From owner-freebsd-ports@FreeBSD.ORG Thu Aug 5 01:59:16 2004 Return-Path: Delivered-To: freebsd-ports@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id A08B016A4CE for ; Thu, 5 Aug 2004 01:59:16 +0000 (GMT) Received: from nagual.pp.ru (pobrecita.freebsd.ru [194.87.13.42]) by mx1.FreeBSD.org (Postfix) with ESMTP id EC11743D1D for ; Thu, 5 Aug 2004 01:59:15 +0000 (GMT) (envelope-from ache@pobrecita.freebsd.ru) Received: from pobrecita.freebsd.ru (ache@localhost [127.0.0.1]) by nagual.pp.ru (8.13.1/8.13.1) with ESMTP id i751xBI7027718; Thu, 5 Aug 2004 05:59:11 +0400 (MSD) (envelope-from ache@pobrecita.freebsd.ru) Received: (from ache@localhost) by pobrecita.freebsd.ru (8.13.1/8.13.1/Submit) id i751x60N027716; Thu, 5 Aug 2004 05:59:06 +0400 (MSD) (envelope-from ache) Date: Thu, 5 Aug 2004 05:59:05 +0400 From: Andrey Chernov To: Charles Swiger Message-ID: <20040805015904.GA27667@nagual.pp.ru> Mail-Followup-To: Andrey Chernov , Charles Swiger , Fernan Aguero , FreeBSD Ports References: <20040804190855.GA69872@iib.unsam.edu.ar> <2E7293C8-E656-11D8-91D1-003065ABFD92@mac.com> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <2E7293C8-E656-11D8-91D1-003065ABFD92@mac.com> User-Agent: Mutt/1.5.6i X-AntiVirus: checked by AntiVir Milter 1.1-beta; AVE 6.26.0.10; VDF 6.26.0.60 (host: pobrecita.freebsd.ru) cc: FreeBSD Ports Subject: Re: update vulnerable libpng to fixed version? X-BeenThere: freebsd-ports@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Porting software to FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 05 Aug 2004 01:59:16 -0000 On Wed, Aug 04, 2004 at 04:38:02PM -0400, Charles Swiger wrote: > On Aug 4, 2004, at 3:08 PM, Fernan Aguero wrote: > >according to this tech report > >http://www.us-cert.gov/cas/techalerts/TA04-217A.html > >there are a number of vulnerabilities in libpng that are > >fixed in 1.2.6rc1 > > > >is an update of the port being worked on? I'm eager to do a > >'portupgrade -r png'. > > Here's a diff which updates the png port to 1.2.6rc1: We can't make public what is intentionally non-public, from libpng-1.2.6rc1-README.txt: Libpng 1.2.6rc1 - August 4, 2004 This is not intended to be a public release. It will be replaced within a few weeks by a public version or by another test version. -- Andrey Chernov | http://ache.pp.ru/