math/sage security risk

Eitan Adler lists at eitanadler.com
Mon May 28 18:39:15 UTC 2012


On 28 May 2012 10:14, Stephen Montgomery-Smith <stephen at missouri.edu> wrote:
> After my recent conversations about creating a print/texlive-install port, I
> realize that my math/sage port might have a security risk.  This only
> happens if the user selects additional optional packages.  But the optional
> packages are downloaded post-fetch.
>
> I'll make some immediate band-aid changes to the port to switch this off,
> but I'll think through the issue in the days to come.

adding ports-security to cc so we could track the issue

-- 
Eitan Adler


More information about the freebsd-ports mailing list