From owner-freebsd-ports-bugs@FreeBSD.ORG  Fri Mar  2 20:00:13 2007
Return-Path: <owner-freebsd-ports-bugs@FreeBSD.ORG>
X-Original-To: freebsd-ports-bugs@hub.freebsd.org
Delivered-To: freebsd-ports-bugs@hub.freebsd.org
Received: from mx1.freebsd.org (mx1.freebsd.org [69.147.83.52])
	by hub.freebsd.org (Postfix) with ESMTP id 69D3516A407
	for <freebsd-ports-bugs@hub.freebsd.org>;
	Fri,  2 Mar 2007 20:00:13 +0000 (UTC)
	(envelope-from gnats@FreeBSD.org)
Received: from freefall.freebsd.org (freefall.freebsd.org [69.147.83.40])
	by mx1.freebsd.org (Postfix) with ESMTP id 38A2A13C4A3
	for <freebsd-ports-bugs@hub.freebsd.org>;
	Fri,  2 Mar 2007 20:00:13 +0000 (UTC)
	(envelope-from gnats@FreeBSD.org)
Received: from freefall.freebsd.org (gnats@localhost [127.0.0.1])
	by freefall.freebsd.org (8.13.4/8.13.4) with ESMTP id l22K0DLZ059819
	for <freebsd-ports-bugs@freefall.freebsd.org>;
	Fri, 2 Mar 2007 20:00:13 GMT
	(envelope-from gnats@freefall.freebsd.org)
Received: (from gnats@localhost)
	by freefall.freebsd.org (8.13.4/8.13.4/Submit) id l22K0CLR059815;
	Fri, 2 Mar 2007 20:00:12 GMT (envelope-from gnats)
Resent-Date: Fri, 2 Mar 2007 20:00:12 GMT
Resent-Message-Id: <200703022000.l22K0CLR059815@freefall.freebsd.org>
Resent-From: FreeBSD-gnats-submit@FreeBSD.org (GNATS Filer)
Resent-To: freebsd-ports-bugs@FreeBSD.org
Resent-Reply-To: FreeBSD-gnats-submit@FreeBSD.org,
	Martin Matuska <martin@matuska.org>
Received: from mx1.freebsd.org (mx1.freebsd.org [69.147.83.52])
	by hub.freebsd.org (Postfix) with ESMTP id 3CED116A403
	for <FreeBSD-gnats-submit@freebsd.org>;
	Fri,  2 Mar 2007 19:57:17 +0000 (UTC)
	(envelope-from rebum@mail.vx.sk)
Received: from mail.vx.sk (neo.vx.sk [88.198.35.14])
	by mx1.freebsd.org (Postfix) with ESMTP id 0554B13C491
	for <FreeBSD-gnats-submit@freebsd.org>;
	Fri,  2 Mar 2007 19:57:16 +0000 (UTC)
	(envelope-from rebum@mail.vx.sk)
Received: from localhost (localhost [127.0.0.1])
	by mail.vx.sk (Postfix) with ESMTP id 765D93F42A
	for <FreeBSD-gnats-submit@freebsd.org>;
	Fri,  2 Mar 2007 20:57:15 +0100 (CET)
Received: from mail.vx.sk ([127.0.0.1])
	by localhost (mail.vx.sk [127.0.0.1]) (amavisd-new, port 10024)
	with LMTP id uC00pmHWHWrj for <FreeBSD-gnats-submit@freebsd.org>;
	Fri,  2 Mar 2007 20:57:12 +0100 (CET)
Received: by mail.vx.sk (Postfix, from userid 1001)
	id 756563F431; Fri,  2 Mar 2007 20:57:12 +0100 (CET)
Message-Id: <20070302195712.756563F431@mail.vx.sk>
Date: Fri,  2 Mar 2007 20:57:12 +0100 (CET)
From: Martin Matuska <martin@matuska.org>
To: FreeBSD-gnats-submit@FreeBSD.org
X-Send-Pr-Version: 3.113
Cc: 
Subject: ports/109766: [PATCH] security/amavisd-new bugfix
X-BeenThere: freebsd-ports-bugs@freebsd.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Ports bug reports <freebsd-ports-bugs.freebsd.org>
List-Unsubscribe: <http://lists.freebsd.org/mailman/listinfo/freebsd-ports-bugs>, 
	<mailto:freebsd-ports-bugs-request@freebsd.org?subject=unsubscribe>
List-Archive: <http://lists.freebsd.org/pipermail/freebsd-ports-bugs>
List-Post: <mailto:freebsd-ports-bugs@freebsd.org>
List-Help: <mailto:freebsd-ports-bugs-request@freebsd.org?subject=help>
List-Subscribe: <http://lists.freebsd.org/mailman/listinfo/freebsd-ports-bugs>, 
	<mailto:freebsd-ports-bugs-request@freebsd.org?subject=subscribe>
X-List-Received-Date: Fri, 02 Mar 2007 20:00:13 -0000


>Number:         109766
>Category:       ports
>Synopsis:       [PATCH] security/amavisd-new bugfix
>Confidential:   no
>Severity:       non-critical
>Priority:       medium
>Responsible:    freebsd-ports-bugs
>State:          open
>Quarter:        
>Keywords:       
>Date-Required:
>Class:          change-request
>Submitter-Id:   current-users
>Arrival-Date:   Fri Mar 02 20:00:12 GMT 2007
>Closed-Date:
>Last-Modified:
>Originator:     Martin Matuska
>Release:        FreeBSD 6.2-RELEASE
>Organization:
>Environment:
System: FreeBSD 6.2-RELEASE i386 and amd64
>Description:
sbin/amavisd uses the 'file' utility.
Path to this utility is specified in sbin/amavisd as 'file'. 
This can be dangerous as it is searched in all of PATH.

The patch fixes this by replacing 'file' with 
contents of ${FILE} from bsd.port.mk.
>How-To-Repeat:
>Fix:
diff -Nbur security/amavisd-new.orig/Makefile security/amavisd-new/Makefile
--- security/amavisd-new.orig/Makefile	Fri Mar  2 20:38:46 2007
+++ security/amavisd-new/Makefile	Fri Mar  2 20:43:08 2007
@@ -210,7 +210,8 @@
 	@${REINPLACE_CMD} "s|/var/amavis/db|${AMAVISDIR}/db|" ${WRKSRC}/amavisd-nanny
 	@${REINPLACE_CMD} "s|#define HAVE_MKTEMP|#undef HAVE_MKTEMP|" \
 			${WRKSRC}/helper-progs/config.h.in
-	@${REINPLACE_CMD} "s|/etc/amavisd.conf|${PREFIX}/etc/amavisd.conf|" \
+	@${REINPLACE_CMD} -e "s|/etc/amavisd.conf|${PREFIX}/etc/amavisd.conf|" \
+			-e "s|\$$file = 'file'|\$$file = '${FILE}'|" \
 			${WRKSRC}/amavisd
 
 .if defined(AMAVIS_NOAMAVIS)
>Release-Note:
>Audit-Trail:
>Unformatted: