Re: git: e9f01757b5b0 - main - databases/sqlcipher: Update 4.16.0 => 4.17.0

Vladimir Druzenko <[email protected]>
Newsgroups gmane.os.freebsd.devel.cvs.ports
Message-ID <[email protected]>
13.08.2026 18:18, Jochen Neumeister пишет:
> Am 13.08.26 um 16:54 schrieb Vladimir Druzenko:
>> The branch main has been updated by vvd:
>>
>> URL: 
>> https://cgit.FreeBSD.org/ports/commit/?id=e9f01757b5b01424c3c70e1648cd234588b907d4
>>
>> commit e9f01757b5b01424c3c70e1648cd234588b907d4
>> Author:     Herbert J. Skuhra <[email protected]>
>> AuthorDate: 2026-08-13 14:32:52 +0000
>> Commit:     Vladimir Druzenko <[email protected]>
>> CommitDate: 2026-08-13 14:54:21 +0000
>>
>>      databases/sqlcipher: Update 4.16.0 => 4.17.0
>>           Release Notes:
>> https://www.zetetic.net/blog/2026/07/08/sqlcipher-4.17.0-release/
>>           Changelog:
>> https://github.com/sqlcipher/sqlcipher/releases/tag/v4.17.0
>>           PR:             296869
>>      Approved by: [email protected] (maintainer, timeout 26 days)
>>      Security:       CVE-2026-11822
>>      Security:       CVE-2026-11824
>
> Hi,
> Please create a vuxml entry. Thank you 
Hello!
These are "Upstream SQLite CVEs", not sqlcipher's:

>
>       Upstream SQLite CVEs
>
> The new SQLite 3.53.3 baseline fixes two memory corruption issues in 
> the FTS5 full-text search extension, CVE-2026-11822 
> <https://nvd.nist.gov/vuln/detail/CVE-2026-11822> and CVE-2026-11824 
> <https://nvd.nist.gov/vuln/detail/CVE-2026-11824>. These can be 
> triggered by a FTS5 query running against a database that contains 
> specially attacker-crafted data. They also require the application to 
> have disabled defensive mode 
> <https://sqlite.org/c3ref/c_dbconfig_defensive.html> 
> (|SQLITE_DBCONFIG_DEFENSIVE|). Further details are available on the 
> SQLite CVE list <https://www.sqlite.org/cves.html>.
>
> For SQLCipher users, the practical risk of these CVEs is low. Because 
> SQLCipher databases are encrypted, an attacker can’t construct 
> malicious database contents needed to trigger these issues without 
> knowing the database key. Therefore, applications that maintain strong 
> key controls and work with their own encrypted databases (i.e. not 
> ones supplied by third parties) have very little exposure. However, we 
> still recommend upgrading to address these fixes, especially for 
> applications that could possibly open databases from untrusted sources.
>
https://www.zetetic.net/blog/2026/07/08/sqlcipher-4.17.0-release/

>
> Greetings
>
>
>>      Sponsored by:   UNIS Labs
>>      MFH:            2026Q3
>> ---
>>   databases/sqlcipher/Makefile  | 2 +-
>>   databases/sqlcipher/distinfo  | 6 +++---
>>   databases/sqlcipher/pkg-plist | 2 +-
>>   3 files changed, 5 insertions(+), 5 deletions(-)
>>
>> diff --git a/databases/sqlcipher/Makefile b/databases/sqlcipher/Makefile
>> index 0287afeb41be..cfc8ca10e011 100644
>> --- a/databases/sqlcipher/Makefile
>> +++ b/databases/sqlcipher/Makefile
>> @@ -1,6 +1,6 @@
>>   PORTNAME=    sqlcipher
>>   DISTVERSIONPREFIX=    v
>> -DISTVERSION=    4.16.0
>> +DISTVERSION=    4.17.0
>>   CATEGORIES=    databases
>>     MAINTAINER= [email protected]
>> diff --git a/databases/sqlcipher/distinfo b/databases/sqlcipher/distinfo
>> index d068c39f2aa9..f2fca94d15ae 100644
>> --- a/databases/sqlcipher/distinfo
>> +++ b/databases/sqlcipher/distinfo
>> @@ -1,3 +1,3 @@
>> -TIMESTAMP = 1778653941
>> -SHA256 (sqlcipher-sqlcipher-v4.16.0_GH0.tar.gz) = 
>> d687bf981199ac019c6c87b11f92a5900aec777855e7ba5b30e5e1192933ce8a
>> -SIZE (sqlcipher-sqlcipher-v4.16.0_GH0.tar.gz) = 19314061
>> +TIMESTAMP = 1783757770
>> +SHA256 (sqlcipher-sqlcipher-v4.17.0_GH0.tar.gz) = 
>> 79c0e164b9c059e7487bf8f29272f601cca5f3312cc267461f81e349962a5058
>> +SIZE (sqlcipher-sqlcipher-v4.17.0_GH0.tar.gz) = 19336303
>> diff --git a/databases/sqlcipher/pkg-plist 
>> b/databases/sqlcipher/pkg-plist
>> index cb0c4ea15683..8bb3f5412d2c 100644
>> --- a/databases/sqlcipher/pkg-plist
>> +++ b/databases/sqlcipher/pkg-plist
>> @@ -4,6 +4,6 @@ include/sqlcipher/sqlite3ext.h
>>   lib/libsqlcipher.a
>>   lib/libsqlcipher.so
>>   lib/libsqlcipher.so.0
>> -lib/libsqlcipher.so.3.53.1
>> +lib/libsqlcipher.so.3.53.3
>>   libdata/pkgconfig/sqlcipher.pc
>>   share/man/man1/sqlcipher.1.gz
>>
>>
>
>

-- 
Best regards,
Vladimir Druzenko
OpenPGP_0x8006FAABBF942F73.asc (application/pgp-keys, 1022 B)
-----BEGIN PGP PUBLIC KEY BLOCK-----

xjMEZEmcEhYJKwYBBAHaRw8BAQdAzzVRU/u5Oe4kUEFSvaiRoAPwsXMi4uBnfKqF
TOIxjaDNI1ZsYWRpbWlyIERydXplbmtvIDx2dmRAZnJlZWJzZC5vcmc+wo8EExYI
ADcWIQQJVt5Qnq2dfk5hjMKABvqrv5QvcwUCacM8GwUJCx5LPgIbAwQLCQgHBRUI
CQoLBRYCAwEAAAoJEIAG+qu/lC9zh6kBAN/ygnmea43X5OKnYKyPknpHMbmUaU2t
TxSu4tnm/zarAP9t0OZWAD4Xkf0jI7pBXzRJ2r0MJkunctLjnoHjMK8WBMKPBBMW
CAA3FiEECVbeUJ6tnX5OYYzCgAb6q7+UL3MFAmRJnBIFCQWjmoACGwMECwkIBwUV
CAkKCwUWAgMBAAAKCRCABvqrv5Qvc/6nAQC74iaaQn6TfHy4+R350O+QEUv0bzi/
mzxweNtrr/TxTgD/fNpoOLqqGK9Qb0lapq7Qe/6MZKkXiHongSJMgUzPewLOOARk
SZwTEgorBgEEAZdVAQUBAQdA+NRiYD7F1MlkHJEX+9uc/ArBgAzI5SKSW1YVlEC4
uH8DAQgHwn4EGBYIACYWIQQJVt5Qnq2dfk5hjMKABvqrv5QvcwUCacM8GwUJCx5L
PgIbDAAKCRCABvqrv5Qvc/osAQDgIEyDPHlC2Ypgop3Oo8kpk8cBW5ZIHrmdWba+
16tOKwEAwj1c/N93P9KvE4ejG1NC6K9TpjZMCR6Na8GLJYkZlQLCfgQYFggAJhYh
BAlW3lCerZ1+TmGMwoAG+qu/lC9zBQJkSZwTBQkFo5qAAhsMAAoJEIAG+qu/lC9z
4bgA/jGNXk0cGGKii1lXk55Gwh2EQhC4pLxQe/36TZiR29IBAP40fSUJOJ41IS0d
8k6d5DQ0E9BJuRf+1S5AzsAUz0rmBQ==
=dXPi
-----END PGP PUBLIC KEY BLOCK-----
OpenPGP_signature.asc (application/pgp-signature, 236 B)
-----BEGIN PGP SIGNATURE-----

wnsEABYIACMWIQQJVt5Qnq2dfk5hjMKABvqrv5QvcwUCan4cmAUDAAAAAAAKCRCABvqrv5Qvc8mO
APwNAt0GbTky4/YL7cwSwN1y7UWKdvxwSBQdBPyhPI9d7gEAnrIA2PocEeuHsxqyhBu1qS5Snuzd
Sd3dQJrvkeXRGQs=
=4i4x
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.