Date: Thu, 07 Oct 2010 22:02:09 +0100 From: Matthew Seaman <m.seaman@infracaninophile.co.uk> To: Harlan Stenn <stenn@ntp.org> Cc: ports@freebsd.org Subject: Re: horde-base? Message-ID: <4CAE3551.3070404@infracaninophile.co.uk> In-Reply-To: <201010072047.o97KlYOR030025@stenn.ntp.org> References: <201010072047.o97KlYOR030025@stenn.ntp.org>
next in thread | previous in thread | raw e-mail | index | archive | help
This is an OpenPGP/MIME signed message (RFC 2440 and 3156) --------------enig11A49E1B46F69B08A31D149D Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable On 07/10/2010 21:47:34, Harlan Stenn wrote: > Hi, >=20 > I've seen the security alert for the current horde-base (3.3.8) port. >=20 > It looks like 3.3.9 was released just over a week ago, and the release > notes seem to indicate it fixes the security problems. >=20 > I also see http://www.freebsd.org/cgi/query-pr.cgi?pr=3Dports/151191, b= ut > I have no idea if that patch will actually fix the problem or not, or > when that PR will be resolved. >=20 > Should I just wait quietly, or is there a minimally-intrusive way I > could figure out the timeline on these things? >=20 Hmmmm... that PR doesn't really help itself much. It would receive more attention if it mentioned the magic word "security" in the subject line. Even better would be to CC it to sec-team@...[*] Best of all though would be both of the above plus being sent as a maintainer-update. Unfortunately it seems the horde apps are without a Maintainer at the moment. Cheers, Matthew [*] This isn't intended as a criticism of the person generating the PR -- looks like they are writing in what to them is a foreign language, and they've done a lot better than I would if I had to try and write in their language. --=20 Dr Matthew J Seaman MA, D.Phil. 7 Priory Courtyard Flat 3 PGP: http://www.infracaninophile.co.uk/pgpkey Ramsgate JID: matthew@infracaninophile.co.uk Kent, CT11 9PW --------------enig11A49E1B46F69B08A31D149D Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" -----BEGIN PGP SIGNATURE----- Version: GnuPG/MacGPG2 v2.0.14 (Darwin) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/ iEYEARECAAYFAkyuNVkACgkQ8Mjk52CukIyJfgCfaJAa/jLG3EFmhOkGsCTnsPFG QPQAni1wkRqqi1KaT/cMi9P6cpV98BkO =4f/k -----END PGP SIGNATURE----- --------------enig11A49E1B46F69B08A31D149D--
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?4CAE3551.3070404>