mail/postfix-policyd-spf relies on vulnerable mail/libspf2-10

Uffe R. B. Andersen urb at twe.net
Sat Aug 27 18:07:29 UTC 2011


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Den 26-08-2011 22:22, Doug Barton skrev:
> Howdy,
> 
> Doing some port updates and noticed that mail/postfix-policyd-spf
> relies on mail/libspf2-10, which according to 
> http://portaudit.FreeBSD.org/2ddbfd29-a455-11dd-a55e-00163e000016.html
>
> 
is vulnerable. There is a port of mail/libspf2 which is not vulnerable,
> is it possible to update mail/postfix-policyd-spf to rely on it
> instead?

libspf2 port is currently libspf2-1.2.9_1 and according to the page
you refer to, the vulnerability affects libspf2 <1.2.8.

- -- 
Med venlig hilsen - Sincerely
Uffe R. B. Andersen - mailto:urb at twe.net
http://blog.andersen.nu/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.12 (MingW32)

iEYEARECAAYFAk5ZMk4ACgkQxC95nUQcrphdDACgylOM4Jw4D+JHh4aHbI1e6Lgy
XgoAoMk09edbD58jkuD4Noar+boPiSmI
=TRMu
-----END PGP SIGNATURE-----


More information about the freebsd-ports mailing list