From owner-freebsd-security@freebsd.org Wed Nov 22 03:50:27 2017 Return-Path: Delivered-To: freebsd-security@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id EA014DDDF6B for ; Wed, 22 Nov 2017 03:50:27 +0000 (UTC) (envelope-from list_freebsd@bluerosetech.com) Received: from echo.brtsvcs.net (echo.brtsvcs.net [208.111.40.118]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id D7A586A43C for ; Wed, 22 Nov 2017 03:50:27 +0000 (UTC) (envelope-from list_freebsd@bluerosetech.com) Received: from chombo.houseloki.net (c-73-240-250-185.hsd1.or.comcast.net [73.240.250.185]) by echo.brtsvcs.net (Postfix) with ESMTPS id 1E2BC38F89; Tue, 21 Nov 2017 19:50:27 -0800 (PST) Received: from [IPv6:fe80::4055:e8ed:3d40:2f96] (unknown [IPv6:fe80::4055:e8ed:3d40:2f96]) by chombo.houseloki.net (Postfix) with ESMTPSA id 34588BE0; Tue, 21 Nov 2017 19:50:25 -0800 (PST) Subject: Re: Why no update of base/ports openssl for recent CVEs? To: Robert Simmons , freebsd-security@freebsd.org References: <9a41694c-fffb-e58c-5946-abbc99160fb4@bluerosetech.com> From: Mel Pilgrim Message-ID: <9ebd9468-7c26-de75-79ea-5a8829399d51@bluerosetech.com> Date: Tue, 21 Nov 2017 19:50:11 -0800 User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Thunderbird/52.4.0 MIME-Version: 1.0 In-Reply-To: Content-Type: text/plain; charset=utf-8; format=flowed Content-Language: en-US Content-Transfer-Encoding: 7bit X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.25 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 22 Nov 2017 03:50:28 -0000 On 2017-11-21 17:11, Robert Simmons wrote: > I don't have an answer for base, but I think if you just update your ports > tree, you will see the update to 1.0.2m was committed on Nov 2nd (2 weeks > and 5 days ago): > https://svnweb.freebsd.org/ports?view=revision&revision=453380 That explains ports: it was never merged to quarterly. Submitted ports/223797 to ask for MFH to 2017Q4.