The cvsupit port has a special user friendly application that builds a cvsupfile for you. This file is flawed by default and does NOT include src-crypto or src-secure, meaning that openssl and openssh do NOT get updated when you run make world, and thus remain the older (READ: Vulnerable) versions of the software. Fix: Change the defaults to read src-all, instead of individually listing every category except the REALLY important ones like security and crypto :) the port should also create an empty /usr/sup/refuse and tell the user of it's existence. So the users know they can add "russian", or whatever other ports from the collection they dont want to it. By default this isn't explained. How-To-Repeat: install cvsupit and look at the file created in /etc/cvsupfile notice how src-secure and src-crypto are NOT included.
Responsible Changed From-To: freebsd-ports->jkh over to maintainer
State Changed From-To: open->closed Port was updated.