Bug 286590 - security/vuxml: add entry for fcgi < 2.4.5
Summary: security/vuxml: add entry for fcgi < 2.4.5
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: --- Affects Only Me
Assignee: Fernando Apesteguía
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2025-05-05 00:09 UTC by Christos Chatzaras
Modified: 2025-05-05 18:10 UTC (History)
1 user (show)

See Also:
fernape: maintainer-feedback+


Attachments
add vuxml entry for fcgi < 2.4.5 (1.84 KB, patch)
2025-05-05 00:17 UTC, Christos Chatzaras
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Christos Chatzaras 2025-05-05 00:09:47 UTC
add entry for fcgi < 2.4.5

https://github.com/advisories/GHSA-9825-56cx-cfg6
Comment 1 Christos Chatzaras 2025-05-05 00:17:46 UTC
Created attachment 260161 [details]
add vuxml entry for fcgi < 2.4.5
Comment 2 Fernando Apesteguía freebsd_committer freebsd_triage 2025-05-05 16:01:42 UTC
Thanks for the patch.
Did you copy-paste the patch? It contained ^M characters at the end and the format was a bit mangled :-)
Comment 3 Fernando Apesteguía freebsd_committer freebsd_triage 2025-05-05 16:05:10 UTC
Committed,

Thanks!
Comment 4 commit-hook freebsd_committer freebsd_triage 2025-05-05 16:05:40 UTC
A commit in branch main references this bug:

URL: https://cgit.FreeBSD.org/ports/commit/?id=a8dd74f93979678a560ba287e39045b45146211d

commit a8dd74f93979678a560ba287e39045b45146211d
Author:     Christos Chatzaras <chris@cretaforce.gr>
AuthorDate: 2025-05-05 16:03:39 +0000
Commit:     Fernando Apesteguía <fernape@FreeBSD.org>
CommitDate: 2025-05-05 16:03:39 +0000

    security/vuxml: Add entry for fcgi < 2.4.5

    PR:             286590
    Reported by:    chris@cretaforce.gr

 security/vuxml/vuln/2025.xml | 30 ++++++++++++++++++++++++++++++
 1 file changed, 30 insertions(+)
Comment 5 Christos Chatzaras 2025-05-05 18:10:25 UTC
(In reply to Fernando Apesteguía from comment #2)

That’s right, I copy-and-pasted it. Next time, I’ll attach it as a file.