port php5 - what I am supposed to do here?

Matt Emmerton matt at gsicomp.on.ca
Thu Oct 5 20:52:22 PDT 2006

> Hello List,
> Portuadit telles my about the "open_basedir Race Condition
> Vulnerability", OK.
> By reading the advisory on
> http://www.hardened-php.net/advisory_082006.132.html I can safely say
> this does not apply to our environment, we don't use open_basedir or
> safe_mode and Suhosin is planned anyway (after test).
> With a "portsnap fetch update" I get a new version php5-5.1.6_1 in my
> portstree, OK.
> But "portmanager -u" or even manually with "make install clean"
> everything fails with the following message:
> ===>  php5-5.1.6_1 has known vulnerabilities:
> => php -- open_basedir Race Condition Vulnerability.
>    Reference:
> => Please update your ports tree and try again.
> *** Error code 1
> So what to do now?

You've established that the security issue doesn't apply to your

1) Add "DISABLE_VULNERABILITIES=yes" to /etc/make.conf
2) Run "portupgrade -u" or "make install clean"

Matt Emmerton

More information about the freebsd-questions mailing list