XMPP Service Operators - 2026-05-16


  1. tom

    will pkg audit catch this?

  2. tom

    https://vuxml.freebsd.org/freebsd/3414ac89-4f9f-11f1-a1c0-0050569f0b83.html

  3. tom

    strange, it says less then 1.30 is affected but 1.28 doesn't seem to be

  4. tom

    https://vuxml.freebsd.org/freebsd/3414ac89-4f9f-11f1-a1c0-0050569f0b83.html

  5. icebound.dev

    tom, if 1.28 is not affected then no

  6. icebound.dev

    but afaik 1.28 *IS* affected

  7. icebound.dev

    I looked into this on Debian for a project I help out

  8. icebound.dev

    1.30.1+ and 1.31.0+ is the patched versions

  9. icebound.dev

    pkg audit will flag any version below 1.30.1, so yes it will flag 1.28 and I think its rightfully

  10. icebound.dev

    pkg audit will flag any version below 1.30.1, so yes it will flag 1.28 and I think its rightfully so

  11. icebound.dev

    tom, https://cgit.freebsd.org/ports/commit/?id=901ca63a3839d33d65e53a0417736e48af89e0d7 patch hit the port repo

  12. icebound.dev

    its yet to be backported yet, so if you are running quarterly ports *you are vulnerable*