www/dotproject out of date and vulnerable

Kris Kennaway kris at obsecurity.org
Tue Sep 19 17:56:44 PDT 2006


On Tue, Sep 19, 2006 at 05:15:45PM -0700, Fred Cox wrote:

> Actually, it doesn't.  It goes ahead and installs it,
> even though I specified these:
> 
> WITH_MYSQL=     yes
> WANT_MYSQL_VER= 323
> IGNORE_WITH_MYSQL=5
> 
> Starting with a system that had no MySQL or PHP
> installed on it, I did a make install in the
> dotproject port with the Makefile and distinfo I
> specified earlier.
> 
> It seems to look for mysql.so, and if that's found, it
> doesn't worry about the version.

OK, so it's just silently broken, which is worse.

> See the log at http://fcox.net/dp.log, when no mysql
> or php was installed on the system.
> 
> Perhaps this is a bug in the dependencies system.

Dunno without investigating.  Anyway, the correct solution is the
same.

Kris


More information about the freebsd-ports mailing list