Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 29 Sep 2008 16:08:40 +0400
From:      Eygene Ryabinkin <rea-fbsd@codelabs.ru>
To:        miwi@FreeBSD.org
Cc:        freebsd-ports-bugs@FreeBSD.org, simon@freebsd.org, secteam@freebsd.org, eik@freebsd.org
Subject:   Re: ports/127712: bad version specification for firefox3 in VuXML entry 2273879e-8a2f-11dd-a6fe-0030843d3802
Message-ID:  <4q1MIJYnkAI2/uhQIJO5iMTkJO8@jzvzJIf8fRWoTzX3FjwxUqmHGm0>
In-Reply-To: <200809291146.m8TBk1WE048611@freefall.freebsd.org>
References:  <200809291146.m8TBk1WE048611@freefall.freebsd.org>

next in thread | previous in thread | raw e-mail | index | archive | help

--MrRUTeZlqqNo1jQ9
Content-Type: text/plain; charset=koi8-r
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

Martin, good day.

Mon, Sep 29, 2008 at 11:46:01AM +0000, miwi@FreeBSD.org wrote:
> State-Changed-Why:=20
> Committed. Thanks!

I think that just changing 'firefox3' to 'firefox' is not enough:
such specification will catch firefox 2.x too:
-----
$ pkg_info -E 'firefox<3.0.2,1'
firefox-2.0.0.17,1

$ sh portaudit -a
Affected package: firefox-2.0.0.17,1
Type of problem: mozilla -- multiple vulnerabilities.
Reference: <http://www.FreeBSD.org/ports/portaudit/2273879e-8a2f-11dd-a6fe-=
0030843d3802.html>

1 problem(s) in your installed packages found.

You are advised to update or deinstall the affected package(s) immediately.
-----
One should put a lower bound on firefox 3.x too: '>=3D3.0.0,1<3.0.2,1'.
Or I am missing something?

Thanks!
--=20
Eygene
 _                ___       _.--.   #
 \`.|\..----...-'`   `-._.-'_.-'`   #  Remember that it is hard
 /  ' `         ,       __.--'      #  to read the on-line manual  =20
 )/' _/     \   `-_,   /            #  while single-stepping the kernel.
 `-'" `"\_  ,_.-;_.-\_ ',  fsc/as   #
     _.-'_./   {_.'   ; /           #    -- FreeBSD Developers handbook=20
    {_.-``-'         {_/            #

--MrRUTeZlqqNo1jQ9
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.9 (FreeBSD)

iEYEARECAAYFAkjgxUgACgkQthUKNsbL7YhFfwCfcPi/tS7UhxV1O9vjQ4cvND0t
3CQAn2oQjtDHYCosf6vESMmRVF/66qhN
=U+b/
-----END PGP SIGNATURE-----

--MrRUTeZlqqNo1jQ9--



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?4q1MIJYnkAI2/uhQIJO5iMTkJO8>