pkg/60612: doc/pkg-vulnerabilities: fix empty version ranges to match the affected versions

"Showta Ishizaki via gnats" <[email protected]>
Newsgroups gmane.os.netbsd.devel.pkgsrc.bugs
Message-ID <[email protected]>
>Number:         60612
>Category:       pkg
>Synopsis:       doc/pkg-vulnerabilities: fix empty version ranges to match the affected versions
>Confidential:   no
>Severity:       non-critical
>Priority:       medium
>Responsible:    pkg-manager
>State:          open
>Class:          doc-bug
>Submitter-Id:   net
>Arrival-Date:   Mon Aug 17 09:00:01 +0000 2026
>Originator:     Showta Ishizaki
>Release:        NetBSD 10.1 / pkgsrc doc/pkg-vulnerabilities rev 1.779
>Organization:
>Environment:
System: NetBSD bambi.snowrabbit.org 10.1 NetBSD 10.1 (GENERIC) #0: Mon Dec 16 13:08:11 UTC 2024 [email protected]:/usr/src/sys/arch/i386/compile/GENERIC i386
Architecture: i386
Machine: i386
>Description:
	In pkg_install dewey semantics "X.Y" == "X.Y.0", and pre-release
	suffixes (alpha/beta/rc) sort BELOW the plain version.  A range
	like ">=7.1<7.1.0" is therefore empty: it matches nothing at
	all, not even the pre-releases it was presumably meant to
	cover.  An audit against rev 1.779 found 9 such entries; the
	patch rewrites them so they match the versions the referenced
	advisories actually list as affected:

	- libreoffice>=5.0.0alpha1<5.0.0 (was >=5.0<5.0.0):
	  CVE-2015-4551 was fixed in 4.4.5/5.0.0, so on the 5.0 branch
	  only the pre-releases were affected.  (pkgsrc never shipped
	  5.x pre-releases, so this mainly makes the entry
	  self-consistent.)
	- libreoffice>=5.2.0alpha1<5.2.0 and
	  libreoffice5-bin>=5.2.0alpha1<5.2.0 (were >5.2<5.2.0):
	  CVE-2016-4324, fixed in 5.1.4/5.2.0.  Same remark as above;
	  the second entry also fixes the PKGBASE ("libreoffice-bin"
	  never existed; the binary package of that era is
	  libreoffice5-bin).  Released versions were and are covered
	  by the libreoffice<5.1.4 entry above (pkgsrc shipped
	  5.1.2.2/5.1.3.2 at the time).
	- php>=7.1.0alpha1<7.1.0 (3 entries, were >=7.1<7.1.0):
	  CVE-2016-9933/9934/9936 were fixed before 7.1.0 was
	  released.  pkgsrc shipped php-7.1.0beta1 (added 2016-08-04)
	  through php-7.1.0rc6, so these entries now match actual
	  historic packages.
	- libreoffice / CVE-2017-3157: the advisory's fixed versions
	  are 5.1.6, 5.2.2 and 5.3.0, but for the main libreoffice
	  package only the empty 5.3 range existed (lines 11249-11250
	  cover libreoffice5-bin only) -- a real false negative:
	  pkgsrc shipped libreoffice 5.0.3.2 through 5.1.5.2, all
	  matched by the new libreoffice<5.1.6 entry added at the end
	  of the file.  The 5.3 entry becomes >=5.3.0alpha1<5.3.0,
	  and libreoffice>=5.2<5.2.2 is added for completeness
	  (pkgsrc's first 5.2 package was already-fixed 5.2.3.3).
	- mongodb>=8.1<8.1.1 (was >=8.1<8.1.0): CVE-2025-7259 affects
	  exactly 8.1.0; the old range excluded the one affected
	  version.  (pkgsrc mongodb is 6.0.x; corrected for accuracy.)
	- zabbix-server-{mysql,postgresql} / CVE-2024-22116: affected
	  are 6.4.9-6.4.15 (fixed 6.4.16) and 7.0.0alpha1-7.0.0rc2
	  (fixed 7.0.0rc3); the old ">=7.0<7.0.0" matched neither.
	  Rewritten to >=6.4.9<6.4.16 with a companion
	  >=7.0.0alpha1<7.0.0rc3 entry added at the end.  (Neither
	  branch was ever packaged in pkgsrc.)

	Thanks as always for the prompt handling of these reports.
>How-To-Repeat:
	pkg_admin pmatch 'php>=7.1<7.1.0' php-7.1.0rc6 (no match) vs
	pkg_admin pmatch 'php>=7.1.0alpha1<7.1.0' php-7.1.0rc6 (match).
>Fix:
	Apply the following patch (against rev 1.779):

--- pkg-vulnerabilities.cvshead	2026-08-17 16:35:32
+++ pkg-vulnerabilities.1779.emptyfix	2026-08-17 17:33:07
@@ -9427,7 +9427,7 @@
 libreoffice4>=4.0<4.4.6		denial-of-service		http://www.libreoffice.org/about-us/security/advisories/cve-2015-5214/
 libreoffice4-bin>=4.0<4.4.6	denial-of-service		http://www.libreoffice.org/about-us/security/advisories/cve-2015-5214/
 libreoffice43-[0-9]*		denial-of-service		http://www.libreoffice.org/about-us/security/advisories/cve-2015-5214/
-libreoffice>=5.0<5.0.0		denial-of-service		http://www.libreoffice.org/about-us/security/advisories/cve-2015-4551/
+libreoffice>=5.0.0alpha1<5.0.0		denial-of-service		http://www.libreoffice.org/about-us/security/advisories/cve-2015-4551/
 libreoffice4>=4.0<4.4.5		denial-of-service		http://www.libreoffice.org/about-us/security/advisories/cve-2015-4551/
 libreoffice4-bin>=4.0<4.4.5	denial-of-service		http://www.libreoffice.org/about-us/security/advisories/cve-2015-4551/
 libreoffice43-[0-9]*		denial-of-service		http://www.libreoffice.org/about-us/security/advisories/cve-2015-4551/
@@ -10258,8 +10258,8 @@
 apache-tomcat>=8.0<8.0.36 		denial-of-service		https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3092
 libreoffice<5.1.4 			remote-code-execution		http://www.libreoffice.org/about-us/security/advisories/cve-2016-4324/
 libreoffice-bin<5.1.4 			remote-code-execution		http://www.libreoffice.org/about-us/security/advisories/cve-2016-4324/
-libreoffice>5.2<5.2.0			remote-code-execution		http://www.libreoffice.org/about-us/security/advisories/cve-2016-4324/
-libreoffice-bin>5.2<5.2.0		remote-code-execution		http://www.libreoffice.org/about-us/security/advisories/cve-2016-4324/
+libreoffice>=5.2.0alpha1<5.2.0			remote-code-execution		http://www.libreoffice.org/about-us/security/advisories/cve-2016-4324/
+libreoffice5-bin>=5.2.0alpha1<5.2.0		remote-code-execution		http://www.libreoffice.org/about-us/security/advisories/cve-2016-4324/
 dnsmasq<2.76 				denial-of-service		https://nvd.nist.gov/vuln/detail/CVE-2015-8899
 haproxy<1.6.6 				denial-of-service		https://nvd.nist.gov/vuln/detail/CVE-2016-5360
 bzip2<1.0.7 				denial-of-service		https://nvd.nist.gov/vuln/detail/CVE-2016-3189
@@ -10816,14 +10816,14 @@
 firefox45<45.6		multiple-vulnerabilities	https://www.mozilla.org/en-US/security/advisories/mfsa2016-95/
 php>=5.6<5.6.28		denial-of-service	https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9933
 php>=7.0<7.0.13		denial-of-service	https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9933
-php>=7.1<7.1.0		denial-of-service	https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9933
+php>=7.1.0alpha1<7.1.0		denial-of-service	https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9933
 php>=5.6<5.6.28		denial-of-service	https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9934
 php>=7.0<7.0.13		denial-of-service	https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9934
-php>=7.1<7.1.0		denial-of-service	https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9934
+php>=7.1.0alpha1<7.1.0		denial-of-service	https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9934
 php>=5.6<5.6.29		denial-of-service	https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9935
 php>=7.0<7.0.14		denial-of-service	https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9935
 php>=7.0<7.0.14		use-after-free		https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9936
-php>=7.1<7.1.0		use-after-free		https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9936
+php>=7.1.0alpha1<7.1.0		use-after-free		https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9936
 lynx<2.8.8.2nb5 	information-leak	http://seclists.org/oss-sec/2016/q4/322
 php{56,70,71}-roundcube<1.2.0	code-injection		https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-4552
 py{27,34,35}-docx<0.8.6 	xml-external-entity	https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-5851
@@ -11248,7 +11248,7 @@
 GraphicsMagick<1.3.24	denial-of-service		https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-5240
 libreoffice5-bin>5.1<5.1.6	arbitrary-file-disclosure	https://www.libreoffice.org/about-us/security/advisories/cve-2017-3157/
 libreoffice5-bin>5.2<5.2.2	arbitrary-file-disclosure	https://www.libreoffice.org/about-us/security/advisories/cve-2017-3157/
-libreoffice>5.3<5.3.0		arbitrary-file-disclosure	https://www.libreoffice.org/about-us/security/advisories/cve-2017-3157/
+libreoffice>=5.3.0alpha1<5.3.0		arbitrary-file-disclosure	https://www.libreoffice.org/about-us/security/advisories/cve-2017-3157/
 jasper<2.0.19		denial-of-service	https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-5498
 jasper<2.0.19		denial-of-service	https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-5499
 jasper<2.0.19		denial-of-service	https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-5500
@@ -27157,7 +27157,7 @@
 mongodb>=8.0<8.0.10	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-6712
 mongodb<6.0.22		authorization-bypass	https://nvd.nist.gov/vuln/detail/CVE-2025-6713
 mongodb<6.0.23		denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-6714
-mongodb>=8.1<8.1.0	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-7259
+mongodb>=8.1<8.1.1	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-7259
 #mtr<0.96		unspecified		https://nvd.nist.gov/vuln/detail/CVE-2025-49809
 pandoc<3.6.4		server-side-request-forgery	https://nvd.nist.gov/vuln/detail/CVE-2025-51591
 plan9port<20250422	heap-overflow		https://nvd.nist.gov/vuln/detail/CVE-2025-7208
@@ -27583,7 +27583,7 @@
 zabbix-server-{mysql,postgresql}<6.0.23	arbitrary-code-execution	https://nvd.nist.gov/vuln/detail/CVE-2023-32727
 zabbix-agent<6.0.24			code-injection		https://nvd.nist.gov/vuln/detail/CVE-2023-32728
 zabbix-server-{mysql,postgresql}<6.0.30	information-disclosure	https://nvd.nist.gov/vuln/detail/CVE-2024-22114
-zabbix-server-{mysql,postgresql}>=7.0<7.0.0	remote-code-execution	https://nvd.nist.gov/vuln/detail/CVE-2024-22116
+zabbix-server-{mysql,postgresql}>=6.4.9<6.4.16	remote-code-execution	https://nvd.nist.gov/vuln/detail/CVE-2024-22116
 zabbix-frontend<6.0.34			input-validation	https://nvd.nist.gov/vuln/detail/CVE-2024-22117
 zabbix-frontend<6.0.24			cross-site-scripting	https://nvd.nist.gov/vuln/detail/CVE-2024-22119
 zabbix-server-{mysql,postgresql}<6.0.31	command-injection	https://nvd.nist.gov/vuln/detail/CVE-2024-22122
@@ -30424,3 +30424,6 @@
 nginx{,-devel}>=1.31.0<1.31.3	sensitive-information-disclosure	https://nvd.nist.gov/vuln/detail/CVE-2026-60005
 nginx{,-devel}>=0.9.6<1.30.4	heap-overflow	https://nvd.nist.gov/vuln/detail/CVE-2026-42533
 nginx{,-devel}>=1.31.0<1.31.3	heap-overflow	https://nvd.nist.gov/vuln/detail/CVE-2026-42533
+libreoffice<5.1.6		arbitrary-file-disclosure	https://www.libreoffice.org/about-us/security/advisories/cve-2017-3157/
+libreoffice>=5.2<5.2.2	arbitrary-file-disclosure	https://www.libreoffice.org/about-us/security/advisories/cve-2017-3157/
+zabbix-server-{mysql,postgresql}>=7.0.0alpha1<7.0.0rc3	remote-code-execution	https://nvd.nist.gov/vuln/detail/CVE-2024-22116
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.