Created attachment 172530 [details] gimp 2.8.18 patch The patch attached updates the port to 2.8.18, along with gimp-app port. Since it fixes CVE-2016-4994, it should be MFH'd. Builds fine on 10.3-RELEASE.
Created attachment 172534 [details] corrected patch for pkg-plist issues
Created attachment 172721 [details] vuln.xml fragment
A commit references this bug: Author: cmt Date: Fri Jul 29 08:38:09 UTC 2016 New revision: 419233 URL: https://svnweb.freebsd.org/changeset/ports/419233 Log: Update The Gimp to 2.8.18 PR: 211124 Submitted by: pkubaj@anongoth.pl Approved by: rene (mentor) Approved by: maintainer-timeout MFH: 2016Q3 Security: 6fb8a90f-c9d5-4d14-b940-aed3d63c2edc Changes: head/graphics/gimp/Makefile head/graphics/gimp-app/Makefile head/graphics/gimp-app/distinfo head/graphics/gimp-app/pkg-plist
Thanks. Committed with some modifications: please do not remove optionised items from pkg-plist without verifying they won't be needed (see JASPER and GHOSTSCRIPT options).
A commit references this bug: Author: cmt Date: Fri Jul 29 20:04:56 UTC 2016 New revision: 419268 URL: https://svnweb.freebsd.org/changeset/ports/419268 Log: MFH: r419233 Update The Gimp to 2.8.18 PR: 211124 Submitted by: pkubaj@anongoth.pl Approved by: rene (mentor) Approved by: maintainer-timeout Security: 6fb8a90f-c9d5-4d14-b940-aed3d63c2edc Approved by: ports-secteam (feld) Changes: _U branches/2016Q3/ branches/2016Q3/graphics/gimp/Makefile branches/2016Q3/graphics/gimp-app/Makefile branches/2016Q3/graphics/gimp-app/distinfo branches/2016Q3/graphics/gimp-app/pkg-plist