Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 08 Aug 2015 12:03:30 +0000
From:      bugzilla-noreply@freebsd.org
To:        freebsd-ports-bugs@FreeBSD.org
Subject:   [Bug 201704] lang/groovy: remote execution of untrusted code vulnerability in 2.3.9
Message-ID:  <bug-201704-13-T8tlKugbtj@https.bugs.freebsd.org/bugzilla/>
In-Reply-To: <bug-201704-13@https.bugs.freebsd.org/bugzilla/>
References:  <bug-201704-13@https.bugs.freebsd.org/bugzilla/>

next in thread | previous in thread | raw e-mail | index | archive | help
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=201704

--- Comment #3 from Jason Unovitch <jason.unovitch@gmail.com> ---
Created attachment 159662
  --> https://bugs.freebsd.org/bugzilla/attachment.cgi?id=159662&action=edit
Poudriere testport log from 10.1-RELEASE jail

QA:

Portlint:

Portlint is showing a false positive as there are multiple DISTFILES in the
form of DISTFILES and DOCS_DISTFILES for the DOCS option.

portlint -ac

WARN: Makefile: use of DISTFILES with single file discouraged. distribution
filename should be set by DISTNAME and EXTRACT_SUFX.
WARN: Makefile: DISTFILES/DISTNAME affects WRKSRC. take caution when changing
them.
0 fatal errors and 2 warnings found.

Poudriere:

Log attached and issues addressed were commented on above.  The patch was
tested across a range of Poudriere jails:

8.4-RELEASE-p36      amd64
8.4-RELEASE-p36      i386
9.3-RELEASE-p21      amd6
9.3-RELEASE-p21      i386
10.1-RELEASE-p16     amd64
10.1-RELEASE-p16     i386
10.2-RC2             amd64
10.2-RC2             i386
11.0-CURRENT r286208 amd64
11.0-CURRENT r286208 i386

Runtime:

Basic sanity checking via the groovysh command in a Poudriere jail.

root@110amd64-default:/usr/local/bin # groovysh
Groovy Shell (2.4.4, JVM: 1.7.0_80)
Type ':help' or ':h' for help.
-------------------------------------------------------------------------------------------------------------------------------------
groovy:000> println "test"
test
===> null
groovy:000> :exit

-- 
You are receiving this mail because:
You are the assignee for the bug.



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?bug-201704-13-T8tlKugbtj>