From owner-svn-ports-branches@freebsd.org Wed May 23 07:52:06 2018 Return-Path: Delivered-To: svn-ports-branches@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id F2C09EF3D80; Wed, 23 May 2018 07:52:05 +0000 (UTC) (envelope-from krion@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "mxrelay.nyi.freebsd.org", Issuer "Let's Encrypt Authority X3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id A366F7D194; Wed, 23 May 2018 07:52:05 +0000 (UTC) (envelope-from krion@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 842B120004; Wed, 23 May 2018 07:52:05 +0000 (UTC) (envelope-from krion@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id w4N7q54N070164; Wed, 23 May 2018 07:52:05 GMT (envelope-from krion@FreeBSD.org) Received: (from krion@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id w4N7q5ge070162; Wed, 23 May 2018 07:52:05 GMT (envelope-from krion@FreeBSD.org) Message-Id: <201805230752.w4N7q5ge070162@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: krion set sender to krion@FreeBSD.org using -f From: Kirill Ponomarev Date: Wed, 23 May 2018 07:52:05 +0000 (UTC) To: ports-committers@freebsd.org, svn-ports-all@freebsd.org, svn-ports-branches@freebsd.org Subject: svn commit: r470685 - branches/2018Q2/mail/sympa X-SVN-Group: ports-branches X-SVN-Commit-Author: krion X-SVN-Commit-Paths: branches/2018Q2/mail/sympa X-SVN-Commit-Revision: 470685 X-SVN-Commit-Repository: ports MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-ports-branches@freebsd.org X-Mailman-Version: 2.1.26 Precedence: list List-Id: SVN commit messages for all the branches of the ports tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 23 May 2018 07:52:06 -0000 Author: krion Date: Wed May 23 07:52:04 2018 New Revision: 470685 URL: https://svnweb.freebsd.org/changeset/ports/470685 Log: MFH: r470654 Security update to 6.2.32 Description: A vulnerability has been discovered in Sympa web interface that allows write access to files on the server filesystem. This flaw allows to create or modify any file writable by the Sympa user, located on the server filesystem, using the function of Sympa web interface template file saving. PR: 227642 Submitted by: maintainer Approved by: ports-secteam Modified: branches/2018Q2/mail/sympa/Makefile branches/2018Q2/mail/sympa/distinfo Directory Properties: branches/2018Q2/ (props changed) Modified: branches/2018Q2/mail/sympa/Makefile ============================================================================== --- branches/2018Q2/mail/sympa/Makefile Wed May 23 07:51:02 2018 (r470684) +++ branches/2018Q2/mail/sympa/Makefile Wed May 23 07:52:04 2018 (r470685) @@ -2,7 +2,7 @@ # $FreeBSD$ PORTNAME= sympa -DISTVERSION= 6.2.30 +DISTVERSION= 6.2.32 CATEGORIES= mail MAINTAINER= dgeo@centrale-marseille.fr Modified: branches/2018Q2/mail/sympa/distinfo ============================================================================== --- branches/2018Q2/mail/sympa/distinfo Wed May 23 07:51:02 2018 (r470684) +++ branches/2018Q2/mail/sympa/distinfo Wed May 23 07:52:04 2018 (r470685) @@ -1,3 +1,3 @@ -TIMESTAMP = 1522755872 -SHA256 (sympa-community-sympa-6.2.30_GH0.tar.gz) = 3613738824c482719461675f93672811ba0618fb53caa5d8e6c9c956bb6d9fb1 -SIZE (sympa-community-sympa-6.2.30_GH0.tar.gz) = 10303628 +TIMESTAMP = 1524158051 +SHA256 (sympa-community-sympa-6.2.32_GH0.tar.gz) = ab3a17826846e74fe222f482aa6ab68fa5349f726dc1700d4512c348ab82807a +SIZE (sympa-community-sympa-6.2.32_GH0.tar.gz) = 10305699