Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 13 Jul 2015 09:54:54 +0200 (CEST)
From:      Jimmy Olgeni <olgeni@olgeni.com>
To:        Ivan Klymenko <fidaj@ukr.net>
Cc:        Koop Mast <kwm@rainbow-runner.nl>, svn-ports-head@freebsd.org,  svn-ports-all@freebsd.org, ports-committers@freebsd.org
Subject:   Re: svn commit: r391619 - in head: mail/thunderbird/files www/firefox-esr/files www/firefox/files www/libxul/files www/seamonkey/files
Message-ID:  <alpine.BSF.2.20.1507130953160.76410@backoffice.olgeni.com>
In-Reply-To: <20150713105036.385e2406@nonamehost.local>
References:  <201507090709.t6979VsY058416@repo.freebsd.org> <20150709115113.3ebb1cc2@nonamehost.local> <559EB2AD.5000004@rainbow-runner.nl> <alpine.BSF.2.20.1507091947380.93772@olgeni.olgeni> <559EC53B.104@rainbow-runner.nl> <20150709221621.5294d65d@nonamehost.local> <alpine.BSF.2.20.1507092143180.93772@olgeni.olgeni> <559EE028.7070203@rainbow-runner.nl> <alpine.BSF.2.20.1507101139070.11542@backoffice.olgeni.com> <55A11EB5.9020600@rainbow-runner.nl> <alpine.BSF.2.20.1507130925270.41549@backoffice.olgeni.com> <20150713105036.385e2406@nonamehost.local>

next in thread | previous in thread | raw e-mail | index | archive | help

On Mon, 13 Jul 2015, Ivan Klymenko wrote:

> Mon, 13 Jul 2015 09:26:55 +0200 (CEST)
> Jimmy Olgeni <olgeni@olgeni.com> написав:
>
> >
> > Hi,
> >
> > On Sat, 11 Jul 2015, Koop Mast wrote:
> >
> > > On 10-7-2015 11:40, Jimmy Olgeni wrote:
> > > > Hi,
> > > >
> > > > On Thu, 9 Jul 2015, Koop Mast wrote:
> > > >
> > > >> If you switch back to GTK2 does it still build? The left overs
> > > >> also showed up suddenly on my builds, no idea where that comes
> > > >> from.
> > > > GTK2 still fails over here (poudriere).
> > > >
> > > > --
> > > > jimmy
> > > So GTK3 builds but GTK2 doesn't ... can you do the following?
> > >
> > > 1) Do you have any non-default settings/options set/unset?
> > > 2) Could you build firefox with -w and put the resulting tarball
> > > somewhere where I can download it and look at it? I'm not sure if I
> > > can find something but I'm willing to try.
> >
> > I disabled ccache and got the build working - something probably got
> > stuck in the cache.
> >
> > Ivan, do you have ccache enabled?
> >
>
> Yes.

I put "MAKE_ENV+=CCACHE_RECACHE=yes" to rebuild the cache and it seems to
work so far.

--
jimmy
From owner-svn-ports-all@freebsd.org  Mon Jul 13 08:39:08 2015
Return-Path: <owner-svn-ports-all@freebsd.org>
Delivered-To: svn-ports-all@mailman.ysv.freebsd.org
Received: from mx1.freebsd.org (mx1.freebsd.org
 [IPv6:2001:1900:2254:206a::19:1])
 by mailman.ysv.freebsd.org (Postfix) with ESMTP id E3F0F99BD43;
 Mon, 13 Jul 2015 08:39:08 +0000 (UTC)
 (envelope-from olgeni@FreeBSD.org)
Received: from repo.freebsd.org (repo.freebsd.org
 [IPv6:2001:1900:2254:2068::e6a:0])
 (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits))
 (Client did not present a certificate)
 by mx1.freebsd.org (Postfix) with ESMTPS id BA78F1E0F;
 Mon, 13 Jul 2015 08:39:08 +0000 (UTC)
 (envelope-from olgeni@FreeBSD.org)
Received: from repo.freebsd.org ([127.0.1.70])
 by repo.freebsd.org (8.14.9/8.14.9) with ESMTP id t6D8d8Om076209;
 Mon, 13 Jul 2015 08:39:08 GMT (envelope-from olgeni@FreeBSD.org)
Received: (from olgeni@localhost)
 by repo.freebsd.org (8.14.9/8.14.9/Submit) id t6D8d8Cp076208;
 Mon, 13 Jul 2015 08:39:08 GMT (envelope-from olgeni@FreeBSD.org)
Message-Id: <201507130839.t6D8d8Cp076208@repo.freebsd.org>
X-Authentication-Warning: repo.freebsd.org: olgeni set sender to
 olgeni@FreeBSD.org using -f
From: Jimmy Olgeni <olgeni@FreeBSD.org>
Date: Mon, 13 Jul 2015 08:39:08 +0000 (UTC)
To: ports-committers@freebsd.org, svn-ports-all@freebsd.org,
 svn-ports-head@freebsd.org
Subject: svn commit: r391882 - head/security/vuxml
X-SVN-Group: ports-head
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
X-BeenThere: svn-ports-all@freebsd.org
X-Mailman-Version: 2.1.20
Precedence: list
List-Id: SVN commit messages for the ports tree <svn-ports-all.freebsd.org>
List-Unsubscribe: <http://lists.freebsd.org/mailman/options/svn-ports-all>,
 <mailto:svn-ports-all-request@freebsd.org?subject=unsubscribe>
List-Archive: <http://lists.freebsd.org/pipermail/svn-ports-all/>;
List-Post: <mailto:svn-ports-all@freebsd.org>
List-Help: <mailto:svn-ports-all-request@freebsd.org?subject=help>
List-Subscribe: <http://lists.freebsd.org/mailman/listinfo/svn-ports-all>,
 <mailto:svn-ports-all-request@freebsd.org?subject=subscribe>
X-List-Received-Date: Mon, 13 Jul 2015 08:39:09 -0000

Author: olgeni
Date: Mon Jul 13 08:39:07 2015
New Revision: 391882
URL: https://svnweb.freebsd.org/changeset/ports/391882

Log:
  Document CSRF remote execution vulnerability for devel/ipython (CVE pending).
  
  PR:		201515
  Submitted by:	Jason Unovitch

Modified:
  head/security/vuxml/vuln.xml

Modified: head/security/vuxml/vuln.xml
==============================================================================
--- head/security/vuxml/vuln.xml	Mon Jul 13 07:47:22 2015	(r391881)
+++ head/security/vuxml/vuln.xml	Mon Jul 13 08:39:07 2015	(r391882)
@@ -58,6 +58,48 @@ Notes:
 
 -->
 <vuxml xmlns="http://www.vuxml.org/apps/vuxml-1">;
+  <vuln vid="81326883-2905-11e5-a4a5-002590263bf5">
+    <topic>devel/ipython -- CSRF possible remote execution vulnerability</topic>
+    <affects>
+      <package>
+	<name>ipython</name>
+	<range><ge>0.12</ge><lt>3.2.1</lt></range>
+      </package>
+    </affects>
+    <description>
+      <body xmlns="http://www.w3.org/1999/xhtml">;
+	<p>Kyle Kelley reports:</p>
+	<blockquote cite="http://seclists.org/oss-sec/2015/q3/92">;
+	  <p>Summary: POST requests exposed via the IPython REST API are
+	    vulnerable to cross-site request forgery (CSRF). Web pages on
+	    different domains can make non-AJAX POST requests to known IPython
+	    URLs, and IPython will honor them. The user's browser will
+	    automatically send IPython cookies along with the requests. The
+	    response is blocked by the Same-Origin Policy, but the request
+	    isn't.</p>
+	  <p>API paths with issues:</p>
+	  <ul>
+	    <li>POST /api/contents/&lt;path&gt;/&lt;file&gt;</li>
+	    <li>POST /api/contents/&lt;path&gt;/&lt;file&gt;/checkpoints</li>
+	    <li>POST /api/contents/&lt;path&gt;/&lt;file&gt;/checkpoints/&lt;checkpoint_id&gt;</li>
+	    <li>POST /api/kernels</li>
+	    <li>POST /api/kernels/&lt;kernel_id&gt;/&lt;action&gt;</li>
+	    <li>POST /api/sessions</li>
+	    <li>POST /api/clusters/&lt;cluster_id&gt;/&lt;action&gt;</li>
+	  </ul>
+	</blockquote>
+      </body>
+    </description>
+    <references>
+      <url>http://seclists.org/oss-sec/2015/q3/92</url>;
+      <url>http://ipython.org/ipython-doc/3/whatsnew/version3.html#ipython-3-2-1</url>;
+    </references>
+    <dates>
+      <discovery>2015-07-12</discovery>
+      <entry>2015-07-13</entry>
+    </dates>
+  </vuln>
+
   <vuln vid="379788f3-2900-11e5-a4a5-002590263bf5">
     <topic>freeradius -- insufficent CRL application vulnerability</topic>
     <affects>



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?alpine.BSF.2.20.1507130953160.76410>