Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 9 Sep 2007 09:32:42 +0100 (GMT+01:00)
From:      "malcolm_green@tiscali.co.uk" <malcolm_green@tiscali.co.uk>
To:        gnome@freebsd.org
Subject:   make gnome2 fails because evince has vulnerability
Message-ID:  <18892771.1189326762105.JavaMail.root@ps26>

next in thread | raw e-mail | index | archive | help


----Original Message----
From: malcolm_green@tiscali.co.uk
Date: 09/09/2007 9:29=20
To: <gnome@freebs.org>
Subj: make gnome2 fails because evince has vulnerability

Dear freebsd-gnome team
    May I enquire of you about a problem when doing   make install  =20
in   /usr/ports/x11/gnome2   under PCBSD 1.4RC . It fails saying  =20
evince    has a vulnerability. I have followed the advice output by=20
the=20
make and used   kports   to    update the ports  ,  fetch a new index=20
,=20
and  update the ports-db . Upon re-issuing   make install   I get the=20
same error.  Now I am unsure what to do.  Surely the   make install  =20
script should not refuse to continue building but merely issue a=20
warning. There must be a way to prevent this blowup, but the whole  =20
ports   system is like a   empty cube in space   to a relatively new=20
BSD person.

I can see that one way to avoid it would be to get a new   evince   ,=20
but   kports   says my copy is the latest.
The ports I am using is supplied on the PCBSD CD so I dont know when=20
it dates from, and in any case I have updated the   ports tree  =20
with  =20
kports .
=20
Perhaps there is a good document I should read.

This is my screen output at the second attempt.

madrid# pwd
/usr/ports/x11/gnome2
madrid# make install
=3D=3D=3D>  Installing for gnome2-2.18.3
=3D=3D=3D>   gnome2-2.18.3 depends on file: /usr/local/libexec/gweather-
applet-2 - found
=3D=3D=3D>   gnome2-2.18.3 depends on executable: gnome-cd - found
=3D=3D=3D>   gnome2-2.18.3 depends on executable: gnome-dictionary - found
=3D=3D=3D>   gnome2-2.18.3 depends on executable: eog - found
=3D=3D=3D>   gnome2-2.18.3 depends on executable: gconf-editor - found
=3D=3D=3D>   gnome2-2.18.3 depends on executable: gnect - found
=3D=3D=3D>   gnome2-2.18.3 depends on executable: gedit - found
=3D=3D=3D>   gnome2-2.18.3 depends on executable: gnome-terminal - found
=3D=3D=3D>   gnome2-2.18.3 depends on executable: gnome-session - found
=3D=3D=3D>   gnome2-2.18.3 depends on executable: bug-buddy - found
=3D=3D=3D>   gnome2-2.18.3 depends on executable: gnome-system-monitor -=20
found
=3D=3D=3D>   gnome2-2.18.3 depends on executable: nautilus - found
=3D=3D=3D>   gnome2-2.18.3 depends on file: /usr/local/sbin/gdm - found
=3D=3D=3D>   gnome2-2.18.3 depends on file:=20
/usr/local/share/gnome/help/user-
guide/C/user-guide.xml - found
=3D=3D=3D>   gnome2-2.18.3 depends on file:=20
/usr/local/share/gnome/sounds/question.wav - found
=3D=3D=3D>   gnome2-2.18.3 depends on file:=20
/usr/local/libdata/pkgconfig/libgail-gnome.pc - found
=3D=3D=3D>   gnome2-2.18.3 depends on executable: file-roller - found
=3D=3D=3D>   gnome2-2.18.3 depends on file:=20
/usr/local/share/themes/HighContrast/gtk-2.0/gtkrc - found
=3D=3D=3D>   gnome2-2.18.3 depends on executable: gok - found
=3D=3D=3D>   gnome2-2.18.3 depends on executable: nautilus-cd-burner - foun=
d
=3D=3D=3D>   gnome2-2.18.3 depends on executable: gcalctool - found
=3D=3D=3D>   gnome2-2.18.3 depends on executable: gucharmap - found
=3D=3D=3D>   gnome2-2.18.3 depends on executable: zenity - found
=3D=3D=3D>   gnome2-2.18.3 depends on file:=20
/usr/local/lib/X11/fonts/bitstream-vera/Vera.ttf - found
=3D=3D=3D>   gnome2-2.18.3 depends on file: /usr/local/libexec/gnome-
netstatus-applet - found
=3D=3D=3D>   gnome2-2.18.3 depends on executable: dasher - found
=3D=3D=3D>   gnome2-2.18.3 depends on executable: evolution-2.10 - found
=3D=3D=3D>   gnome2-2.18.3 depends on file: /usr/local/libexec/evolution-
webcal - found
=3D=3D=3D>   gnome2-2.18.3 depends on executable: network-admin - found
=3D=3D=3D>   gnome2-2.18.3 depends on executable: gnome-nettool - found
=3D=3D=3D>   gnome2-2.18.3 depends on executable: vino-session - found
=3D=3D=3D>   gnome2-2.18.3 depends on executable: exchange-connector-setup-
2.10 - found
=3D=3D=3D>   gnome2-2.18.3 depends on file: /usr/local/lib/gstreamer-0.10/.
gstreamer-plugins-core.keep - found
=3D=3D=3D>   gnome2-2.18.3 depends on file: /usr/local/lib/gstreamer-0.10
/libgstgconfelements.so - found
=3D=3D=3D>   gnome2-2.18.3 depends on executable: totem - found
=3D=3D=3D>   gnome2-2.18.3 depends on executable: gnome-control-center -=20
found
=3D=3D=3D>   gnome2-2.18.3 depends on file: /usr/local/share/gnome/gnome-
background-properties/gnome-branded.xml - found
=3D=3D=3D>   gnome2-2.18.3 depends on executable: sound-juicer - found
=3D=3D=3D>   gnome2-2.18.3 depends on executable: gnome-keyring-manager -=
=20
found
=3D=3D=3D>   gnome2-2.18.3 depends on file:=20
/usr/local/libdata/pkgconfig/libgtkhtml-2.0.pc - found
=3D=3D=3D>   gnome2-2.18.3 depends on executable: evince - not found
=3D=3D=3D>    Verifying install for evince in /usr/ports/graphics/evince
=3D=3D=3D>  evince-0.8.3_1 has known vulnerabilities:
=3D> xpdf -- stack based buffer overflow.
   Reference: <http://www.FreeBSD.org/ports/portaudit/0e43a14d-3f3f-
11dc-a79a-0016179b2dd5.html>
=3D> Please update your ports tree and try again.
*** Error code 1

Stop in /usr/ports/graphics/evince.
*** Error code 1

Stop in /usr/ports/x11/gnome2.
madrid# =20



I apologise if this is not enough evidence.   Thank you

                         malcolm_green@tiscali.co.uk



                    =20



__________________________________________________
Tiscali Broadband only =C2=A37.99 a month for your first 3 months! http:
//www.tiscali.co.uk/products/broadband/





__________________________________________________
Tiscali Broadband only =C2=A37.99 a month for your first 3 months! http://w=
ww.tiscali.co.uk/products/broadband/



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?18892771.1189326762105.JavaMail.root>