From owner-freebsd-ports-bugs@FreeBSD.ORG Thu Feb 2 20:20:10 2012 Return-Path: Delivered-To: freebsd-ports-bugs@hub.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 50DF51065672 for ; Thu, 2 Feb 2012 20:20:10 +0000 (UTC) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (freefall.freebsd.org [IPv6:2001:4f8:fff6::28]) by mx1.freebsd.org (Postfix) with ESMTP id 20A528FC0A for ; Thu, 2 Feb 2012 20:20:10 +0000 (UTC) Received: from freefall.freebsd.org (localhost [127.0.0.1]) by freefall.freebsd.org (8.14.5/8.14.5) with ESMTP id q12KK9LK009072 for ; Thu, 2 Feb 2012 20:20:09 GMT (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.14.5/8.14.5/Submit) id q12KK9oV009067; Thu, 2 Feb 2012 20:20:09 GMT (envelope-from gnats) Resent-Date: Thu, 2 Feb 2012 20:20:09 GMT Resent-Message-Id: <201202022020.q12KK9oV009067@freefall.freebsd.org> Resent-From: FreeBSD-gnats-submit@FreeBSD.org (GNATS Filer) Resent-To: freebsd-ports-bugs@FreeBSD.org Resent-Reply-To: FreeBSD-gnats-submit@FreeBSD.org, Michiel Boland Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 74F2E106566C for ; Thu, 2 Feb 2012 20:13:58 +0000 (UTC) (envelope-from michiel@boland.org) Received: from smtp10.mail.sp.isp-net.nl (smtp10.mail.sp.isp-net.nl [217.149.192.65]) by mx1.freebsd.org (Postfix) with ESMTP id F30658FC17 for ; Thu, 2 Feb 2012 20:13:57 +0000 (UTC) Received: from charlemagne.boland.org by smtp10.mail.sp.isp-net.nl via 150-42-215.ftth.xms.internl.net [82.215.42.150] with ESMTP for id q12K3it0009254 (8.13.2/2.04); Thu, 2 Feb 2012 21:03:44 +0100 (MET) Received: from charlemagne.boland.org (localhost [127.0.0.1]) by charlemagne.boland.org (8.14.5/8.14.5) with ESMTP id q12K3iCi008671 for ; Thu, 2 Feb 2012 21:03:44 +0100 (CET) (envelope-from boland@charlemagne.boland.org) Received: (from boland@localhost) by charlemagne.boland.org (8.14.5/8.14.5/Submit) id q12K3iHY008670; Thu, 2 Feb 2012 21:03:44 +0100 (CET) (envelope-from boland) Message-Id: <201202022003.q12K3iHY008670@charlemagne.boland.org> Date: Thu, 2 Feb 2012 21:03:44 +0100 (CET) From: Michiel Boland To: FreeBSD-gnats-submit@FreeBSD.org X-Send-Pr-Version: 3.113 Cc: Subject: ports/164717: [maintainer update] update www/mathopd to 1.5p7 X-BeenThere: freebsd-ports-bugs@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list Reply-To: Michiel Boland List-Id: Ports bug reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 02 Feb 2012 20:20:10 -0000 >Number: 164717 >Category: ports >Synopsis: [maintainer update] update www/mathopd to 1.5p7 >Confidential: no >Severity: serious >Priority: medium >Responsible: freebsd-ports-bugs >State: open >Quarter: >Keywords: >Date-Required: >Class: maintainer-update >Submitter-Id: current-users >Arrival-Date: Thu Feb 02 20:20:08 UTC 2012 >Closed-Date: >Last-Modified: >Originator: Michiel Boland >Release: FreeBSD 9.0-STABLE amd64 >Organization: >Environment: System: FreeBSD charlemagne.boland.org 9.0-STABLE FreeBSD 9.0-STABLE #0: Sat Jan 14 16:53:56 CET 2012 root@charlemagne.boland.org:/usr/obj/usr/src/sys/CHARLEMAGNE amd64 >Description: Update the www/mathopd port to 1.5p7. The previous version has a vulnerability that could lead to directory traversal when the '*' construct in config files is used. >How-To-Repeat: n/a >Fix: --- mathopd-1.5p7.diff begins here --- diff -ur mathopd.orig/Makefile mathopd/Makefile --- mathopd.orig/Makefile 2007-08-13 10:34:41.000000000 +0200 +++ mathopd/Makefile 2012-02-02 20:26:14.000000000 +0100 @@ -6,12 +6,13 @@ # PORTNAME= mathopd -PORTVERSION= 1.5p6 +PORTVERSION= 1.5p7 CATEGORIES= www MASTER_SITES= http://www.mathopd.org/dist/ MAINTAINER= michiel@boland.org COMMENT= A very small, yet very fast HTTP server + CFLAGS+= -DFREEBSD_SENDFILE MAKE_ARGS= CFLAGS="${CFLAGS}" diff -ur mathopd.orig/distinfo mathopd/distinfo --- mathopd.orig/distinfo 2011-03-27 17:35:51.000000000 +0200 +++ mathopd/distinfo 2012-02-02 20:21:43.000000000 +0100 @@ -1,2 +1,2 @@ -SHA256 (mathopd-1.5p6.tar.gz) = ece0d9d96f114aff39c508de109263213861769aac2592bde27faecca4b615a6 -SIZE (mathopd-1.5p6.tar.gz) = 59578 +SHA256 (mathopd-1.5p7.tar.gz) = b3489e24622574e4e92aa105dad1e1a076a441aa805675d1885a240b15932a4e +SIZE (mathopd-1.5p7.tar.gz) = 59684 --- mathopd-1.5p7.diff ends here --- >Release-Note: >Audit-Trail: >Unformatted: