From owner-freebsd-vuxml@FreeBSD.ORG Mon Sep 13 20:28:40 2004 Return-Path: Delivered-To: freebsd-vuxml@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 5C59C16A4CE for ; Mon, 13 Sep 2004 20:28:40 +0000 (GMT) Received: from gw.celabo.org (gw.celabo.org [208.42.49.153]) by mx1.FreeBSD.org (Postfix) with ESMTP id 0DA0F43D1D for ; Mon, 13 Sep 2004 20:28:40 +0000 (GMT) (envelope-from nectar@celabo.org) Received: from localhost (localhost [127.0.0.1]) by gw.celabo.org (Postfix) with ESMTP id 90F615486E; Mon, 13 Sep 2004 15:28:39 -0500 (CDT) Received: from gw.celabo.org ([127.0.0.1]) by localhost (hellblazer.celabo.org [127.0.0.1]) (amavisd-new, port 10024) with SMTP id 42824-05; Mon, 13 Sep 2004 15:28:29 -0500 (CDT) Received: from madman.celabo.org (madman.celabo.org [10.0.1.111]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client CN "madman.celabo.org", Issuer "celabo.org CA" (not verified)) by gw.celabo.org (Postfix) with ESMTP id 03B7A54861; Mon, 13 Sep 2004 15:28:29 -0500 (CDT) Received: by madman.celabo.org (Postfix, from userid 1001) id CF3AE6D465; Mon, 13 Sep 2004 15:28:20 -0500 (CDT) Date: Mon, 13 Sep 2004 15:28:20 -0500 From: "Jacques A. Vidrine" To: Dan Langille Message-ID: <20040913202820.GC73780@madman.celabo.org> Mail-Followup-To: "Jacques A. Vidrine" , Dan Langille , freebsd-vuxml@freebsd.org References: <20040913123610.G22240@xeon.unixathome.org> <20040913174748.GC71191@madman.celabo.org> <20040913135431.F22240@xeon.unixathome.org> <20040913183627.GG71191@madman.celabo.org> <20040913144103.U22240@xeon.unixathome.org> <20040913190509.GK71191@madman.celabo.org> <20040913160315.C22240@xeon.unixathome.org> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20040913160315.C22240@xeon.unixathome.org> X-Url: http://www.celabo.org/ User-Agent: Mutt/1.5.6i cc: freebsd-vuxml@freebsd.org Subject: Re: Matching a name to a port X-BeenThere: freebsd-vuxml@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Documenting security issues in VuXML List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 13 Sep 2004 20:28:40 -0000 On Mon, Sep 13, 2004 at 04:21:01PM -0400, Dan Langille wrote: > On Mon, 13 Sep 2004, Jacques A. Vidrine wrote: > > > On Mon, Sep 13, 2004 at 02:56:10PM -0400, Dan Langille wrote: > > > FreshPorts knows nothing about ImageMagick-nox11 because there is no such > > > port. It knows only about ImageMagick, against which commits are made. > > > > > > Proposed approach for FreshPorts: I think FreshPorts will ignore package > > > entries for which it cannot find a corresponding port. If all packages > > > for a vuln fail to relate to a port, that will be something which > > > justifies further investigation. > > > > I think that is a reasonable approach. > > FYI, I just realised that FreshPorts can only determine the > ${PKGNAMEPREFIX}${PORTNAME}${PKGNAMESUFFIX} for existing ports. This will > exclude ports which have been deleted. Those values aren't easy to grab. Right, thus my several allusions to a non-existent "package name history" database. :-) Cheers, -- Jacques Vidrine / nectar@celabo.org / jvidrine@verio.net / nectar@freebsd.org