From owner-freebsd-security@freebsd.org Tue Jul 9 18:56:27 2019 Return-Path: Delivered-To: freebsd-security@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 3B8B115E2468 for ; Tue, 9 Jul 2019 18:56:27 +0000 (UTC) (envelope-from rick.chisholm@hubinternational.com) Received: from us-smtp-delivery-103.mimecast.com (us-smtp-delivery-103.mimecast.com [216.205.24.103]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (Client CN "*.mimecast.com", Issuer "DigiCert Global CA G2" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id D021A804B1 for ; Tue, 9 Jul 2019 18:56:23 +0000 (UTC) (envelope-from rick.chisholm@hubinternational.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=hubinternational.com; s=hubinternational20170913; t=1562698583; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=37d48sNW3lcoQnIEnccbyuU0yr+2D/pAAy+UdU4T5Mw=; b=B8xEwxGe3wKIw1rokmXU/C0qJxHwSGdv/bMguWz0YlkRBv4I8THE2akWcVlCOt7U2gSy0k zKs+WpJj1qgNFhIVZeIZpyBXnmuDNjgCOzds3K/inWRDNAg5Lr+NTcUmW9WaWm9mPtQ2/x T1BgOJ9fpXur5DueAKrEk9Uxc4S0ULabdl2DHBbfe3PpAN+22iLV8BdEEg0FXrneYWsg+H NTzL8uZPDlPUvP9fO1Zvmd7U2EjUTfpUtLvbx7L+hcAziPCNtl0dM3ur30BV4UD3DVOZR7 cs5aFN3owNUrYjW0OsJXMA/q6jhowq33AbB1T0nWFKVkGkgHA5KK88x7Pxx4eA== Received: from NAM05-CO1-obe.outbound.protection.outlook.com (mail-co1nam05lp2051.outbound.protection.outlook.com [104.47.48.51]) (Using TLS) by relay.mimecast.com with ESMTP id us-mta-245-29JnnxIWPSC-1kP2Qn2h2Q-1; Tue, 09 Jul 2019 14:56:14 -0400 Received: from CY4PR06CA0055.namprd06.prod.outlook.com (2603:10b6:903:13d::17) by MWHPR06MB2624.namprd06.prod.outlook.com (2603:10b6:300:48::20) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2052.18; Tue, 9 Jul 2019 18:56:12 +0000 Received: from SN1NAM02FT063.eop-nam02.prod.protection.outlook.com (2a01:111:f400:7e44::203) by CY4PR06CA0055.outlook.office365.com (2603:10b6:903:13d::17) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384) id 15.20.2052.18 via Frontend Transport; Tue, 9 Jul 2019 18:56:11 +0000 Received: from EDCV-XHG-MCP01.hub.local (64.14.237.30) by SN1NAM02FT063.mail.protection.outlook.com (10.152.72.213) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384) id 15.20.2032.15 via Frontend Transport; Tue, 9 Jul 2019 18:56:10 +0000 Received: from EDCV-XHG-MCP01.hub.local (10.130.29.195) by EDCV-XHG-MCP01.hub.local (10.130.29.195) with Microsoft SMTP Server (TLS) id 15.0.1395.4; Tue, 9 Jul 2019 13:56:10 -0500 Received: from EDCP-XHG-HCP01.hub.local (10.130.30.60) by EDCV-XHG-MCP01.hub.local (10.130.29.195) with Microsoft SMTP Server (TLS) id 15.0.1395.4 via Frontend Transport; Tue, 9 Jul 2019 13:56:10 -0500 Received: from EDCV-XHG-TNP01.hub.local ([fe80::b084:473e:8d93:3400]) by EDCP-XHG-HCP01.hub.local ([::1]) with mapi id 14.03.0408.000; Tue, 9 Jul 2019 13:55:57 -0500 From: "Chisholm, Rick" To: Miroslav Lachman <000.fbsd@quip.cz>, "freebsd-security@freebsd.org" Subject: RE: [EXTERNAL] Status of FreeBSD vulnerabilities in VUXML database Thread-Topic: [EXTERNAL] Status of FreeBSD vulnerabilities in VUXML database Thread-Index: AQHVNoMinrfT6TuD6kW249GHf/SUvabCon7w Date: Tue, 9 Jul 2019 18:55:56 +0000 Message-ID: <0054FFE9E041FC4EB2D50A99E26B120A06314D8F@EDCV-XHG-TNP01.hub.local> References: In-Reply-To: Accept-Language: en-US Content-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: x-originating-ip: [10.130.30.9] MIME-Version: 1.0 X-EOPAttributedMessage: 0 X-MS-Office365-Filtering-HT: Tenant X-Forefront-Antispam-Report: CIP:64.14.237.30; IPV:NLI; CTRY:US; EFV:NLI; SFV:NSPM; SFS:(10019020)(4636009)(136003)(39860400002)(396003)(346002)(376002)(2980300002)(189003)(199004)(13464003)(7696005)(47776003)(8676002)(76176011)(70206006)(70586007)(6246003)(68736007)(50466002)(97756001)(305945005)(2501003)(37786003)(46406003)(8746002)(7736002)(8936002)(486006)(23726003)(81166006)(81156014)(126002)(55846006)(476003)(11346002)(5660300002)(9686003)(33656002)(2906002)(14444005)(55016002)(86362001)(53936002)(6306002)(110136005)(356004)(229853002)(966005)(26005)(53546011)(102836004)(6116002)(186003)(336012)(478600001)(316002)(3846002)(446003)(130980200001); DIR:OUT; SFP:1102; SCL:1; SRVR:MWHPR06MB2624; H:EDCV-XHG-MCP01.hub.local; FPR:; SPF:SoftFail; LANG:en; PTR:InfoDomainNonexistent; MX:1; A:1; X-MS-PublicTrafficType: Email X-MS-Office365-Filtering-Correlation-Id: f0ff40a0-1cef-47ec-6ea7-08d7049f1be0 X-Microsoft-Antispam: BCL:0; PCL:0; RULEID:(2390118)(7020095)(4652040)(8989299)(4534185)(4627221)(201703031133081)(201702281549075)(8990200)(5600148)(711020)(4605104)(1401327)(2017052603328)(7193020); SRVR:MWHPR06MB2624; X-MS-TrafficTypeDiagnostic: MWHPR06MB2624: X-MS-Exchange-PUrlCount: 4 X-Microsoft-Antispam-PRVS: X-MS-Oob-TLC-OOBClassifiers: OLM:9508; X-Forefront-PRVS: 0093C80C01 X-MS-Exchange-SenderADCheck: 1 X-Microsoft-Antispam-Message-Info: xQAPELaDBnfBkeUoFj7ifNwsjOP5vqdYCnnoTWRk7zy+ELNM9xjpE4Dnoi5VuDF2QJq0MG96XEbiwGB2A3UYOSPyKhFUKgM5qeG81+FeYnz4jLuLWUOkT2B9CYzcTUR9fohgBx3Y0rNqomk9SWPLfQOZEEIYmv4QW1pGtFD0HFmHV1a5DTSBjVqIIvxyWEAIh0T94U7tSPV9Q6My+1XWhEpGQPaLDPTvZZovg6qFL2SSeSX9zgTuHO0h4gKTVUI13IForsNPxppwaWkcZx6ts4qSw/uYKoJsK6sL7F++trB6SdF2ju/QYU8aH84weBxzOfpxUOXPppygEvoeHvmhlK3SuMUDj0VLzvidqZChAEH7rcMbPV8xYzwgNtBXfiTHgY2f18D127JA1LK6OdRKWoCkxIaY6XqMQ3KwAF0fNh0= X-OriginatorOrg: hubinternational.com X-MS-Exchange-CrossTenant-OriginalArrivalTime: 09 Jul 2019 18:56:10.8757 (UTC) X-MS-Exchange-CrossTenant-Network-Message-Id: f0ff40a0-1cef-47ec-6ea7-08d7049f1be0 X-MS-Exchange-CrossTenant-Id: a18515c2-3198-4fad-97ed-29a46c974fdb X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=a18515c2-3198-4fad-97ed-29a46c974fdb; Ip=[64.14.237.30]; Helo=[EDCV-XHG-MCP01.hub.local] X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem X-MS-Exchange-Transport-CrossTenantHeadersStamped: MWHPR06MB2624 X-MC-Unique: 29JnnxIWPSC-1kP2Qn2h2Q-1 X-Mimecast-Spam-Score: 0 Content-Type: text/plain; charset=WINDOWS-1252 Content-Transfer-Encoding: quoted-printable X-Rspamd-Queue-Id: D021A804B1 X-Spamd-Bar: ---- Authentication-Results: mx1.freebsd.org; dkim=pass header.d=hubinternational.com header.s=hubinternational20170913 header.b=B8xEwxGe; dmarc=pass (policy=none) header.from=hubinternational.com; spf=pass (mx1.freebsd.org: domain of rick.chisholm@hubinternational.com designates 216.205.24.103 as permitted sender) smtp.mailfrom=rick.chisholm@hubinternational.com X-Spamd-Result: default: False [-4.71 / 15.00]; ARC_NA(0.00)[]; TO_DN_EQ_ADDR_SOME(0.00)[]; R_DKIM_ALLOW(-0.20)[hubinternational.com:s=hubinternational20170913]; HAS_XOIP(0.00)[]; FROM_HAS_DN(0.00)[]; TO_DN_SOME(0.00)[]; R_SPF_ALLOW(-0.20)[+ip4:216.205.24.0/24]; NEURAL_HAM_LONG(-1.00)[-1.000,0]; MIME_GOOD(-0.10)[text/plain]; IP_SCORE(-0.34)[ipnet: 216.205.24.0/24(-0.83), asn: 30031(-0.83), country: US(-0.06)]; RCVD_DKIM_ARC_DNSWL_MED(-0.50)[]; NEURAL_HAM_MEDIUM(-1.00)[-0.997,0]; TO_MATCH_ENVRCPT_SOME(0.00)[]; MX_GOOD(-0.01)[us-smtp-inbound-1.mimecast.com, us-smtp-inbound-2.mimecast.com, us-smtp-inbound-1.mimecast.com, us-smtp-inbound-2.mimecast.com, us-smtp-inbound-1.mimecast.com, us-smtp-inbound-2.mimecast.com, us-smtp-inbound-1.mimecast.com, us-smtp-inbound-2.mimecast.com, us-smtp-inbound-1.mimecast.com, us-smtp-inbound-2.mimecast.com, us-smtp-inbound-1.mimecast.com, us-smtp-inbound-2.mimecast.com, us-smtp-inbound-1.mimecast.com, us-smtp-inbound-2.mimecast.com, us-smtp-inbound-1.mimecast.com, us-smtp-inbound-2.mimecast.com, us-smtp-inbound-1.mimecast.com, us-smtp-inbound-2.mimecast.com, us-smtp-inbound-1.mimecast.com, us-smtp-inbound-2.mimecast.com, us-smtp-inbound-1.mimecast.com, us-smtp-inbound-2.mimecast.com, us-smtp-inbound-1.mimecast.com, us-smtp-inbound-2.mimecast.com, us-smtp-inbound-1.mimecast.com, us-smtp-inbound-2.mimecast.com, us-smtp-inbound-1.mimecast.com, us-smtp-inbound-2.mimecast.com, us-smtp-inbound-1.mimecast.com, us-smtp-inbound-2.mimecast.com, us-smtp-inbound-1.mimecast.com, us-smtp-inbound-2.mi mecast.com,us-smtp-inbound-1.mimecast.com,us-smtp-inbound-2.mimecast.com,us-smtp-inbound-1.mimecast.com,us-smtp-inbound-2.mimecast.com,us-smtp-inbound-1.mimecast.com,us-smtp-inbound-2.mimecast.com,us-smtp-inbound-1.mimecast.com,us-smtp-inbound-2.mimecast.com,us-smtp-inbound-1.mimecast.com,us-smtp-inbound-2.mimecast.com,us-smtp-inbound-1.mimecast.com,us-smtp-inbound-2.mimecast.com,us-smtp-inbound-1.mimecast.com,us-smtp-inbound-2.mimecast.com,us-smtp-inbound-1.mimecast.com,us-smtp-inbound-2.mimecast.com,us-smtp-inbound-1.mimecast.com,us-smtp-inbound-2.mimecast.com,us-smtp-inbound-1.mimecast.com,us-smtp-inbound-2.mimecast.com,us-smtp-inbound-1.mimecast.com,us-smtp-inbound-2.mimecast.com,us-smtp-inbound-1.mimecast.com,us-smtp-inbound-2.mimecast.com,us-smtp-inbound-1.mimecast.com,us-smtp-inbound-2.mimecast.com,us-smtp-inbound-1.mimecast.com,us-smtp-inbound-2.mimecast.com,us-smtp-inbound-1.mimecast.com,us-smtp-inbound-2.mimecast.com]; DKIM_TRACE(0.00)[hubinternational.com:+]; RCPT_COUNT_TWO(0.00)[2]; RCVD_IN_DNSWL_MED(-0.20)[103.24.205.216.list.dnswl.org : 127.0.3.2]; DMARC_POLICY_ALLOW(-0.50)[hubinternational.com,none]; NEURAL_HAM_SHORT(-0.66)[-0.663,0]; FROM_EQ_ENVFROM(0.00)[]; MIME_TRACE(0.00)[0:+]; RCVD_TLS_LAST(0.00)[]; ASN(0.00)[asn:30031, ipnet:216.205.24.0/24, country:US]; RCVD_COUNT_SEVEN(0.00)[8] X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 09 Jul 2019 18:56:27 -0000 My understanding has always been vuXML is for ports / packages and the advi= sories page is for base. -----Original Message----- From: owner-freebsd-security@freebsd.org On Behalf Of Miroslav Lachman Sent: July 9, 2019 2:14 PM To: freebsd-security@freebsd.org Subject: [EXTERNAL] Status of FreeBSD vulnerabilities in VUXML database This Message originated outside of the organization. What is the official status of FreeBSD Security Advisories and entries in V= UXML database? I am asking especially because new FreeBSD base system vulnerabilities are = not being added to the vuxml database. The last was added 2019-04-23 accord= ing to https://vuxml.freebsd.org/freebsd/ Why? VUXML is FreeBSD's own pet so why new SAs are not added there the same day = they are published as SA on https://www.freebsd.org/security/advisories.htm= l? It makes base-audit periodic useless.=20 https://www.freshports.org/security/base-audit/ Kind regards Miroslav Lachman _______________________________________________ freebsd-security@freebsd.org mailing list https://lists.freebsd.org/mailman= /listinfo/freebsd-security To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"