From owner-freebsd-ports@freebsd.org Tue Aug 25 20:49:33 2020 Return-Path: Delivered-To: freebsd-ports@mailman.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.nyi.freebsd.org (Postfix) with ESMTP id 9582E3BB700 for ; Tue, 25 Aug 2020 20:49:33 +0000 (UTC) (envelope-from jjuanino@gmail.com) Received: from mail-wr1-x430.google.com (mail-wr1-x430.google.com [IPv6:2a00:1450:4864:20::430]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (2048 bits) client-digest SHA256) (Client CN "smtp.gmail.com", Issuer "GTS CA 1O1" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4Bbh1m5Pk6z46XW; Tue, 25 Aug 2020 20:49:32 +0000 (UTC) (envelope-from jjuanino@gmail.com) Received: by mail-wr1-x430.google.com with SMTP id x7so106515wro.3; Tue, 25 Aug 2020 13:49:32 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:from:date:message-id:subject:to:cc; bh=mpoIyId0Y+zBcr+S6ngOsM/ZkE0qaVjGLXRSB50xRRI=; b=ObuJQnr1Een4sjzRg+VzJtK7UYwsqxWYjjCd72xs5P8PylzLJkQUY65SxYeUi3QAfw RXT9omgaFcNncmXzLhTyer2kTRHMXPlurwP/PTRjl0oHRFSYaBatHr88yBDtGJ14VuKi LHmBlSCLS1o+O1mhWyMLgMef61v/C5+ZhPpLyP72ypvtJeAtiDromM286vmDOnmsfiou dp2tXl83aXhE7/Hjxv2MtAwi1bCCNF7g6zpwIzQhlZKfjeXPhIOCu2FZeT/3MagEdKfe v3pQEqOdp65jW/Q4tEI0XziOyS1jJZt4G0atPEQYQUFBPa0heOsd9I1M6H5KMt9WikGj HhWA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:from:date:message-id:subject:to:cc; bh=mpoIyId0Y+zBcr+S6ngOsM/ZkE0qaVjGLXRSB50xRRI=; b=q6GwCKJqpfha1SDviPpq3aKhC+KFyQMWu200f+tiCkZrz7BJwxIKSEnPp9PnwHHf+d oWX4ej7GQZVhPpMds56JG6Y7ts8VTSMi9P4CgsB6HQVbCGB2Eizz2xZxkNbMvjDOUN/j L7lXtzjBuwVeGXTu82NHGWqlmdIOAnrWI/et06rQzTfvMPHO26AwcLwM+LUUBwmt6aON 4MKfkeVo/8iuH2VJ2prNkJ907yWe1Bq6srhSj7zMLzfnoIuDsZF5nat1b9egjdDTL8Jb jVcXKGcYIGNjtGICfVKXDPykuzrv9SEjk/HB/+NZTekLO/LTvin6jv7rnTDQl2pXw0aZ pMbg== X-Gm-Message-State: AOAM53000IN6r9Ba1/QP9WCA8xbnMD19sesY6H+xkNM6BaC6kABf19n1 ytR8c6Df8jJl42wgpgsVPHaU9AaXdszVVOo6nbYpt2c4Xvo= X-Google-Smtp-Source: ABdhPJysVqBpMl0lIZTsjX3KEnStJGHmI6T08PXMFoahAuAJlFIW6fBAGHBtkwBzINlXbt/Xh2o9oJh9BvXbyS5yMII= X-Received: by 2002:adf:90d1:: with SMTP id i75mr11786128wri.278.1598388571009; Tue, 25 Aug 2020 13:49:31 -0700 (PDT) MIME-Version: 1.0 From: =?UTF-8?B?Sm9zw6kgR2FyY8OtYSBKdWFuaW5v?= Date: Tue, 25 Aug 2020 22:49:19 +0200 Message-ID: Subject: lang/php72: last changelog references to wrong version, please update to 7.2.33 To: ports Cc: tz@freebsd.org Content-Type: text/plain; charset="UTF-8" X-Rspamd-Queue-Id: 4Bbh1m5Pk6z46XW X-Spamd-Bar: / Authentication-Results: mx1.freebsd.org; dkim=pass header.d=gmail.com header.s=20161025 header.b=ObuJQnr1; dmarc=pass (policy=none) header.from=gmail.com; spf=pass (mx1.freebsd.org: domain of jjuanino@gmail.com designates 2a00:1450:4864:20::430 as permitted sender) smtp.mailfrom=jjuanino@gmail.com X-Spamd-Result: default: False [-0.85 / 15.00]; RCVD_TLS_ALL(0.00)[]; ARC_NA(0.00)[]; R_DKIM_ALLOW(-0.20)[gmail.com:s=20161025]; NEURAL_HAM_MEDIUM(-0.66)[-0.659]; FROM_HAS_DN(0.00)[]; TO_DN_SOME(0.00)[]; FREEMAIL_FROM(0.00)[gmail.com]; TO_MATCH_ENVRCPT_ALL(0.00)[]; MIME_GOOD(-0.10)[text/plain]; DWL_DNSWL_NONE(0.00)[gmail.com:dkim]; R_SPF_ALLOW(-0.20)[+ip6:2a00:1450:4000::/36]; NEURAL_SPAM_SHORT(0.14)[0.139]; DKIM_TRACE(0.00)[gmail.com:+]; RCPT_COUNT_TWO(0.00)[2]; RCVD_IN_DNSWL_NONE(0.00)[2a00:1450:4864:20::430:from]; DMARC_POLICY_ALLOW(-0.50)[gmail.com,none]; FROM_EQ_ENVFROM(0.00)[]; MIME_TRACE(0.00)[0:+]; FREEMAIL_ENVFROM(0.00)[gmail.com]; ASN(0.00)[asn:15169, ipnet:2a00:1450::/32, country:US]; RCVD_COUNT_TWO(0.00)[2]; R_MIXED_CHARSET(0.67)[subject]; MAILMAN_DEST(0.00)[freebsd-ports] X-BeenThere: freebsd-ports@freebsd.org X-Mailman-Version: 2.1.33 Precedence: list List-Id: Porting software to FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 25 Aug 2020 20:49:33 -0000 Hi all, I am inspecting the last update in lang/php72 port (https://svnweb.freebsd.org/ports?view=revision&revision=545454), and the changelog shows the following: lang/php72: Update from 7.2.22 to 7.2.23 Changelog: Core: Fixed bug #79877 (getimagesize function silently truncates after a null byte) (cmb) Phar: Fixed bug #79797 (Use of freed hash key in the phar_parse_zipfile function). (CVE-2020-7068) Unless I am misunderstanding something, it seems to be wrong: that changelog references to 7.2.33 update instead of the 7.2.23 one, and on the other hand in the Makefile also references the wrong version 7.2.32. In short, I think what needs to be done is to update the port to the 7.2.33 version to cover CVE-2020-7068. Regards