From owner-freebsd-security@FreeBSD.ORG Tue Oct 28 23:54:07 2014 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [8.8.178.115]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id D21D4835; Tue, 28 Oct 2014 23:54:07 +0000 (UTC) Received: from mail-oi0-x236.google.com (mail-oi0-x236.google.com [IPv6:2607:f8b0:4003:c06::236]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (Client CN "smtp.gmail.com", Issuer "Google Internet Authority G2" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 8AAE2B8C; Tue, 28 Oct 2014 23:54:07 +0000 (UTC) Received: by mail-oi0-f54.google.com with SMTP id v63so1460673oia.27 for ; Tue, 28 Oct 2014 16:54:06 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:date:message-id:subject:from:to:cc:content-type; bh=j7KCdFj2cEvgml478mUArMMdmM6cVcIl+je+/C5koU8=; b=ZOlba6WH8I3hDHuIsaYLaOx0iATz13+lVnDoRtcPL8XHex+zLTcwkox28+1IXFNT0j iGIZbGUO9pGOZcfV4tMGSONHDscV5Ld2VWNJAwu6/camZ3Qe0u+CXfoGgkUFWhZHrrqB hjUdrO/j3VOluehoIYK0FZQQBz0x9eSFSK+h4j6ZR3mIYauBv9d2f9yNYJYpVjQFbfXB i6tB+136Lmumz+YmXH2CuQDIyyzEJnOsN4rPXzIahMkBi22IrPAfCSe9TPdLM+Gyr+eU iaRMdHiT3xzgRxxmcGhRFutngpFG1CcyuVmg3+VbpqG/kaXK+IFPeA/+JvGeaVYug26/ V7yw== MIME-Version: 1.0 X-Received: by 10.202.7.21 with SMTP id 21mr5187027oih.6.1414540446810; Tue, 28 Oct 2014 16:54:06 -0700 (PDT) Received: by 10.202.208.150 with HTTP; Tue, 28 Oct 2014 16:54:06 -0700 (PDT) Date: Wed, 29 Oct 2014 00:54:06 +0100 Message-ID: Subject: tnftp update in FreeBSD 11-CURRENT From: Oliver Pinter To: freebsd-security@freebsd.org Content-Type: text/plain; charset=ISO-8859-1 Cc: Xin LI , =?ISO-8859-1?Q?Dag=2DErling_Sm=F8rgrav?= X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.18-1 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 28 Oct 2014 23:54:07 -0000 Hi All! If there are any plan to update tnftp in FreeBSD 11-CURRENT, than there is the port: https://github.com/HardenedBSD/hardenedBSD/tree/hardened/current/tnftp-update This containes the latest fix from christos's NetBSD commit too. From owner-freebsd-security@FreeBSD.ORG Wed Oct 29 15:26:40 2014 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id 7D79332C; Wed, 29 Oct 2014 15:26:40 +0000 (UTC) Received: from smtp.des.no (smtp.des.no [194.63.250.102]) by mx1.freebsd.org (Postfix) with ESMTP id 40FBE8B5; Wed, 29 Oct 2014 15:26:40 +0000 (UTC) Received: from nine.des.no (smtp.des.no [194.63.250.102]) by smtp-int.des.no (Postfix) with ESMTP id 874B2AC7F; Wed, 29 Oct 2014 15:26:33 +0000 (UTC) Received: by nine.des.no (Postfix, from userid 1001) id D32E2107C3; Wed, 29 Oct 2014 16:26:33 +0100 (CET) From: =?utf-8?Q?Dag-Erling_Sm=C3=B8rgrav?= To: Oliver Pinter Subject: Re: tnftp update in FreeBSD 11-CURRENT References: Date: Wed, 29 Oct 2014 16:26:33 +0100 In-Reply-To: (Oliver Pinter's message of "Wed, 29 Oct 2014 00:54:06 +0100") Message-ID: <86lhnydhhy.fsf@nine.des.no> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/24.3 (berkeley-unix) MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Cc: freebsd-security@freebsd.org, Xin LI X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.18-1 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 29 Oct 2014 15:26:40 -0000 Oliver Pinter writes: > If there are any plan to update tnftp in FreeBSD 11-CURRENT [...] Yes, we are working on it. DES --=20 Dag-Erling Sm=C3=B8rgrav - des@des.no From owner-freebsd-security@FreeBSD.ORG Wed Oct 29 15:40:50 2014 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id 93417F36 for ; Wed, 29 Oct 2014 15:40:50 +0000 (UTC) Received: from mail-yh0-f52.google.com (mail-yh0-f52.google.com [209.85.213.52]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (Client CN "smtp.gmail.com", Issuer "Google Internet Authority G2" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 5618DA7B for ; Wed, 29 Oct 2014 15:40:49 +0000 (UTC) Received: by mail-yh0-f52.google.com with SMTP id a41so677889yho.25 for ; Wed, 29 Oct 2014 08:40:43 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:in-reply-to:references:date :message-id:subject:from:to:cc:content-type :content-transfer-encoding; bh=qYNRZlGplJE93ZUgucvL8Oi+hroB4oU1X6mhZGaAErU=; b=Ydxk25UIkjmh5JQXh2K4htXrWv+PoxxVE0NtcRP0fNfjWxL3LmEpMlNaAhLLbie/+/ H/4GcJdsexAxF9EeQMFzUNRVdDgc2vxzkKO+MtiNlqJhnDthVMYYd0x7pQhvpf+s9oBE C/P1kO3d29ErdMYYl24gIki5Puqum4ZplMACRW+OJ97r335XJfakWhLu8mbi6lAlNG73 rBlf96YBojRg8VAiUsnwdvvj/j26o1bhsNDpqS+ZPEr9yyLmEfeaCO1B0rNC9Qjq7jy5 OfeYSAZGzTx3mN2D4J93vWf0C/hOF1ou/rYWAifJOA38nmcErngVV+RYpz5nT2eWfzuc qJeQ== X-Gm-Message-State: ALoCoQkyXjfodUzNOlq82SDQfQOUWWnlzvbFncYck5qipzv9K+sRpfqvTcucdmomd/vuQ0f2MPpu MIME-Version: 1.0 X-Received: by 10.236.229.164 with SMTP id h34mr1016880yhq.199.1414596747762; Wed, 29 Oct 2014 08:32:27 -0700 (PDT) Received: by 10.170.46.203 with HTTP; Wed, 29 Oct 2014 08:32:27 -0700 (PDT) X-Originating-IP: [62.165.198.134] In-Reply-To: <86lhnydhhy.fsf@nine.des.no> References: <86lhnydhhy.fsf@nine.des.no> Date: Wed, 29 Oct 2014 16:32:27 +0100 Message-ID: Subject: Re: tnftp update in FreeBSD 11-CURRENT From: Oliver Pinter To: =?UTF-8?Q?Dag=2DErling_Sm=C3=B8rgrav?= Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable Cc: freebsd-security@freebsd.org, Xin LI , Oliver Pinter X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.18-1 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 29 Oct 2014 15:40:50 -0000 On 10/29/14, Dag-Erling Sm=C3=B8rgrav wrote: > Oliver Pinter writes: >> If there are any plan to update tnftp in FreeBSD 11-CURRENT [...] > > Yes, we are working on it. On fix only or on whole update? (I think for releases only the fix.) > > DES > -- > Dag-Erling Sm=C3=B8rgrav - des@des.no > _______________________________________________ > freebsd-security@freebsd.org mailing list > http://lists.freebsd.org/mailman/listinfo/freebsd-security > To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.or= g" From owner-freebsd-security@FreeBSD.ORG Wed Oct 29 15:46:13 2014 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id 97A644BA; Wed, 29 Oct 2014 15:46:13 +0000 (UTC) Received: from smtp.des.no (smtp.des.no [194.63.250.102]) by mx1.freebsd.org (Postfix) with ESMTP id 591DCB8D; Wed, 29 Oct 2014 15:46:13 +0000 (UTC) Received: from nine.des.no (smtp.des.no [194.63.250.102]) by smtp-int.des.no (Postfix) with ESMTP id 27397AD74; Wed, 29 Oct 2014 15:46:12 +0000 (UTC) Received: by nine.des.no (Postfix, from userid 1001) id DD5E1107CB; Wed, 29 Oct 2014 16:46:12 +0100 (CET) From: =?utf-8?Q?Dag-Erling_Sm=C3=B8rgrav?= To: Oliver Pinter Subject: Re: tnftp update in FreeBSD 11-CURRENT References: <86lhnydhhy.fsf@nine.des.no> Date: Wed, 29 Oct 2014 16:46:12 +0100 In-Reply-To: (Oliver Pinter's message of "Wed, 29 Oct 2014 16:32:27 +0100") Message-ID: <868ujydgl7.fsf@nine.des.no> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/24.3 (berkeley-unix) MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Cc: freebsd-security@freebsd.org, Xin LI , Oliver Pinter X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.18-1 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 29 Oct 2014 15:46:13 -0000 Oliver Pinter writes: > Dag-Erling Sm=C3=B8rgrav writes: > > Oliver Pinter writes: > > > If there are any plan to update tnftp in FreeBSD 11-CURRENT [...] > > Yes, we are working on it. > On fix only or on whole update? (I think for releases only the fix.) Just the fix for now - someone else can take care of the update. DES --=20 Dag-Erling Sm=C3=B8rgrav - des@des.no From owner-freebsd-security@FreeBSD.ORG Wed Oct 29 20:45:05 2014 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id 989F230C for ; Wed, 29 Oct 2014 20:45:05 +0000 (UTC) Received: from mail-wi0-f179.google.com (mail-wi0-f179.google.com [209.85.212.179]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (Client CN "smtp.gmail.com", Issuer "Google Internet Authority G2" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 30C332EF for ; Wed, 29 Oct 2014 20:45:04 +0000 (UTC) Received: by mail-wi0-f179.google.com with SMTP id h11so5691394wiw.6 for ; Wed, 29 Oct 2014 13:45:02 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:date:from:to:subject:message-id:mail-followup-to :mime-version:content-type:content-disposition:user-agent; bh=iuIojOcLcorXB2slwCuXxlms7WyDKdI3PpXi/HXjAPo=; b=Mw4WGZXLY0FChb7fxCKHHvJw/2PQQRbmOCeqPzIwHmebRd+CngLutT9Vizjd2/fCQv DlR+YvDC/pb0NiYwYs/aAsH5rnAWz56OiMg1qFyKRlDvkr1+Sw2GFuio1ZX1Lsg3sN5t IHhnFI4CTRWehzfew8YVDE129tSlazUPl8p4Qj0DZ5drWrU97M1z0Dtwx6AH1t4CrVkB tdx/a5emXEBHzdoTPjDD6EXasMBkqjObbvX2EKzbIkFP7OaJt9gUOiM2YBQhXZ+e+rX3 kiCHaAUwhTRoAiZMGAXT6tP6/lL2VjeLLFQeNRAHnmO6zsDMRS5nCUXOFthJKz1wdxdx /Bow== X-Gm-Message-State: ALoCoQl5qRrcpmtdwig7Xn8aZOSoi0HzumbtYXR1DhUXOwvcxtKgTyIY3JivNfbmPzkytwqyaSeg X-Received: by 10.180.103.233 with SMTP id fz9mr37763083wib.80.1414615502784; Wed, 29 Oct 2014 13:45:02 -0700 (PDT) Received: from localhost (itcom245.staff.itd.umich.edu. [141.213.135.249]) by mx.google.com with ESMTPSA id mc4sm6730308wic.6.2014.10.29.13.45.01 for (version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Wed, 29 Oct 2014 13:45:02 -0700 (PDT) Date: Wed, 29 Oct 2014 16:42:03 -0400 From: William Bulley To: freebsd-security@freebsd.org Subject: broken portaudit !! Message-ID: <20141029204203.GA1265@itcom245.staff.itd.umich.edu> Mail-Followup-To: freebsd-security@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline User-Agent: Mutt/1.5.23 (2014-03-12) X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.18-1 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 29 Oct 2014 20:45:05 -0000 Thinking that I might wish to upgrade my 9.2-STABLE system (to 9.3-STABLE), I decided to run "# /usr/local/sbin/portaudit -Fda" only to find that someone at FreeBSD.org has borked the system: unix# /usr/local/sbin/portaudit -Fda fetch: http://portaudit.FreeBSD.org/auditfile.tbz: Not Found Couldn't fetch database. Old database restored. portaudit: Download failed. I think some folks have moved on (to the new system) without having given any thought to those folks (like me!) who are just a tad bit behind the herd... :-( See the security risks here: http://vuxml.freebsd.org/freebsd/ [[Note: portaudit.FreeBSD.org resolves to vuxml.freebsd.org/freebsd/]] unix% dig -t A portaudit.FreeBSD.org ; <<>> DiG 9.9.3-P2 <<>> -t A portaudit.FreeBSD.org ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 60842 ;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 4096 ;; QUESTION SECTION: ;portaudit.FreeBSD.org. IN A ;; ANSWER SECTION: portaudit.freebsd.org. 3600 IN CNAME wfe0.ysv.freebsd.org. wfe0.ysv.FreeBSD.org. 2737 IN A 8.8.178.110 ;; Query time: 51 msec ;; SERVER: 68.94.156.1#53(68.94.156.1) ;; WHEN: Wed Oct 29 16:43:38 EDT 2014 ;; MSG SIZE rcvd: 116 unix% dig -t A vuxml.freebsd.org ; <<>> DiG 9.9.3-P2 <<>> -t A vuxml.freebsd.org ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 41971 ;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 4096 ;; QUESTION SECTION: ;vuxml.freebsd.org. IN A ;; ANSWER SECTION: vuxml.freebsd.org. 3600 IN CNAME wfe0.ysv.freebsd.org. wfe0.ysv.freebsd.org. 3600 IN A 8.8.178.110 ;; Query time: 90 msec ;; SERVER: 68.94.156.1#53(68.94.156.1) ;; WHEN: Wed Oct 29 16:43:50 EDT 2014 ;; MSG SIZE rcvd: 85 I also note that not only is the database MIA, but there is at least one bad link at the bottom of: http://vuxml.freebsd.org/ and that (borked) link would be: http://svnweb.freebsd.org/ports/head/ports-mgmt/portaudit :-( Regards, web... -- /"\ ASCII RIBBON / William Bulley \ / CAMPAIGN AGAINST / X HTML E-MAIL AND / E-MAIL: web@umich.edu / \ LISTSERV POSTINGS / 72 characters width template ----------------------------------------->| From owner-freebsd-security@FreeBSD.ORG Wed Oct 29 21:08:29 2014 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id 72315C4C for ; Wed, 29 Oct 2014 21:08:29 +0000 (UTC) Received: from mailrelay10.public.one.com (mailrelay10.public.one.com [195.47.247.78]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id B15A279C for ; Wed, 29 Oct 2014 21:08:28 +0000 (UTC) X-HalOne-Cookie: 1eb148c3018667621611ee4f35e970078dbf793e DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=cederstrand.dk; s=20140924; h=from:subject:date:message-id:to:cc:mime-version:content-type: content-transfer-encoding:in-reply-to:references; bh=gB9rDNopO1CE+/PLnbsIkVHjdcO7WztooYoKiFRgu88=; b=Vl67JZOo6RsUepopfldv6GFPD9t4mNMpGd8MevSUFkAieSmAwgKDlDPOyE+QTgyLUO2xaHZrvh9+X bABeOzBd0KI1ZVuWlbav3VHySSjNeWIirwJYKoxd/WbQ07Z6gGSL6j265CX++KV6W2nWAzmTzf+Prd kXKNUVpzOq1iZCAg= Received: from [10.105.124.100] (unknown [176.222.238.90]) by smtpfilter3.public.one.com (Halon Mail Gateway) with ESMTPSA; Wed, 29 Oct 2014 21:06:27 +0000 (GMT) Content-Type: text/plain; charset=us-ascii Mime-Version: 1.0 (Mac OS X Mail 8.0 \(1990.1\)) Subject: Re: broken portaudit !! From: Erik Cederstrand In-Reply-To: <20141029204203.GA1265@itcom245.staff.itd.umich.edu> Date: Wed, 29 Oct 2014 22:07:18 +0100 Content-Transfer-Encoding: quoted-printable Message-Id: References: <20141029204203.GA1265@itcom245.staff.itd.umich.edu> To: William Bulley X-Mailer: Apple Mail (2.1990.1) Cc: "freebsd-security@freebsd.org" X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.18-1 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 29 Oct 2014 21:08:29 -0000 > Den 29/10/2014 kl. 21.42 skrev William Bulley : >=20 > Thinking that I might wish to upgrade my 9.2-STABLE system (to = 9.3-STABLE), > I decided to run "# /usr/local/sbin/portaudit -Fda" only to find that = someone > at FreeBSD.org has borked the system portaudit and the pkg_* tools are deprecated. Upgrade to pkg = (https://www.freebsd.org/doc/handbook/pkgng-intro.html) and use 'pkg = audit' instead. Erik= From owner-freebsd-security@FreeBSD.ORG Thu Oct 30 00:00:01 2014 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [8.8.178.115]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id 80F1FC8D for ; Thu, 30 Oct 2014 00:00:01 +0000 (UTC) Received: from smtp.des.no (smtp.des.no [194.63.250.102]) by mx1.freebsd.org (Postfix) with ESMTP id 454EFCE9 for ; Thu, 30 Oct 2014 00:00:00 +0000 (UTC) Received: from nine.des.no (smtp.des.no [194.63.250.102]) by smtp-int.des.no (Postfix) with ESMTP id 3825BA956 for ; Thu, 30 Oct 2014 00:00:00 +0000 (UTC) Received: by nine.des.no (Postfix, from userid 1001) id D558D1080D; Thu, 30 Oct 2014 01:00:00 +0100 (CET) From: =?utf-8?Q?Dag-Erling_Sm=C3=B8rgrav?= To: freebsd-security@freebsd.org Subject: Re: broken portaudit !! References: <20141029204203.GA1265@itcom245.staff.itd.umich.edu> Date: Thu, 30 Oct 2014 01:00:00 +0100 In-Reply-To: <20141029204203.GA1265@itcom245.staff.itd.umich.edu> (William Bulley's message of "Wed, 29 Oct 2014 16:42:03 -0400") Message-ID: <86vbn2bf5r.fsf@nine.des.no> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/24.3 (berkeley-unix) MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.18-1 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 30 Oct 2014 00:00:01 -0000 William Bulley writes: > Thinking that I might wish to upgrade my 9.2-STABLE system (to 9.3-STABLE= ), > I decided to run "# /usr/local/sbin/portaudit -Fda" only to find that som= eone > at FreeBSD.org has borked the system: We didn't "bork the system". The old pkg_* tools were removed over a month ago after a six-month deprecation period, at which point portaudit also stopped working, although it wasn't removed from ports until two weeks ago. The new package system has equivalent functionality built-in with the "audit" command: des@nine ~% sudo pkg audit -F Password: Fetching vuln.xml.bz2: 100% 455 kB 466.3k/s 00:01=20=20=20=20 0 problem(s) in the installed packages found. > [[Note: portaudit.FreeBSD.org resolves to vuxml.freebsd.org/freebsd/]] You mean redirects. They already resolved to the same IP address(es), which, as far as I know, is a reverse proxy that handles most of the project's web sites. DES --=20 Dag-Erling Sm=C3=B8rgrav - des@des.no