Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 25 Aug 2005 19:48:47 +0200
From:      Roland Smith <rsmith@xs4all.nl>
To:        Joe Auty <joe@netmusician.org>
Cc:        freebsd-questions@freebsd.org
Subject:   Re: question about Portaudit and code freezes
Message-ID:  <20050825174847.GB10790@slackbox.xs4all.nl>
In-Reply-To: <DCEF4E5A-564C-4F10-AB30-C75C744F637B@netmusician.org>
References:  <7F8BEA4C-2CD8-4744-88D4-B55FB029EC43@netmusician.org> <20050825161224.GC10134@slackbox.xs4all.nl> <DCEF4E5A-564C-4F10-AB30-C75C744F637B@netmusician.org>

next in thread | previous in thread | raw e-mail | index | archive | help

--xgyAXRrhYN0wYx8y
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Thu, Aug 25, 2005 at 12:29:10PM -0500, Joe Auty wrote:
> On Aug 25, 2005, at 11:12 AM, Roland Smith wrote:
>=20
> >On Thu, Aug 25, 2005 at 03:23:11AM -0500, Joe Auty wrote:
> >
> >>Hello,
> >>
> >>How come xpdf is still showing up as a vulnerability, even though the
> >>latest portrevision was supposed to resolve these problems? Has the
> >>portaudit database not been updated because of the code freeze?
> >>
> >
> >Some other ports (like cups-base) incorporate part of the xpdf
> >code. so they will still show up as vulnerable. But I think that the
> >message shouldn't refer to xpdf. It's confusing.
> >
> >Roland

(please, do not top-post)=20
> Is Xpdf still listed in the portsaudit database as being vulnerable =20
> for you?

No, it isn't. I think you misunderstand. AFAIK, cups includes a copy of
(part of?) xpdf. Even if the original xpdf is fixed, cups-base won't be
until a equivalent fix is applied, or the fixed code is imported into
cups-base.=20

> If so, I guess there is nothing I can do except wait... I was just =20
> wondering if this has not been corrected because of the freeze?

Could be, but I guess such a safety-related fix would not be held
back. Maybe a fix hasn't been applied to cups yet.

Roland
--=20
R.F.Smith (http://www.xs4all.nl/~rsmith/) Please send e-mail as plain text.
public key: http://www.xs4all.nl/~rsmith/pubkey.txt

--xgyAXRrhYN0wYx8y
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (FreeBSD)

iD8DBQFDDgR/EnfvsMMhpyURAl3QAJ9M5/QVFL2TjJZvJ/4BRHNrkDpxpwCeNps8
eFBRVjxPdcosh9bQNzvbQTo=
=wZen
-----END PGP SIGNATURE-----

--xgyAXRrhYN0wYx8y--



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20050825174847.GB10790>