From owner-freebsd-questions@FreeBSD.ORG Sat May 21 14:38:57 2005 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 09E0C16A4CE for ; Sat, 21 May 2005 14:38:57 +0000 (GMT) Received: from smtp.owt.com (smtp.owt.com [204.118.6.19]) by mx1.FreeBSD.org (Postfix) with ESMTP id 6D64843D77 for ; Sat, 21 May 2005 14:38:56 +0000 (GMT) (envelope-from kstewart@owt.com) Received: from [207.41.94.233] (owt-207-41-94-233.owt.com [207.41.94.233]) by smtp.owt.com (8.12.8/8.12.8) with ESMTP id j4LEcgJJ015854; Sat, 21 May 2005 07:38:42 -0700 From: Kent Stewart To: freebsd-questions@freebsd.org, Robert S Date: Sat, 21 May 2005 07:38:54 -0700 User-Agent: KMail/1.8 References: <7093dffb05052106296c487773@mail.gmail.com> In-Reply-To: <7093dffb05052106296c487773@mail.gmail.com> MIME-Version: 1.0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: 7bit Content-Disposition: inline Message-Id: <200505210738.54793.kstewart@owt.com> Subject: Re: portaudit: recommended packages can't be installed X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 21 May 2005 14:38:57 -0000 On Saturday 21 May 2005 06:29 am, Robert S wrote: > 8I've just started playing around with FreeBSD. One of my main > priorities of an OS is ease of upgrading. If I run portaudit, I get > a list of insecure packages (here is an excerpt from the output): > > Affected package: firefox-1.0.3,1 > Type of problem: mozilla -- code execution via javascript: IconURL > vulnerability. > Reference: > b08fc24.html> > > Affected package: kdelibs-3.4.0_1 > Type of problem: kdelibs -- kimgio input validation errors. > Reference: > 20eed82.html> > > 4 problem(s) in your installed packages found. > > You are advised to update or deinstall the affected package(s) > immediately. freebsd # > > If I try to replace kdelibs with a binary package, or install it > through ports (after doing a cvsup), I still get verion 3.4.0_1. You are doing something fundamentaly wrong. The latest /usr/ports/INDEX[-5] shows a kdelibs-3.4.0_4. How did you cvsup and did you update the INDEX files? Kent > > Are fixes not necessarily made available when security > vulnerabilities are found? > > Also -- is there a similar utility to portaudit and freebsd-update, > that can be used on the base operating system (not through ports)? > _______________________________________________ > freebsd-questions@freebsd.org mailing list > http://lists.freebsd.org/mailman/listinfo/freebsd-questions > To unsubscribe, send any mail to > "freebsd-questions-unsubscribe@freebsd.org" -- Kent Stewart Richland, WA http://users.owt.com/kstewart/index.html