[Bug 201704] lang/groovy: remote execution of untrusted code vulnerability in 2.3.9

bugzilla-noreply at freebsd.org bugzilla-noreply at freebsd.org
Sat Aug 8 12:03:30 UTC 2015


https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=201704

--- Comment #3 from Jason Unovitch <jason.unovitch at gmail.com> ---
Created attachment 159662
  --> https://bugs.freebsd.org/bugzilla/attachment.cgi?id=159662&action=edit
Poudriere testport log from 10.1-RELEASE jail

QA:

Portlint:

Portlint is showing a false positive as there are multiple DISTFILES in the
form of DISTFILES and DOCS_DISTFILES for the DOCS option.

portlint -ac

WARN: Makefile: use of DISTFILES with single file discouraged. distribution
filename should be set by DISTNAME and EXTRACT_SUFX.
WARN: Makefile: DISTFILES/DISTNAME affects WRKSRC. take caution when changing
them.
0 fatal errors and 2 warnings found.

Poudriere:

Log attached and issues addressed were commented on above.  The patch was
tested across a range of Poudriere jails:

8.4-RELEASE-p36      amd64
8.4-RELEASE-p36      i386
9.3-RELEASE-p21      amd6
9.3-RELEASE-p21      i386
10.1-RELEASE-p16     amd64
10.1-RELEASE-p16     i386
10.2-RC2             amd64
10.2-RC2             i386
11.0-CURRENT r286208 amd64
11.0-CURRENT r286208 i386

Runtime:

Basic sanity checking via the groovysh command in a Poudriere jail.

root at 110amd64-default:/usr/local/bin # groovysh
Groovy Shell (2.4.4, JVM: 1.7.0_80)
Type ':help' or ':h' for help.
-------------------------------------------------------------------------------------------------------------------------------------
groovy:000> println "test"
test
===> null
groovy:000> :exit

-- 
You are receiving this mail because:
You are the assignee for the bug.


More information about the freebsd-ports-bugs mailing list