From owner-freebsd-questions@FreeBSD.ORG Thu May 18 18:27:38 2006 Return-Path: X-Original-To: freebsd-questions@freebsd.org Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id D107A16A4FA for ; Thu, 18 May 2006 18:27:38 +0000 (UTC) (envelope-from jimajima9@yahoo.com) Received: from web50004.mail.yahoo.com (web50004.mail.yahoo.com [206.190.38.19]) by mx1.FreeBSD.org (Postfix) with SMTP id 0DA2D43D58 for ; Thu, 18 May 2006 18:27:37 +0000 (GMT) (envelope-from jimajima9@yahoo.com) Received: (qmail 27189 invoked by uid 60001); 18 May 2006 18:27:37 -0000 DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=s1024; d=yahoo.com; h=Message-ID:Received:Date:From:Subject:To:MIME-Version:Content-Type:Content-Transfer-Encoding; b=uK0tXrtzod4ugrC/2w4r5HikrXerVcoyenV9+CIbO2H5v52h8fBBwRcokqEfnl2053aYqVAXiK2RGNbj2/SK9QRhE/vzKMcgk1iMzhxgGA8hat765p/sTwQta44frRAhLaOHpfN6pSIOz9kfenBh1Mc6UIUJp6NxLg+thN5FxUg= ; Message-ID: <20060518182737.27187.qmail@web50004.mail.yahoo.com> Received: from [67.174.41.131] by web50004.mail.yahoo.com via HTTP; Thu, 18 May 2006 11:27:37 PDT Date: Thu, 18 May 2006 11:27:37 -0700 (PDT) From: Jim Angstadt To: freebsd-questions@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=iso-8859-1 Content-Transfer-Encoding: 8bit Subject: portaudit report vs. portupgrade report X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 18 May 2006 18:27:39 -0000 Hi All, I'm new to FreeBSD. The daily security report lists 9 problems with installed packages. In an earlier message I was advised to use the ports system to avoid dealing with package dependencies. Thanks to all for that advice. So I have done the cvsup, buildworld, buildkernel, ..., process and completed without errors. (Thanks to all who have posted helpful messages on this subject.) Running "portaudit -Fa" advised me that the same 9 packages were still a problem. Running "portupgrade -n firefox" advised me: ** No need to upgrade 'firefox-1.0.7_1,1' (>= firefox-1.0.7_1,1). Same thing with mozilla: ** No need to upgrade 'mozilla-1.7.12,2' (>= mozilla-1.7.12,2). I did not check the other 7 packages in question. On the surface, to me, it seems as if these two tools are giving me opposite information. So, ... what is going on here? What should I do to get right. Please see below for the actual console traffic, slightly snipped. # ----------- actual console traffic ----------- tiny# uname -a FreeBSD tiny.brc.localnet 6.0-RELEASE-p7 FreeBSD 6.0-RELEASE-p7 #0: Wed May 17 16:26:53 PDT 2006 root@tiny.brc.localnet:/usr/obj/usr/src/sys/GENERIC i386 tiny# portaudit -Fa auditfile.tbz 100% of 35 kB 154 kBps New database installed. Affected package: firefox-1.0.7_1,1 Type of problem: mozilla -- multiple vulnerabilities. Reference: Affected package: mozilla-1.7.12,2 Type of problem: mozilla -- multiple vulnerabilities. Reference: [ 7 other packages snipped ] 9 problem(s) in your installed packages found. You are advised to update or deinstall the affected package(s) immediately. tiny# portupgrade -n firefox ---> Session started at: Wed, 17 May 2006 18:55:20 -0700 [Rebuilding the pkgdb in /var/db/pkg ... - 241 packages found (-0 +241) ................................................................................................................................................................................................................................................. done] [Updating the portsdb in /usr/ports ... - 13306 port entries found .........1000.........2000.........3000.........4000.........5000.........6000.........7000.........8000.........9000.........10000.........11000.........12000.........13000... ..... done] ** No need to upgrade 'firefox-1.0.7_1,1' (>= firefox-1.0.7_1,1). (specify -f to force) ---> Listing the results (+:done / -:ignored / *:skipped / !:failed) - www/firefox (firefox-1.0.7_1,1) ---> Packages processed: 0 done, 1 ignored, 0 skipped and 0 failed ---> Session ended at: Wed, 17 May 2006 18:57:17 -0700 (consumed 00:01:57) tiny# portupgrade -n mozilla ---> Session started at: Wed, 17 May 2006 18:58:49 -0700 ** No need to upgrade 'mozilla-1.7.12,2' (>= mozilla-1.7.12,2). (specify -f to force) ---> Listing the results (+:done / -:ignored / *:skipped / !:failed) - www/mozilla (mozilla-1.7.12,2) ---> Packages processed: 0 done, 1 ignored, 0 skipped and 0 failed ---> Session ended at: Wed, 17 May 2006 18:58:53 -0700 (consumed 00:00:03) # ------------- end of console traffic --------- __________________________________________________ Do You Yahoo!? Tired of spam? Yahoo! Mail has the best spam protection around http://mail.yahoo.com