From owner-cvs-all@FreeBSD.ORG Fri Mar 30 18:15:08 2007 Return-Path: X-Original-To: cvs-all@FreeBSD.org Delivered-To: cvs-all@FreeBSD.org Received: from mx1.freebsd.org (mx1.freebsd.org [69.147.83.52]) by hub.freebsd.org (Postfix) with ESMTP id 77A0816A407; Fri, 30 Mar 2007 18:15:08 +0000 (UTC) (envelope-from lofi@FreeBSD.org) Received: from repoman.freebsd.org (repoman.freebsd.org [69.147.83.41]) by mx1.freebsd.org (Postfix) with ESMTP id 6617013C4D5; Fri, 30 Mar 2007 18:15:08 +0000 (UTC) (envelope-from lofi@FreeBSD.org) Received: from repoman.freebsd.org (localhost [127.0.0.1]) by repoman.freebsd.org (8.13.8/8.13.8) with ESMTP id l2UIF8BV062103; Fri, 30 Mar 2007 18:15:08 GMT (envelope-from lofi@repoman.freebsd.org) Received: (from lofi@localhost) by repoman.freebsd.org (8.13.8/8.13.8/Submit) id l2UIF8Hi062102; Fri, 30 Mar 2007 18:15:08 GMT (envelope-from lofi) Message-Id: <200703301815.l2UIF8Hi062102@repoman.freebsd.org> From: Michael Nottebrock Date: Fri, 30 Mar 2007 18:15:08 +0000 (UTC) To: ports-committers@FreeBSD.org, cvs-ports@FreeBSD.org, cvs-all@FreeBSD.org X-FreeBSD-CVS-Branch: HEAD Cc: Subject: cvs commit: ports/devel/qt4-corelib Makefile ports/devel/qt4-corelib/files patch-utf8-bug-qt4 ports/x11-toolkits/qt33 Makefile ports/x11-toolkits/qt33/files patch-utf8-bug-qt3 ports/x11/kdelibs3 Makefile ports/x11/kdelibs3/files patch-kdelibs-kjs X-BeenThere: cvs-all@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: CVS commit messages for the entire tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 30 Mar 2007 18:15:08 -0000 lofi 2007-03-30 18:15:08 UTC FreeBSD ports repository Modified files: devel/qt4-corelib Makefile x11-toolkits/qt33 Makefile x11/kdelibs3 Makefile Added files: devel/qt4-corelib/files patch-utf8-bug-qt4 x11-toolkits/qt33/files patch-utf8-bug-qt3 x11/kdelibs3/files patch-kdelibs-kjs Log: Fix handling of overlong UTF8 sequences in Qt and kdelibs, which, unpatched, introduces XSS vulnerabilities in Konqueror and potentially affect any Qt/KDE applications which deal with URLs or paths from untrusted locations. Security: CVE-2007-0242 Revision Changes Path 1.6 +2 -1 ports/devel/qt4-corelib/Makefile 1.1 +132 -0 ports/devel/qt4-corelib/files/patch-utf8-bug-qt4 (new) 1.208 +1 -0 ports/x11-toolkits/qt33/Makefile 1.1 +101 -0 ports/x11-toolkits/qt33/files/patch-utf8-bug-qt3 (new) 1.214 +1 -1 ports/x11/kdelibs3/Makefile 1.1 +38 -0 ports/x11/kdelibs3/files/patch-kdelibs-kjs (new)