http://www.ocert.org/advisories/ocert-2015-006.html
A commit references this bug: Author: feld Date: Fri Jan 8 17:53:09 UTC 2016 New revision: 405576 URL: https://svnweb.freebsd.org/changeset/ports/405576 Log: graphics/exact-image: Update to 0.9.1 Add patch to resolve CVE PR: 200201 MFH: 2016Q1 Security: CVE-2015-3885 Changes: head/graphics/exact-image/Makefile head/graphics/exact-image/distinfo head/graphics/exact-image/files/patch-codecs_dcraw.h
A commit references this bug: Author: feld Date: Fri Jan 8 17:53:54 UTC 2016 New revision: 405577 URL: https://svnweb.freebsd.org/changeset/ports/405577 Log: MFH: r405576 graphics/exact-image: Update to 0.9.1 Add patch to resolve CVE PR: 200201 Security: CVE-2015-3885 Approved by: ports-secteam (with hat) Changes: _U branches/2016Q1/ branches/2016Q1/graphics/exact-image/Makefile branches/2016Q1/graphics/exact-image/distinfo branches/2016Q1/graphics/exact-image/files/patch-codecs_dcraw.h
vuxml has also been updated at r405578