From owner-freebsd-ports-bugs@FreeBSD.ORG Wed Jul 14 15:48:04 2004 Return-Path: Delivered-To: freebsd-ports-bugs@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 53B3816A4CE for ; Wed, 14 Jul 2004 15:48:04 +0000 (GMT) Received: from pittgoth.com (14.zlnp1.xdsl.nauticom.net [209.195.149.111]) by mx1.FreeBSD.org (Postfix) with ESMTP id EAA5243D31 for ; Wed, 14 Jul 2004 15:47:58 +0000 (GMT) (envelope-from trhodes@FreeBSD.org) Received: from localhost.pittgoth.com (acs-24-154-239-141.zoominternet.net [24.154.239.141]) (authenticated bits=0) by pittgoth.com (8.12.11/8.12.11) with ESMTP id i6EFlXab050818 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT); Wed, 14 Jul 2004 11:47:34 -0400 (EDT) (envelope-from trhodes@FreeBSD.org) Date: Wed, 14 Jul 2004 11:48:06 -0400 From: Tom Rhodes To: Xin LI Message-Id: <20040714114806.2e35c10c@localhost.pittgoth.com> In-Reply-To: <20040714082045.GA823@frontfree.net> References: <200407140720.i6E7KFJ8030737@freefall.freebsd.org> <20040714082045.GA823@frontfree.net> X-Mailer: Sylpheed-Claws 0.9.12 (GTK+ 1.2.10; i386-portbld-freebsd5.2) Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit cc: freebsd-ports-bugs@FreeBSD.org Subject: Re: ports/69042: [PATCH] Update www/phpbb to 2.0.9 X-BeenThere: freebsd-ports-bugs@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Ports bug reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 14 Jul 2004 15:48:04 -0000 On Wed, 14 Jul 2004 16:20:45 +0800 Xin LI wrote: > Hi Oliver, > > On Wed, Jul 14, 2004 at 07:20:15AM +0000, Oliver Eikemeier wrote: > > Xin LI wrote: > > > > > Update phpbb to latest released version, 2.0.9. This version > > > contains important security updates. > > > For detailed information, please check out here: > > > http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=209797 > > > > It seems like they are already fixed in previous revisions: > > > > Partly. As the URL said, there are many vulnerablities fixed, however, > there was no more detailed information. > > > If there are any unfixed vulnerabilities please don't forget to add an > > entry to the security database, see > > > > Yes, there are. > > I heisistate to suggest the following vuxml hunk, because it contains no > detailed information :-( I'll look into this. FWIW, I'm reviewing a possible 'issue' right now so this will be an area I'll be around tonight. -- Tom Rhodes