FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The VUXML data was last processed by FreshPorts on 2024-04-23 14:57:51 UTC

List all Vulnerabilities, by package

List all Vulnerabilities, by date

k68

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
4ebaa983-3299-11ed-95f8-901b0e9408dcdendrite -- Signature checks not applied to some retrieved missing events

Dendrite team reports:

Events retrieved from a remote homeserver using /get_missing_events did not have their signatures verified correctly. This could potentially allow a remote homeserver to provide invalid/modified events to Dendrite via this endpoint.

Note that this does not apply to events retrieved through other endpoints (e.g. /event, /state) as they have been correctly verified.

Homeservers that have federation disabled are not vulnerable.


Discovery 2022-09-12
Entry 2022-09-12
dendrite
< 0.9.8

https://github.com/matrix-org/dendrite/security/advisories/GHSA-pfw4-xjgm-267c