From owner-dev-commits-ports-all@freebsd.org Mon Sep 27 18:29:23 2021 Return-Path: Delivered-To: dev-commits-ports-all@mailman.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.nyi.freebsd.org (Postfix) with ESMTP id 2D2DF66DA8A; Mon, 27 Sep 2021 18:29:23 +0000 (UTC) (envelope-from danfe@freebsd.org) Received: from freefall.freebsd.org (freefall.freebsd.org [96.47.72.132]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "freefall.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4HJB4M0WMbz4Wyt; Mon, 27 Sep 2021 18:29:23 +0000 (UTC) (envelope-from danfe@freebsd.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1632767363; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references; bh=Tl8lW46YDmcaSJxb+ddrl5xcetmCPiy5Q6dW8rgxxCg=; b=cYjLuIWYqPmvMJEt1CdvP8tMe5SKSjGERnEeiVUhK4+lA1T2QS4xKKJopIMQ2cQwnFS87h UhOZcEkNBCv3Dz/xJJdnhoXNMqOk4H4KBlt8ybvTj6AMtJfJJiV5BkhZ8PPJjwEMmUn6cN kUQFgXibpp9VO3SUkX7grCdJixBVvA+GKFGLe3u659dQgjIkrWWLcqYmILMsjQL8Y1NRtS p6pXrx7UuPHHNX03EUrKrwdjH386Yw9E/6d+tGEeqZJ0keT3jc7w6CByDkOqG9uPtHtDML sFLPV7tGbEqW3AmUlUz4Q4DqLYAxS0OBd2mDqCOqhNMUwX0E/Bgn8Q1pg//ciA== Received: by freefall.freebsd.org (Postfix, from userid 1033) id F2AD291B8; Mon, 27 Sep 2021 18:29:22 +0000 (UTC) Date: Mon, 27 Sep 2021 18:29:22 +0000 From: Alexey Dokuchaev To: Alex Kozlov Cc: Bernhard Fr?hlich , ports-committers@freebsd.org, dev-commits-ports-all@freebsd.org, dev-commits-ports-main@freebsd.org Subject: Re: git: 8e36aa89c535 - main - archivers/ha: Add CPE information Message-ID: References: <202109201433.18KEXHRJ053338@gitrepo.freebsd.org> <20210927091710.GA21625@ravenloft.kiev.ua> <20210927182255.GA37696@ravenloft.kiev.ua> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20210927182255.GA37696@ravenloft.kiev.ua> ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1632767363; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references; bh=Tl8lW46YDmcaSJxb+ddrl5xcetmCPiy5Q6dW8rgxxCg=; b=NWtbcrdIL90Znhx2BD5S5SI1uJ/rvP+G+M9b4anMcOiu+gS/2h0k/OZ6xJKdPc/P83lumi VRaoREdGppsQdjJ7woSNHvCl44s0BTB4BolEFbU5geiTInG/Q780phwu3wD0YwinQrOIRK eYEZIdGZg5SI3699A1U9ZpITWb3VFpJg9Eaz9csnl9/UDojEs9E3vxnrxGGQAuN9UFNGy6 d533C3ESTiZnpc73jc42SMEckjrsVviS3rRuxdzwnqNUSNz5JONBgcWm7hLDsoDk1pao7Y TTlvW2stQvPangFYVfMe/lexA1hNbKWZBlEMuxDW68U8+9uAnIN9sno81ekMfw== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1632767363; a=rsa-sha256; cv=none; b=NwinX9Iv5nJtK4DqUJfs9DaYI90gYNecfH/KZQ6Jbj7igP/VOsJprdYRAOxRV8JDNLxjVX e401n20FzQRuUPREVQvCeZiU70bmpT2N38A6lSRdB8gRGFrepAYH5b/zLyttH+haylfdOa mP4wzFpxc7rrLMj/7VKZO2nU3BR2KVbz3XKiM/knT/Fz4k7cFQaArHXVCo3Qn5XDJ9Rm1W oOZgZpAeBuQaHHCRs8p/U+rzAqgKvftXayREq1HXJSsYkLet5TiY3JEiT+tTcPLSaY7GOS 7KaSdLH/+fWYXkuSdJ+B0CwuiTrzGZrssBvyytKLUGY1sT/wM6gbFrRMA2wNYg== ARC-Authentication-Results: i=1; mx1.freebsd.org; none X-BeenThere: dev-commits-ports-all@freebsd.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: Commit messages for all branches of the ports repository List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 27 Sep 2021 18:29:23 -0000 On Mon, Sep 27, 2021 at 08:22:55PM +0200, Alex Kozlov wrote: > ... > > Please also have a look at CVE-2015-1198 and take some actions because > > our port is very likely also vulnerable. > > There was incomplete attempt to fix this/similar vulnerability, but > the path part of attack still worked. So I cooked up some quick fix > by analogy with resemblant vulnerability in archivers/unarj. > Reviews are welcome. Thanks for taking care of `archivers/ha' Alex, I remember using it back in MSDOS times as it offered better compression ratios than other archivers available back in those times. Fond memories! :-) ./danfe