From owner-freebsd-python@freebsd.org Mon Nov 30 01:26:30 2020 Return-Path: Delivered-To: freebsd-python@mailman.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.nyi.freebsd.org (Postfix) with ESMTP id 7EDCB46B017 for ; Mon, 30 Nov 2020 01:26:30 +0000 (UTC) (envelope-from koobs.freebsd@gmail.com) Received: from mailman.nyi.freebsd.org (mailman.nyi.freebsd.org [IPv6:2610:1c1:1:606c::50:13]) by mx1.freebsd.org (Postfix) with ESMTP id 4Cknd21zm4z3vQR for ; Mon, 30 Nov 2020 01:26:30 +0000 (UTC) (envelope-from koobs.freebsd@gmail.com) Received: by mailman.nyi.freebsd.org (Postfix) id 43F9C46AEC4; Mon, 30 Nov 2020 01:26:30 +0000 (UTC) Delivered-To: python@mailman.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.nyi.freebsd.org (Postfix) with ESMTP id 4299B46AEC3; Mon, 30 Nov 2020 01:26:30 +0000 (UTC) (envelope-from koobs.freebsd@gmail.com) Received: from mail-pj1-x1030.google.com (mail-pj1-x1030.google.com [IPv6:2607:f8b0:4864:20::1030]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (2048 bits) client-digest SHA256) (Client CN "smtp.gmail.com", Issuer "GTS CA 1O1" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4Cknd10Z1nz3vQQ; Mon, 30 Nov 2020 01:26:28 +0000 (UTC) (envelope-from koobs.freebsd@gmail.com) Received: by mail-pj1-x1030.google.com with SMTP id ms7so285000pjb.4; Sun, 29 Nov 2020 17:26:28 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=sender:reply-to:subject:to:references:from:message-id:date :user-agent:mime-version:in-reply-to:content-language :content-transfer-encoding; bh=xM6UwPhwbnfn91ZNZAsLvLsOT0FUIvpfFgSavdNxRr0=; b=I6m4y4ZSLqSV/7zZF1oyF69448NsjXMCWRI+XNx9fUAuYmlot/xT14FquBNUWcc8RR 4GD9TRB/go810mn09zPpJjx4FVPwk2YeP+td5SMkA8fd4El+cKqL6OV9yAJwhmiEJ/pE VFMrgbmJOLvn2wza0nRu6hixGJdSsirORiZVCRxnjPWjY7g091fE6M886erDfxt1aLew k1yHJlI+mvgoxqY5hoDQ08GFsIa+kc+5V9Ncpckz1m5LCqUCC0pRpnPYVI2lwVJj2/vu LBbQcmqDSBcXqonk4gWNfg9c0xJtIhjqdv+ABvZhvzRPOUG5VsVPmCeuPfnJPlL3j3f1 OoxA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:sender:reply-to:subject:to:references:from :message-id:date:user-agent:mime-version:in-reply-to :content-language:content-transfer-encoding; bh=xM6UwPhwbnfn91ZNZAsLvLsOT0FUIvpfFgSavdNxRr0=; b=D+6G5M0uyI3XoB+gjXfGBXZoc/Ti/gJApF5wPMFW2sHKBvCJojb7twdXytkFbjrD/o 7EUW7b4bl6tRW94RCuj7ef8CayWR1CZn+9uIA0/Podc0Ca4D3B4XJCCyy6p6vLB3v+F1 84n5u+n5hEl/YLh6wq4ExSUlFQR4XfaJFnvlWDeKLVhWIZ46ePGzUm30VDn6HF8rE+Sz mQ4xQlS/raT8Vln2S3iLBbg3A5y2J6hc1YqiejT/lemN1MmOFZNlmj/598mfYeCyTKQk YLrtm4Lw0tncTiRpzPF0cUXoKOA/bjTiwFi3hTzAOcYAMax9Hyee+Sf+uAlzMg9/XHf5 i8Vw== X-Gm-Message-State: AOAM533n6dxRO0Jninb9Iq4v4jxJZ2gs0euZ3RhNMaieLSWq8XzXBuVn eH365AdBbN2Fk2W05MuPZ9Ofgp7fKfw= X-Google-Smtp-Source: ABdhPJzRPVv8AqRqfHVDIXsMIzwE6TfCxeD8HmNiGJ67QkP8ocfYNJDrtNwZJVNhpXwpfdCYlfnB7w== X-Received: by 2002:a17:90a:62c4:: with SMTP id k4mr23486125pjs.32.1606699587303; Sun, 29 Nov 2020 17:26:27 -0800 (PST) Received: from [192.168.1.100] (180-150-68-130.b49644.syd.nbn.aussiebb.net. [180.150.68.130]) by smtp.gmail.com with UTF8SMTPSA id l76sm14920706pfd.82.2020.11.29.17.26.25 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Sun, 29 Nov 2020 17:26:26 -0800 (PST) Sender: Kubilay Kocak Reply-To: koobs@FreeBSD.org Subject: Re: Moinmoin To: Roger Marquis , freebsd-security@freebsd.org, python References: <8o206235-597-p266-o7s-oqn87s1np279@mx.roble.com> From: Kubilay Kocak Message-ID: Date: Mon, 30 Nov 2020 12:26:23 +1100 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:84.0) Gecko/20100101 Thunderbird/84.0 MIME-Version: 1.0 In-Reply-To: <8o206235-597-p266-o7s-oqn87s1np279@mx.roble.com> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Language: en-US Content-Transfer-Encoding: 8bit X-Rspamd-Queue-Id: 4Cknd10Z1nz3vQQ X-Spamd-Bar: --- Authentication-Results: mx1.freebsd.org; dkim=pass header.d=gmail.com header.s=20161025 header.b=I6m4y4ZS; dmarc=none; spf=pass (mx1.freebsd.org: domain of koobsfreebsd@gmail.com designates 2607:f8b0:4864:20::1030 as permitted sender) smtp.mailfrom=koobsfreebsd@gmail.com X-Spamd-Result: default: False [-3.20 / 15.00]; HAS_REPLYTO(0.00)[koobs@FreeBSD.org]; TO_DN_SOME(0.00)[]; R_SPF_ALLOW(-0.20)[+ip6:2607:f8b0:4000::/36]; REPLYTO_ADDR_EQ_FROM(0.00)[]; RCVD_COUNT_THREE(0.00)[3]; DKIM_TRACE(0.00)[gmail.com:+]; NEURAL_HAM_SHORT(-1.00)[-1.000]; FORGED_SENDER(0.30)[koobs@FreeBSD.org,koobsfreebsd@gmail.com]; RCVD_TLS_LAST(0.00)[]; RBL_DBL_DONT_QUERY_IPS(0.00)[2607:f8b0:4864:20::1030:from]; FREEMAIL_ENVFROM(0.00)[gmail.com]; MID_RHS_MATCH_FROM(0.00)[]; TAGGED_FROM(0.00)[]; ASN(0.00)[asn:15169, ipnet:2607:f8b0::/32, country:US]; ARC_NA(0.00)[]; NEURAL_HAM_MEDIUM(-1.00)[-1.000]; R_DKIM_ALLOW(-0.20)[gmail.com:s=20161025]; FROM_NEQ_ENVFROM(0.00)[koobs@FreeBSD.org,koobsfreebsd@gmail.com]; FROM_HAS_DN(0.00)[]; RCPT_COUNT_THREE(0.00)[3]; NEURAL_HAM_LONG(-1.00)[-1.000]; MIME_GOOD(-0.10)[text/plain]; DMARC_NA(0.00)[FreeBSD.org]; SPAMHAUS_ZRD(0.00)[2607:f8b0:4864:20::1030:from:127.0.2.255]; TO_MATCH_ENVRCPT_SOME(0.00)[]; RCVD_IN_DNSWL_NONE(0.00)[2607:f8b0:4864:20::1030:from]; MIME_TRACE(0.00)[0:+]; MAILMAN_DEST(0.00)[python,freebsd-security] X-BeenThere: freebsd-python@freebsd.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: FreeBSD-specific Python issues List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 30 Nov 2020 01:26:30 -0000 On 28/11/2020 12:55 pm, Roger Marquis wrote: > Anyone know if www/moinmoin is abandonware?  The maintainer is listed as > python@freebsd.org and the version in ports has had an unpatched > vulnerability for the last couple of weeks. > Hi Roger, I don't believe so, but development is slow Can you point us to references for the vulnerability and/or any other references (cve, anouncements, commits, issues, patches in other OS's, etc) ./koobs