From owner-freebsd-ports-bugs Thu Mar 20 14:40:29 2003 Delivered-To: freebsd-ports-bugs@hub.freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id D496137B401 for ; Thu, 20 Mar 2003 14:40:16 -0800 (PST) Received: from freefall.freebsd.org (freefall.freebsd.org [216.136.204.21]) by mx1.FreeBSD.org (Postfix) with ESMTP id 255CA43FBF for ; Thu, 20 Mar 2003 14:40:13 -0800 (PST) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (gnats@localhost [127.0.0.1]) by freefall.freebsd.org (8.12.6/8.12.6) with ESMTP id h2KMeDNS043379 for ; Thu, 20 Mar 2003 14:40:13 -0800 (PST) (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.12.6/8.12.6/Submit) id h2KMeDpp043378; Thu, 20 Mar 2003 14:40:13 -0800 (PST) Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id B5F2937B401; Thu, 20 Mar 2003 14:35:46 -0800 (PST) Received: from thoth.sbs.de (thoth.sbs.de [192.35.17.2]) by mx1.FreeBSD.org (Postfix) with ESMTP id A326E43FB1; Thu, 20 Mar 2003 14:35:44 -0800 (PST) (envelope-from udo.schweigert@siemens.com) Received: from mail1.siemens.de (mail1.siemens.de [139.23.33.14]) by thoth.sbs.de (8.11.6/8.11.6) with ESMTP id h2KMZhX27722; Thu, 20 Mar 2003 23:35:43 +0100 (MET) Received: from mars.cert.siemens.de (ust.mchp.siemens.de [139.23.201.17]) by mail1.siemens.de (8.11.6/8.11.6) with ESMTP id h2KMZhX21333; Thu, 20 Mar 2003 23:35:43 +0100 (MET) Received: from alaska.cert.siemens.de (alaska.cert.siemens.de [139.23.202.134]) by mars.cert.siemens.de (8.12.8/8.12.8/$SiemensCERT: mail/cert.mc,v 1.42 2003/02/21 12:06:56 ust Exp $) with ESMTP id h2KMZhbL085525; Thu, 20 Mar 2003 23:35:43 +0100 (CET) Received: from alaska.cert.siemens.de (alaska.cert.siemens.de [127.0.0.1]) by alaska.cert.siemens.de (8.12.8/8.12.8/$Ust: hosts/alaska/mail/config.mc,v 1.15 2002/12/31 15:32:17 ust Exp $) with ESMTP id h2KMZhks082372; Thu, 20 Mar 2003 23:35:43 +0100 (CET) (envelope-from ust@alaska.cert.siemens.de) Received: (from ust@localhost) by alaska.cert.siemens.de (8.12.8/8.12.8/$Ust: hosts/alaska/mail/submit.mc,v 1.4 2002/12/31 15:32:17 ust Exp $) id h2KMZhsV099184; Thu, 20 Mar 2003 23:35:43 +0100 (CET) (envelope-from ust) Message-Id: <200303202235.h2KMZhsV099184@alaska.cert.siemens.de> Date: Thu, 20 Mar 2003 23:35:43 +0100 (CET) From: Udo Schweigert Reply-To: Udo Schweigert To: FreeBSD-gnats-submit@FreeBSD.org Cc: security-officer@FreeBSD.org X-Send-Pr-Version: 3.113 Subject: ports/50150: SECURITY-UPDATE of port mail/mutt-devel Sender: owner-freebsd-ports-bugs@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org >Number: 50150 >Category: ports >Synopsis: SECURITY-UPDATE of port mail/mutt-devel >Confidential: no >Severity: non-critical >Priority: medium >Responsible: freebsd-ports-bugs >State: open >Quarter: >Keywords: >Date-Required: >Class: maintainer-update >Submitter-Id: current-users >Arrival-Date: Thu Mar 20 14:40:12 PST 2003 >Closed-Date: >Last-Modified: >Originator: Udo Schweigert >Release: FreeBSD 4.8-RC i386 >Organization: >Environment: System: FreeBSD alaska.cert.siemens.de 4.8-RC FreeBSD 4.8-RC #51: Sun Mar 16 11:47:16 CET 2003 ust@alaska.cert.siemens.de:/usr/obj/work/src/RELENG_4/sys/alaska i386 >Description: Maintainer update of mail/mutt-devel: - Upgrade to 1.5.4. - Fix a buffer overflow in mutt's IMAP client code. - Remove WITHOUT_MUTT_SMIME_OUTLOOK_COMPAT knob - The WITHOUT_MUTT_NNTP and the WITH_MUTT_SIGNATURE_MENU knob are not available at the moment. - Fix a wrong checksum in distinfo. >How-To-Repeat: >Fix: cvs rm -f files/smime.h files/extra-patch-smime-no-outlook diff -ru /usr/ports/mail/mutt-devel/Makefile ./Makefile --- /usr/ports/mail/mutt-devel/Makefile Mon Mar 17 08:09:24 2003 +++ ./Makefile Thu Mar 20 23:06:49 2003 @@ -47,9 +47,6 @@ # If you want to enable extended quoting functions define: # WITH_MUTT_QUOTE_PATCH # -# If you want to disable a outlook_compat function for use with smime define: -# WITHOUT_MUTT_SMIME_OUTLOOK_COMPAT -# # If you want to use the rethreading functions define: # WITH_MUTT_EDIT_THREADS # @@ -67,7 +64,7 @@ # WITH_MUTT_IFDEF_PATCH PORTNAME= mutt-devel -PORTVERSION= 1.5.3 +PORTVERSION= 1.5.4 #PORTREVISION?= 0 CATEGORIES+= mail .if defined(WITH_MUTT_NNTP) @@ -100,8 +97,10 @@ .include -.if defined(WITH_MUTT_COMPRESSED_FOLDERS) || defined(WITH_MUTT_NNTP) || \ - defined(WITH_MUTT_QUOTE_PATCH) +.if defined(WITH_MUTT_COMPRESSED_FOLDERS) +PATCH_SITES+= http://www.spinnaker.de/mutt/compressed/:spinnaker +.endif +.if defined(WITH_MUTT_NNTP) || defined(WITH_MUTT_QUOTE_PATCH) PATCH_SITES+= http://www.mutt.org.ua/download/mutt-${PATCH_VERSION}/:vvv \ http://www2.mutt.org.ua/download/mutt-${PATCH_VERSION}/:vvv \ ftp://ftp.mutt.org.ua/pub/mutt/mutt-${PATCH_VERSION}/:vvv \ @@ -112,7 +111,7 @@ defined(WITH_MUTT_IFDEF_PATCH) PATCH_SITES+= http://cedricduval.free.fr/download/mutt/:cd .endif -.if defined(WITH_MUTT_MBOX_HOOK_PATCH) +.if defined(WITH_MUTT_MBOX_HOOK_PATCH) PATCH_SITES+= http://home.woolridge.ca/mutt/patches/:dw .endif @@ -126,6 +125,7 @@ -e "s|^(AUTOHEADER = ).+|\1${AUTOHEADER}|" \ ${BUILD_WRKSRC}/Makefile +PATCH_VERSION= 1.5.3 .if !defined(PATCH_VERSION) PATCH_VERSION= ${PORTVERSION} .endif @@ -183,10 +183,6 @@ pre-configure:: ${PATCH} ${PATCH_ARGS} < ${PATCHDIR}/extra-patch-pgp-dw .endif -.if defined(WITHOUT_MUTT_SMIME_OUTLOOK_COMPAT) -pre-configure:: - ${PATCH} ${PATCH_ARGS} < ${PATCHDIR}/extra-patch-smime-no-outlook -.endif .if defined(WITH_MUTT_LOCALES_FIX) CONFIGURE_ARGS+= --enable-locales-fix @@ -206,11 +202,12 @@ PATCH_DIST_STRIP= -p1 .if defined(WITH_MUTT_COMPRESSED_FOLDERS) -PATCHFILES+= patch-${PATCH_VERSION}.rr.compressed.gz:vvv +PATCHFILES+= patch-${PORTVERSION}.rr.compressed.1.gz:spinnaker CONFIGURE_ARGS+= --enable-compressed SGML_NEEDED= yes .endif .if defined(WITH_MUTT_NNTP) +.error The WITH_MUTT_NNTP is not available at the moment. PATCHFILES+= patch-${PATCH_VERSION}.vvv.nntp.gz:vvv CONFIGURE_ARGS+= --enable-nntp SGML_NEEDED= yes @@ -226,6 +223,7 @@ SGML_NEEDED= yes .endif .if defined(WITH_MUTT_SIGNATURE_MENU) +.error The WITH_MUTT_SIGNATURE_MENU is not available at the moment. PATCHFILES+= patch-${PATCH_VERSION}.cd.signatures_menu.2.1:cd SGML_NEEDED= yes .endif @@ -244,7 +242,6 @@ post-patch:: @${REINPLACE_CMD} -e 's,/usr/bin/gpg,${LOCALBASE}/bin/gpg,g' \ ${WRKSRC}/contrib/gpg.rc - @${CP} ${PATCHDIR}/smime.h ${WRKSRC} pre-configure:: @(cd ${WRKSRC}; ${SETENV} ${AUTOMAKE_ENV} ${ACLOCAL} -I m4) diff -ru /usr/ports/mail/mutt-devel/distinfo ./distinfo --- /usr/ports/mail/mutt-devel/distinfo Mon Mar 17 08:09:24 2003 +++ ./distinfo Thu Mar 20 23:30:37 2003 @@ -1,9 +1,9 @@ -MD5 (mutt/mutt-1.5.3i.tar.gz) = 38a3dec075c7954a5fe62ce178310d22 -MD5 (mutt/patch-1.5.3.rr.compressed.gz) = 029b7bf58f53f4c7dcd542beac0c4757 +MD5 (mutt/mutt-1.5.4i.tar.gz) = 3d4088f25892af6d71148eef26604f33 +MD5 (mutt/patch-1.5.4.rr.compressed.1.gz) = e2c0b3bb0be0e19a4a6cda01078e3eae MD5 (mutt/patch-1.5.3.vvv.nntp.gz) = 6399a40b4a7ce3448b0329ceec38f35b MD5 (mutt/patch-1.5.3.vvv.initials.gz) = 9397128c901c32b6de585ef089ead87f MD5 (mutt/patch-1.5.3.vvv.quote.gz) = dc24cc5765dfbbf98a9c2027d950c07a MD5 (mutt/patch-1.5.3.cd.edit_threads.9.3) = 753a19d8efdece04cd521c3a3079dc9f MD5 (mutt/patch-1.5.3.cd.signatures_menu.2.1) = 6db636f0004e73ee2d9f577acd4ed380 MD5 (mutt/patch-1.5.3.cd.ifdef.1) = 01b47e075364834b82da053cac4eb69f -MD5 (mutt/p0-patch-1.5.3.dw.mbox-hook.1) = e7a0a57023cfdfd909f6040e632fff1f +MD5 (mutt/p0-patch-1.5.3.dw.mbox-hook.1) = 09f9b4229a2d63c81cfee7e1d811f84f diff -ru /usr/ports/mail/mutt-devel/files/extra-patch-pgp-dw ./files/extra-patch-pgp-dw --- /usr/ports/mail/mutt-devel/files/extra-patch-pgp-dw Mon Mar 17 08:09:24 2003 +++ ./files/extra-patch-pgp-dw Thu Mar 20 21:43:45 2003 @@ -1,16 +1,12 @@ -Base: http://home.woolridge.ca/mutt/patches/patch-1.5.3.dw.confirm-crypt-hook.1 - http://home.woolridge.ca/mutt/patches/patch-1.5.3.dw.multiple-crypt-hook.1 - http://home.woolridge.ca/mutt/patches/patch-1.5.3.dw.crypt-autoselectkey.1 - ---- PATCHES Tue Dec 17 10:47:20 2002 -+++ PATCHES Fri Jan 24 11:27:21 2003 +--- PATCHES Wed Mar 19 22:33:37 2003 ++++ PATCHES Thu Mar 20 21:38:55 2003 @@ -0,0 +1,3 @@ -+patch-1.5.3.dw.crypt-autoselectkey.1 -+patch-1.5.3.dw.confirm-crypt-hook.1 -+patch-1.5.3.dw.multiple-crypt-hook.1 ---- doc/manual.sgml.head Tue Dec 17 10:36:42 2002 -+++ doc/manual.sgml.head Fri Jan 24 11:26:59 2003 -@@ -1423,7 +1423,9 @@ ++patch-1.5.4.dw.confirm-crypt-hook.1 ++patch-1.5.4.dw.multiple-crypt-hook.2 ++patch-1.5.4.dw.crypt-autoselectkey.1 +--- doc/manual.sgml.head Tue Mar 4 08:49:49 2003 ++++ doc/manual.sgml.head Thu Mar 20 21:38:47 2003 +@@ -1422,7 +1422,9 @@ or because, for some reasons, you need to override the key Mutt would normally use. The crypt-hook command provides a method by which you can specify the ID of the public key to be used when encrypting messages to @@ -19,18 +15,25 @@ +pattern; multiple matching pgp-hook's result in the use of multiple +keyids for recipient. - Adding key sequences to the keyboard buffer