From owner-freebsd-ports-bugs@FreeBSD.ORG Sun Jan 4 15:43:19 2004 Return-Path: Delivered-To: freebsd-ports-bugs@hub.freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id C89CF16A4CE; Sun, 4 Jan 2004 15:43:19 -0800 (PST) Received: from freefall.freebsd.org (freefall.freebsd.org [216.136.204.21]) by mx1.FreeBSD.org (Postfix) with ESMTP id 0DC9A43D53; Sun, 4 Jan 2004 15:43:19 -0800 (PST) (envelope-from petef@FreeBSD.org) Received: from freefall.freebsd.org (petef@localhost [127.0.0.1]) i04NhIFR045458; Sun, 4 Jan 2004 15:43:18 -0800 (PST) (envelope-from petef@freefall.freebsd.org) Received: (from petef@localhost) by freefall.freebsd.org (8.12.10/8.12.10/Submit) id i04NhIrn045454; Sun, 4 Jan 2004 17:43:18 -0600 (CST) (envelope-from petef) Date: Sun, 4 Jan 2004 17:43:18 -0600 (CST) From: Pete Fritchman Message-Id: <200401042343.i04NhIrn045454@freefall.freebsd.org> To: expires20031214T0931MST@gtcs.com, petef@FreeBSD.org, freebsd-ports-bugs@FreeBSD.org Subject: Re: ports/59088: Security problem in nvi-perl port X-BeenThere: freebsd-ports-bugs@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Ports bug reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 04 Jan 2004 23:43:19 -0000 Synopsis: Security problem in nvi-perl port State-Changed-From-To: open->closed State-Changed-By: petef State-Changed-When: Sun Jan 4 17:42:13 CST 2004 State-Changed-Why: Good find. I added a patch so 'pnview' sets readonly by default. Do you think we should update pkg-message about the Perl warnings? If so, what wording do you think might be appropriate? I don't agree we should completely remove pnview; obviously perl could write to the file, and so could the user with :w!, :set noreadonly, etc. http://www.freebsd.org/cgi/query-pr.cgi?pr=59088