Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 14 Feb 2016 13:05:15 +0000
From:      bugzilla-noreply@freebsd.org
To:        freebsd-ports-bugs@FreeBSD.org
Subject:   [Bug 207187] www/horde-base & devel/pear-Horde_Core: XSS vulnerabilites in 2016Q4 version
Message-ID:  <bug-207187-13@https.bugs.freebsd.org/bugzilla/>

next in thread | raw e-mail | index | archive | help
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D207187

            Bug ID: 207187
           Summary: www/horde-base & devel/pear-Horde_Core: XSS
                    vulnerabilites in 2016Q4 version
           Product: Ports & Packages
           Version: Latest
          Hardware: Any
                OS: Any
            Status: New
          Keywords: security
          Severity: Affects Some People
          Priority: ---
         Component: Individual Port(s)
          Assignee: horde@FreeBSD.org
          Reporter: junovitch@freebsd.org
                CC: ports-secteam@FreeBSD.org
          Assignee: horde@FreeBSD.org
             Flags: maintainer-feedback?(horde@FreeBSD.org),
                    merge-quarterly?

https://github.com/horde/horde/commit/11d74fa5a22fe626c5e5a010b703cd46a136f=
253
https://github.com/horde/horde/commit/f03301cf6edcca57121a15e80014c4d0f29d9=
9a0

This was documented in:
https://svnweb.FreeBSD.org/changeset/ports/408841

These are addressed in the recent Horde package updates SVN commits:
https://svnweb.FreeBSD.org/changeset/ports/407900
https://svnweb.FreeBSD.org/changeset/ports/407927
https://svnweb.FreeBSD.org/changeset/ports/408020

This touches a lot of packages though.  Should the 3 Horde updates be bulk
MFH'd at once or just the patches from git applied?

--=20
You are receiving this mail because:
You are the assignee for the bug.=



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?bug-207187-13>