Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 26 Dec 2018 23:38:18 +0900
From:      =?utf-8?B?5YaF6JekIOelkOS4gOmDjg==?= <naito.yuichiro@gmail.com>
To:        =?utf-8?Q?T=C4=B3l_Coosemans?= <tijl@FreeBSD.org>
Cc:        Thomas Zander <riggs@FreeBSD.org>, ports-committers@freebsd.org, svn-ports-all@freebsd.org, svn-ports-head@freebsd.org
Subject:   Re: svn commit: r488386 - in head/multimedia/handbrake: . files
Message-ID:  <32C7BD39-3712-4ED2-8736-C2668BCB42A8@gmail.com>
In-Reply-To: <20181226144746.4b37384f@kalimero.tijl.coosemans.org>
References:  <201812261323.wBQDNxD0027352@repo.freebsd.org> <20181226144746.4b37384f@kalimero.tijl.coosemans.org>

next in thread | previous in thread | raw e-mail | index | archive | help

--Apple-Mail=_2D019A75-E33E-4FBD-A5D2-F3D5123CA6AA
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8

Hi

> 2018/12/26 22:47=E3=80=81T=C4=B3l Coosemans =
<tijl@FreeBSD.org>=E3=81=AE=E3=83=A1=E3=83=BC=E3=83=AB:
>=20
> On Wed, 26 Dec 2018 13:23:59 +0000 (UTC) Thomas Zander =
<riggs@FreeBSD.org> wrote:
>> Author: riggs
>> Date: Wed Dec 26 13:23:59 2018
>> New Revision: 488386
>> URL: https://svnweb.freebsd.org/changeset/ports/488386
>>=20
>> Log:
>>  Update to upstream version 1.2.0
>>=20
>>  Detailed maintainer log:
>>  - Runtime feature:
>>    - Backend library has been changed from libav to ffmpeg-4.1.
>>      Vulnerabilities of libav have been solved.
>=20
> There are several ffmpeg entries in security/vuxml/vuln.xml that list
> handbrake>=3D0.  Maybe you can add <lt>1.2.0</lt> to those entries =
now?

Yes, all vulnerabilities listed in security/vuxml/vuln.xml have been =
solved in HandBrake-1.2.0,
because libav is no longer used.

I want to update vuln.xml like the attached patch.



--Apple-Mail=_2D019A75-E33E-4FBD-A5D2-F3D5123CA6AA
Content-Disposition: attachment;
	filename=vuln.xml.patch
Content-Type: application/octet-stream;
	x-unix-mode=0644;
	name="vuln.xml.patch"
Content-Transfer-Encoding: 7bit

Index: vuln.xml
===================================================================
--- vuln.xml	(revision 488390)
+++ vuln.xml	(working copy)
@@ -46097,9 +46097,9 @@
       </package>
       <package>
 	<name>handbrake</name>
-	<!-- handbrake-0.10.2 has libav-10.1 -->
-	<!-- no known fixed version -->
-	<range><ge>0</ge></range>
+	<!-- handbrake prior to 1.2.0 has libav-10.1 -->
+	<!-- backend library has been switched from libav to ffmpeg since 1.2.0 -->
+	<range><lt>1.2.0</lt></range>
       </package>
       <package>
 	<name>ffmpeg</name>
@@ -47968,9 +47968,9 @@
       </package>
       <package>
 	<name>handbrake</name>
-	<!-- handbrake-0.10.2 has libav-10.1 -->
-	<!-- no known fixed version -->
-	<range><ge>0</ge></range>
+	<!-- handbrake prior to 1.2.0 has libav-10.1 -->
+	<!-- backend library has been switched from libav to ffmpeg since 1.2.0 -->
+	<range><lt>1.2.0</lt></range>
       </package>
       <package>
 	<name>ffmpeg</name>
@@ -51573,9 +51573,9 @@
       </package>
       <package>
 	<name>handbrake</name>
-	<!-- handbrake-0.10.2 has libav-10.1 -->
-	<!-- no known fixed version -->
-	<range><ge>0</ge></range>
+	<!-- handbrake prior to 1.2.0 has libav-10.1 -->
+	<!-- backend library has been switched from libav to ffmpeg since 1.2.0 -->
+	<range><lt>1.2.0</lt></range>
       </package>
       <package>
 	<name>ffmpeg</name>
@@ -52781,9 +52781,9 @@
       </package>
       <package>
 	<name>handbrake</name>
-	<!-- handbrake-0.10.2 has libav-10.1 -->
-	<!-- no known fixed version -->
-	<range><ge>0</ge></range>
+	<!-- handbrake prior to 1.2.0 has libav-10.1 -->
+	<!-- backend library has been switched from libav to ffmpeg since 1.2.0 -->
+	<range><lt>1.2.0</lt></range>
       </package>
       <package>
 	<name>ffmpeg</name>
@@ -52880,9 +52880,9 @@
       </package>
       <package>
 	<name>handbrake</name>
-	<!-- handbrake-0.10.2 has libav-10.1 -->
-	<!-- no known fixed version -->
-	<range><ge>0</ge></range>
+	<!-- handbrake prior to 1.2.0 has libav-10.1 -->
+	<!-- backend library has been switched from libav to ffmpeg since 1.2.0 -->
+	<range><lt>1.2.0</lt></range>
       </package>
       <package>
 	<name>ffmpeg</name>

--Apple-Mail=_2D019A75-E33E-4FBD-A5D2-F3D5123CA6AA
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8


=E2=80=94
Yuichiro NAITO
naito.yuichiro@gmail.com




--Apple-Mail=_2D019A75-E33E-4FBD-A5D2-F3D5123CA6AA--



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?32C7BD39-3712-4ED2-8736-C2668BCB42A8>