From owner-freebsd-ports@FreeBSD.ORG Thu Sep 16 05:11:50 2010 Return-Path: Delivered-To: freebsd-ports@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 080431065693 for ; Thu, 16 Sep 2010 05:11:50 +0000 (UTC) (envelope-from cvs-src@yandex.ru) Received: from forward11.mail.yandex.net (forward11.mail.yandex.net [95.108.130.93]) by mx1.freebsd.org (Postfix) with ESMTP id AAF348FC21 for ; Thu, 16 Sep 2010 05:11:49 +0000 (UTC) Received: from smtp12.mail.yandex.net (smtp12.mail.yandex.net [95.108.131.191]) by forward11.mail.yandex.net (Yandex) with ESMTP id DCF223ED00AD; Thu, 16 Sep 2010 09:11:47 +0400 (MSD) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yandex.ru; s=mail; t=1284613907; bh=Q8/iqeX8y58P3q3YZUAmpSIujhSeqaeVotSwqXNP+WE=; h=Message-ID:Date:From:MIME-Version:To:CC:Subject:References: In-Reply-To:Content-Type:Content-Transfer-Encoding; b=cKX9ibqGFTL0oXY/eIzW2HQDkDL692gN/xkpl7GGBU+VTIAey7QK7/x5ao7v+Iv/z qZGZNE2rPr83VXTQr7/z6INq4bsXBnwzFxNm50Mn6tu7BxFkV+cDIJZts8+B09PBhg ITeoF04mnl9X+sJyqLpQLQAI/uSOfwBbanJT3N+8= Received: from smeshariki2.local (unknown [77.66.145.223]) by smtp12.mail.yandex.net (Yandex) with ESMTPSA id 877A113E80A3; Thu, 16 Sep 2010 09:11:47 +0400 (MSD) Message-ID: <4C91A6A2.90602@yandex.ru> Date: Thu, 16 Sep 2010 09:09:54 +0400 From: Ruslan Mahmatkhanov User-Agent: Mozilla/5.0 (X11; U; FreeBSD i386; ru-RU; rv:1.9.2.9) Gecko/20100908 Thunderbird/3.1.3 MIME-Version: 1.0 To: Dan Langille References: <4C9176BD.3020903@langille.org> In-Reply-To: <4C9176BD.3020903@langille.org> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit X-Yandex-TimeMark: 1284613907 X-Yandex-Spam: 1 X-Yandex-Front: smtp12.mail.yandex.net Cc: freebsd-ports@freebsd.org Subject: Re: www/openx vuln X-BeenThere: freebsd-ports@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Porting software to FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 16 Sep 2010 05:11:50 -0000 16.09.2010 05:45, Dan Langille пишет: > This came in last night: http://blog.openx.org/09/security-update/ > > Port needs to be upgraded to 2.8.8 and a vuln entry created.... Sorry, > bags not me. > Until update is not come up, user can apply this workaround: echo "RemoveType .php" > www/images/.htaccess -- Regards, Ruslan