Bug 208385 - security/linux-c6-nss needs updating to resolve vulnerabilities
Summary: security/linux-c6-nss needs updating to resolve vulnerabilities
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: --- Affects Only Me
Assignee: Tijl Coosemans
URL:
Keywords: security
Depends on:
Blocks:
 
Reported: 2016-03-29 19:54 UTC by Mikhail Teterin
Modified: 2016-09-05 21:42 UTC (History)
2 users (show)

See Also:
bugzilla: maintainer-feedback? (emulation)


Attachments
nss diff (9.31 KB, patch)
2016-07-13 22:58 UTC, Piotr Kubaj
pkubaj: maintainer-approval? (emulation)
Details | Diff
vuln.xml change (404 bytes, patch)
2016-07-13 23:01 UTC, Piotr Kubaj
pkubaj: maintainer-approval? (emulation)
Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Mikhail Teterin freebsd_committer freebsd_triage 2016-03-29 19:54:55 UTC
The port is currently failing due to two vulnerabilities:
https://vuxml.FreeBSD.org/freebsd/c4292768-5273-4f17-a267-c5fe35125ce4.html
https://vuxml.FreeBSD.org/freebsd/75091516-6f4b-4059-9884-6727023dc366.html

Both were filed on March 8th, and both were addressed by RedHat/CentOS the next day with: 
http://rhn.redhat.com/errata/RHSA-2016-0370.html

The change for the port is simple enough -- just replace -2 with -5 in the nss-util RPM-version and update distinfo-files.

But vuln.xml is harder...
Comment 1 Piotr Kubaj freebsd_committer freebsd_triage 2016-07-13 22:58:57 UTC
Created attachment 172488 [details]
nss diff

There's a new update to nss packages. Here's the diff.
Comment 2 Piotr Kubaj freebsd_committer freebsd_triage 2016-07-13 23:01:19 UTC
Created attachment 172489 [details]
vuln.xml change

And the vuln.xml part seems easy too - 3.20_1 is the patched version of the port.
Comment 3 commit-hook freebsd_committer freebsd_triage 2016-09-05 21:32:00 UTC
A commit references this bug:

Author: tijl
Date: Mon Sep  5 21:31:45 UTC 2016
New revision: 421398
URL: https://svnweb.freebsd.org/changeset/ports/421398

Log:
  Update to nss-softokn 3.14.3-23.3.el6_8.

  PR:		208385
  Submitted by:	Piotr Kubaj <pkubaj@anongoth.pl>

Changes:
  head/security/linux-c6-nss/Makefile
  head/security/linux-c6-nss/distinfo.i386
  head/security/linux-c6-nss/distinfo.x86_64
  head/security/linux-c6-nss/pkg-plist.i386
  head/security/linux-c6-nss/pkg-plist.x86_64
Comment 4 commit-hook freebsd_committer freebsd_triage 2016-09-05 21:41:03 UTC
A commit references this bug:

Author: tijl
Date: Mon Sep  5 21:40:38 UTC 2016
New revision: 421399
URL: https://svnweb.freebsd.org/changeset/ports/421399

Log:
  Fix the version range for a linux-c6-nss vulnerability.

  PR:		208385

Changes:
  head/security/vuxml/vuln.xml