From owner-dev-commits-ports-all@freebsd.org Fri Jun 11 17:26:55 2021 Return-Path: Delivered-To: dev-commits-ports-all@mailman.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.nyi.freebsd.org (Postfix) with ESMTP id F341B662012; Fri, 11 Jun 2021 17:26:54 +0000 (UTC) (envelope-from thierry@pompo.net) Received: from edna.lautre.net (edna.lautre.net [80.67.160.88]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "lautre.net", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4G1np65ly2z3wRc; Fri, 11 Jun 2021 17:26:54 +0000 (UTC) (envelope-from thierry@pompo.net) Received: from graf.pompo.net (graf.pompo.net [82.66.0.218]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by edna.lautre.net (Postfix) with ESMTPSA id B2A00101C11; Fri, 11 Jun 2021 19:26:46 +0200 (CEST) Received: by graf.pompo.net (Postfix, from userid 1001) id 5F18D309246; Fri, 11 Jun 2021 19:26:46 +0200 (CEST) Date: Fri, 11 Jun 2021 19:26:46 +0200 From: Thierry Thomas To: Dan Langille Cc: "ports-committers@freebsd.org" , "dev-commits-ports-all@freebsd.org" , "dev-commits-ports-main@freebsd.org" Subject: Re: git: 0605ef1bd0c2 - main - graphics/ImageMagick6: upgrade to 6.9.12-12 Message-ID: Mail-Followup-To: Dan Langille , "ports-committers@freebsd.org" , "dev-commits-ports-all@freebsd.org" , "dev-commits-ports-main@freebsd.org" References: <202105272056.14RKuNKf097784@gitrepo.freebsd.org> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="T0JI6v8mJh8/lULE" Content-Disposition: inline In-Reply-To: X-Operating-System: FreeBSD 13.0-STABLE amd64 Organization: Kabbale Eros X-Face: (hRbQnK~Pt7$ct`!fupO(`y_WL4^-Iwn4@ly-.,[4xC4xc; y=\ipKMNm<1J>lv@PP~7Z<.tKjAnXLs: X-PGP: 0xF1C516B3C8359753 X-Rspamd-Queue-Id: 4G1np65ly2z3wRc X-Spamd-Bar: ---- Authentication-Results: mx1.freebsd.org; none X-Spamd-Result: default: False [-4.00 / 15.00]; REPLY(-4.00)[] X-BeenThere: dev-commits-ports-all@freebsd.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: Commit messages for all branches of the ports repository List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 11 Jun 2021 17:26:55 -0000 --T0JI6v8mJh8/lULE Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Le ven. 11 juin 21 =C3=A0 18:48:18 +0200, Dan Langille =C3=A9crivait=C2=A0: > > Note: this might fix some vulnerabilities, e.g. CVE-2021-20244, > > CVE-2021-20243, CVE-2021-20176 or CVE-2020-27829, but this is not cl= ear > > for me. > >=20 > > PR: 255818 > > Approved by: maintainer=E2=80=99s time-out >=20 > This was a vuln fix and not backported to 2021Q2? >=20 > Is there any reason I should not do that backport now? Yes, please! I sent a mail to ports-secteam@ and to the maintainer, but did not get any answer, and then I forgot about it=E2=80=A6 --=20 Th. Thomas. --T0JI6v8mJh8/lULE Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQJ8BAEBCgBmBQJgw5zWXxSAAAAAAC4AKGlzc3Vlci1mcHJAbm90YXRpb25zLm9w ZW5wZ3AuZmlmdGhob3JzZW1hbi5uZXRFNTM2QkU4NTM4NTM5OUQwMEI2RkFBNzZG MUM1MTZCM0M4MzU5NzUzAAoJEPHFFrPINZdTPycQAIXRdO/zbLdjWAIdWy56OANH hsFxGHkdQ1DH1UygpH9gMQj+HIq/IbKMCOWAPgHqwkmSgkdrNikp1CVBXm7jGbDc LX8dmZIeT9deDS7mqOXzogN1nZaBF0kwuaRsCZ2wdb63sXLK2ganIG8BcJFP2MFy f5bIZxORpaMiUx4gvVzYv14/zQRQLvMyLkHaHRPeZUKaTW5Y50vbAZ4Ckyw7ayt1 06KUZJqL4K6jrA1v3CWKW/allN7xfWRHDCfwGfvsJzE71a1CuOiJhbW/Ly1k4u9k aOePrIdY4+256/pqFBCeeorBN+N4rDSHx/es3VHPbHzY6aX2yHiDCj5sRhtZRHdM YaMPj0N6z7YVdp/Jxkla44oP3fVoJVL9xgIacpIKCQwKBEku4CzDVOnZ39Is5EH4 nSDM0MgFtw7skMyPCD6ebrkTSTOo8HAxrM0SJd45Lr1pU/ugsollyztgEBmbNtDn +gV2YaUAZB4M/bJlFPHvOdXA1AiGVIZNNWLuRMsjQ4J6/4JVl4O937e9flzOFntT Iy0C89+Pinjx4eqJITspq0LEVyRidl1Y5bK30tl4UECtEf3fscIQMPa0kGIiURik nACHiBWpinw9H+Ebe6ft8wF/3JppJ0Fr1wVdhcF5yS5jEFfH7h6/HWe4jC56H0r7 nLrhWw0GmHg2jT1LWrHc =FpDc -----END PGP SIGNATURE----- --T0JI6v8mJh8/lULE--