockquote>
+ =C2=A0=C2=A0</body>
+ =C2=A0=C2=A0=C2=A0</description>
+ =C2=A0=C2=A0=C2=A0<references>
+ =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0<cvename>CVE-2024-43113</cvename&g= t;
+ =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0<url>https://nvd.nist.gov/v= uln/detail/CVE-2024-43113</url>
+ =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0<cvename>CVE-2024-43112</cvename&g= t;
+ =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0<url>https://nvd.nist.gov/v= uln/detail/CVE-2024-43112</url>
+ =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0<cvename>CVE-2024-43111</cvename&g= t;
+ =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0<url>https://nvd.nist.gov/v= uln/detail/CVE-2024-43111</url>
+ =C2=A0=C2=A0=C2=A0</references>
+ =C2=A0=C2=A0=C2=A0<dates>
+ =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0<discovery>2024-08-06</discovery&g= t;
+ =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0<entry>2024-08-29</entry>
+ =C2=A0=C2=A0=C2=A0</dates>
+ =C2=A0</vuln>
+
=C2=A0=C2=A0=C2=A0<vuln vid=3D"6f2545bb-65e8-11ef-8a0f-a8a1599412c6= ">
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0<topic>chromium -- multiple security fi= xes</topic>
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0<affects>


=C2=A0
--000000000000a9a84f0620e0c93b--