pkgsrc-Users archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: Removal of rxvt/mrxvt from pkgsrc?





On Sat, 20 Jun 2026, Rares Aioanei wrote:

I'd like to propose the removal of mrxvt from pkgsrc on the grounds that

1. it's not maintained anymore (last release was in 2008)
2. it's vulnerable to https://nvd.nist.gov/vuln/detail/CVE-2017-7483 and there is no fix from upstream 3. probably because of 1. and 2. OpenBSD and FreeBSD removed it from their respective ports system -- https://marc.info/?l=openbsd-ports-cvs&m=149833297519829&w=2

PS : On this note, the last release of rxvt was in March 2003, and looks like it's also vulnerable to the same CVE listed above.

I am fine with removing rxvt and mrxvt. I would also be fine with an update of rxvt-unicode, the somewhat maintained fork, to 9.31 :)

--
Benny


Home | Main Index | Thread Index | Old Index