diff options
author | Matthias Andree <mandree@FreeBSD.org> | 2020-05-07 20:04:23 +0000 |
---|---|---|
committer | Matthias Andree <mandree@FreeBSD.org> | 2020-05-07 20:04:23 +0000 |
commit | 717726c568ba8486a0ec586a39d29aaec73447ea (patch) | |
tree | ab55d612db19f8f17b9223aeaddc7a60e29d32ea /mail/mailman | |
parent | 49a38bef41a2dbbc0e182295579f964c3ae75612 (diff) | |
download | ports-717726c568ba8486a0ec586a39d29aaec73447ea.tar.gz ports-717726c568ba8486a0ec586a39d29aaec73447ea.zip |
mail/mailman: security update to 2.1.33
Fixing another content injection vulnerability,
this time via private archive login if the list's roster visibility
(private_roster) setting is 'Anyone'.
https://bugs.launchpad.net/mailman/+bug/1877379
https://launchpadlibrarian.net/478684932/private.diff
https://mail.python.org/archives/list/mailman-developers@python.org/thread/SYBIZ3MNSQZLKN6PVKO7ZKR7QMOBMS45/
Security: 88760f4d-8ef7-11ea-a66d-4b2ef158be83
Notes
Notes:
svn path=/head/; revision=534286
Diffstat (limited to 'mail/mailman')
-rw-r--r-- | mail/mailman/Makefile | 8 | ||||
-rw-r--r-- | mail/mailman/distinfo | 10 |
2 files changed, 9 insertions, 9 deletions
diff --git a/mail/mailman/Makefile b/mail/mailman/Makefile index 3e90ed1b7681..5358da564423 100644 --- a/mail/mailman/Makefile +++ b/mail/mailman/Makefile @@ -2,7 +2,7 @@ # $FreeBSD$ PORTNAME= mailman -DISTVERSION= 2.1.32 +DISTVERSION= 2.1.33 PORTREVISION= 0 CATEGORIES= mail MASTER_SITES= GNU \ @@ -128,11 +128,11 @@ MAIL_GID?= _smtpd PKGNAMESUFFIX+= -with-htdig # how to create PATCHFILES: #X identify what is the version of msapiro's patches corresponding to the release. -#X fetch http://bazaar.launchpad.net/~msapiro/mailman/htdig/tarball/1814 +#X fetch http://bazaar.launchpad.net/~msapiro/mailman/htdig/tarball/1815 #X unpack this tarball, and the original distfile -#X diff -NEur original-unpack bazaar-unpack | xz --best -c >msapiro-htdig-1814.patch.xz +#X diff -NEur original-unpack bazaar-unpack | xz --best -c >msapiro-htdig-1815.patch.xz #X upload the latter with mode 0644 or similar to freefall's public_distfiles/ directory -_HTDIGREV= 1814 +_HTDIGREV= 1815 PATCHFILES+= msapiro-htdig-${_HTDIGREV}.patch.xz RUN_DEPENDS+= htdig:textproc/htdig PLIST_SUB+= SUB_HTDIG="" diff --git a/mail/mailman/distinfo b/mail/mailman/distinfo index 2b8cfbc6ec9f..48e6c5388617 100644 --- a/mail/mailman/distinfo +++ b/mail/mailman/distinfo @@ -1,5 +1,5 @@ -TIMESTAMP = 1588720179 -SHA256 (mailman/mailman-2.1.32.tgz) = 3755322b23cb41cd726407658dc1ae0d2dcc9887c9239945491a551933505e5d -SIZE (mailman/mailman-2.1.32.tgz) = 9413055 -SHA256 (mailman/msapiro-htdig-1814.patch.xz) = 91c69185f06e2d581d5a4429e678b740074016511557dae4aa5ee7ded0be349c -SIZE (mailman/msapiro-htdig-1814.patch.xz) = 50400 +TIMESTAMP = 1588881655 +SHA256 (mailman/mailman-2.1.33.tgz) = 6d7e81753c78120f479a275ea623194cac188a3daf301eb76aa9d39a942d5234 +SIZE (mailman/mailman-2.1.33.tgz) = 9412979 +SHA256 (mailman/msapiro-htdig-1815.patch.xz) = 740aeb99b1e25706ad32bd73ac2035f758b5ec566856d6816aed76496931563b +SIZE (mailman/msapiro-htdig-1815.patch.xz) = 50408 |