From owner-svn-ports-all@freebsd.org Tue Jan 17 03:14:24 2017 Return-Path: Delivered-To: svn-ports-all@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id CBB81CB322F; Tue, 17 Jan 2017 03:14:24 +0000 (UTC) (envelope-from junovitch@FreeBSD.org) Received: from freefall.freebsd.org (freefall.freebsd.org [IPv6:2610:1c1:1:6074::16:84]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "freefall.freebsd.org", Issuer "Let's Encrypt Authority X3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id A891810BA; Tue, 17 Jan 2017 03:14:24 +0000 (UTC) (envelope-from junovitch@FreeBSD.org) Received: from Silverstone (freefall.freebsd.org [IPv6:2610:1c1:1:6074::16:84]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (Client did not present a certificate) by freefall.freebsd.org (Postfix) with ESMTPS id AED7D53F4; Tue, 17 Jan 2017 03:14:23 +0000 (UTC) (envelope-from junovitch@FreeBSD.org) Date: Mon, 16 Jan 2017 22:14:22 -0500 From: Jason Unovitch To: Thierry Thomas Cc: adamw@FreeBSD.org, ports-secteam@freebsd.org, svn-ports-head@freebsd.org, svn-ports-all@freebsd.org, ports-committers@freebsd.org Subject: Re: svn commit: r431689 - head/www/tt-rss Message-ID: <20170117031422.GD19388@Silverstone> References: <201701161855.v0GItwYn000700@repo.freebsd.org> <20170116190730.GH2202@graf.pompo.net> MIME-Version: 1.0 Content-Type: text/plain; charset=iso-8859-1 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: User-Agent: Mutt/1.5.24 (2015-08-30) X-BeenThere: svn-ports-all@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the ports tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 17 Jan 2017 03:14:24 -0000 On Mon, Jan 16, 2017 at 12:58:38PM -0700, Adam Weinberger wrote: > > On 16 Jan, 2017, at 12:07, Thierry Thomas wrote: > > > > Le lun. 16 janv. 17 à 19:55:58 +0100, Thierry Thomas > > écrivait : > >> Author: thierry > >> Date: Mon Jan 16 18:55:58 2017 > >> New Revision: 431689 > >> URL: https://svnweb.freebsd.org/changeset/ports/431689 > >> > >> Log: > >> Fix another phpmailer vulnerability. > >> > >> MFC after: 1 day > >> Security: CVE-2016-10033 > > > > The message on the mailing list is about CVE-2016-10033, but actually it > > should be: > > > > Security: CVE-2017-5223 > > (fixed in phpmailer 5.2.22) > > The "MFH" key triggers an automatic review by ports-secteam. So, > > MFH: 2017Q1 > > "MFC after" does not trigger this. > > Cc'ing ports-secteam on this message to make sure it's on their radar. > > # Adam Thanks Adam. Thierry, Consider this approved for MFH with `Tools/scripts/mfh 2017Q1 431689'.