From owner-freebsd-ports-bugs@FreeBSD.ORG Tue Feb 28 14:50:08 2006 Return-Path: X-Original-To: freebsd-ports-bugs@hub.freebsd.org Delivered-To: freebsd-ports-bugs@hub.freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 10A3C16A420 for ; Tue, 28 Feb 2006 14:50:08 +0000 (GMT) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (freefall.freebsd.org [216.136.204.21]) by mx1.FreeBSD.org (Postfix) with ESMTP id B67C443D45 for ; Tue, 28 Feb 2006 14:50:07 +0000 (GMT) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (gnats@localhost [127.0.0.1]) by freefall.freebsd.org (8.13.4/8.13.4) with ESMTP id k1SEo7bF064093 for ; Tue, 28 Feb 2006 14:50:07 GMT (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.13.4/8.13.4/Submit) id k1SEo7v7064092; Tue, 28 Feb 2006 14:50:07 GMT (envelope-from gnats) Date: Tue, 28 Feb 2006 14:50:07 GMT Message-Id: <200602281450.k1SEo7v7064092@freefall.freebsd.org> To: freebsd-ports-bugs@FreeBSD.org From: NAKAJI Hiroyuki Cc: Subject: Re: ports/92498: japanese/hns update to version 2.19.6 X-BeenThere: freebsd-ports-bugs@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list Reply-To: NAKAJI Hiroyuki List-Id: Ports bug reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 28 Feb 2006 14:50:08 -0000 The following reply was made to PR ports/92498; it has been noted by GNATS. From: NAKAJI Hiroyuki To: FreeBSD-gnats-submit@FreeBSD.org Cc: freebsd-ports-bugs@FreeBSD.org Subject: Re: ports/92498: japanese/hns update to version 2.19.6 Date: Tue, 28 Feb 2006 23:40:25 +0900 A security advisory written in Japanese was announced. http://www.h14m.org/SA/2006/hns-SA-2006-01.txt (The make-rurimap.cgi script may cause your blog server to become spammer.) On Feb 28 2006, the latest version of hns to fix this security problem was released. I have updated the patch for ports-current. Please update as soon as possible, or mark it as broken for security reason. Index: Makefile =================================================================== RCS file: /net/www/home/ncvs/ports/japanese/hns/Makefile,v retrieving revision 1.12 diff -u -u -r1.12 Makefile --- Makefile 22 Jan 2004 11:05:55 -0000 1.12 +++ Makefile 28 Feb 2006 14:30:25 -0000 @@ -6,10 +6,10 @@ # PORTNAME= hns -PORTVERSION= 2.10.3 +PORTVERSION= 2.19.7 CATEGORIES= japanese www perl5 -MASTER_SITES= http://downloads.sourceforge.jp/h14m/3249/ -DISTNAME= ${PORTNAME}-${PORTVERSION:R}-pl${PORTVERSION:E} +MASTER_SITES= http://www.h14m.org/dist/ \ + http://prdownloads.sourceforge.jp/h14m/19119/ MAINTAINER= hnsmaster@h14m.org COMMENT= Hyper NIKKI System, a CGI system for Electric Diary Interchange @@ -17,8 +17,6 @@ USE_PERL5= yes NO_BUILD= yes -WRKSRC= ${WRKDIR}/${PORTNAME}-${PORTVERSION:R}-pl${PORTVERSION:E} - do-install: @if [ -d ${DATADIR} ]; then ${RM} -rf ${DATADIR}; fi ${MKDIR} ${DATADIR} @@ -29,9 +27,9 @@ post-install: @cd ${WRKSRC} && ${FIND} . -type f -o -type l | \ - sed 's,^\.,share/${PORTNAME},' | ${SORT} >> ${TMPPLIST} + ${SED} 's,^\.,share/${PORTNAME},' | ${SORT} >> ${TMPPLIST} @cd ${WRKSRC} && ${FIND} . -type d | \ - sed 's,^\.,@dirrm share/${PORTNAME},' | ${SORT} -r \ + ${SED} 's,^\.,@dirrm share/${PORTNAME},' | ${SORT} -r \ >> ${TMPPLIST} @${CAT} ${PKGMESSAGE} Index: distinfo =================================================================== RCS file: /net/www/home/ncvs/ports/japanese/hns/distinfo,v retrieving revision 1.7 diff -u -u -r1.7 distinfo --- distinfo 31 Mar 2004 03:08:41 -0000 1.7 +++ distinfo 28 Feb 2006 14:30:32 -0000 @@ -1,2 +1,3 @@ -MD5 (hns-2.10-pl3.tar.gz) = 9428cbc3791fbd6530e28f43d31ffa99 -SIZE (hns-2.10-pl3.tar.gz) = 975507 +MD5 (hns-2.19.7.tar.gz) = 2063053d032885eb9469aea6446fec89 +SHA256 (hns-2.19.7.tar.gz) = e68513cf8ee8ba2d85b36626e6de20f683a4b8ac381a90893a5ef86f99939353 +SIZE (hns-2.19.7.tar.gz) = 747596 -- NAKAJI Hiroyuki