Created attachment 237287 [details] update Hi, Since vulnerability exists here is the port update including: https://github.com/strongswan/strongswan/releases/tag/5.9.7 https://github.com/strongswan/strongswan/releases/tag/5.9.8 Cheers, Franco
^Triage: If there is a changelog or release notes URL available for this version, please add it to the URL field. Franco, what vulnerability are you referring to? Thanks!
https://cgit.freebsd.org/ports/commit/?id=c1b081145ff7f719c3867702e9d83718b674505d I found it odd that it was registered there already but no update was proposed. Cheers, Franco
A commit in branch main references this bug: URL: https://cgit.FreeBSD.org/ports/commit/?id=a28166f3b1e22d446f76d5f71f27f082b0e7e19f commit a28166f3b1e22d446f76d5f71f27f082b0e7e19f Author: Franco Fichtner <franco@opnsense.org> AuthorDate: 2022-10-17 06:06:35 +0000 Commit: Fernando Apesteguía <fernape@FreeBSD.org> CommitDate: 2022-10-19 16:45:55 +0000 security/strongswan: update to 5.9.8 ChangeLog: https://github.com/strongswan/strongswan/releases/tag/5.9.8 Fixes CVE-2022-40617. PR: 267037 Reported by: franco@opnsense.org Approved by: strongswan@Nanoteq.com (maintainer, implicit) MFH: 2022Q4 (security update) Security: CVE-2022-40617 DoS attack vulnerability security/strongswan/Makefile | 3 +-- security/strongswan/distinfo | 6 +++--- security/strongswan/pkg-plist | 5 ++++- 3 files changed, 8 insertions(+), 6 deletions(-)
Committed and merged to 2022Q4, Thanks!
A commit in branch 2022Q4 references this bug: URL: https://cgit.FreeBSD.org/ports/commit/?id=de86c5fe2678752cf798a2fc3294fd13202eaae9 commit de86c5fe2678752cf798a2fc3294fd13202eaae9 Author: Franco Fichtner <franco@opnsense.org> AuthorDate: 2022-10-17 06:06:35 +0000 Commit: Fernando Apesteguía <fernape@FreeBSD.org> CommitDate: 2022-10-19 16:46:51 +0000 security/strongswan: update to 5.9.8 ChangeLog: https://github.com/strongswan/strongswan/releases/tag/5.9.8 Fixes CVE-2022-40617. PR: 267037 Reported by: franco@opnsense.org Approved by: strongswan@Nanoteq.com (maintainer, implicit) MFH: 2022Q4 (security update) Security: CVE-2022-40617 DoS attack vulnerability (cherry picked from commit a28166f3b1e22d446f76d5f71f27f082b0e7e19f) security/strongswan/Makefile | 3 +-- security/strongswan/distinfo | 6 +++--- security/strongswan/pkg-plist | 5 ++++- 3 files changed, 8 insertions(+), 6 deletions(-)