Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 14 Nov 2020 18:56:28 +0000
From:      bugzilla-noreply@freebsd.org
To:        ports-bugs@FreeBSD.org
Subject:   [Bug 251141] databases/mantis: update to 2.24.3 [3 CVEs fixed]
Message-ID:  <bug-251141-7788@https.bugs.freebsd.org/bugzilla/>

next in thread | raw e-mail | index | archive | help
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D251141

            Bug ID: 251141
           Summary: databases/mantis: update to 2.24.3 [3 CVEs fixed]
           Product: Ports & Packages
           Version: Latest
          Hardware: Any
                OS: Any
            Status: New
          Severity: Affects Some People
          Priority: ---
         Component: Individual Port(s)
          Assignee: ports-bugs@FreeBSD.org
          Reporter: zab@zltech.eu

Created attachment 219687
  --> https://bugs.freebsd.org/bugzilla/attachment.cgi?id=3D219687&action=
=3Dedit
update to 2.24.3

There is a new version available:
https://mantisbt.org/bugs/changelog_page.php?project=3Dmantisbt&version=3D2=
.24.3

This is a security release fixing:
- CVE-2020-25781
- CVE-2020-25288
- CVE-2020-25830
(no VuXML entry yet)

I created a patch for version update.
Changes:
- version to 2.24.3
- added files/patch-.imgbotconfig (its original exists in git repo but not
included in official 2.24.3 package, there might be some users with configu=
red
imgbot depending on it + there is a PLIST_FILES entry in Makefile)
- adopt maintainership

QA:
- portlint: no new warns/errors (actual repo has 15)
- poudriere: ok (13-CURRENT, with/without my,pg,plugins)
- fresh install: works similar to previous version (12.2-RELEASE)
- update existing mantis 2.24.2 system to 2.24.3: works like 2.24.2, no cha=
nges
seen in user flows (except fixed errors :)
- database schema: unchanged (checked on pg-12)

--=20
You are receiving this mail because:
You are the assignee for the bug.=



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?bug-251141-7788>