security/gnutls update when...

Jason Hellenthal jhellenthal at dataix.net
Thu Mar 29 23:30:43 UTC 2012


There are no problems with this that can be seen. Thank you Roman.

On Sun, Mar 25, 2012 at 07:26:34PM +0400, Roman Bogorodskiy wrote:
>   Jason Hellenthal wrote:
> 
> > 
> > Apparently this port has fell two versions behind. Is there anything
> > that is going to happen to update it to the current stable version ?
> > 
> > 
> > These advisories have been out for a week now. And the current version
> > is 2.12.18.
> > 
> > 
> > Database created: Sat Mar 24 13:15:03 EDT 2012
> > Affected package: gnutls-2.12.16
> > Type of problem: libtasn1 -- ASN.1 length decoding vulnerability.
> > Reference:
> > http://portaudit.FreeBSD.org/2e7e9072-73a0-11e1-a883-001cc0a36e12.html
> > 
> > Affected package: gnutls-2.12.16
> > Type of problem: gnutls -- possible overflow/Denial of service
> > vulnerabilities.
> > Reference:
> > http://portaudit.FreeBSD.org/aecee357-739e-11e1-a883-001cc0a36e12.html
> > 
> > 2 problem(s) in your installed packages found.
> 
> The port was updated to 2.12.18 with some hacks to prevent shlib version
> bump. Please report if you have any problems with that.
> 
> Roman Bogorodskiy



-- 
;s =;
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 455 bytes
Desc: not available
Url : http://lists.freebsd.org/pipermail/freebsd-ports/attachments/20120329/adec0015/attachment.pgp


More information about the freebsd-ports mailing list