pkg/60616: doc/pkg-vulnerabilities: fix entries applying CVEs to the wrong product

"Showta Ishizaki via gnats" <[email protected]>
Newsgroups gmane.os.netbsd.devel.pkgsrc.bugs
Message-ID <[email protected]>
>Number:         60616
>Category:       pkg
>Synopsis:       doc/pkg-vulnerabilities: fix entries applying CVEs to the wrong product
>Confidential:   no
>Severity:       non-critical
>Priority:       medium
>Responsible:    pkg-manager
>State:          open
>Class:          doc-bug
>Submitter-Id:   net
>Arrival-Date:   Mon Aug 17 15:35:02 +0000 2026
>Originator:     Showta Ishizaki
>Release:        NetBSD 10.1 / pkgsrc doc/pkg-vulnerabilities rev 1.779
>Organization:
>Environment:
System: NetBSD bambi.snowrabbit.org 10.1 NetBSD 10.1 (GENERIC) #0: Mon Dec 16 13:08:11 UTC 2024 [email protected]:/usr/src/sys/arch/i386/compile/GENERIC i386
Architecture: i386
Machine: i386
>Description:
	These entries cite CVEs that belong to a different product than
	the pkgsrc package they are written against, producing false
	positives in "pkg_admin audit" (or, in one case, pointing at
	the wrong package entirely):

	- 9 phppgadmin entries carry pgAdmin 4 CVEs (CVE-2022-4223,
	  CVE-2023-22298, CVE-2025-9636, CVE-2025-12762..12765,
	  CVE-2025-13780, CVE-2026-1707).  pgAdmin 4 (a Python
	  application by the pgAdmin project) and phpPgAdmin (a PHP
	  application) are unrelated codebases, and pkgsrc has no
	  pgAdmin 4 package.  Because phpPgAdmin's real versions
	  (7.14.x) are below bounds like "<9.10", pkg_admin audit flags
	  php8x-phppgadmin users with pgAdmin 4 vulnerabilities today.
	  Commented out.

	- icinga-base>=2 / CVE-2018-18248: the CVE is an XSS in Icinga
	  Web 2; net/icinga-base packages Icinga 1.x (frozen at 1.9.4),
	  which never reached version 2, so this entry could never
	  match.  Commented out; the corrected entry icingaweb2<2.6.2
	  is added at the end of the file (net/icingaweb2 exists and
	  its other CVEs already use that PKGBASE).

	- php81<8.1.32 and php82<8.2.28 / CVE-2024-11235: per the PHP
	  CNA record the CVE affects only PHP 8.3 (< 8.3.19) and 8.4
	  (< 8.4.5), and the 8.1.32/8.2.28 ChangeLogs do not contain
	  this fix.  The correct php83/php84 entries already exist
	  directly below.  Commented out.

	- go123<1.23.10 / CVE-2025-22874: affects only Go 1.24 (the
	  affected VerifyOptions/ExtKeyUsageAny policy-validation code
	  was introduced in 1.24); fixed in 1.24.4.  The correct go124
	  entry is directly above.  Commented out.

	- blosc-[0-9]* / CVE-2020-29367: the CVE is a heap overflow in
	  blosc2.c of C-Blosc2 (through 2.0.0.beta.5); c-blosc 1.x
	  (PKGBASE blosc) never contained that file, so blosc users
	  were falsely flagged.  Corrected to blosc2<2.0.0rc1 -- the
	  fix commit c4c6470e is first contained in v2.0.0.rc1 (no
	  beta.6 exists), and devel/blosc2's PKGBASE is blosc2.

	- py{...}-installer<6.0.0 / CVE-2025-59042: the CVE is
	  PyInstaller's local privilege escalation; pkgsrc's
	  misc/py-installer is pypa/installer, an unrelated product,
	  and pkgsrc does not package PyInstaller at all.  Commented
	  out.

	Thanks as always for the prompt handling of these reports.

How-To-Repeat:
	pkg_admin audit with php83-phppgadmin-7.14.7 installed reports
	the pgAdmin 4 CVEs listed above.
>Fix:
	Apply the following patch (against rev 1.779):

--- pkg-vulnerabilities.cvshead	2026-08-17 16:35:32
+++ pkg-vulnerabilities.1779.batchB	2026-08-18 00:32:10
@@ -16403,7 +16403,7 @@
 nagios-base<4.4.3	cross-site-scripting	https://nvd.nist.gov/vuln/detail/CVE-2018-18245
 icinga-base>=2<2.6.2	cross-site-request-forgery		https://nvd.nist.gov/vuln/detail/CVE-2018-18246
 icinga-base>=2<2.6.2	cross-site-scripting			https://nvd.nist.gov/vuln/detail/CVE-2018-18247
-icinga-base>=2		cross-site-scripting			https://nvd.nist.gov/vuln/detail/CVE-2018-18248
+#icinga-base>=2		cross-site-scripting			https://nvd.nist.gov/vuln/detail/CVE-2018-18248	# CVE is for Icinga Web 2, not Icinga 1.x; corrected entry added at end of file
 icinga-base>=2<2.6.2	code-injection				https://nvd.nist.gov/vuln/detail/CVE-2018-18249
 icinga-base>=2<2.6.2	sensitive-information-disclosure	https://nvd.nist.gov/vuln/detail/CVE-2018-18250
 yara-[0-9]*	arbitrary-code-execution	https://nvd.nist.gov/vuln/detail/CVE-2018-19974
@@ -20210,7 +20210,7 @@
 xpdf-[0-9]*	use-after-free	https://nvd.nist.gov/vuln/detail/CVE-2020-25725
 webkit-gtk<2.30.3	multiple-vulnerabilities	https://webkitgtk.org/security/WSA-2020-0008.html
 webkit-gtk<2.30.3	multiple-vulnerabilities	https://webkitgtk.org/security/WSA-2020-0009.html
-blosc-[0-9]*	heap-overflow				https://nvd.nist.gov/vuln/detail/CVE-2020-29367
+blosc2<2.0.0rc1	heap-overflow				https://nvd.nist.gov/vuln/detail/CVE-2020-29367
 consul<1.6.10	sensitive-information-disclosure	https://nvd.nist.gov/vuln/detail/CVE-2020-28053
 gitea<1.12.6	crlf-attack				https://nvd.nist.gov/vuln/detail/CVE-2020-28991
 jetty<9.4.35.20201120	memory-corruption	https://nvd.nist.gov/vuln/detail/CVE-2020-27218
@@ -24802,10 +24802,10 @@
 php{56,73,74,80,81}-gd>=8.0.0<8.0.25	sensitive-information-disclosure	https://nvd.nist.gov/vuln/detail/CVE-2022-31630
 php{56,73,74,80,81}-gd>=8.1.0<8.1.12	sensitive-information-disclosure	https://nvd.nist.gov/vuln/detail/CVE-2022-31630
 php{73,74,80,81}-phpmyadmin>=5<5.2.0	sql-injection	https://nvd.nist.gov/vuln/detail/CVE-2020-22452
-phppgadmin<6.17	arbitrary-code-execution	https://nvd.nist.gov/vuln/detail/CVE-2022-4223
+#phppgadmin<6.17	arbitrary-code-execution	https://nvd.nist.gov/vuln/detail/CVE-2022-4223	# CVE is for pgAdmin 4, not phpPgAdmin; pkgsrc has no pgAdmin 4 package
 php{56,73,74,80,81}-phpmyadmin<4.9.11	cross-site-scripting	https://nvd.nist.gov/vuln/detail/CVE-2023-25727
 php{73,74,80,81}-phpmyadmin>=5<5.2.1	cross-site-scripting	https://nvd.nist.gov/vuln/detail/CVE-2023-25727
-phppgadmin>=4<6.14	authentication-bypass	https://nvd.nist.gov/vuln/detail/CVE-2023-22298
+#phppgadmin>=4<6.14	authentication-bypass	https://nvd.nist.gov/vuln/detail/CVE-2023-22298	# CVE is for pgAdmin 4, not phpPgAdmin; pkgsrc has no pgAdmin 4 package
 phoronix-test-suite-[0-9]*	cross-site-scripting	https://nvd.nist.gov/vuln/detail/CVE-2022-40704
 mplayer<15.0	division-by-zero	https://nvd.nist.gov/vuln/detail/CVE-2022-38865
 mencoder<15.0	division-by-zero	https://nvd.nist.gov/vuln/detail/CVE-2022-38865
@@ -26151,8 +26151,8 @@
 thunderbird<128.8		use-after-free		https://nvd.nist.gov/vuln/detail/CVE-2025-1931
 tinyxml2<10.1.0	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2024-50615
 freetype2<2.13.3	arbitrary-code-execution	https://nvd.nist.gov/vuln/detail/CVE-2025-27363
-php81<8.1.32	use-after-free	https://nvd.nist.gov/vuln/detail/CVE-2024-11235
-php82<8.2.28	use-after-free	https://nvd.nist.gov/vuln/detail/CVE-2024-11235
+#php81<8.1.32	use-after-free	https://nvd.nist.gov/vuln/detail/CVE-2024-11235	# CVE-2024-11235 affects only PHP 8.3/8.4 (see entries below)
+#php82<8.2.28	use-after-free	https://nvd.nist.gov/vuln/detail/CVE-2024-11235	# CVE-2024-11235 affects only PHP 8.3/8.4 (see entries below)
 php83<8.3.19	use-after-free	https://nvd.nist.gov/vuln/detail/CVE-2024-11235
 php84<8.4.5	use-after-free	https://nvd.nist.gov/vuln/detail/CVE-2024-11235
 expat<2.7.3	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2024-8176
@@ -26368,7 +26368,7 @@
 go124<1.24.4	http-header-injection	https://nvd.nist.gov/vuln/detail/CVE-2025-4673
 go123<1.23.10	http-header-injection	https://nvd.nist.gov/vuln/detail/CVE-2025-4673
 go124<1.24.4	insecure-key-validation	https://nvd.nist.gov/vuln/detail/CVE-2025-22874
-go123<1.23.10	insecure-key-validation	https://nvd.nist.gov/vuln/detail/CVE-2025-22874
+#go123<1.23.10	insecure-key-validation	https://nvd.nist.gov/vuln/detail/CVE-2025-22874	# CVE-2025-22874 affects only Go 1.24 (see previous entry)
 assimp<6.0.2	out-of-bounds-write	https://nvd.nist.gov/vuln/detail/CVE-2025-2750
 assimp<6.0.2	out-of-bounds-read	https://nvd.nist.gov/vuln/detail/CVE-2025-2751
 assimp<6.0.2	heap-overflow		https://nvd.nist.gov/vuln/detail/CVE-2025-2757
@@ -27523,7 +27523,7 @@
 p5-Cpanel-JSON-XS<4.40	integer-overflow	https://nvd.nist.gov/vuln/detail/CVE-2025-40929
 p5-JSON-XS<4.04		integer-overflow	https://nvd.nist.gov/vuln/detail/CVE-2025-40928
 pcre2<10.46	heap-overflow	https://nvd.nist.gov/vuln/detail/CVE-2025-58050
-php{56,74,81,82,83,84}-phppgadmin<9.8	unauthorized-access	https://nvd.nist.gov/vuln/detail/CVE-2025-9636
+#php{56,74,81,82,83,84}-phppgadmin<9.8	unauthorized-access	https://nvd.nist.gov/vuln/detail/CVE-2025-9636	# CVE is for pgAdmin 4, not phpPgAdmin; pkgsrc has no pgAdmin 4 package
 podman>=4.0.0<5.6.1	arbitrary-file-write	https://nvd.nist.gov/vuln/detail/CVE-2025-9566
 py{27,39,310,311,312,313}-deepdiff<8.6.1	arbitrary-code-execution	https://nvd.nist.gov/vuln/detail/CVE-2025-58367
 py{27,39,310,311,312,313}-django<4.2.24		sql-injection	https://nvd.nist.gov/vuln/detail/CVE-2025-57833
@@ -27538,7 +27538,7 @@
 ffmpeg7-[0-9]*	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-9951
 ffmpeg8-[0-9]*	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-9951
 libssh<0.113	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-8277
-py{27,39,310,311,312,313}-installer<6.0.0	privilege-escalation	https://nvd.nist.gov/vuln/detail/CVE-2025-59042
+#py{27,39,310,311,312,313}-installer<6.0.0	privilege-escalation	https://nvd.nist.gov/vuln/detail/CVE-2025-59042	# CVE is for PyInstaller, not pypa/installer; pkgsrc does not package PyInstaller
 py{27,39,310,311,312,313}-octoprint<1.11.3	command-injection	https://nvd.nist.gov/vuln/detail/CVE-2025-58180
 shibboleth-sp<3.5.1	sql-injection	https://nvd.nist.gov/vuln/detail/CVE-2025-9943
 php{56,74,81,82,83,84}-typo3<13.4.18	open-redirect		https://nvd.nist.gov/vuln/detail/CVE-2025-59013
@@ -28912,10 +28912,10 @@
 chromium<140.0.7339.80	ui-spoofing		https://nvd.nist.gov/vuln/detail/CVE-2025-13107
 chromium<133.0.6943.141	memory-corruption	https://nvd.nist.gov/vuln/detail/CVE-2025-9479
 jitsi-meet<2.0.10532	authentication-bypass	https://nvd.nist.gov/vuln/detail/CVE-2025-64754
-php{56,74,81,82,83,84}-phppgadmin<9.10	remote-code-execution		https://nvd.nist.gov/vuln/detail/CVE-2025-12762
-php{56,74,81,82,83,84}-phppgadmin<9.10	command-injection		https://nvd.nist.gov/vuln/detail/CVE-2025-12763
-php{56,74,81,82,83,84}-phppgadmin<9.10	denial-of-service		https://nvd.nist.gov/vuln/detail/CVE-2025-12764
-php{56,74,81,82,83,84}-phppgadmin<9.10	improper-certificate-validation	https://nvd.nist.gov/vuln/detail/CVE-2025-12765
+#php{56,74,81,82,83,84}-phppgadmin<9.10	remote-code-execution		https://nvd.nist.gov/vuln/detail/CVE-2025-12762	# CVE is for pgAdmin 4, not phpPgAdmin; pkgsrc has no pgAdmin 4 package
+#php{56,74,81,82,83,84}-phppgadmin<9.10	command-injection		https://nvd.nist.gov/vuln/detail/CVE-2025-12763	# CVE is for pgAdmin 4, not phpPgAdmin; pkgsrc has no pgAdmin 4 package
+#php{56,74,81,82,83,84}-phppgadmin<9.10	denial-of-service		https://nvd.nist.gov/vuln/detail/CVE-2025-12764	# CVE is for pgAdmin 4, not phpPgAdmin; pkgsrc has no pgAdmin 4 package
+#php{56,74,81,82,83,84}-phppgadmin<9.10	improper-certificate-validation	https://nvd.nist.gov/vuln/detail/CVE-2025-12765	# CVE is for pgAdmin 4, not phpPgAdmin; pkgsrc has no pgAdmin 4 package
 postgresql-client<13.23	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-12818
 postgresql-client>=14<14.20	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-12818
 postgresql-client>=15<15.15	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-12818
@@ -29097,7 +29097,7 @@
 jenkins<2.540	cross-site-request-forgery	https://nvd.nist.gov/vuln/detail/CVE-2025-67639
 libsoup-[0-9]*	http-request-smuggling	https://nvd.nist.gov/vuln/detail/CVE-2025-14523
 miniflux<2.2.15	open-redirect	https://nvd.nist.gov/vuln/detail/CVE-2025-67713
-php{56,74,81,82,83,84}-phppgadmin<9.11	remote-code-execution	https://nvd.nist.gov/vuln/detail/CVE-2025-13780
+#php{56,74,81,82,83,84}-phppgadmin<9.11	remote-code-execution	https://nvd.nist.gov/vuln/detail/CVE-2025-13780	# CVE is for pgAdmin 4, not phpPgAdmin; pkgsrc has no pgAdmin 4 package
 py{27,39,310,311,312,313,314}-tornado<6.5.3	cross-site-scripting	https://nvd.nist.gov/vuln/detail/CVE-2025-67724
 py{27,39,310,311,312,313,314}-tornado<6.5.3	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-67725
 py{27,39,310,311,312,313,314}-tornado<6.5.3	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-67726
@@ -29704,7 +29704,7 @@
 moodle<5.0.4	privilege-escalation			https://nvd.nist.gov/vuln/detail/CVE-2025-67856
 moodle<5.0.4	sensitive-information-disclosure	https://nvd.nist.gov/vuln/detail/CVE-2025-67857
 mupdf<1.27.1	double-free	https://nvd.nist.gov/vuln/detail/CVE-2026-25556
-php{56,74,81,82,83,84}-phppgadmin<9.122	command-injection	https://nvd.nist.gov/vuln/detail/CVE-2026-1707
+#php{56,74,81,82,83,84}-phppgadmin<9.122	command-injection	https://nvd.nist.gov/vuln/detail/CVE-2026-1707	# CVE is for pgAdmin 4, not phpPgAdmin; pkgsrc has no pgAdmin 4 package
 py{27,310,311,312,313,314}-django<4.2.28	timing-attack		https://nvd.nist.gov/vuln/detail/CVE-2025-13473
 py{27,310,311,312,313,314}-django>=5<5.2.11	timing-attack		https://nvd.nist.gov/vuln/detail/CVE-2025-13473
 py{27,310,311,312,313,314}-django<4.2.28	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-14550
@@ -30424,3 +30424,4 @@
 nginx{,-devel}>=1.31.0<1.31.3	sensitive-information-disclosure	https://nvd.nist.gov/vuln/detail/CVE-2026-60005
 nginx{,-devel}>=0.9.6<1.30.4	heap-overflow	https://nvd.nist.gov/vuln/detail/CVE-2026-42533
 nginx{,-devel}>=1.31.0<1.31.3	heap-overflow	https://nvd.nist.gov/vuln/detail/CVE-2026-42533
+icingaweb2<2.6.2	cross-site-scripting	https://nvd.nist.gov/vuln/detail/CVE-2018-18248
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.