Bug 210421 - ftp/wget: Update to 1.18 (Fixes CVE-2016-4971)
Summary: ftp/wget: Update to 1.18 (Fixes CVE-2016-4971)
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: Normal Affects Many People
Assignee: Vasil Dimov
URL: http://lists.gnu.org/archive/html/inf...
Keywords: easy, patch, patch-ready, security
Depends on:
Blocks: 210512
  Show dependency treegraph
 
Reported: 2016-06-20 23:29 UTC by VK
Modified: 2016-06-24 17:10 UTC (History)
3 users (show)

See Also:
vd: maintainer-feedback+
vd: merge-quarterly+


Attachments
Update wget to 1.18 (1.49 KB, patch)
2016-06-20 23:29 UTC, VK
vlad-fbsd: maintainer-approval? (vd)
Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description VK freebsd_triage 2016-06-20 23:29:53 UTC
Created attachment 171629 [details]
Update wget to 1.18

Please update wget to 1.18. Patch attached. Fixes CVE-2016-4971.

* Upstream announcement:
  http://lists.gnu.org/archive/html/info-gnu/2016-06/msg00004.html

NOTE backwards incompatibility introduced with the fix. The patch carries recommended UPDATING entry.

Passes portlint (a warning from before). Passes poudriere 10.3-p5 amd64 build.

Request MFH.
Comment 1 commit-hook freebsd_committer freebsd_triage 2016-06-21 08:03:24 UTC
A commit references this bug:

Author: vd
Date: Tue Jun 21 08:02:57 UTC 2016
New revision: 417188
URL: https://svnweb.freebsd.org/changeset/ports/417188

Log:
  ftp/wget: Upgrade from 1.16.3_1 to 1.18

  PR:		210421
  Submitted by:	Vladimir Krstulja <vlad-fbsd@acheronmedia.com>
  Security:	CVE-2016-4971

Changes:
  head/UPDATING
  head/ftp/wget/Makefile
  head/ftp/wget/distinfo
Comment 2 Vasil Dimov freebsd_committer freebsd_triage 2016-06-21 08:19:55 UTC
Committed, thanks!
Comment 3 Kubilay Kocak freebsd_committer freebsd_triage 2016-06-24 08:26:20 UTC
Re-open for merge to quarterly branch
Comment 4 commit-hook freebsd_committer freebsd_triage 2016-06-24 17:09:02 UTC
A commit references this bug:

Author: vd
Date: Fri Jun 24 17:08:43 UTC 2016
New revision: 417438
URL: https://svnweb.freebsd.org/changeset/ports/417438

Log:
  MFH: r417188 r417282 r417417

  ftp/wget: Upgrade from 1.16.3_1 to 1.18

  PR:		210421 [1], 210512
  Submitted by:	Vladimir Krstulja <vlad-fbsd@acheronmedia.com> [1]
  Security:	CVE-2016-4971

  ftp/wget: fix compilation when IDN and NLS are disabled

  PR:		210441
  Submitted by:	Helge Oldach <freebsd@oldach.net>

  Change AUTHOR: entry in UPDATING to committer

  Suggested by:	koobs@

  Approved by:	ports-secteam

Changes:
_U  branches/2016Q2/
  branches/2016Q2/UPDATING
  branches/2016Q2/ftp/wget/Makefile
  branches/2016Q2/ftp/wget/distinfo