git: 941a70f2042b - main - security/vuxml: Fix affected port version of mail/thunderbird by CVE-2026-6778

Koichiro Iwao <[email protected]> Wed, 05 Aug 2026 02:49:54 +0000
Newsgroups gmane.os.freebsd.devel.cvs.ports
Message-ID <[email protected]>
The branch main has been updated by meta:

URL: https://cgit.FreeBSD.org/ports/commit/?id=941a70f2042b46f1e5d2d599887100e57f9baff9

commit 941a70f2042b46f1e5d2d599887100e57f9baff9
Author:     Koichiro Iwao <[email protected]>
AuthorDate: 2026-08-05 02:32:34 +0000
Commit:     Koichiro Iwao <[email protected]>
CommitDate: 2026-08-05 02:48:08 +0000

    security/vuxml: Fix affected port version of mail/thunderbird by CVE-2026-6778
    
    Although mail/thunderbird does not actually have PORTEPOCH, one is included in vuxml.
    As a result, even fixed versions were still incorrectly reported as vulnerable.
    
    The incorrect report was as follows:
    
    ===>  thunderbird-153.0.2 has known vulnerabilities:
    thunderbird-153.0.2 is vulnerable:
      Mozilla -- Invalid pointer
      CVE: CVE-2026-6778
      WWW: https://vuxml.FreeBSD.org/freebsd/5124ce36-430a-11f1-a627-b42e991fc52e.html
---
 security/vuxml/vuln/2026.xml | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/security/vuxml/vuln/2026.xml b/security/vuxml/vuln/2026.xml
index 2387bbdffc59..56e4eb1c290a 100644
--- a/security/vuxml/vuln/2026.xml
+++ b/security/vuxml/vuln/2026.xml
@@ -11656,7 +11656,7 @@ affected.</p>
     </package>
     <package>
 	<name>thunderbird</name>
-	<range><lt>150.0.0,2</lt></range>
+	<range><lt>150.0.0</lt></range>
     </package>
     </affects>
     <description>