From owner-svn-ports-all@freebsd.org Thu Jul 9 13:02:56 2015 Return-Path: Delivered-To: svn-ports-all@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 817E7997DE9; Thu, 9 Jul 2015 13:02:56 +0000 (UTC) (envelope-from tijl@freebsd.org) Received: from mailrelay107.isp.belgacom.be (mailrelay107.isp.belgacom.be [195.238.20.134]) by mx1.freebsd.org (Postfix) with ESMTP id 9980C113F; Thu, 9 Jul 2015 13:02:55 +0000 (UTC) (envelope-from tijl@freebsd.org) X-Belgacom-Dynamic: yes X-Cloudmark-SP-Filtered: true X-Cloudmark-SP-Result: v=1.1 cv=LOuw2EFi1HDSQg+ei2vZVMH4RVJmMX849kfT6mZcEoQ= c=1 sm=2 a=6I5d2MoRAAAA:8 a=69g06OIpMbhz_s_Nf84A:9 a=CjuIK1q_8ugA:10 X-IronPort-Anti-Spam-Filtered: true X-IronPort-Anti-Spam-Result: A2BRBgAhcJ5V/++YsFtbgxJUUw29FoV3AoFgTQEBAQEBAYELhCQBAQQ6HCMQCw4GBAklDyoeBhOIMgEIzlEBAQEBAQEBAwEBAQEBAQEXBItLhFMzB4QrAQSULIRnhxiYZiaDfTwxgksBAQE Received: from 239.152-176-91.adsl-dyn.isp.belgacom.be (HELO kalimero.tijl.coosemans.org) ([91.176.152.239]) by relay.skynet.be with ESMTP; 09 Jul 2015 15:01:44 +0200 Received: from kalimero.tijl.coosemans.org (kalimero.tijl.coosemans.org [127.0.0.1]) by kalimero.tijl.coosemans.org (8.14.9/8.14.9) with ESMTP id t69D1hEV003278; Thu, 9 Jul 2015 15:01:43 +0200 (CEST) (envelope-from tijl@FreeBSD.org) Date: Thu, 9 Jul 2015 15:01:43 +0200 From: Tijl Coosemans To: Mark Felder Cc: ports-committers@freebsd.org, svn-ports-all@freebsd.org, svn-ports-head@freebsd.org Subject: Re: svn commit: r391576 - head/security/vuxml Message-ID: <20150709150143.22c91137@kalimero.tijl.coosemans.org> In-Reply-To: <201507081705.t68H515b023864@repo.freebsd.org> References: <201507081705.t68H515b023864@repo.freebsd.org> MIME-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit X-BeenThere: svn-ports-all@freebsd.org X-Mailman-Version: 2.1.20 Precedence: list List-Id: SVN commit messages for the ports tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 09 Jul 2015 13:02:56 -0000 On Wed, 8 Jul 2015 17:05:01 +0000 (UTC) Mark Felder wrote: > Author: feld > Date: Wed Jul 8 17:05:00 2015 > New Revision: 391576 > URL: https://svnweb.freebsd.org/changeset/ports/391576 > > Log: > Fix formatting by adding some breaks > > Security: 038a5808-24b3-11e5-b0c8-bf4d8935d4fa > > Modified: > head/security/vuxml/vuln.xml > > Modified: head/security/vuxml/vuln.xml > ============================================================================== > --- head/security/vuxml/vuln.xml Wed Jul 8 17:00:39 2015 (r391575) > +++ head/security/vuxml/vuln.xml Wed Jul 8 17:05:00 2015 (r391576) > @@ -159,12 +159,12 @@ Notes: > 1.1 after fixing many minor bugs and adding some security improvements > to the 1.1 release branch. Version 1.0.6 comes with cherry-picked fixes > from the more recent version to ensure proper long term support > - especially in regards of security and compatibility. > - > - The security-related fixes in particular are: > - > - * XSS vulnerability in _mbox argument > - * security improvement in contact photo handling > + especially in regards of security and compatibility.
> +
> + The security-related fixes in particular are:
> +
> + * XSS vulnerability in _mbox argument
> + * security improvement in contact photo handling
> * potential info disclosure from temp directory

> > It's better to mark paragraphs with

instead of

and lists can be created with
    and
  • instead of ascii art like this: --- vuln.xml (revision 391631) +++ vuln.xml (working copy) @@ -195,13 +195,13 @@ Notes: 1.1 after fixing many minor bugs and adding some security improvements to the 1.1 release branch. Version 1.0.6 comes with cherry-picked fixes from the more recent version to ensure proper long term support - especially in regards of security and compatibility.
    -
    - The security-related fixes in particular are:
    -
    - * XSS vulnerability in _mbox argument
    - * security improvement in contact photo handling
    - * potential info disclosure from temp directory

    + especially in regards of security and compatibility.

    +

    The security-related fixes in particular are:

    +
      +
    • XSS vulnerability in _mbox argument
    • +
    • security improvement in contact photo handling
    • +
    • potential info disclosure from temp directory
    • +