From owner-svn-ports-head@FreeBSD.ORG Thu Feb 28 01:46:42 2013 Return-Path: Delivered-To: svn-ports-head@freebsd.org Received: from mx1.freebsd.org (mx1.FreeBSD.org [8.8.178.115]) by hub.freebsd.org (Postfix) with ESMTP id 98F7C1D5; Thu, 28 Feb 2013 01:46:42 +0000 (UTC) (envelope-from swills@FreeBSD.org) Received: from svn.freebsd.org (svn.freebsd.org [IPv6:2001:1900:2254:2068::e6a:0]) by mx1.freebsd.org (Postfix) with ESMTP id 86814122; Thu, 28 Feb 2013 01:46:42 +0000 (UTC) Received: from svn.freebsd.org ([127.0.1.70]) by svn.freebsd.org (8.14.5/8.14.5) with ESMTP id r1S1kgqj090310; Thu, 28 Feb 2013 01:46:42 GMT (envelope-from swills@svn.freebsd.org) Received: (from swills@localhost) by svn.freebsd.org (8.14.5/8.14.5/Submit) id r1S1kfil090304; Thu, 28 Feb 2013 01:46:41 GMT (envelope-from swills@svn.freebsd.org) Message-Id: <201302280146.r1S1kfil090304@svn.freebsd.org> From: Steve Wills Date: Thu, 28 Feb 2013 01:46:41 +0000 (UTC) To: ports-committers@freebsd.org, svn-ports-all@freebsd.org, svn-ports-head@freebsd.org Subject: svn commit: r313076 - in head: graphics/rubygem-dragonfly security/vuxml X-SVN-Group: ports-head MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-ports-head@freebsd.org X-Mailman-Version: 2.1.14 Precedence: list List-Id: SVN commit messages for the ports tree for head List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 28 Feb 2013 01:46:42 -0000 Author: swills Date: Thu Feb 28 01:46:41 2013 New Revision: 313076 URL: http://svnweb.freebsd.org/changeset/ports/313076 Log: - Update to 0.9.14 to fix CVE-2013-1756 Security: aa7764af-0b5e-4ddc-bc65-38ad697a484f Modified: head/graphics/rubygem-dragonfly/Makefile (contents, props changed) head/graphics/rubygem-dragonfly/distinfo (contents, props changed) head/security/vuxml/vuln.xml Modified: head/graphics/rubygem-dragonfly/Makefile ============================================================================== --- head/graphics/rubygem-dragonfly/Makefile Thu Feb 28 01:43:31 2013 (r313075) +++ head/graphics/rubygem-dragonfly/Makefile Thu Feb 28 01:46:41 2013 (r313076) @@ -1,18 +1,17 @@ -# Ports collection makefile for: rubygem-dragonfly -# Date created: 13 January 2011 -# Whom: Jason Helfman -# +# Created by: Jason Helfman # $FreeBSD$ PORTNAME= dragonfly -PORTVERSION= 0.9.12 +PORTVERSION= 0.9.14 CATEGORIES= graphics rubygems MASTER_SITES= RG MAINTAINER= ruby@FreeBSD.org COMMENT= On-the-fly Rack-based image handling framework -RUN_DEPENDS+= rubygem-rack>=0:${PORTSDIR}/www/rubygem-rack +RUN_DEPENDS+= rubygem-rack>=0:${PORTSDIR}/www/rubygem-rack \ + rubygem-multi_json>=1.0:${PORTSDIR}/devel/rubygem-multi_json + USE_RUBY= yes USE_RUBYGEMS= yes Modified: head/graphics/rubygem-dragonfly/distinfo ============================================================================== --- head/graphics/rubygem-dragonfly/distinfo Thu Feb 28 01:43:31 2013 (r313075) +++ head/graphics/rubygem-dragonfly/distinfo Thu Feb 28 01:46:41 2013 (r313076) @@ -1,2 +1,2 @@ -SHA256 (rubygem/dragonfly-0.9.12.gem) = 52c3beec7e9be7560158b1a31126966a28b4ed74141caaef5d550936d6cf4851 -SIZE (rubygem/dragonfly-0.9.12.gem) = 444416 +SHA256 (rubygem/dragonfly-0.9.14.gem) = 6b364299b25aee6f5928dc6cb13677f27c892b0a090dc0a5b6d7ac465dfa1234 +SIZE (rubygem/dragonfly-0.9.14.gem) = 446976 Modified: head/security/vuxml/vuln.xml ============================================================================== --- head/security/vuxml/vuln.xml Thu Feb 28 01:43:31 2013 (r313075) +++ head/security/vuxml/vuln.xml Thu Feb 28 01:46:41 2013 (r313076) @@ -51,6 +51,37 @@ Note: Please add new entries to the beg --> + + rubygem-dragonfly -- arbitrary code execution + + + rubygem18-dragonfly + rubygem19-dragonfly + rubygem20-dragonfly + 0.9.14 + + + + +

Mark Evans reports:

+
+

Unfortunately there is a security vulnerability in Dragonfly when + used with Rails which would potentially allow an attacker to run + arbitrary code on a host machine using carefully crafted + requests. +

+
+ +
+ + CVE-2013-1756 + + + 2013-02-19 + 2013-02-28 + +
+ linux-flashplugin -- multiple vulnerabilities