Bug 198816 - devel/cross-binutils: Multiple security vulnerabilities
Summary: devel/cross-binutils: Multiple security vulnerabilities
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: --- Affects Many People
Assignee: Brooks Davis
URL:
Keywords: needs-patch, security
Depends on:
Blocks:
 
Reported: 2015-03-23 01:19 UTC by Sevan Janiyan
Modified: 2015-03-24 22:03 UTC (History)
0 users

See Also:
bugzilla: maintainer-feedback? (brooks)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 commit-hook freebsd_committer freebsd_triage 2015-03-24 21:32:37 UTC
A commit references this bug:

Author: brooks
Date: Tue Mar 24 21:32:05 UTC 2015
New revision: 382177
URL: https://svnweb.freebsd.org/changeset/ports/382177

Log:
  The ancient version of binutils in the cross-binutils port suffers for
  several vulnerabilities.

  This also effects devel/mingw64-binutils.

  PR:		198816
  Reported by:	Sevan Janiyan <venture37@geeklan.co.uk>

Changes:
  head/security/vuxml/vuln.xml
Comment 2 commit-hook freebsd_committer freebsd_triage 2015-03-24 21:33:40 UTC
A commit references this bug:

Author: brooks
Date: Tue Mar 24 21:32:48 UTC 2015
New revision: 382179
URL: https://svnweb.freebsd.org/changeset/ports/382179

Log:
  The ancient version of binutils in the cross-binutils port suffers for
  several vulnerabilities.  Mark it FORBIDDEN and DEPRECATED and set it expire
  April 15th.

  This also effects devel/mingw64-binutils.

  Consumers of this port should switch to devel/binutil or slave ports
  there of.

  PR:		198816
  Reported by:	Sevan Janiyan <venture37@geeklan.co.uk>

Changes:
  head/devel/cross-binutils/Makefile
Comment 3 Brooks Davis freebsd_committer freebsd_triage 2015-03-24 22:03:44 UTC
This port is old, broken on CURRENT, and has few consumers so I've set it to expire shortly which will finish fixing the problem.