From owner-freebsd-stable@FreeBSD.ORG Mon Aug 10 08:02:28 2009 Return-Path: Delivered-To: freebsd-stable@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 16915106566B for ; Mon, 10 Aug 2009 08:02:28 +0000 (UTC) (envelope-from me@pollux.local.net) Received: from smtp5-g21.free.fr (smtp5-g21.free.fr [212.27.42.5]) by mx1.freebsd.org (Postfix) with ESMTP id 886388FC22 for ; Mon, 10 Aug 2009 08:02:24 +0000 (UTC) Received: from smtp5-g21.free.fr (localhost [127.0.0.1]) by smtp5-g21.free.fr (Postfix) with ESMTP id 90916D4811D for ; Mon, 10 Aug 2009 10:02:20 +0200 (CEST) Received: from pollux.local.net (che78-3-82-246-31-201.fbx.proxad.net [82.246.31.201]) by smtp5-g21.free.fr (Postfix) with ESMTP id ACAB0D48157 for ; Mon, 10 Aug 2009 10:02:18 +0200 (CEST) Received: by pollux.local.net (Postfix, from userid 2000) id A022D1CDD4; Mon, 10 Aug 2009 10:04:06 +0200 (CEST) Date: Mon, 10 Aug 2009 10:04:06 +0200 From: Harald To: freebsd-stable@freebsd.org Message-ID: <20090810080406.GA1608@pollux.local.net> Mail-Followup-To: freebsd-stable@freebsd.org References: <20090725013500.GC62402@onelab2.iet.unipi.it> <20090725073805.GA11455@abigail.blackend.org> <20090806211401.GB2546@pollux.local.net> <68208453@h30.sp.ipt.ru> <20090809220452.GA56972@osiris.mauzo.dyndns.org> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20090809220452.GA56972@osiris.mauzo.dyndns.org> User-Agent: Mutt/1.4.2.3i Subject: Re: status of flash9/flash10 support in RELENG_7 ? X-BeenThere: freebsd-stable@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Production branch of FreeBSD source code List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 10 Aug 2009 08:02:28 -0000 On Sun, Aug 09, 2009 at 11:04:52PM +0100, Ben Morrow wrote: > I was about to say 'I believe the vuxml entry for firefox is incorrect', > but I see it's been fixed. Neither 3.0.13 nor 3.5.2 are vulnerable, and > vuxml now correctly reports this. Today security/vuxml/vuln.xml says: firefox linux-firefox 3.*,1 3.*,13.0.13,1 3.5.*,13.5.2,1 1. Could someone tell me the meaning of the ``*'' values please ? I can't see the logic of the range lines. 2. Yesterday I installed firefox quickly with ``pkg_add -r firefox3'' and got firefox-3.0.10,1. Portaudit declares it vulnerable which seems to correspond to the second range line. I guess I have to compile firefox3 to be clean ? Harald