[Bug 241422] textproc/unoconv: Update to 0.8.2, Fix CVE-2019-17400

bugzilla-noreply at freebsd.org bugzilla-noreply at freebsd.org
Sun Nov 3 12:17:51 UTC 2019


https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=241422

Raphael Kubo da Costa <rakuco at FreeBSD.org> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |rakuco at FreeBSD.org

--- Comment #7 from Raphael Kubo da Costa <rakuco at FreeBSD.org> ---
files/patch_unoconv is not in a unified diff format -- see how there are
multiple "<<<<< HEAD", "======" and ">>>>> " lines in there.

If the upstream commit applies cleanly on 0.8.2, I suggest just downloading the
commit from GitHub in a diff format
(https://github.com/unoconv/unoconv/commit/acfac594e643f9c44f1c3b8d6d8957190a4d76f2.diff)
and removing the "a/" and "b/" from the paths.

The VuXML entry needs to be adjusted too:
- The <topic> entry usually begins with "$packagename --" (so "unoconv -- SSRF
and local file inclusion").
- The <p> entry inside the <blockquote> has a leading "escription" that
shouldn't be there.
- You should add <freebsdpr> and <cvename> entries to <references>

-- 
You are receiving this mail because:
You are the assignee for the bug.


More information about the freebsd-ports-bugs mailing list