Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 20 Sep 2024 06:48:11 GMT
From:      Philip Paeps <philip@FreeBSD.org>
To:        ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-main@FreeBSD.org
Subject:   git: 11f549f3b97d - main - security/vuxml: reference FreeBSD-SA-24:04.openssh in CVE-2024-6387
Message-ID:  <202409200648.48K6mBGc010337@gitrepo.freebsd.org>

next in thread | raw e-mail | index | archive | help
The branch main has been updated by philip:

URL: https://cgit.FreeBSD.org/ports/commit/?id=11f549f3b97dc63c7b4b5aa15404f12a45f3187c

commit 11f549f3b97dc63c7b4b5aa15404f12a45f3187c
Author:     Philip Paeps <philip@FreeBSD.org>
AuthorDate: 2024-09-20 06:24:06 +0000
Commit:     Philip Paeps <philip@FreeBSD.org>
CommitDate: 2024-09-20 06:48:04 +0000

    security/vuxml: reference FreeBSD-SA-24:04.openssh in CVE-2024-6387
    
    All supported versions of FreeBSD were affected by CVE-2024-6387,
    announced on 2024-07-01.  Reference FreeBSD-SA-24:04.openssh in the
    vuxml entry.
---
 security/vuxml/vuln/2024.xml | 10 +++++++++-
 1 file changed, 9 insertions(+), 1 deletion(-)

diff --git a/security/vuxml/vuln/2024.xml b/security/vuxml/vuln/2024.xml
index e770bbdf338e..7d8fa4057f5f 100644
--- a/security/vuxml/vuln/2024.xml
+++ b/security/vuxml/vuln/2024.xml
@@ -2971,6 +2971,13 @@ All of these are related to the CometVisu add-on for openHAB - if you are a user
 	<name>openssh-portable</name>
 	<range><lt>9.7.p1_2,1</lt></range>
       </package>
+      <package>
+	<name>FreeBSD</name>
+	<range><ge>14.1</ge><lt>14.1_2</lt></range>
+	<range><ge>14.0</ge><lt>14.0_8</lt></range>
+	<range><ge>13.3</ge><lt>13.3_4</lt></range>
+	<range><ge>13.2</ge><lt>13.2_12</lt></range>
+      </package>
     </affects>
     <description>
 	<body xmlns="http://www.w3.org/1999/xhtml">;
@@ -2983,11 +2990,12 @@ All of these are related to the CometVisu add-on for openHAB - if you are a user
     <references>
       <cvename>CVE-2024-6387</cvename>
       <url>https://www.openssh.com/security.html</url>;
+      <freebsdsa>SA-24:04.openssh</freebsdsa>
     </references>
     <dates>
       <discovery>2024-07-01</discovery>
       <entry>2024-07-01</entry>
-      <modified>2024-07-03</modified>
+      <modified>2024-09-20</modified>
     </dates>
   </vuln>
 



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?202409200648.48K6mBGc010337>