From nobody Sun Dec 7 11:35:27 2025 X-Original-To: freebsd-security@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4dPNMj1yxJz6KHyt for ; Sun, 07 Dec 2025 11:35:29 +0000 (UTC) (envelope-from dim@FreeBSD.org) Received: from smtp.freebsd.org (smtp.freebsd.org [96.47.72.83]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "smtp.freebsd.org", Issuer "R13" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4dPNMj1S7rz3H86; Sun, 07 Dec 2025 11:35:29 +0000 (UTC) (envelope-from dim@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1765107329; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=d1kErx0+WTuCKc4vBwtXR33CgPY4cR8my7MR68jBQa0=; b=iNnhjg5qQy8qIE3NmkeR8OzrPs0cDuIvxocQgnBdpvQ2d0fGT+4s/JeV08bqCQ9vyFCb4g UOH4W6KUfEIwh/ViPcwygSzF5qrMYDIPUvp/C1flZQwLyWaN7iisB74j7jfJ+nX2jmP+xd 315qCk1UbDiFlHLAsKMz1aVGkkHEwYDGg+Bt7LTqSiexJhSURNKUa7hLpZHhptdr/DN3GV wrtkC+6L2CifhnkTrKOpltp9JzaP1aSTIgPlzwzAzG0T5Q2YTA6ow8OCqt3Rgs3EjSp7Xc NuMRmYkB2Sr2c4zXuCQ2ZRQf3/Jdn6060MIDrkbcvdQ4uiR7a8z2A0CROObsvA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1765107329; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=d1kErx0+WTuCKc4vBwtXR33CgPY4cR8my7MR68jBQa0=; b=HlMZFcZuWoGzGiopD73d6Hr2WadDm2IY0yDfpnq1fxHKYFb7yWMy1RmcDsQ4Gwz3BuMlws zU4renMtkEh7EpTGXUzbZhkxw2mt/Qp/0yIop2mgGi/iTSTHPzP2Qh4oXHPzv+19kks0PC 9ESyG3xnG5DsDLwvfwRTLCHNP11yqaau0CilM2r1ZW1XUUtGWMcB8P+mGMowCiOOM6VDZz h27lJdOAn3DeOJyqAPx/g2KzcGOwGEyXf+hcPKC5aj0lS5+AEQl9Jyk/EuyAVxZkMaXRXv B3oLSMZE0K0M9d5EGpMMROAKFKMNbj5Layxu6ZDttUE26wcG2W85wWCAXczR8A== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1765107329; a=rsa-sha256; cv=none; b=UsRDT/l2D1GBp0SqzGagbrNlPQ6f5LXk1Gw6sasB8yZm2mmg/Wxeb6T7vt6Tyf9lT8Ggqb bFSBHCVboN+5ozHipFKYuoYRyvMqzSxiRn/1ZPLKnh4J0Qk/2hpAbies4qUljgiMmo/+3C XMg1ryDCIUEBYvQGHAJpsmLSBPlSgLe4NxgnSZa+ukCM8r50OIleFUBI341Nrc14kE9Wq7 gOhtG3O99m1q/BYJ/LZp+eLIQJLbk5FPKW+mxRpB8lIa3DNbOroiwSU/a0+Zy0Gtk702oO qK63LG7NGVoW6K0hGBNEqS65gYcx9ckG03uVe8B5jricPNW24DCS86Sa1DUlXQ== ARC-Authentication-Results: i=1; mx1.freebsd.org; none Received: from tensor.andric.com (tensor.andric.com [87.251.56.140]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature ECDSA (prime256v1) client-digest SHA256) (Client CN "tensor.andric.com", Issuer "E7" (verified OK)) (Authenticated sender: dim) by smtp.freebsd.org (Postfix) with ESMTPSA id 4dPNMj093TzGs9; Sun, 07 Dec 2025 11:35:28 +0000 (UTC) (envelope-from dim@FreeBSD.org) Received: from smtpclient.apple (bladnoch.home.andric.com [192.168.0.20]) (using TLSv1.2 with cipher ECDHE-ECDSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by tensor.andric.com (Postfix) with ESMTPSA id A7DFA75179; Sun, 07 Dec 2025 12:35:27 +0100 (CET) Content-Type: text/plain; charset=us-ascii List-Id: Security issues List-Archive: https://lists.freebsd.org/archives/freebsd-security List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: freebsd-security@freebsd.org Sender: owner-freebsd-security@FreeBSD.org Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3826.700.81.1.3\)) Subject: Re: Guidance on how to handle FreeBSD port vulnerability From: Dimitry Andric In-Reply-To: Date: Sun, 7 Dec 2025 12:35:27 +0100 Cc: "freebsd-security@FreeBSD.org" Content-Transfer-Encoding: quoted-printable Message-Id: <11DA25E7-8840-4182-995A-B976439C2E04@FreeBSD.org> References: To: Bacula-Web project maintainer X-Mailer: Apple Mail (2.3826.700.81.1.3) On 7 Dec 2025, at 12:28, Bacula-Web project maintainer = wrote: >=20 >=20 > Hello there, >=20 > I'd need some help to tackle a known FreeBSD port vulnerability which = doesn't seem to be referenced on FreshPort.org. >=20 > The affected port is https://www.freshports.org/www/bacula-web/. >=20 > Also, I'd like to put some efforts to keep updated above ports as it = deserve some more "love". >=20 > An hints / link to documented process would be nice. Report a bug on https://bugs.freebsd.org/bugzilla/, the "Report an = update or defect to a port" link there is the most appropriate. If you = start the subject of the bug report with the string "www/bacula-web: " = it will automatically get assigned to the port maintainer, which at the = moment is ler@FreeBSD.org . -Dimitry