From owner-cvs-ports@FreeBSD.ORG Sun Jul 8 19:27:49 2012 Return-Path: Delivered-To: cvs-ports@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 112D21065670; Sun, 8 Jul 2012 19:27:49 +0000 (UTC) (envelope-from delphij@gmail.com) Received: from mail-qc0-f182.google.com (mail-qc0-f182.google.com [209.85.216.182]) by mx1.freebsd.org (Postfix) with ESMTP id 7DB898FC08; Sun, 8 Jul 2012 19:27:48 +0000 (UTC) Received: by qcsg15 with SMTP id g15so7166879qcs.13 for ; Sun, 08 Jul 2012 12:27:48 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=Aqxqou9l9n81qCr53DOCWAWF6s6CuDd8JOWlNwTF3MM=; b=h3ZzCC8r3zxSGxcM5vg3LI8bmnEbEKui4q2zuz/l3tG1GR+3rT5Vm9Oe7/yZPirOkK e9epWBRh4oB112+0hh7FwUDtDN4rf1b8Pf4iRzgl4vsPVikAmkYfKoNgk1JeU/M0Z+oo 070vS+6+MalERqj1hdk2EXg6fj9SHWOMkffFEEt6CB3HD60syyrCL8/DbGBTdDViRr4c LqMdcGdB2V+e+r+63fc+lsfUBFJtt6oFJ2k2L0iDY0owIK7CbszQkCMJBDJdbVlwmXfq OySV5TzazpQhuhpCtPo8AFm564HYM4xE9lior9jXGEuZ1AUTH+cHvKDJsii6H1QnUbqw 5O6Q== MIME-Version: 1.0 Received: by 10.224.208.194 with SMTP id gd2mr39869374qab.96.1341775667893; Sun, 08 Jul 2012 12:27:47 -0700 (PDT) Received: by 10.229.27.146 with HTTP; Sun, 8 Jul 2012 12:27:47 -0700 (PDT) In-Reply-To: <201207081900.q68J08f7088286@repoman.freebsd.org> References: <201207081900.q68J08f7088286@repoman.freebsd.org> Date: Sun, 8 Jul 2012 12:27:47 -0700 Message-ID: From: Xin LI To: Eitan Adler Content-Type: text/plain; charset=UTF-8 Cc: cvs-ports@freebsd.org, cvs-all@freebsd.org, ports-committers@freebsd.org Subject: Re: cvs commit: ports/security/vuxml vuln.xml X-BeenThere: cvs-ports@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: CVS commit messages for the ports tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 08 Jul 2012 19:27:49 -0000 On Sun, Jul 8, 2012 at 12:00 PM, Eitan Adler wrote: > eadler 2012-07-08 19:00:08 UTC > > FreeBSD ports repository > > Modified files: > security/vuxml vuln.xml > Log: > openx reported a new security issue but does not provide any details: inform users of this. I don't think it's right to assign same identifier to different issues. For 2.8.9 I think it was: http://www.infosecstuff.com/openx-releases-patch-for-csrf-vulnerability/ And for 2.8.8 it was: http://secunia.com/advisories/48275/ It seems that OpenX does not release any information about the vulnerability which is a bad practice in my opinion by the way. Cheers, -- Xin LI https://www.delphij.net/ FreeBSD - The Power to Serve! Live free or die