Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 10 Feb 2002 15:05:22 -0800 (PST)
From:      Trevor Johnson <trevor@FreeBSD.org>
To:        cvs-committers@FreeBSD.org, cvs-all@FreeBSD.org
Subject:   cvs commit: ports/www/bsdi-netscape47-communicator Makefile pkg-comment pkg-descr pkg-message pkg-plist ports/www/bsdi-netscape47-communicator/files mailcap ports/www/bsdi-netscape47-navigator Makefile pkg-comment pkg-descr pkg-plist
Message-ID:  <200202102305.g1AN5M628195@freefall.freebsd.org>

next in thread | raw e-mail | index | archive | help
trevor      2002/02/10 15:05:22 PST

  Removed files:
    www/bsdi-netscape47-communicator Makefile pkg-comment 
                                     pkg-descr pkg-message 
                                     pkg-plist 
    www/bsdi-netscape47-communicator/files mailcap 
    www/bsdi-netscape47-navigator Makefile pkg-comment pkg-descr 
                                  pkg-plist 
  Log:
  Send the BSD/OS Netscape ports to Davy Jones' locker.
  They have at least two dangerous bugs:
  
  - a buffer overflow in the password field of HTML forms can lead
    to execution of hostile code, as reported by Michal Zalewski at
    (URL:http://www.securityfocus.com/archive/1/136137).  This was the
    subject of advisory FreeBSD-SA-00:66.
  
  - if JavaScript is enabled, JavaScript code embedded in the comment
    blocks of images can be executed.  This can result in sensitive
    information being sent to a Web server. The bug was reported by
    Florian Wesch at (URL:http://www.securityfocus.com/archive/1/175060)
    and (URL:http://www.dividuum.de/).
  
  Requested by:   nectar
  
  Revision  Changes    Path
  1.75      +0 -42     ports/www/bsdi-netscape47-communicator/Makefile (dead)
  1.2       +0 -69     ports/www/bsdi-netscape47-communicator/files/mailcap (dead)
  1.11      +0 -1      ports/www/bsdi-netscape47-communicator/pkg-comment (dead)
  1.23      +0 -15     ports/www/bsdi-netscape47-communicator/pkg-descr (dead)
  1.2       +0 -11     ports/www/bsdi-netscape47-communicator/pkg-message (dead)
  1.30      +0 -199    ports/www/bsdi-netscape47-communicator/pkg-plist (dead)
  1.55      +0 -12     ports/www/bsdi-netscape47-navigator/Makefile (dead)
  1.12      +0 -1      ports/www/bsdi-netscape47-navigator/pkg-comment (dead)
  1.22      +0 -14     ports/www/bsdi-netscape47-navigator/pkg-descr (dead)
  1.32      +0 -156    ports/www/bsdi-netscape47-navigator/pkg-plist (dead)

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe cvs-all" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?200202102305.g1AN5M628195>