pkgsrc-Users archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: pkg-vulnerabilities, vulnerable packages, Opera 9.23, README.htmls



Gary Thorpe wrote:
> --- Dennis den Brok <d.den.brok%uni-bonn.de@localhost> wrote:
...
>>    * What I'm wondering about: Firefox 2.0.0.6 has this long-standing
>> remote-information-exposure issue which prevents it from being built
>> without ALLOW_VULNERABLE=yes; yet, there's a binary package available
>> from
>> a directory different from packages/vulnerable, and the corresponding
>> README.html doesn't mention any vulnerabilities at all. I reckon this
>> is
>> to not confuse new users with such a popular package being not
>> instantly
>> available, but I haven't found anything about a change of policy
>> regarding
>> that matter; ISTR that earlier, Firefox was being treated
>> differently?
...
> Using the current pkgsrc, this is partially fixed: README.html now
> includes vulnerabilities on my system (maybe yours would need
> updating). However, vulnerability information for Firefox specifically
> is missing (and a huge number of them, which says the file is still not
> being properly generated). While others seem complete, future
> vulnerabilities may also get left out of others somehow.
...

Hi,

If you 'cvs update' your sources and upgrade to the latest version of
the pkg_install tools (technically >=20070714 will do) this problem
should be fixed.

adrian.



Home | Main Index | Thread Index | Old Index