Bug 83753 - Update port: devel/viewcvs to 0.9.3 (security fix)
Summary: Update port: devel/viewcvs to 0.9.3 (security fix)
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: Normal Affects Only Me
Assignee: Roman Bogorodskiy
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2005-07-19 23:00 UTC by Vsevolod Stakhov
Modified: 2005-07-20 06:03 UTC (History)
0 users

See Also:


Attachments
viewcvs-0.9.3.patch (2.59 KB, patch)
2005-07-19 23:00 UTC, Vsevolod Stakhov
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Vsevolod Stakhov 2005-07-19 23:00:33 UTC
Update to 0.9.3.
Security fixes are included:
* security fix: disallow bad "content-type" input [CAN-2004-1062]
* security fix: disallow bad "sortby" and "cvsroot" input [CAN-2002-0771]
* security fix: omit forbidden/hidden modules from tarballs [CAN-2004-0915]

Removed file(s):
- files/patch-CAN-2004-0915
Comment 1 Roman Bogorodskiy freebsd_committer freebsd_triage 2005-07-20 05:58:20 UTC
Responsible Changed
From-To: freebsd-ports-bugs->novel

I'll take it.
Comment 2 Roman Bogorodskiy freebsd_committer freebsd_triage 2005-07-20 06:03:23 UTC
State Changed
From-To: open->closed

Committed, thanks!