Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 21 Nov 2014 08:24:46 +0000 (UTC)
From:      Raphael Kubo da Costa <rakuco@FreeBSD.org>
To:        ports-committers@freebsd.org, svn-ports-all@freebsd.org, svn-ports-branches@freebsd.org
Subject:   svn commit: r372983 - in branches/2014Q4/x11/kde4-runtime: . files
Message-ID:  <201411210824.sAL8OkGF055496@svn.freebsd.org>

next in thread | raw e-mail | index | archive | help
Author: rakuco
Date: Fri Nov 21 08:24:45 2014
New Revision: 372983
URL: https://svnweb.freebsd.org/changeset/ports/372983
QAT: https://qat.redports.org/buildarchive/r372983/

Log:
  MFH: r372966
  
  Add upstream patch for CVE-2014-8600 (insufficient input validation).
  
  Security:	890b6b22-70fa-11e4-91ae-5453ed2e2b49
  Approved by:	ports-secteam (rea)

Added:
  branches/2014Q4/x11/kde4-runtime/files/patch-kioslave__bookmarks__kio_bookmarks.cpp
     - copied unchanged from r372966, head/x11/kde4-runtime/files/patch-kioslave__bookmarks__kio_bookmarks.cpp
Modified:
  branches/2014Q4/x11/kde4-runtime/Makefile
Directory Properties:
  branches/2014Q4/   (props changed)

Modified: branches/2014Q4/x11/kde4-runtime/Makefile
==============================================================================
--- branches/2014Q4/x11/kde4-runtime/Makefile	Fri Nov 21 08:20:01 2014	(r372982)
+++ branches/2014Q4/x11/kde4-runtime/Makefile	Fri Nov 21 08:24:45 2014	(r372983)
@@ -2,7 +2,7 @@
 
 PORTNAME=	kde-runtime
 PORTVERSION=	${KDE4_VERSION}
-PORTREVISION=	2
+PORTREVISION=	3
 CATEGORIES=	x11 kde
 MASTER_SITES=	KDE/${KDE4_BRANCH}/${PORTVERSION}/src
 DIST_SUBDIR=	KDE/${PORTVERSION}

Copied: branches/2014Q4/x11/kde4-runtime/files/patch-kioslave__bookmarks__kio_bookmarks.cpp (from r372966, head/x11/kde4-runtime/files/patch-kioslave__bookmarks__kio_bookmarks.cpp)
==============================================================================
--- /dev/null	00:00:00 1970	(empty, because file is newly added)
+++ branches/2014Q4/x11/kde4-runtime/files/patch-kioslave__bookmarks__kio_bookmarks.cpp	Fri Nov 21 08:24:45 2014	(r372983, copy of r372966, head/x11/kde4-runtime/files/patch-kioslave__bookmarks__kio_bookmarks.cpp)
@@ -0,0 +1,25 @@
+commit d68703900edc8416fbcd2550cd336cbbb76decb9
+Author: Martin Sandsmark <martin.sandsmark@kde.org>
+Date:   Thu Nov 13 13:29:01 2014 +0100
+
+    Sanitize path
+
+--- kioslave/bookmarks/kio_bookmarks.cpp
++++ kioslave/bookmarks/kio_bookmarks.cpp
+@@ -22,6 +22,7 @@
+ #include <stdlib.h>
+ 
+ #include <qregexp.h>
++#include <qtextdocument.h>
+ 
+ #include <kapplication.h>
+ #include <kcmdlineargs.h>
+@@ -197,7 +198,7 @@ void BookmarksProtocol::get( const KUrl& url )
+     echoImage(regexp.cap(1), regexp.cap(2), url.queryItem("size"));
+   } else {
+     echoHead();
+-    echo("<p class=\"message\">" + i18n("Wrong request: %1",path) + "</p>");
++    echo("<p class=\"message\">" + i18n("Bad request: %1", Qt::escape(Qt::escape(url.prettyUrl()))) + "</p>");
+   }
+   finished();
+ }



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?201411210824.sAL8OkGF055496>