Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 15 Nov 2016 20:54:42 +0000
From:      bugzilla-noreply@freebsd.org
To:        freebsd-ports-bugs@FreeBSD.org
Subject:   [Bug 214546] www/libwww: Security vulnerabilities
Message-ID:  <bug-214546-13@https.bugs.freebsd.org/bugzilla/>

next in thread | raw e-mail | index | archive | help
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D214546

            Bug ID: 214546
           Summary: www/libwww: Security vulnerabilities
           Product: Ports & Packages
           Version: Latest
          Hardware: Any
                OS: Any
            Status: New
          Keywords: patch, security
          Severity: Affects Some People
          Priority: ---
         Component: Individual Port(s)
          Assignee: freebsd-ports-bugs@FreeBSD.org
          Reporter: dbaio@bsd.com.br
                CC: marius@nuenneri.ch
             Flags: maintainer-feedback?(marius@nuenneri.ch),
                    merge-quarterly?
                CC: marius@nuenneri.ch

Created attachment 177035
  --> https://bugs.freebsd.org/bugzilla/attachment.cgi?id=3D177035&action=
=3Dedit
libwww-5.4.0_6.patch

- Add three patches from NetBSD pkgsrc for fix CVE's:
  CVE-2005-3183 (files/patch-Library_src_HTBound.c)
  CVE-2009-3560 (files/patch-modules_expat_xmlparse_xmlparse.c)
  CVE-2009-3720 (files/patch-modules_expat_xmltok_xmltok__impl.c)
- Add License
- Add USES=3Dssl
- Strip .so files (Q/A warnings)
- Regenerate old patches
- Bump PORTREVISION

[Q/A]

portlint: OK (looks fine.)
testport:=20
        poudriere: i386,  9.3   (OK)
        poudriere: amd64, 9.3   (OK)
        poudriere: i386,  10.3  (OK)
        poudriere: amd64, 10.3  (OK)
        poudriere: i386,  11    (OK)
        poudriere: amd64, 11    (OK)
        poudriere: i386,  12    (OK)
        poudriere: amd64, 12    (OK)

--=20
You are receiving this mail because:
You are the assignee for the bug.=



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?bug-214546-13>