While compiling some utility,
That is after installing fbsd 14.0 with ports and running freebsd-update.
There seems to be no update yet (empty result):
The vuxml link above reports:
Affected packages
7.69.0 < curl < 8.4.0
cmake-core < 3.27.8
Neither corrected packages have appeared yet in 14.0, three months after the correction was published. My curl is 8.3.0 and cmake-core 3.26.1.
Code:
===> cmake-core-3.26.1_3 has known vulnerabilities:
cmake-core-3.26.1_3 is vulnerable:
curl -- SOCKS5 heap buffer overflow
CVE: CVE-2023-38545
WWW: https://vuxml.FreeBSD.org/freebsd/d6c19e8c-6806-11ee-9464-b42e991fc52e.html
1 problem(s) in 1 installed package(s) found.
=> Please update your ports tree and try again.
=> Note: Vulnerable ports are marked as such even if there is no update available.
=> If you wish to ignore this vulnerability rebuild with 'make DISABLE_VULNERABILITIES=yes'
*** Error code 1
That is after installing fbsd 14.0 with ports and running freebsd-update.
There seems to be no update yet (empty result):
Code:
# pkg version -l "<"
The vuxml link above reports:
Affected packages
7.69.0 < curl < 8.4.0
cmake-core < 3.27.8
Neither corrected packages have appeared yet in 14.0, three months after the correction was published. My curl is 8.3.0 and cmake-core 3.26.1.