From owner-freebsd-stable@FreeBSD.ORG Mon Jun 27 19:52:50 2005 Return-Path: X-Original-To: freebsd-stable@freebsd.org Delivered-To: freebsd-stable@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 9E46416A41C for ; Mon, 27 Jun 2005 19:52:50 +0000 (GMT) (envelope-from simon@zaphod.nitro.dk) Received: from zaphod.nitro.dk (port324.ds1-khk.adsl.cybercity.dk [212.242.113.79]) by mx1.FreeBSD.org (Postfix) with ESMTP id 4FC3143D1F for ; Mon, 27 Jun 2005 19:52:50 +0000 (GMT) (envelope-from simon@zaphod.nitro.dk) Received: by zaphod.nitro.dk (Postfix, from userid 3000) id DCDFE119E6; Mon, 27 Jun 2005 21:52:48 +0200 (CEST) Date: Mon, 27 Jun 2005 21:52:48 +0200 From: "Simon L. Nielsen" To: Dick Davies Message-ID: <20050627195248.GE958@zaphod.nitro.dk> References: <20050624095836.GB1311@eris.tenfour> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="TiqCXmo5T1hvSQQg" Content-Disposition: inline In-Reply-To: <20050624095836.GB1311@eris.tenfour> User-Agent: Mutt/1.5.9i Cc: FreeBSD Stable Users Subject: Re: marking ports as 'cleaned' in portaudit.conf ? X-BeenThere: freebsd-stable@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Production branch of FreeBSD source code List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 27 Jun 2005 19:52:50 -0000 --TiqCXmo5T1hvSQQg Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On 2005.06.24 10:58:36 +0100, Dick Davies wrote: > > I just manually patched up my ruby18 install and tried to tell > portaudit that the local port is now clean, but it doesn't want to > know: > > root@eris rasputnik # portaudit > Affected package: ruby-1.8.2_3 > Type of problem: ruby -- arbitrary command execution on XMLRPC server. > Reference: > > ^C > root@eris rasputnik # cat /usr/local/etc/portaudit.conf > portaudit_fixed=3D"594eb447-e398-11d9-a8bd-000cf18bbe54" > root@eris rasputnik # > > what did I miss? It seems like portaudit_fixed only works for "system" entries, ie. base system vulnerabilities and is ignored package entries. I think it would be useful to be able to suppress the certain package vulnerabilities like you are trying to, but I don't think I will get around to looking at implementing it any time soon. Of cause the real solution to this particular problem would be for someone to submit a patch for the port :-). --=20 Simon L. Nielsen --TiqCXmo5T1hvSQQg Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.1 (FreeBSD) iD8DBQFCwFkQh9pcDSc1mlERAq0JAJ95dB8pU86HfcYOQRYXJnSRywljZwCfQI9g pd2AGd9n91OncvtMfaLLYHQ= =GpVs -----END PGP SIGNATURE----- --TiqCXmo5T1hvSQQg--