Date: Wed, 03 Jul 2024 01:44:10 +0000 From: bugzilla-noreply@freebsd.org To: ports-bugs@FreeBSD.org Subject: [Bug 280103] www/yt-dlp: update to 2024.07.01 to solve 2 vulnerabilities Message-ID: <bug-280103-7788@https.bugs.freebsd.org/bugzilla/>
next in thread | raw e-mail | index | archive | help
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D280103 Bug ID: 280103 Summary: www/yt-dlp: update to 2024.07.01 to solve 2 vulnerabilities Product: Ports & Packages Version: Latest Hardware: Any OS: Any Status: New Severity: Affects Some People Priority: --- Component: Individual Port(s) Assignee: yuri@freebsd.org Reporter: diario202@outlook.com Flags: maintainer-feedback?(yuri@freebsd.org) Assignee: yuri@freebsd.org I suggest an exp-run, since yt-dlp 2024.07.01 fixes 2 CVEs: Properly sanitize file-extension to prevent file system modification and RC= E: https://github.com/yt-dlp/yt-dlp/security/advisories/GHSA-79w7-vh3h-8g4j=20 https://nvd.nist.gov/vuln/detail/CVE-2024-10123 Disallow unsafe extensions:=20 CVE-2024-38519=20 https://github.com/yt-dlp/yt-dlp/commit/5ce582448ececb8d 9c30c8c31f58330090ced03a --=20 You are receiving this mail because: You are the assignee for the bug.=
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?bug-280103-7788>