From nobody Fri Feb 23 22:52:30 2024 X-Original-To: dev-commits-ports-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4ThQJH3t3zz5BhB1; Fri, 23 Feb 2024 22:52:31 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4ThQJH0kjMz4Fyb; Fri, 23 Feb 2024 22:52:31 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1708728751; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=cbO3xMjANeY3TOwyE6Of6l+PLeN+jre9kBWgwP6Qr0M=; b=Tl+sKmmFTdO8PfDp0QSaklGmd9WTht+KjzpjLJck/bKJVlJvf46uwvdmL6fijcfRtWBpij NShj8jgXIy7CVHv/W3TWOYRiyA/8sM+GFSRzBJta7fk5t7t7sxZan2JKLFPSVcSLi2sugE GMVVGNAxgZKN3F9/ZFtv0pBhqrMo9Bw5viKlARh/stkP8hOH/gkOnge1mmtMFBJSazA9lF 41mVTXIUoBHJCEdrp0mT21VqFR9j6jC0LvtQKkllge4VQg/5zRjjK7z5v+Ox06Axe7B2Ry /zsE+nFjwsDby/sSy3M6jCQRvIM6n3n9l0Ba7cNBmdpQQGRYt/3SOtL1Mcw4OA== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1708728751; a=rsa-sha256; cv=none; b=uPbh412/zUejF6lpwV9ouCQEzhLrsvoRAYKCzYiOw9N73MNRuZ0qFyYLdhMfXVYe+mVOW4 rt2VLxeC9QTcbnB6oNqLdLp2fnjx3EOlox+fWfAgGYM+A2DHdCSsulREjPHbBLVNj+L3w1 B+JdkPVoV3OKD7Fetca/NcZD26oYD9Bv9bi0u9yPqyDpuMo6kITq0ujhsGHGj95A8F4Ntz Ajkm4ay4CAWhab9z9lCiIuSgj9EcVlW2Yherr3SX0Kt6wpghQ8vnQ23yXQM5sBKMbN/ayb xAHLoVjWLAEyi3aN3XVwy6hhOgtLFaVCSaaAlxT5b2DLiaaNgb5J9tTVqtAClw== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1708728751; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=cbO3xMjANeY3TOwyE6Of6l+PLeN+jre9kBWgwP6Qr0M=; b=V899LgTywpD23MkNU0I+z/hrwU9Fen86OJ5ccXlnjG05j/TWzQz7EWjstFCrYRAROPjP/B icQQjXQdbCiRHDti2l7EdUQURxeKmyHDUp0ymweR3nT+ZYJc6c7q1MNCo0zPdRBKZxwVs3 jnFigSHQHl0GClKEN3riJtwknHArFAokyfYx48cXfemHw7VE4rUgc6XoXDhQ1MKqaFV2E8 p/q0jDGjnr1JnOd3Vbtto+NpnL7VpUszLwA6AX89sHL+UwaGPHocmNCdrZbiuHUd3LZY0a Ylg0U0M5URvLSJttWxA0qv1PcFW8xnfyXbW0k2sVoidwm5H5MWJFbZqFrbhsWw== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4ThQJG6y3hzb4N; Fri, 23 Feb 2024 22:52:30 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.17.1/8.17.1) with ESMTP id 41NMqUFH027166; Fri, 23 Feb 2024 22:52:30 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.17.1/8.17.1/Submit) id 41NMqU3O027163; Fri, 23 Feb 2024 22:52:30 GMT (envelope-from git) Date: Fri, 23 Feb 2024 22:52:30 GMT Message-Id: <202402232252.41NMqU3O027163@gitrepo.freebsd.org> To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-main@FreeBSD.org From: Rodrigo Osorio Subject: git: 10eebcc6aee5 - main - security/vuxml: Record dns/c-ares vulnerability List-Id: Commit messages for all branches of the ports repository List-Archive: https://lists.freebsd.org/archives/dev-commits-ports-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-dev-commits-ports-all@freebsd.org X-BeenThere: dev-commits-ports-all@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: rodrigo X-Git-Repository: ports X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: 10eebcc6aee54431ff7bcf6c14f25c8142214ad5 Auto-Submitted: auto-generated The branch main has been updated by rodrigo: URL: https://cgit.FreeBSD.org/ports/commit/?id=10eebcc6aee54431ff7bcf6c14f25c8142214ad5 commit 10eebcc6aee54431ff7bcf6c14f25c8142214ad5 Author: Rodrigo Osorio AuthorDate: 2024-02-23 22:33:06 +0000 Commit: Rodrigo Osorio CommitDate: 2024-02-23 22:51:42 +0000 security/vuxml: Record dns/c-ares vulnerability --- security/vuxml/vuln/2024.xml | 26 ++++++++++++++++++++++++++ 1 file changed, 26 insertions(+) diff --git a/security/vuxml/vuln/2024.xml b/security/vuxml/vuln/2024.xml index b66c5c5bc5cd..44a77b7a4679 100644 --- a/security/vuxml/vuln/2024.xml +++ b/security/vuxml/vuln/2024.xml @@ -1,3 +1,29 @@ + + dns/c-ares -- malformatted file causes application crash + + + c-ares + 1.27.0 + + + + +

c-ares project reports:

+
+

Reading malformatted /etc/resolv.conf, /etc/nsswitch.conf or the HOSTALIASES file could result in a crash.

+
+ +
+ + CVE-2024-25629 + https://github.com/c-ares/c-ares/security/advisories/GHSA-mg26-v6qh-x48q + + + 2024-02-23 + 2024-02-23 + +
+ suricata -- multiple vulnerabilities