xterm vuln

RW rwmaillists at googlemail.com
Tue Jan 6 13:06:29 UTC 2009


On Tue, 6 Jan 2009 06:55:04 +0100
Martin Wilke <miwi at FreeBSD.org> wrote:

> On Tue, Jan 06, 2009 at 01:51:29PM +0900, Randy Bush wrote:
> > so portaudit reported an xterm vuln.  i cvsupped which did change
> > things in xterm.
> > ...
> > ===>  Cleaning for xterm-238
> > ===>  xterm-238 has known vulnerabilities:
> > => xterm -- DECRQSS remote command execution vulnerability.
> >     Reference: 
> > <http://www.FreeBSD.org/ports/portaudit/d5e1aac8-db0b-11dd-ae30-001cc0377035.html>
> > => Please update your ports tree and try again.
> > *** Error code 1


> Was fixed few hours ago :).

But it's not just a case of updating the ports tree, you also need
to do a portaudit -F. 


More information about the freebsd-ports mailing list