Created attachment 173231 [details] libtiff-3.9.4-18.el6_8 The attached patch updates the port to 3.9.4-18.el6_8 version (CentOS 6 versioning) and sets LICENSE. Builds fine on 10.3-RELEASE.
Patch does not apply. Recent PORTVERSION is PORTVERSION= 4.0.6_2. (Is not changed in this patch - if 3.9.4 is right?).
Sorry, my error , it is not tiff, but linux-c6_64-tiff.
This new version seems to add patches for 19 CVE's and is rated Important: https://rhn.redhat.com/errata/RHSA-2016-1547.html Given above, I think it's reasonable to MFH it.
Created attachment 173252 [details] vuxml patch
A commit references this bug: Author: tijl Date: Mon Sep 5 20:55:55 UTC 2016 New revision: 421395 URL: https://svnweb.freebsd.org/changeset/ports/421395 Log: Update to libtiff 3.9.4-18.el6_8. PR: 211552 Submitted by: Piotr Kubaj <pkubaj@anongoth.pl> MFH: 2016Q2 Security: https://rhn.redhat.com/errata/RHSA-2016-1547.html Changes: head/graphics/linux-c6-tiff/Makefile head/graphics/linux-c6-tiff/distinfo.i386 head/graphics/linux-c6-tiff/distinfo.x86_64 head/graphics/linux-c6-tiff/pkg-plist.i386 head/graphics/linux-c6-tiff/pkg-plist.x86_64
A commit references this bug: Author: tijl Date: Tue Sep 6 10:23:38 UTC 2016 New revision: 421416 URL: https://svnweb.freebsd.org/changeset/ports/421416 Log: MFH: r421395 Update to libtiff 3.9.4-18.el6_8. PR: 211552 Submitted by: Piotr Kubaj <pkubaj@anongoth.pl> Security: https://rhn.redhat.com/errata/RHSA-2016-1547.html Approved by: ports-secteam (delphij) Changes: _U branches/2016Q3/ branches/2016Q3/graphics/linux-c6-tiff/Makefile branches/2016Q3/graphics/linux-c6-tiff/distinfo.i686 branches/2016Q3/graphics/linux-c6-tiff/distinfo.x86_64 branches/2016Q3/graphics/linux-c6-tiff/pkg-plist.i686 branches/2016Q3/graphics/linux-c6-tiff/pkg-plist.x86_64
A commit references this bug: Author: tijl Date: Tue Sep 6 17:08:31 UTC 2016 New revision: 421447 URL: https://svnweb.freebsd.org/changeset/ports/421447 Log: - Add linux-*-tiff information to existing tiff vulnerabilities. - Like r419692, cancel a gif2tiff vulnerability that upstream marked WONTFIX: http://bugzilla.maptools.org/show_bug.cgi?id=2536 PR: 211552 Changes: head/security/vuxml/vuln.xml