Date: Sun, 9 Sep 2007 09:32:42 +0100 (GMT+01:00) From: "malcolm_green@tiscali.co.uk" <malcolm_green@tiscali.co.uk> To: gnome@freebsd.org Subject: make gnome2 fails because evince has vulnerability Message-ID: <18892771.1189326762105.JavaMail.root@ps26>
next in thread | raw e-mail | index | archive | help
----Original Message---- From: malcolm_green@tiscali.co.uk Date: 09/09/2007 9:29=20 To: <gnome@freebs.org> Subj: make gnome2 fails because evince has vulnerability Dear freebsd-gnome team May I enquire of you about a problem when doing make install =20 in /usr/ports/x11/gnome2 under PCBSD 1.4RC . It fails saying =20 evince has a vulnerability. I have followed the advice output by=20 the=20 make and used kports to update the ports , fetch a new index=20 ,=20 and update the ports-db . Upon re-issuing make install I get the=20 same error. Now I am unsure what to do. Surely the make install =20 script should not refuse to continue building but merely issue a=20 warning. There must be a way to prevent this blowup, but the whole =20 ports system is like a empty cube in space to a relatively new=20 BSD person. I can see that one way to avoid it would be to get a new evince ,=20 but kports says my copy is the latest. The ports I am using is supplied on the PCBSD CD so I dont know when=20 it dates from, and in any case I have updated the ports tree =20 with =20 kports . =20 Perhaps there is a good document I should read. This is my screen output at the second attempt. madrid# pwd /usr/ports/x11/gnome2 madrid# make install =3D=3D=3D> Installing for gnome2-2.18.3 =3D=3D=3D> gnome2-2.18.3 depends on file: /usr/local/libexec/gweather- applet-2 - found =3D=3D=3D> gnome2-2.18.3 depends on executable: gnome-cd - found =3D=3D=3D> gnome2-2.18.3 depends on executable: gnome-dictionary - found =3D=3D=3D> gnome2-2.18.3 depends on executable: eog - found =3D=3D=3D> gnome2-2.18.3 depends on executable: gconf-editor - found =3D=3D=3D> gnome2-2.18.3 depends on executable: gnect - found =3D=3D=3D> gnome2-2.18.3 depends on executable: gedit - found =3D=3D=3D> gnome2-2.18.3 depends on executable: gnome-terminal - found =3D=3D=3D> gnome2-2.18.3 depends on executable: gnome-session - found =3D=3D=3D> gnome2-2.18.3 depends on executable: bug-buddy - found =3D=3D=3D> gnome2-2.18.3 depends on executable: gnome-system-monitor -=20 found =3D=3D=3D> gnome2-2.18.3 depends on executable: nautilus - found =3D=3D=3D> gnome2-2.18.3 depends on file: /usr/local/sbin/gdm - found =3D=3D=3D> gnome2-2.18.3 depends on file:=20 /usr/local/share/gnome/help/user- guide/C/user-guide.xml - found =3D=3D=3D> gnome2-2.18.3 depends on file:=20 /usr/local/share/gnome/sounds/question.wav - found =3D=3D=3D> gnome2-2.18.3 depends on file:=20 /usr/local/libdata/pkgconfig/libgail-gnome.pc - found =3D=3D=3D> gnome2-2.18.3 depends on executable: file-roller - found =3D=3D=3D> gnome2-2.18.3 depends on file:=20 /usr/local/share/themes/HighContrast/gtk-2.0/gtkrc - found =3D=3D=3D> gnome2-2.18.3 depends on executable: gok - found =3D=3D=3D> gnome2-2.18.3 depends on executable: nautilus-cd-burner - foun= d =3D=3D=3D> gnome2-2.18.3 depends on executable: gcalctool - found =3D=3D=3D> gnome2-2.18.3 depends on executable: gucharmap - found =3D=3D=3D> gnome2-2.18.3 depends on executable: zenity - found =3D=3D=3D> gnome2-2.18.3 depends on file:=20 /usr/local/lib/X11/fonts/bitstream-vera/Vera.ttf - found =3D=3D=3D> gnome2-2.18.3 depends on file: /usr/local/libexec/gnome- netstatus-applet - found =3D=3D=3D> gnome2-2.18.3 depends on executable: dasher - found =3D=3D=3D> gnome2-2.18.3 depends on executable: evolution-2.10 - found =3D=3D=3D> gnome2-2.18.3 depends on file: /usr/local/libexec/evolution- webcal - found =3D=3D=3D> gnome2-2.18.3 depends on executable: network-admin - found =3D=3D=3D> gnome2-2.18.3 depends on executable: gnome-nettool - found =3D=3D=3D> gnome2-2.18.3 depends on executable: vino-session - found =3D=3D=3D> gnome2-2.18.3 depends on executable: exchange-connector-setup- 2.10 - found =3D=3D=3D> gnome2-2.18.3 depends on file: /usr/local/lib/gstreamer-0.10/. gstreamer-plugins-core.keep - found =3D=3D=3D> gnome2-2.18.3 depends on file: /usr/local/lib/gstreamer-0.10 /libgstgconfelements.so - found =3D=3D=3D> gnome2-2.18.3 depends on executable: totem - found =3D=3D=3D> gnome2-2.18.3 depends on executable: gnome-control-center -=20 found =3D=3D=3D> gnome2-2.18.3 depends on file: /usr/local/share/gnome/gnome- background-properties/gnome-branded.xml - found =3D=3D=3D> gnome2-2.18.3 depends on executable: sound-juicer - found =3D=3D=3D> gnome2-2.18.3 depends on executable: gnome-keyring-manager -= =20 found =3D=3D=3D> gnome2-2.18.3 depends on file:=20 /usr/local/libdata/pkgconfig/libgtkhtml-2.0.pc - found =3D=3D=3D> gnome2-2.18.3 depends on executable: evince - not found =3D=3D=3D> Verifying install for evince in /usr/ports/graphics/evince =3D=3D=3D> evince-0.8.3_1 has known vulnerabilities: =3D> xpdf -- stack based buffer overflow. Reference: <http://www.FreeBSD.org/ports/portaudit/0e43a14d-3f3f- 11dc-a79a-0016179b2dd5.html> =3D> Please update your ports tree and try again. *** Error code 1 Stop in /usr/ports/graphics/evince. *** Error code 1 Stop in /usr/ports/x11/gnome2. madrid# =20 I apologise if this is not enough evidence. Thank you malcolm_green@tiscali.co.uk =20 __________________________________________________ Tiscali Broadband only =C2=A37.99 a month for your first 3 months! http: //www.tiscali.co.uk/products/broadband/ __________________________________________________ Tiscali Broadband only =C2=A37.99 a month for your first 3 months! http://w= ww.tiscali.co.uk/products/broadband/
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?18892771.1189326762105.JavaMail.root>