From owner-freebsd-ports-bugs@FreeBSD.ORG Wed Mar 14 22:30:05 2007 Return-Path: X-Original-To: freebsd-ports-bugs@hub.freebsd.org Delivered-To: freebsd-ports-bugs@hub.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [69.147.83.52]) by hub.freebsd.org (Postfix) with ESMTP id 77C7116A55A for ; Wed, 14 Mar 2007 22:30:04 +0000 (UTC) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (freefall.freebsd.org [69.147.83.40]) by mx1.freebsd.org (Postfix) with ESMTP id AF31C13C483 for ; Wed, 14 Mar 2007 22:30:04 +0000 (UTC) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (gnats@localhost [127.0.0.1]) by freefall.freebsd.org (8.13.4/8.13.4) with ESMTP id l2EMU4MC020479 for ; Wed, 14 Mar 2007 22:30:04 GMT (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.13.4/8.13.4/Submit) id l2EMU4TU020478; Wed, 14 Mar 2007 22:30:04 GMT (envelope-from gnats) Resent-Date: Wed, 14 Mar 2007 22:30:04 GMT Resent-Message-Id: <200703142230.l2EMU4TU020478@freefall.freebsd.org> Resent-From: FreeBSD-gnats-submit@FreeBSD.org (GNATS Filer) Resent-To: freebsd-ports-bugs@FreeBSD.org Resent-Reply-To: FreeBSD-gnats-submit@FreeBSD.org, "Beech Rintoul" Received: from mx1.freebsd.org (mx1.freebsd.org [69.147.83.52]) by hub.freebsd.org (Postfix) with ESMTP id 0DDCB16A401; Wed, 14 Mar 2007 22:29:12 +0000 (UTC) (envelope-from beech@alaskaparadise.com) Received: from pinnacle.akherb.com (60-105-237-24.gci.net [24.237.105.60]) by mx1.freebsd.org (Postfix) with ESMTP id D258113C457; Wed, 14 Mar 2007 22:29:11 +0000 (UTC) (envelope-from beech@alaskaparadise.com) Received: by pinnacle.akherb.com (Postfix, from userid 1007) id 197625E26; Wed, 14 Mar 2007 14:29:11 -0800 (AKDT) Received: from stargate.alaskaparadise.com (7-137-58-66.gci.net [66.58.137.7]) by pinnacle.akherb.com (Postfix) with ESMTP id EC8E55D5D; Wed, 14 Mar 2007 14:29:07 -0800 (AKDT) Message-Id: <1173911347.10153@stargate.alaskaparadise.com> Date: Wed, 14 Mar 2007 14:29:07 -0800 From: "Beech Rintoul" To: "FreeBSD gnats submit" X-Send-Pr-Version: gtk-send-pr 0.4.8 Cc: infofarmer@FreeBSD.org Subject: ports/110304: [Maintainer Update] www/horde-base - Update to 3.1.4 (Final) X-BeenThere: freebsd-ports-bugs@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Ports bug reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 14 Mar 2007 22:30:05 -0000 >Number: 110304 >Category: ports >Synopsis: [Maintainer Update] www/horde-base - Update to 3.1.4 (Final) >Confidential: no >Severity: non-critical >Priority: low >Responsible: freebsd-ports-bugs >State: open >Quarter: >Keywords: >Date-Required: >Class: maintainer-update >Submitter-Id: current-users >Arrival-Date: Wed Mar 14 22:30:04 GMT 2007 >Closed-Date: >Last-Modified: >Originator: Beech Rintoul >Release: FreeBSD 7.0-CURRENT i386 >Organization: Alaska Paradise >Environment: System: FreeBSD 7.0-CURRENT #108: Tue Mar 6 20:59:53 AKST 2007 root@stargate.alaskaparadise.com:/usr/obj/usr/src/sys/STARGATE >Description: Update to 3.1.4 (Final) This is a bugfix release that also fixes an arbitrary file deletion vulnerability exploitable by local system (not Horde) users on systems using the example cron cleanup script. Major changes compared to Horde 3.1.4-RC1 are:     * Correctly quote file names in cleanup script for temporary files.     * Detect unencrypted PGP messa >How-To-Repeat: >Fix: diff -ruN --exclude=CVS /usr/ports/www/horde-base.orig/Makefile /usr/ports/www/horde-base/Makefile --- /usr/ports/www/horde-base.orig/Makefile Wed Mar 7 10:51:46 2007 +++ /usr/ports/www/horde-base/Makefile Wed Mar 14 12:26:58 2007 @@ -6,7 +6,7 @@ # PORTNAME= horde -DISTVERSION= 3.1.4-rc1 +DISTVERSION= 3.1.4 CATEGORIES= www MASTER_SITES= HORDE PKGNAMESUFFIX= -base diff -ruN --exclude=CVS /usr/ports/www/horde-base.orig/distinfo /usr/ports/www/horde-base/distinfo --- /usr/ports/www/horde-base.orig/distinfo Wed Feb 28 13:26:03 2007 +++ /usr/ports/www/horde-base/distinfo Wed Mar 14 12:30:42 2007 @@ -1,3 +1,3 @@ -MD5 (horde-3.1.4-rc1.tar.gz) = 5a494f618568c4682a2483240a1f4a1a -SHA256 (horde-3.1.4-rc1.tar.gz) = 6806c8ed1987ffba35cebc590c4ff582d71ddc57503ea0ea254e3efa9b9a5653 -SIZE (horde-3.1.4-rc1.tar.gz) = 5259321 +MD5 (horde-3.1.4.tar.gz) = 90bb96e810f165c2a853175303bd2dbb +SHA256 (horde-3.1.4.tar.gz) = 4f4ce3d95ef5425caa08dd19cf0e4f934a044c5dbd4f3a2aec9be8020baaf21c +SIZE (horde-3.1.4.tar.gz) = 5262198 >Release-Note: >Audit-Trail: >Unformatted: