From owner-freebsd-chromium@freebsd.org Sat Jan 23 00:35:33 2016 Return-Path: Delivered-To: freebsd-chromium@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 071D8A8ED07 for ; Sat, 23 Jan 2016 00:35:33 +0000 (UTC) (envelope-from philneaton95@gmail.com) Received: from mailman.ysv.freebsd.org (mailman.ysv.freebsd.org [IPv6:2001:1900:2254:206a::50:5]) by mx1.freebsd.org (Postfix) with ESMTP id DBB051B10 for ; Sat, 23 Jan 2016 00:35:32 +0000 (UTC) (envelope-from philneaton95@gmail.com) Received: by mailman.ysv.freebsd.org (Postfix) id D8B97A8ED06; Sat, 23 Jan 2016 00:35:32 +0000 (UTC) Delivered-To: chromium@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id BEFCEA8ED05 for ; Sat, 23 Jan 2016 00:35:32 +0000 (UTC) (envelope-from philneaton95@gmail.com) Received: from mail-pf0-x236.google.com (mail-pf0-x236.google.com [IPv6:2607:f8b0:400e:c00::236]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (Client CN "smtp.gmail.com", Issuer "Google Internet Authority G2" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 9288F1B0F; Sat, 23 Jan 2016 00:35:32 +0000 (UTC) (envelope-from philneaton95@gmail.com) Received: by mail-pf0-x236.google.com with SMTP id 65so50110914pff.2; Fri, 22 Jan 2016 16:35:32 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=ijhXG78wjFxgP6CLVVfd5eFjzPFJt09mIlpN/QDgqnY=; b=dmtDeqCuY3zuZkCK1+OouJxv9khGsWO2lPCdsORlKatvppmoX793P/pFXt80ETd4U6 iBZXH5xF3NV4raRIESuxHFi2Lb0km98xbYo7kGiBS0898Bb93jWQ3gZ861WXUkuemZsS ziqS7dULw6yzRPjx+hJhm5o/ihQ8RAS/h0ApeRhEU7MeEkahlRNGzTvWzRkpiSBr0F71 pF6ejYYCP5waJygz47k8G8s1gCFkTHe+8IYouUfsEtZmxAly01SKjF6AZ7ifVHZY/Hys eVUr8SAamkOwTny8wTqLGAl4ROEef7xqBv4oLhMKfpRDfDRg360aznmrYSb48aPteItx 7U3w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:in-reply-to:references:date :message-id:subject:from:to:cc:content-type; bh=ijhXG78wjFxgP6CLVVfd5eFjzPFJt09mIlpN/QDgqnY=; b=j9Hkgc9KOZid1OeouoW4kPut7gHY1nPCBv8unkk0mnZnTf16L5NyN/sYL7RJe5bnX5 LpmzgFZQCSdESq7zvX6Nu6nrKBjlIUocxk/DR1phAWTByehSeTxXDoraPQMnirbW+NOJ W15P6zD978z4YF+h+Rcyl2Y88Vl+wVJh/37mx+KlHNLRLSakBzzez7XWpVdHcVJ3twIe hf1AhCsKpk7luQnrm9dBNC7tIlK4Xtz6L/c/HKJRrfYMJKY2fisfMJc+h36qo6CsLe/Z fRxX/aX6P1MtazTXBjVvkyKN0JE0svs+dLnHE3if1EvdQSoPcHjhnjg4UbS2Aj4oE386 WOzA== X-Gm-Message-State: AG10YORRJttniae/21gprEvVPNJWS00PlZWd461Y0ROMLdorDGAcEzRIesCEGW+wMe/0EuBCePAd5pjd8e53Eg== MIME-Version: 1.0 X-Received: by 10.98.65.148 with SMTP id g20mr8570106pfd.21.1453509332124; Fri, 22 Jan 2016 16:35:32 -0800 (PST) Received: by 10.67.2.5 with HTTP; Fri, 22 Jan 2016 16:35:32 -0800 (PST) In-Reply-To: References: Date: Fri, 22 Jan 2016 19:35:32 -0500 Message-ID: Subject: Re: current chromium version in ports tree giving vulnerabilities warnings From: Phil Eaton To: =?UTF-8?Q?Ren=C3=A9_Ladan?= Cc: chromium@freebsd.org Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable X-Content-Filtered-By: Mailman/MimeDel 2.1.20 X-BeenThere: freebsd-chromium@freebsd.org X-Mailman-Version: 2.1.20 Precedence: list List-Id: FreeBSD-specific Chromium issues List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 23 Jan 2016 00:35:33 -0000 Great, thanks! Phil On Fri, Jan 22, 2016 at 7:00 PM, Ren=C3=A9 Ladan wrote: > > Op 23 jan. 2016 00:39 schreef "Phil Eaton" : > > > > Hi, > > > > I just tried to update chromium but the build is failing with a number = of > > vulnerabilities. I understand that I can build and ignore these > > vulnerabilities, but I wanted to report this anyway. Here is the result > of > > make install: > > > This is correct, the new version should be in the tree this weekend. > > > To build Chromium, you should have around 2 GB of memory > > and a fair amount of free diskspace (~ 3.7GB). > > > > Make sure you have Python build with the SEM option ON > > (default in python27-2.7.8 since r361735) > > =3D=3D=3D> chromium-47.0.2526.111 has known vulnerabilities: > > chromium-47.0.2526.111 is vulnerable: > > chromium -- multiple vulnerabilities > > CVE: CVE-2016-1620 > > CVE: CVE-2016-1619 > > CVE: CVE-2016-1618 > > CVE: CVE-2016-1617 > > CVE: CVE-2016-1616 > > CVE: CVE-2016-1615 > > CVE: CVE-2016-1614 > > CVE: CVE-2016-1613 > > CVE: CVE-2016-1612 > > WWW: > > > https://vuxml.FreeBSD.org/freebsd/371bbea9-3836-4832-9e70-e8e928727f8c.ht= ml > > > > 1 problem(s) in the installed packages found. > > =3D> Please update your ports tree and try again. > > =3D> Note: Vulnerable ports are marked as such even if there is no upda= te > > available. > > =3D> If you wish to ignore this vulnerability rebuild with 'make > > DISABLE_VULNERABILITIES=3Dyes' > > *** Error code 1 > > > > Stop. > > make[1]: stopped in /usr/ports/www/chromium > > *** Error code 1 > > > > Stop. > > make: stopped in /usr/ports/www/chromium > > > Regards, > Ren=C3=A9 > > --=20 Phil Eaton