pkg/60616: doc/pkg-vulnerabilities: fix entries applying CVEs to the wrong product
"Showta Ishizaki via gnats" <[email protected]>
| Newsgroups | gmane.os.netbsd.devel.pkgsrc.bugs |
|---|---|
| Message-ID | <[email protected]> |
>Number: 60616 >Category: pkg >Synopsis: doc/pkg-vulnerabilities: fix entries applying CVEs to the wrong product >Confidential: no >Severity: non-critical >Priority: medium >Responsible: pkg-manager >State: open >Class: doc-bug >Submitter-Id: net >Arrival-Date: Mon Aug 17 15:35:02 +0000 2026 >Originator: Showta Ishizaki >Release: NetBSD 10.1 / pkgsrc doc/pkg-vulnerabilities rev 1.779 >Organization: >Environment: System: NetBSD bambi.snowrabbit.org 10.1 NetBSD 10.1 (GENERIC) #0: Mon Dec 16 13:08:11 UTC 2024 [email protected]:/usr/src/sys/arch/i386/compile/GENERIC i386 Architecture: i386 Machine: i386 >Description: These entries cite CVEs that belong to a different product than the pkgsrc package they are written against, producing false positives in "pkg_admin audit" (or, in one case, pointing at the wrong package entirely): - 9 phppgadmin entries carry pgAdmin 4 CVEs (CVE-2022-4223, CVE-2023-22298, CVE-2025-9636, CVE-2025-12762..12765, CVE-2025-13780, CVE-2026-1707). pgAdmin 4 (a Python application by the pgAdmin project) and phpPgAdmin (a PHP application) are unrelated codebases, and pkgsrc has no pgAdmin 4 package. Because phpPgAdmin's real versions (7.14.x) are below bounds like "<9.10", pkg_admin audit flags php8x-phppgadmin users with pgAdmin 4 vulnerabilities today. Commented out. - icinga-base>=2 / CVE-2018-18248: the CVE is an XSS in Icinga Web 2; net/icinga-base packages Icinga 1.x (frozen at 1.9.4), which never reached version 2, so this entry could never match. Commented out; the corrected entry icingaweb2<2.6.2 is added at the end of the file (net/icingaweb2 exists and its other CVEs already use that PKGBASE). - php81<8.1.32 and php82<8.2.28 / CVE-2024-11235: per the PHP CNA record the CVE affects only PHP 8.3 (< 8.3.19) and 8.4 (< 8.4.5), and the 8.1.32/8.2.28 ChangeLogs do not contain this fix. The correct php83/php84 entries already exist directly below. Commented out. - go123<1.23.10 / CVE-2025-22874: affects only Go 1.24 (the affected VerifyOptions/ExtKeyUsageAny policy-validation code was introduced in 1.24); fixed in 1.24.4. The correct go124 entry is directly above. Commented out. - blosc-[0-9]* / CVE-2020-29367: the CVE is a heap overflow in blosc2.c of C-Blosc2 (through 2.0.0.beta.5); c-blosc 1.x (PKGBASE blosc) never contained that file, so blosc users were falsely flagged. Corrected to blosc2<2.0.0rc1 -- the fix commit c4c6470e is first contained in v2.0.0.rc1 (no beta.6 exists), and devel/blosc2's PKGBASE is blosc2. - py{...}-installer<6.0.0 / CVE-2025-59042: the CVE is PyInstaller's local privilege escalation; pkgsrc's misc/py-installer is pypa/installer, an unrelated product, and pkgsrc does not package PyInstaller at all. Commented out. Thanks as always for the prompt handling of these reports. How-To-Repeat: pkg_admin audit with php83-phppgadmin-7.14.7 installed reports the pgAdmin 4 CVEs listed above. >Fix: Apply the following patch (against rev 1.779): --- pkg-vulnerabilities.cvshead 2026-08-17 16:35:32 +++ pkg-vulnerabilities.1779.batchB 2026-08-18 00:32:10 @@ -16403,7 +16403,7 @@ nagios-base<4.4.3 cross-site-scripting https://nvd.nist.gov/vuln/detail/CVE-2018-18245 icinga-base>=2<2.6.2 cross-site-request-forgery https://nvd.nist.gov/vuln/detail/CVE-2018-18246 icinga-base>=2<2.6.2 cross-site-scripting https://nvd.nist.gov/vuln/detail/CVE-2018-18247 -icinga-base>=2 cross-site-scripting https://nvd.nist.gov/vuln/detail/CVE-2018-18248 +#icinga-base>=2 cross-site-scripting https://nvd.nist.gov/vuln/detail/CVE-2018-18248 # CVE is for Icinga Web 2, not Icinga 1.x; corrected entry added at end of file icinga-base>=2<2.6.2 code-injection https://nvd.nist.gov/vuln/detail/CVE-2018-18249 icinga-base>=2<2.6.2 sensitive-information-disclosure https://nvd.nist.gov/vuln/detail/CVE-2018-18250 yara-[0-9]* arbitrary-code-execution https://nvd.nist.gov/vuln/detail/CVE-2018-19974 @@ -20210,7 +20210,7 @@ xpdf-[0-9]* use-after-free https://nvd.nist.gov/vuln/detail/CVE-2020-25725 webkit-gtk<2.30.3 multiple-vulnerabilities https://webkitgtk.org/security/WSA-2020-0008.html webkit-gtk<2.30.3 multiple-vulnerabilities https://webkitgtk.org/security/WSA-2020-0009.html -blosc-[0-9]* heap-overflow https://nvd.nist.gov/vuln/detail/CVE-2020-29367 +blosc2<2.0.0rc1 heap-overflow https://nvd.nist.gov/vuln/detail/CVE-2020-29367 consul<1.6.10 sensitive-information-disclosure https://nvd.nist.gov/vuln/detail/CVE-2020-28053 gitea<1.12.6 crlf-attack https://nvd.nist.gov/vuln/detail/CVE-2020-28991 jetty<9.4.35.20201120 memory-corruption https://nvd.nist.gov/vuln/detail/CVE-2020-27218 @@ -24802,10 +24802,10 @@ php{56,73,74,80,81}-gd>=8.0.0<8.0.25 sensitive-information-disclosure https://nvd.nist.gov/vuln/detail/CVE-2022-31630 php{56,73,74,80,81}-gd>=8.1.0<8.1.12 sensitive-information-disclosure https://nvd.nist.gov/vuln/detail/CVE-2022-31630 php{73,74,80,81}-phpmyadmin>=5<5.2.0 sql-injection https://nvd.nist.gov/vuln/detail/CVE-2020-22452 -phppgadmin<6.17 arbitrary-code-execution https://nvd.nist.gov/vuln/detail/CVE-2022-4223 +#phppgadmin<6.17 arbitrary-code-execution https://nvd.nist.gov/vuln/detail/CVE-2022-4223 # CVE is for pgAdmin 4, not phpPgAdmin; pkgsrc has no pgAdmin 4 package php{56,73,74,80,81}-phpmyadmin<4.9.11 cross-site-scripting https://nvd.nist.gov/vuln/detail/CVE-2023-25727 php{73,74,80,81}-phpmyadmin>=5<5.2.1 cross-site-scripting https://nvd.nist.gov/vuln/detail/CVE-2023-25727 -phppgadmin>=4<6.14 authentication-bypass https://nvd.nist.gov/vuln/detail/CVE-2023-22298 +#phppgadmin>=4<6.14 authentication-bypass https://nvd.nist.gov/vuln/detail/CVE-2023-22298 # CVE is for pgAdmin 4, not phpPgAdmin; pkgsrc has no pgAdmin 4 package phoronix-test-suite-[0-9]* cross-site-scripting https://nvd.nist.gov/vuln/detail/CVE-2022-40704 mplayer<15.0 division-by-zero https://nvd.nist.gov/vuln/detail/CVE-2022-38865 mencoder<15.0 division-by-zero https://nvd.nist.gov/vuln/detail/CVE-2022-38865 @@ -26151,8 +26151,8 @@ thunderbird<128.8 use-after-free https://nvd.nist.gov/vuln/detail/CVE-2025-1931 tinyxml2<10.1.0 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2024-50615 freetype2<2.13.3 arbitrary-code-execution https://nvd.nist.gov/vuln/detail/CVE-2025-27363 -php81<8.1.32 use-after-free https://nvd.nist.gov/vuln/detail/CVE-2024-11235 -php82<8.2.28 use-after-free https://nvd.nist.gov/vuln/detail/CVE-2024-11235 +#php81<8.1.32 use-after-free https://nvd.nist.gov/vuln/detail/CVE-2024-11235 # CVE-2024-11235 affects only PHP 8.3/8.4 (see entries below) +#php82<8.2.28 use-after-free https://nvd.nist.gov/vuln/detail/CVE-2024-11235 # CVE-2024-11235 affects only PHP 8.3/8.4 (see entries below) php83<8.3.19 use-after-free https://nvd.nist.gov/vuln/detail/CVE-2024-11235 php84<8.4.5 use-after-free https://nvd.nist.gov/vuln/detail/CVE-2024-11235 expat<2.7.3 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2024-8176 @@ -26368,7 +26368,7 @@ go124<1.24.4 http-header-injection https://nvd.nist.gov/vuln/detail/CVE-2025-4673 go123<1.23.10 http-header-injection https://nvd.nist.gov/vuln/detail/CVE-2025-4673 go124<1.24.4 insecure-key-validation https://nvd.nist.gov/vuln/detail/CVE-2025-22874 -go123<1.23.10 insecure-key-validation https://nvd.nist.gov/vuln/detail/CVE-2025-22874 +#go123<1.23.10 insecure-key-validation https://nvd.nist.gov/vuln/detail/CVE-2025-22874 # CVE-2025-22874 affects only Go 1.24 (see previous entry) assimp<6.0.2 out-of-bounds-write https://nvd.nist.gov/vuln/detail/CVE-2025-2750 assimp<6.0.2 out-of-bounds-read https://nvd.nist.gov/vuln/detail/CVE-2025-2751 assimp<6.0.2 heap-overflow https://nvd.nist.gov/vuln/detail/CVE-2025-2757 @@ -27523,7 +27523,7 @@ p5-Cpanel-JSON-XS<4.40 integer-overflow https://nvd.nist.gov/vuln/detail/CVE-2025-40929 p5-JSON-XS<4.04 integer-overflow https://nvd.nist.gov/vuln/detail/CVE-2025-40928 pcre2<10.46 heap-overflow https://nvd.nist.gov/vuln/detail/CVE-2025-58050 -php{56,74,81,82,83,84}-phppgadmin<9.8 unauthorized-access https://nvd.nist.gov/vuln/detail/CVE-2025-9636 +#php{56,74,81,82,83,84}-phppgadmin<9.8 unauthorized-access https://nvd.nist.gov/vuln/detail/CVE-2025-9636 # CVE is for pgAdmin 4, not phpPgAdmin; pkgsrc has no pgAdmin 4 package podman>=4.0.0<5.6.1 arbitrary-file-write https://nvd.nist.gov/vuln/detail/CVE-2025-9566 py{27,39,310,311,312,313}-deepdiff<8.6.1 arbitrary-code-execution https://nvd.nist.gov/vuln/detail/CVE-2025-58367 py{27,39,310,311,312,313}-django<4.2.24 sql-injection https://nvd.nist.gov/vuln/detail/CVE-2025-57833 @@ -27538,7 +27538,7 @@ ffmpeg7-[0-9]* denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-9951 ffmpeg8-[0-9]* denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-9951 libssh<0.113 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-8277 -py{27,39,310,311,312,313}-installer<6.0.0 privilege-escalation https://nvd.nist.gov/vuln/detail/CVE-2025-59042 +#py{27,39,310,311,312,313}-installer<6.0.0 privilege-escalation https://nvd.nist.gov/vuln/detail/CVE-2025-59042 # CVE is for PyInstaller, not pypa/installer; pkgsrc does not package PyInstaller py{27,39,310,311,312,313}-octoprint<1.11.3 command-injection https://nvd.nist.gov/vuln/detail/CVE-2025-58180 shibboleth-sp<3.5.1 sql-injection https://nvd.nist.gov/vuln/detail/CVE-2025-9943 php{56,74,81,82,83,84}-typo3<13.4.18 open-redirect https://nvd.nist.gov/vuln/detail/CVE-2025-59013 @@ -28912,10 +28912,10 @@ chromium<140.0.7339.80 ui-spoofing https://nvd.nist.gov/vuln/detail/CVE-2025-13107 chromium<133.0.6943.141 memory-corruption https://nvd.nist.gov/vuln/detail/CVE-2025-9479 jitsi-meet<2.0.10532 authentication-bypass https://nvd.nist.gov/vuln/detail/CVE-2025-64754 -php{56,74,81,82,83,84}-phppgadmin<9.10 remote-code-execution https://nvd.nist.gov/vuln/detail/CVE-2025-12762 -php{56,74,81,82,83,84}-phppgadmin<9.10 command-injection https://nvd.nist.gov/vuln/detail/CVE-2025-12763 -php{56,74,81,82,83,84}-phppgadmin<9.10 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-12764 -php{56,74,81,82,83,84}-phppgadmin<9.10 improper-certificate-validation https://nvd.nist.gov/vuln/detail/CVE-2025-12765 +#php{56,74,81,82,83,84}-phppgadmin<9.10 remote-code-execution https://nvd.nist.gov/vuln/detail/CVE-2025-12762 # CVE is for pgAdmin 4, not phpPgAdmin; pkgsrc has no pgAdmin 4 package +#php{56,74,81,82,83,84}-phppgadmin<9.10 command-injection https://nvd.nist.gov/vuln/detail/CVE-2025-12763 # CVE is for pgAdmin 4, not phpPgAdmin; pkgsrc has no pgAdmin 4 package +#php{56,74,81,82,83,84}-phppgadmin<9.10 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-12764 # CVE is for pgAdmin 4, not phpPgAdmin; pkgsrc has no pgAdmin 4 package +#php{56,74,81,82,83,84}-phppgadmin<9.10 improper-certificate-validation https://nvd.nist.gov/vuln/detail/CVE-2025-12765 # CVE is for pgAdmin 4, not phpPgAdmin; pkgsrc has no pgAdmin 4 package postgresql-client<13.23 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-12818 postgresql-client>=14<14.20 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-12818 postgresql-client>=15<15.15 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-12818 @@ -29097,7 +29097,7 @@ jenkins<2.540 cross-site-request-forgery https://nvd.nist.gov/vuln/detail/CVE-2025-67639 libsoup-[0-9]* http-request-smuggling https://nvd.nist.gov/vuln/detail/CVE-2025-14523 miniflux<2.2.15 open-redirect https://nvd.nist.gov/vuln/detail/CVE-2025-67713 -php{56,74,81,82,83,84}-phppgadmin<9.11 remote-code-execution https://nvd.nist.gov/vuln/detail/CVE-2025-13780 +#php{56,74,81,82,83,84}-phppgadmin<9.11 remote-code-execution https://nvd.nist.gov/vuln/detail/CVE-2025-13780 # CVE is for pgAdmin 4, not phpPgAdmin; pkgsrc has no pgAdmin 4 package py{27,39,310,311,312,313,314}-tornado<6.5.3 cross-site-scripting https://nvd.nist.gov/vuln/detail/CVE-2025-67724 py{27,39,310,311,312,313,314}-tornado<6.5.3 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-67725 py{27,39,310,311,312,313,314}-tornado<6.5.3 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-67726 @@ -29704,7 +29704,7 @@ moodle<5.0.4 privilege-escalation https://nvd.nist.gov/vuln/detail/CVE-2025-67856 moodle<5.0.4 sensitive-information-disclosure https://nvd.nist.gov/vuln/detail/CVE-2025-67857 mupdf<1.27.1 double-free https://nvd.nist.gov/vuln/detail/CVE-2026-25556 -php{56,74,81,82,83,84}-phppgadmin<9.122 command-injection https://nvd.nist.gov/vuln/detail/CVE-2026-1707 +#php{56,74,81,82,83,84}-phppgadmin<9.122 command-injection https://nvd.nist.gov/vuln/detail/CVE-2026-1707 # CVE is for pgAdmin 4, not phpPgAdmin; pkgsrc has no pgAdmin 4 package py{27,310,311,312,313,314}-django<4.2.28 timing-attack https://nvd.nist.gov/vuln/detail/CVE-2025-13473 py{27,310,311,312,313,314}-django>=5<5.2.11 timing-attack https://nvd.nist.gov/vuln/detail/CVE-2025-13473 py{27,310,311,312,313,314}-django<4.2.28 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-14550 @@ -30424,3 +30424,4 @@ nginx{,-devel}>=1.31.0<1.31.3 sensitive-information-disclosure https://nvd.nist.gov/vuln/detail/CVE-2026-60005 nginx{,-devel}>=0.9.6<1.30.4 heap-overflow https://nvd.nist.gov/vuln/detail/CVE-2026-42533 nginx{,-devel}>=1.31.0<1.31.3 heap-overflow https://nvd.nist.gov/vuln/detail/CVE-2026-42533 +icingaweb2<2.6.2 cross-site-scripting https://nvd.nist.gov/vuln/detail/CVE-2018-18248