From owner-svn-ports-head@freebsd.org Wed Aug 12 14:01:42 2015 Return-Path: Delivered-To: svn-ports-head@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 027639A008A for ; Wed, 12 Aug 2015 14:01:42 +0000 (UTC) (envelope-from feld@feld.me) Received: from out3-smtp.messagingengine.com (out3-smtp.messagingengine.com [66.111.4.27]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id C2265E0B for ; Wed, 12 Aug 2015 14:01:41 +0000 (UTC) (envelope-from feld@feld.me) Received: from compute3.internal (compute3.nyi.internal [10.202.2.43]) by mailout.nyi.internal (Postfix) with ESMTP id CFF8E21F85 for ; Wed, 12 Aug 2015 10:01:40 -0400 (EDT) Received: from web3 ([10.202.2.213]) by compute3.internal (MEProxy); Wed, 12 Aug 2015 10:01:40 -0400 DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=feld.me; h= content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to:x-sasl-enc :x-sasl-enc; s=mesmtp; bh=UBPC5nzhLz6yk3VQSbNbMM0em8k=; b=HHm7WW uoDMV9n+KbAqTcLf1D061LI9cYD0X1nXmOC0osaQxKfGQk8ngarvEDBTpNWz+3OD 52/g6JHx0RJl9Ltf9U813t+df99clEZu7b85hndh/06BlUTcmPwM7LODAx/g7SEt 3YVRrN7bEFBRcBvDMYBz0sV/5FlmrUxapYaKs= DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d= messagingengine.com; h=content-transfer-encoding:content-type :date:from:in-reply-to:message-id:mime-version:references :subject:to:x-sasl-enc:x-sasl-enc; s=smtpout; bh=UBPC5nzhLz6yk3V QSbNbMM0em8k=; b=EeU8y6PvQx8CdERXBK1tPwhp8rm/4wpWbMVoxyBA2aC59FF ftIkwURQTG6N4NsWgzIoOkGnqzLCAjHy/GmhtiWh8GxP+8HFsnycWWnMbl4FRY6o MYuZ/xo4+4a//WiN72mvLdEMVcYVphgtQwGmQQkHtB+hWTEm6QLduy8pRTUI= Received: by web3.nyi.internal (Postfix, from userid 99) id A8E87115466; Wed, 12 Aug 2015 10:01:40 -0400 (EDT) Message-Id: <1439388100.608633.354360737.36774BC8@webmail.messagingengine.com> X-Sasl-Enc: +NNy9UaXwdz8OMoVSXtm/IYDxU3zt7DfG+lp/h0IHdMt 1439388100 From: Mark Felder To: Jan Beich , ports-committers@freebsd.org, svn-ports-all@freebsd.org, svn-ports-head@freebsd.org MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Type: text/plain X-Mailer: MessagingEngine.com Webmail Interface - ajax-eca00311 Subject: Re: svn commit: r393962 - head/security/vuxml Date: Wed, 12 Aug 2015 09:01:40 -0500 In-Reply-To: <201508111903.t7BJ3aD3086878@repo.freebsd.org> References: <201508111903.t7BJ3aD3086878@repo.freebsd.org> X-BeenThere: svn-ports-head@freebsd.org X-Mailman-Version: 2.1.20 Precedence: list List-Id: SVN commit messages for the ports tree for head List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 12 Aug 2015 14:01:42 -0000 On Tue, Aug 11, 2015, at 14:03, Jan Beich wrote: > Author: jbeich > Date: Tue Aug 11 19:03:36 2015 > New Revision: 393962 > URL: https://svnweb.freebsd.org/changeset/ports/393962 > > Log: > Move libvpx vulnerability into its own entry > > Modified: > head/security/vuxml/vuln.xml > > Modified: head/security/vuxml/vuln.xml > ============================================================================== > --- head/security/vuxml/vuln.xml Tue Aug 11 18:51:57 2015 > (r393961) > +++ head/security/vuxml/vuln.xml Tue Aug 11 19:03:36 2015 > (r393962) > @@ -58,6 +58,38 @@ Notes: > > --> > > + > + libvpx -- multiple buffer overflows > + > + > + libvpx > + 1.5.0 > + > + This should probably be 1.4.0 as although their release process seems obvious, they could release 1.4.1 or we could backport security fixes to 1.4.0_1 if we can locate the commits and the fix is simple enough, but they haven't cut a formal release yet. I'll try to keep an eye on this too.