tabthorpe at freebsd.org
Tue Sep 1 13:14:03 UTC 2009
-----BEGIN PGP SIGNED MESSAGE-----
On September 1, 2009 07:36:56 am Johan Hendriks wrote:
> Since when are we using release candidate's of squirrelmail in the ports
> I think we need an devel port for that so that we can use the stable
> squirrelmail port as stable, and use the devel port if we want to use
> beta's and release candidates.
Once the XSS vulnerability was brought to my attention,
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2964 (plus related
links) I decided to err on the side of caution, and upgrade to a more stable
version, albeit an RC.
Yes I know I could have patched it, but chose not to. I am hoping that the
release branch will be out sooner than later.
Thomas Abthorpe | FreeBSD Committer
tabthorpe at FreeBSD.org | http://people.freebsd.org/~tabthorpe
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.12 (FreeBSD)
-----END PGP SIGNATURE-----
More information about the freebsd-ports