Vulnerable & missing vuxml entry https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-7162
A commit references this bug: Author: feld Date: Wed Oct 12 04:47:34 UTC 2016 New revision: 423829 URL: https://svnweb.freebsd.org/changeset/ports/423829 Log: Document file-roller vulnerability PR: 213199 Security: CVE-2016-7162 Changes: head/security/vuxml/vuln.xml
documented vulnerability in vuxml. Can someone from gnome comment on updating this to an unaffected version?
A commit references this bug: Author: kwm Date: Wed Oct 26 14:40:05 UTC 2016 New revision: 424708 URL: https://svnweb.freebsd.org/changeset/ports/424708 Log: Update file-roller to 3.20.3. PR: 213199 Reported by: Sevan Janiyan <venture37@geeklan.co.uk> MFH: 2016Q4 Security: ad479f89-9020-11e6-a590-14dae9d210b8 Changes: head/archivers/file-roller/Makefile head/archivers/file-roller/distinfo head/archivers/file-roller/pkg-plist
It appears I forgot to close this bug. Fix committed back in oktober. Thanks for reporting!
A commit references this bug: Author: junovitch Date: Wed Dec 28 02:31:21 UTC 2016 New revision: 429687 URL: https://svnweb.freebsd.org/changeset/ports/429687 Log: MFH: r424708 Update file-roller to 3.20.3. PR: 213199 Reported by: Sevan Janiyan <venture37@geeklan.co.uk> Security: ad479f89-9020-11e6-a590-14dae9d210b8 Approved by: ports-secteam (with hat) Changes: _U branches/2016Q4/ branches/2016Q4/archivers/file-roller/Makefile branches/2016Q4/archivers/file-roller/distinfo branches/2016Q4/archivers/file-roller/pkg-plist
Hmmm, looks like we somehow missed the MFH. Fixed and set the Bugzilla tag to match.