From owner-freebsd-ports@FreeBSD.ORG Thu Dec 7 00:26:44 2006 Return-Path: X-Original-To: freebsd-ports@freebsd.org Delivered-To: freebsd-ports@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [69.147.83.52]) by hub.freebsd.org (Postfix) with ESMTP id 06B5416A416 for ; Thu, 7 Dec 2006 00:26:44 +0000 (UTC) (envelope-from freebsd-ports@m.gmane.org) Received: from ciao.gmane.org (main.gmane.org [80.91.229.2]) by mx1.FreeBSD.org (Postfix) with ESMTP id BC96643CAE for ; Thu, 7 Dec 2006 00:25:51 +0000 (GMT) (envelope-from freebsd-ports@m.gmane.org) Received: from list by ciao.gmane.org with local (Exim 4.43) id 1Gs75i-0003O2-30 for freebsd-ports@freebsd.org; Thu, 07 Dec 2006 01:26:22 +0100 Received: from r5h168.net.upc.cz ([86.49.7.168]) by main.gmane.org with esmtp (Gmexim 0.1 (Debian)) id 1AlnuQ-0007hv-00 for ; Thu, 07 Dec 2006 01:26:22 +0100 Received: from gamato by r5h168.net.upc.cz with local (Gmexim 0.1 (Debian)) id 1AlnuQ-0007hv-00 for ; Thu, 07 Dec 2006 01:26:22 +0100 X-Injected-Via-Gmane: http://gmane.org/ To: freebsd-ports@freebsd.org From: martinko Date: Thu, 07 Dec 2006 01:26:08 +0100 Lines: 42 Message-ID: <45775FA0.7020206@users.sf.net> References: <20061206233232.GA72778@xor.obsecurity.org> Mime-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-2 Content-Transfer-Encoding: 7bit X-Complaints-To: usenet@sea.gmane.org X-Gmane-NNTP-Posting-Host: r5h168.net.upc.cz User-Agent: Mozilla/5.0 (X11; U; FreeBSD i386; en-US; rv:1.8.0.8) Gecko/20061111 SeaMonkey/1.0.6 In-Reply-To: <20061206233232.GA72778@xor.obsecurity.org> Sender: news Cc: freebsd-questions@freebsd.org Subject: Re: portupgrade refusin to upgrade a port .. when it shouldn't imho X-BeenThere: freebsd-ports@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Porting software to FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 07 Dec 2006 00:26:44 -0000 Kris Kennaway wrote: > On Wed, Dec 06, 2006 at 10:55:40PM +0100, martinko wrote: >> Hello, >> >> According to freshports.org the newest multimedia/win32-codecs port >> (3.1.0.r1,1) is not vulnerable. I'm trying to upgrade version >> win32-codecs-3.1.0.p8,1 on my system but portupgrade + portaudit refuse >> me to do so: >> >> ** Port marked as IGNORE: multimedia/win32-codecs: >> is forbidden: Remote code execution: >> http://vuxml.FreeBSD.org/24f6b1eb-43d5-11db-81e1-000e0c2e438a.html >> >> Isn't this behaviour flawed ?? Or am I missing something ? > > Did you update your portaudit database? > > Kris Sure thing: mb-aw1n-bsd[/root]# portaudit -Fda New database installed. Database created: Thu Dec 7 01:10:04 CET 2006 Affected package: win32-codecs-3.1.0.p8,1 Type of problem: win32-codecs -- multiple vulnerabilities. Reference: 1 problem(s) in your installed packages found. You are advised to update or deinstall the affected package(s) immediately. mb-aw1n-bsd[/root]# portupgrade -if win32-codecs ---> Session started at: Thu, 07 Dec 2006 01:24:42 +0100 ** Port marked as IGNORE: multimedia/win32-codecs: is forbidden: Remote code execution: http://vuxml.FreeBSD.org/24f6b1eb-43d5-11db-81e1-000e0c2e438a.html ---> ** Upgrade tasks 1: 0 done, 1 ignored, 0 skipped and 0 failed ---> Listing the results (+:done / -:ignored / *:skipped / !:failed) - multimedia/win32-codecs (win32-codecs-3.1.0.p8,1) ---> Packages processed: 0 done, 1 ignored, 0 skipped and 0 failed ---> Session ended at: Thu, 07 Dec 2006 01:24:43 +0100 (consumed 00:00:01)