From owner-freebsd-ports@freebsd.org Mon May 4 23:52:15 2020 Return-Path: Delivered-To: freebsd-ports@mailman.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.nyi.freebsd.org (Postfix) with ESMTP id EF75E2C7556 for ; Mon, 4 May 2020 23:52:15 +0000 (UTC) (envelope-from kurt.buff@gmail.com) Received: from mailman.nyi.freebsd.org (mailman.nyi.freebsd.org [IPv6:2610:1c1:1:606c::50:13]) by mx1.freebsd.org (Postfix) with ESMTP id 49GKQl0M0vz40fY for ; Mon, 4 May 2020 23:52:15 +0000 (UTC) (envelope-from kurt.buff@gmail.com) Received: by mailman.nyi.freebsd.org (Postfix) id 0A3122C7555; Mon, 4 May 2020 23:52:15 +0000 (UTC) Delivered-To: ports@mailman.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.nyi.freebsd.org (Postfix) with ESMTP id 09F7A2C7553 for ; Mon, 4 May 2020 23:52:15 +0000 (UTC) (envelope-from kurt.buff@gmail.com) Received: from mail-ot1-x32e.google.com (mail-ot1-x32e.google.com [IPv6:2607:f8b0:4864:20::32e]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) server-signature RSA-PSS (4096 bits) client-signature RSA-PSS (2048 bits) client-digest SHA256) (Client CN "smtp.gmail.com", Issuer "GTS CA 1O1" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 49GKQk6Z1Pz40fX; Mon, 4 May 2020 23:52:14 +0000 (UTC) (envelope-from kurt.buff@gmail.com) Received: by mail-ot1-x32e.google.com with SMTP id m13so141385otf.6; Mon, 04 May 2020 16:52:14 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=UDWC2dWiNzWkfnGvupOX39JtGSoW+4xskw3ABAA5OeQ=; b=HMBR5we4Y8BGhTHSFt3oqUNsikXT7D68oQ4kb9FIUI2EqtcudKeQKAF8VT1y8gG7DH W3hK4p+SjD5Q5a9p6FyNc4sQrBsa53GsxXIEWfikmdvTg7xZasW7Naflfc27K2btai+A kN6V64EWh2S/B6ZbDrpfhDQQJEbs0PSY1e6s7I/BQQBhXX4+EMIlJYdjnhrdnie2Mdcx 0nfBBQqbMqAvBHtQ9N65tspnQXpm57V/VpVgqyqG5gLSG4VQm6P3U+RxJYRWHnMy3xka WtOufeHZOcfWGxlDm6oKDS1WwEBvyfhIA9SBydyjZWGCwDQQ/CEJGRsor+qsn/GW8zJp YejQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=UDWC2dWiNzWkfnGvupOX39JtGSoW+4xskw3ABAA5OeQ=; b=aP4cua6CFwOabuPOlvEvPSt1Ilh6s8F3P1rl1yeg93XDuEBFW/HEY8xL5JwdOQi7l8 ewzOFYWvSdsSfVjX0X1cfO/8vKMP2E5fR/ZRHnwg3pVnyG3a1TKxOajyMIpVOn7zvwuy bQiBDCCZfQL7iJ2+suYGyHBGUZLgmo3lsVspbvZhnt2PKk8BexXGG3XM7xL213JyGbba SEl5vSHHXG+BhGehQ7cdFEM6SoFuD31Kc6Ospr9cdsr9jGo5+bnEbKMKuXppq6no9vK2 q2925DTLB6gnEYW0oIr/J14B7oZehY44nIwQsb/PLPtiz/szB6ER8Gg0ombJeuGrjxr4 UGFA== X-Gm-Message-State: AGi0PuYD6IfFI5oT26rZXTvppIwE7OiXWTxaWAtm4b/dFfuG1vE4i3hG g+p//gK5mH92AWXtX8FwKEuO2GEVdptOCic2sMRSkBvkg8A= X-Google-Smtp-Source: APiQypIb5AjgLrWqwWOURrR7eZwkXI3Vbr2yG52HWulXKl5qT7a+tWqOOvGeOVInSx0eWgMZAlyEz0PH8d4q3UGFJH0= X-Received: by 2002:a9d:784b:: with SMTP id c11mr415837otm.28.1588636333096; Mon, 04 May 2020 16:52:13 -0700 (PDT) MIME-Version: 1.0 References: <000001d61e62$52544110$f6fcc330$@quicknet.nl> In-Reply-To: From: "Kurt Buff - GSEC, GCIH" Date: Mon, 4 May 2020 17:51:59 -0600 Message-ID: Subject: Re: FreeBSD Port: open-vm-tools-11.0.1_3,2 To: Josh Paetzel Cc: Dutchman01 , ports@freebsd.org Content-Type: text/plain; charset="UTF-8" X-Rspamd-Queue-Id: 49GKQk6Z1Pz40fX X-Spamd-Bar: ----- Authentication-Results: mx1.freebsd.org; none X-Spamd-Result: default: False [-6.00 / 15.00]; NEURAL_HAM_MEDIUM(-1.00)[-0.999,0]; REPLY(-4.00)[]; TAGGED_FROM(0.00)[]; NEURAL_HAM_LONG(-1.00)[-1.000,0] X-BeenThere: freebsd-ports@freebsd.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: Porting software to FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 04 May 2020 23:52:16 -0000 On Mon, May 4, 2020 at 4:46 PM Josh Paetzel wrote: > On Mon, May 4, 2020, at 5:08 PM, Kurt Buff - GSEC, GCIH wrote: > > All, > > > > Has been done? > > > > I just built a new machine on our VMware cluster and tried to install this > > from ports on 12.1-RELEASE-p3 with an updated tree, and it complained about > > a dependency: > > > > ===> python27-2.7.17_1 has known vulnerabilities: > > python27-2.7.17_1 is vulnerable: > > Python -- Regular Expression DoS attack against client > > CVE: CVE-2020-8492 > > WWW: > > https://vuxml.FreeBSD.org/freebsd/a27b0bb6-84fc-11ea-b5b4-641c67a117d8.html > > > > Thanks, > > > > Kurt > > That doesn't have anything to do with an open-vm-tools version bump. > > The issue you are seeing is due to the fact that https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=245776 hasn't been committed yet. > > -- > > Thanks, > > Josh Paetzel Got it. I'll keep an eye on that bug. Thanks, Kurt