<feed xmlns='http://www.w3.org/2005/Atom'>
<title>ports/security, branch 2023Q4</title>
<subtitle>FreeBSD ports tree</subtitle>
<id>https://cgit-dev.freebsd.org/ports/atom?h=2023Q4</id>
<link rel='self' href='https://cgit-dev.freebsd.org/ports/atom?h=2023Q4'/>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/'/>
<updated>2023-12-31T06:27:34Z</updated>
<entry>
<title>security/openvpn-devel: upgrade port to git commit efad93d049 (2023-11-17)</title>
<updated>2023-12-31T06:27:34Z</updated>
<author>
<name>Matthias Andree</name>
<email>mandree@FreeBSD.org</email>
</author>
<published>2023-12-31T06:16:28Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=b185a32f717e323c27cb0394d177ac4c78547b35'/>
<id>urn:sha1:b185a32f717e323c27cb0394d177ac4c78547b35</id>
<content type='text'>
contains a number of bugfixes and minor improvements, plus fixes
for two bugs that have been assigned CVEs:

- CVE-2023-46850 OpenVPN versions between 2.6.0 and 2.6.6 incorrectly use
  a send buffer after it has been free()d in some circumstances, causing
  some free()d memory to be sent to the peer.  All configurations using TLS
  (e.g. not using --secret) are affected by this issue.
  (found while tracking down CVE-2023-46849 / Github #400, #417)

- CVE-2023-46849 OpenVPN versions between 2.6.0 and 2.6.6 incorrectly
  restore "--fragment" configuration in some circumstances, leading to
  a division by zero when "--fragment" is used.  On platforms where
  division by zero is fatal, this will cause an OpenVPN crash.

see also https://community.openvpn.net/openvpn/wiki/SecurityAnnouncements

Also adjust files/patch-tests__t_cltsrv.sh because upstream commit
d623aa6c29 conflicts with this patch.

Security:	2fe004f5-83fd-11ee-9f5d-31909fb2f495
Security:	CVE-2023-46849
Security:	CVE-2023-46850
(cherry picked from commit 110af6a7bee600b9382fd568beecb28593378df4)
</content>
</entry>
<entry>
<title>security/py-asyncssh: Update to 2.14.2</title>
<updated>2023-12-25T09:40:18Z</updated>
<author>
<name>Po-Chuan Hsieh</name>
<email>sunpoet@FreeBSD.org</email>
</author>
<published>2023-12-25T09:00:47Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=f9198490dc5ec1a017a3cb4f4378b5d41369a1b0'/>
<id>urn:sha1:f9198490dc5ec1a017a3cb4f4378b5d41369a1b0</id>
<content type='text'>
Changes:	https://github.com/ronf/asyncssh/blob/master/docs/changes.rst
Security:	CVE-2023-48795
(cherry picked from commit 023c9e1d0a7bdbb38437bb5803bbb8f06c5233aa)
</content>
</entry>
<entry>
<title>security/py-asyncssh: Update to 2.14.1</title>
<updated>2023-12-25T09:40:18Z</updated>
<author>
<name>Po-Chuan Hsieh</name>
<email>sunpoet@FreeBSD.org</email>
</author>
<published>2023-11-14T16:39:58Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=60583f7ebb77a480605979e0ebbac86ff4899324'/>
<id>urn:sha1:60583f7ebb77a480605979e0ebbac86ff4899324</id>
<content type='text'>
Changes:	https://github.com/ronf/asyncssh/blob/master/docs/changes.rst
Security:	CVE-2023-46445, CVE-2023-46446
(cherry picked from commit dcd570adaeb52fed4925a53c9101dea9f35c9078)
</content>
</entry>
<entry>
<title>security/py-asyncssh: Update to 2.14.0</title>
<updated>2023-12-25T09:40:17Z</updated>
<author>
<name>Po-Chuan Hsieh</name>
<email>sunpoet@FreeBSD.org</email>
</author>
<published>2023-10-05T01:57:04Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=238163754131387903e1744c35ae8cce1b16a92d'/>
<id>urn:sha1:238163754131387903e1744c35ae8cce1b16a92d</id>
<content type='text'>
- Update version requirement of RUN_DEPENDS

Changes:	https://github.com/ronf/asyncssh/blob/master/docs/changes.rst
(cherry picked from commit 74187afa7b529fcd107c7ae4e0ce802ad6b25f94)
</content>
</entry>
<entry>
<title>security/py-pysodium: Update to 0.7.17</title>
<updated>2023-12-25T09:40:16Z</updated>
<author>
<name>Po-Chuan Hsieh</name>
<email>sunpoet@FreeBSD.org</email>
</author>
<published>2023-12-14T20:46:02Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=5885a928895864813303b43f3f68d65dcefaa140'/>
<id>urn:sha1:5885a928895864813303b43f3f68d65dcefaa140</id>
<content type='text'>
Changes:	https://github.com/stef/pysodium/releases
(cherry picked from commit ba5a472818820ee560903d7a5509b19570ffa7ce)
</content>
</entry>
<entry>
<title>security/py-pysodium: Update to 0.7.16</title>
<updated>2023-12-25T09:40:16Z</updated>
<author>
<name>Po-Chuan Hsieh</name>
<email>sunpoet@FreeBSD.org</email>
</author>
<published>2023-12-01T22:02:30Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=5a79b8acf4a75ddf32bf41cda613897a3578ff04'/>
<id>urn:sha1:5a79b8acf4a75ddf32bf41cda613897a3578ff04</id>
<content type='text'>
Changes:	https://github.com/stef/pysodium/releases
(cherry picked from commit 7db4dafd3c841410854ccc8178fc10dae208b099)
</content>
</entry>
<entry>
<title>security/py-pysodium: Update to 0.7.14</title>
<updated>2023-12-25T09:40:15Z</updated>
<author>
<name>Po-Chuan Hsieh</name>
<email>sunpoet@FreeBSD.org</email>
</author>
<published>2023-10-08T11:55:32Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=4639a6af34eb0db968eee366cbbdbf632dffd777'/>
<id>urn:sha1:4639a6af34eb0db968eee366cbbdbf632dffd777</id>
<content type='text'>
Changes:	https://github.com/stef/pysodium/releases
(cherry picked from commit a510dd9bc3c190a5daf2f1f1ba3d6f2da64959b7)
</content>
</entry>
<entry>
<title>security/nebula: Update to 1.8.1</title>
<updated>2023-12-21T09:51:35Z</updated>
<author>
<name>Ashish SHUKLA</name>
<email>ashish@FreeBSD.org</email>
</author>
<published>2023-12-21T09:50:55Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=a3a6fbc4fe19015dad9d3d7552982892175351fd'/>
<id>urn:sha1:a3a6fbc4fe19015dad9d3d7552982892175351fd</id>
<content type='text'>
MFH:		2023Q4
Security:	CVE-2023-48795
Security:	0f7598cc-9fe2-11ee-b47f-901b0e9408dc
(cherry picked from commit 9ebc503a446f553862b1676ab890d46e16f1ff65)
</content>
</entry>
<entry>
<title>security/nebula: Update to 1.8.0</title>
<updated>2023-12-21T09:51:22Z</updated>
<author>
<name>Ashish SHUKLA</name>
<email>ashish@FreeBSD.org</email>
</author>
<published>2023-12-21T09:49:58Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=18d2a81fb485db455f9404aaeca4e14583248e13'/>
<id>urn:sha1:18d2a81fb485db455f9404aaeca4e14583248e13</id>
<content type='text'>
(cherry picked from commit 7f9c3e0dff1e2671b41b091ad6185e8a3b9e98f3)
</content>
</entry>
<entry>
<title>security/putty: security update → 0.80 to fix Terrapin vulnerability</title>
<updated>2023-12-19T22:34:41Z</updated>
<author>
<name>Matthias Andree</name>
<email>mandree@FreeBSD.org</email>
</author>
<published>2023-12-19T22:24:04Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=bf2dac0a449cdcd19275c8c6965e2f863a930412'/>
<id>urn:sha1:bf2dac0a449cdcd19275c8c6965e2f863a930412</id>
<content type='text'>
Note this requires the server side to also add the protocol extension.

Security:	91955195-9ebb-11ee-bc14-a703705db3a6
Security:	CVE-2023-48795
Changelog:	https://lists.tartarus.org/pipermail/putty-announce/2023/000037.html
MFH:		2023Q4
(cherry picked from commit f9007a580563292af2d4ad675a6b414d26096438)
</content>
</entry>
</feed>
