From owner-cvs-all@FreeBSD.ORG Sun Jun 20 14:46:18 2004 Return-Path: Delivered-To: cvs-all@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id C47C916A4CE; Sun, 20 Jun 2004 14:46:18 +0000 (GMT) Received: from fillmore.dyndns.org (port-212-202-50-15.dynamic.qsc.de [212.202.50.15]) by mx1.FreeBSD.org (Postfix) with ESMTP id 6E88A43D1F; Sun, 20 Jun 2004 14:46:18 +0000 (GMT) (envelope-from eikemeier@fillmore-labs.com) Received: from [172.16.0.13] (helo=localhost) by fillmore.dyndns.org with esmtp (TLSv1:DES-CBC3-SHA:168) (Exim 4.34 (FreeBSD)) id 1Bc3aI-0002rf-MS; Sun, 20 Jun 2004 16:46:17 +0200 Date: Sun, 20 Jun 2004 16:46:16 +0200 Content-Type: text/plain; charset=US-ASCII; format=flowed Mime-Version: 1.0 (Apple Message framework v482) To: Thierry Thomas From: Oliver Eikemeier In-Reply-To: <200406200904.i5K94W0c087695@repoman.freebsd.org> Message-Id: <95D06D00-C2C8-11D8-9250-00039312D914@fillmore-labs.com> Content-Transfer-Encoding: 7bit User-Agent: KMail/1.5.9 cc: cvs-ports@FreeBSD.org cc: cvs-all@FreeBSD.org cc: ports-committers@FreeBSD.org Subject: Re: cvs commit: ports/textproc/aspell Makefile ports/textproc/aspell/files patch-prog-compress.c ports/security/portaudit-db/database portaudit.txt X-BeenThere: cvs-all@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: CVS commit messages for the entire tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 20 Jun 2004 14:46:18 -0000 Thierry Thomas wrote: > thierry 2004-06-20 09:04:32 UTC > > FreeBSD ports repository > > Modified files: > textproc/aspell Makefile > security/portaudit-db/database portaudit.txt > Added files: > textproc/aspell/files patch-prog-compress.c > Log: > Security: fix a buffer overflow in word-list-compress: > - > > - > Thanks for the entry. This matches - linux-aspell-0.50.4.1 - ruby18-raspell-0.1 which may be unintentional. Could you verify that? May I suggest using {,af-,bg-,br-,ca-,cs-,cy-,da-,de-,el-,eo-,es-,fo-,fr-,ga-,gd-,gl-,gv-,hr-,ia-, id-,is-,it-,mi-,ms-,mt-,nb-,nl-,nn-,pl-,pt-,ro-,ru-,sk-,sl-,sv-,sw-,tn-,tr-, uk-,wa-,zu-}aspell<=0.50.5_2 ? Also an seperate entry for linux-aspell-0.50.4.1 (with the same UUID and references) seems appropriate. You can test which ports are match by doing awk -F\| -vpattern='*aspell<=0.50.5_2' '{if(\!system("/usr/local/sbin/pkg_version -T \"" $1 "\" \"" pattern "\"")) print $2}' /usr/ports/INDEX Thanks again -Oliver