CVS commit: pkgsrc/doc
"Leonardo Taccari" <[email protected]>
| Newsgroups | gmane.os.netbsd.devel.pkgsrc.cvs |
|---|---|
| Message-ID | <[email protected]> |
Module Name: pkgsrc Committed By: leot Date: Fri Aug 14 21:38:07 UTC 2026 Modified Files: pkgsrc/doc: pkg-vulnerabilities Log Message: pkg-vulnerabilities: CVE-2025-69720 was fixed in ncurses-6.6 According upstream NEWS it was fixed in 20251213 and 6.6 was released on 20251230. Reported via PR pkg/60589 from Showta Ishizaki, thanks! To generate a diff of this commit: cvs rdiff -u -r1.776 -r1.777 pkgsrc/doc/pkg-vulnerabilities Please note that diffs are not public domain; they are subject to the copyright notices on the relevant files.
(unnamed)
(text/x-diff, 1.1 KB)
Modified files: Index: pkgsrc/doc/pkg-vulnerabilities diff -u pkgsrc/doc/pkg-vulnerabilities:1.776 pkgsrc/doc/pkg-vulnerabilities:1.777 --- pkgsrc/doc/pkg-vulnerabilities:1.776 Fri Aug 14 14:49:56 2026 +++ pkgsrc/doc/pkg-vulnerabilities Fri Aug 14 21:38:06 2026 @@ -1,4 +1,4 @@ -# $NetBSD: pkg-vulnerabilities,v 1.776 2026/08/14 14:49:56 leot Exp $ +# $NetBSD: pkg-vulnerabilities,v 1.777 2026/08/14 21:38:06 leot Exp $ # #FORMAT 1.0.0 # @@ -30254,7 +30254,7 @@ mongodb<7.0.31 information-disclosure ht mongodb<7.0.31 use-after-free https://nvd.nist.gov/vuln/detail/CVE-2026-4148 mongodb<7.0.31 double-free https://nvd.nist.gov/vuln/detail/CVE-2026-4358 mumble<1.6.870 out-of-bounds-read https://nvd.nist.gov/vuln/detail/CVE-2025-71264 -ncurses-[0-9]* buffer-overflow https://nvd.nist.gov/vuln/detail/CVE-2025-69720 +ncurses<6.6 buffer-overflow https://nvd.nist.gov/vuln/detail/CVE-2025-69720 nghttp2<1.68.1 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2026-27135 p5-XML-Parser<2.48 heap-overflow https://nvd.nist.gov/vuln/detail/CVE-2006-10002 p5-XML-Parser<2.48 heap-overflow https://nvd.nist.gov/vuln/detail/CVE-2006-10003