From owner-cvs-all@FreeBSD.ORG Fri Dec 23 20:06:24 2011 Return-Path: Delivered-To: cvs-all@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 8A7F1106566C; Fri, 23 Dec 2011 20:06:24 +0000 (UTC) (envelope-from stephen@missouri.edu) Received: from wilberforce.math.missouri.edu (wilberforce.math.missouri.edu [128.206.184.213]) by mx1.freebsd.org (Postfix) with ESMTP id 4C1898FC15; Fri, 23 Dec 2011 20:06:24 +0000 (UTC) Received: from [127.0.0.1] (wilberforce.math.missouri.edu [128.206.184.213]) by wilberforce.math.missouri.edu (8.14.5/8.14.5) with ESMTP id pBNJXZD1053241; Fri, 23 Dec 2011 13:33:35 -0600 (CST) (envelope-from stephen@missouri.edu) Message-ID: <4EF4D78F.6010308@missouri.edu> Date: Fri, 23 Dec 2011 13:33:35 -0600 From: Stephen Montgomery-Smith User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9.2.23) Gecko/20110921 Thunderbird/3.1.15 MIME-Version: 1.0 To: Xin LI References: <201112231908.pBNJ8d3B018482@repoman.freebsd.org> In-Reply-To: <201112231908.pBNJ8d3B018482@repoman.freebsd.org> Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Cc: cvs-ports@freebsd.org, cvs-all@freebsd.org, ports-committers@freebsd.org Subject: Re: cvs commit: ports/ftp/proftpd Makefile ports/ftp/proftpd/files patch-src-fsio.c X-BeenThere: cvs-all@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: **OBSOLETE** CVS commit messages for the entire tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 23 Dec 2011 20:06:24 -0000 On 12/23/2011 01:08 PM, Xin LI wrote: > delphij 2011-12-23 19:08:39 UTC > > FreeBSD ports repository > > Modified files: > ftp/proftpd Makefile > Added files: > ftp/proftpd/files patch-src-fsio.c > Log: > Apply a patch after FreeBSD-SA-11:07.chroot which addresses an arbitrary > code execution vulnerability. > > Please note that in order to build this the system needs to be patched > with FreeBSD-SA-11:07.chroot and the resulting binary also needs to the > change because it depends on a new libc API. Probably this note needs to go into ports/UPDATING.