Date: Fri, 12 Jan 2024 08:51:56 GMT From: Hiroki Tagato <tagattie@FreeBSD.org> To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-main@FreeBSD.org Subject: git: 38706004d1f8 - main - security/vuxml: document electron{26,27} multiple vulnerabilities Message-ID: <202401120851.40C8puw6083157@gitrepo.freebsd.org>
next in thread | raw e-mail | index | archive | help
The branch main has been updated by tagattie: URL: https://cgit.FreeBSD.org/ports/commit/?id=38706004d1f8fb6744a31850bb60feeb82b48709 commit 38706004d1f8fb6744a31850bb60feeb82b48709 Author: Hiroki Tagato <tagattie@FreeBSD.org> AuthorDate: 2024-01-12 08:50:16 +0000 Commit: Hiroki Tagato <tagattie@FreeBSD.org> CommitDate: 2024-01-12 08:50:16 +0000 security/vuxml: document electron{26,27} multiple vulnerabilities Obtained from: https://github.com/electron/electron/releases/tag/v26.6.5, https://github.com/electron/electron/releases/tag/v27.2.2 --- security/vuxml/vuln/2024.xml | 42 ++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 42 insertions(+) diff --git a/security/vuxml/vuln/2024.xml b/security/vuxml/vuln/2024.xml index 127620a3cc58..6a87603e946c 100644 --- a/security/vuxml/vuln/2024.xml +++ b/security/vuxml/vuln/2024.xml @@ -1,3 +1,45 @@ + <vuln vid="28b42ef5-80cd-440c-904b-b7fbca74c73d"> + <topic>electron{26,27} -- multiple vulnerabilities</topic> + <affects> + <package> + <name>electron26</name> + <range><lt>26.6.5</lt></range> + </package> + <package> + <name>electron27</name> + <range><lt>27.2.2</lt></range> + </package> + </affects> + <description> + <body xmlns="http://www.w3.org/1999/xhtml"> + <p>Electron developers report:</p> + <blockquote cite="https://github.com/electron/electron/releases/tag/v26.6.5"> + <p>This update fixes the following vulnerabilities:</p> + <ul> + <li>Security: backported fix for CVE-2024-0224.</li> + <li>Security: backported fix for CVE-2024-0225.</li> + <li>Security: backported fix for CVE-2024-0223.</li> + <li>Security: backported fix for CVE-2024-0222.</li> + </ul> + </blockquote> + </body> + </description> + <references> + <cvename>CVE-2024-0224</cvename> + <url>https://github.com/advisories/GHSA-83wx-v283-85g9</url> + <cvename>CVE-2024-0225</cvename> + <url>https://github.com/advisories/GHSA-gqr9-4fcc-c9jq</url> + <cvename>CVE-2024-0223</cvename> + <url>https://github.com/advisories/GHSA-w8x8-g534-x4rp</url> + <cvename>CVE-2024-0222</cvename> + <url>https://github.com/advisories/GHSA-c87c-56pw-mwgh</url> + </references> + <dates> + <discovery>2024-01-10</discovery> + <entry>2024-01-12</entry> + </dates> + </vuln> + <vuln vid="4c8c2218-b120-11ee-90ec-001b217b3468"> <topic>Gitlab -- vulnerabilities</topic> <affects>
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?202401120851.40C8puw6083157>