From owner-freebsd-ports-bugs@FreeBSD.ORG Wed Aug 7 19:30:02 2013 Return-Path: Delivered-To: freebsd-ports-bugs@smarthost.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTP id 543C8B04 for ; Wed, 7 Aug 2013 19:30:02 +0000 (UTC) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (freefall.freebsd.org [IPv6:2001:1900:2254:206c::16:87]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mx1.freebsd.org (Postfix) with ESMTPS id 40F452349 for ; Wed, 7 Aug 2013 19:30:02 +0000 (UTC) Received: from freefall.freebsd.org (localhost [127.0.0.1]) by freefall.freebsd.org (8.14.7/8.14.7) with ESMTP id r77JU1Lp049704 for ; Wed, 7 Aug 2013 19:30:01 GMT (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.14.7/8.14.7/Submit) id r77JU1f8049703; Wed, 7 Aug 2013 19:30:01 GMT (envelope-from gnats) Date: Wed, 7 Aug 2013 19:30:01 GMT Message-Id: <201308071930.r77JU1f8049703@freefall.freebsd.org> To: freebsd-ports-bugs@FreeBSD.org Cc: From: Piotr Rybicki Subject: Re: ports/181087: www/openx - backdoor discovered X-BeenThere: freebsd-ports-bugs@freebsd.org X-Mailman-Version: 2.1.14 Precedence: list Reply-To: Piotr Rybicki List-Id: Ports bug reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 07 Aug 2013 19:30:02 -0000 The following reply was made to PR ports/181087; it has been noted by GNATS. From: Piotr Rybicki To: bug-followup@FreeBSD.org, rainer@ultra-secure.de Cc: Subject: Re: ports/181087: www/openx - backdoor discovered Date: Wed, 07 Aug 2013 21:21:52 +0200 Please update www/openx ASAP, since new version adresses critical security issues. diff -ur openx-old/Makefile openx/Makefile --- openx-old/Makefile 2013-08-07 21:02:49.000000000 +0200 +++ openx/Makefile 2013-08-07 21:03:34.000000000 +0200 @@ -2,7 +2,7 @@ # $FreeBSD: head/www/openx/Makefile 305200 2012-10-03 12:33:38Z rm $ PORTNAME= openx -PORTVERSION= 2.8.10 +PORTVERSION= 2.8.11 CATEGORIES= www MASTER_SITES= http://download.openx.org/ diff -ur openx-old/distinfo openx/distinfo --- openx-old/distinfo 2013-08-07 21:02:49.000000000 +0200 +++ openx/distinfo 2013-08-07 21:05:25.000000000 +0200 @@ -1,2 +1,2 @@ -SHA256 (openx-2.8.10.tar.bz2) = 91418dcd3896e19532c4144e5f4c56bcfa49164e3304fa7240f2a1cc8b90bfc2 -SIZE (openx-2.8.10.tar.bz2) = 9787343 +SHA256 (openx-2.8.11.tar.bz2) = 1a9e1e0e0165c45584968c7c6dd9401425a2ff79d48e453fdb049a34f8b88607 +SIZE (openx-2.8.11.tar.bz2) = 9617410 Best regards -- Piotr Rybicki, Prezes Zarządu InnerVision Sp. z o.o. http://www.innervision.pl