From owner-freebsd-ports@FreeBSD.ORG Sun Dec 12 23:25:28 2010 Return-Path: Delivered-To: freebsd-ports@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 3A82B106566B for ; Sun, 12 Dec 2010 23:25:28 +0000 (UTC) (envelope-from dougb@FreeBSD.org) Received: from mail2.fluidhosting.com (mx23.fluidhosting.com [204.14.89.6]) by mx1.freebsd.org (Postfix) with ESMTP id BBDE08FC12 for ; Sun, 12 Dec 2010 23:25:27 +0000 (UTC) Received: (qmail 30549 invoked by uid 399); 12 Dec 2010 23:25:26 -0000 Received: from localhost (HELO doug-optiplex.ka9q.net) (dougb@dougbarton.us@127.0.0.1) by localhost with ESMTPAM; 12 Dec 2010 23:25:26 -0000 X-Originating-IP: 127.0.0.1 X-Sender: dougb@dougbarton.us Message-ID: <4D0559E5.4030409@FreeBSD.org> Date: Sun, 12 Dec 2010 15:25:25 -0800 From: Doug Barton Organization: http://SupersetSolutions.com/ User-Agent: Mozilla/5.0 (X11; U; FreeBSD amd64; en-US; rv:1.9.2.13) Gecko/20101210 Thunderbird/3.1.7 MIME-Version: 1.0 To: freebsd-ports@freebsd.org References: In-Reply-To: X-Enigmail-Version: 1.1.2 OpenPGP: id=1A1ABC84 Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Subject: Re: Security updates for packages? X-BeenThere: freebsd-ports@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Porting software to FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 12 Dec 2010 23:25:28 -0000 On 12/12/2010 12:28, Kevin Kreamer wrote: > Hi, > > Having not used FreeBSD for several years, I did a fresh install yesterday > of 8.1-RELEASE, and then used pkg_add -r to install several packages. I > then came across portaudit, ran it, and it indicated that I had three > vulnerable packages (git, ruby, and sudo). Looking at > http://www.vuxml.org/freebsd/, it appears that these were reported in July, > August, and September respectively. How did you install the package? -- Nothin' ever doesn't change, but nothin' changes much. -- OK Go Breadth of IT experience, and depth of knowledge in the DNS. Yours for the right price. :) http://SupersetSolutions.com/