HomeFreeBSD

www/forgejo: update to 7.0.4 (fixes security vulnerabilities)

Description

www/forgejo: update to 7.0.4 (fixes security vulnerabilities)

CVE-2024-24789: the archive/zip package's handling of certain types of invalid
zip files differs from the behavior of most zip implementations. This
misalignment could be exploited to create an zip file with contents that vary
depending on the implementation reading the file.

PR: 279781
Reported by: stb@lassitu.de (maintainer)
MFH: 2024Q2
Security: CVE-2024-24789

(cherry picked from commit be43fb2830c94e23e0d9aa49ef9b982b0ab31e2c)

Details

Provenance
stbAuthored on Mon, Jun 17, 5:16 PM
fernapeCommitted on Wed, Jun 19, 6:42 AM
Parents
R11:8e227742d596: www/tomcat-devel: update 11.0.0-M20 → 11.0.0-M21
Branches
Unknown
Tags
Unknown