$ tar xjf opera-10.60-6386.amd64.freebsd.tar.bz2
$ tar xjf opera-10.60-6386.i386.linux.tar.bz2
$ cd opera-10.60-6386.amd64.freebsd/lib/opera
$ mv operapluginwrapper operapluginwrapper.freebsd
$ mv ../../../opera-10.60-6386.i386.linux/lib/opera/operapluginwrapper operapluginwrapper.linux
drp said:The "pango -- integer overflow" vulnerability is keeping me from installing Flash 10, using FreeBSD 8.0. I'm going to wait until this is cleared up. This is not a double-post, because the other thread is specifically linux pango, but the linux pango integer overflow vulnerability I'm planning on just skipping on. I don't want to use DISABLE_VULNERABILITIES and just brush it off. I'm going to wait until it's updated or fixed, personally.
Andres said:The vulnerability has already been fixed. The question is whether anybody is motivated enough to identify the commit and backport it to f10, which is unmaintained.
===> Installing for nspluginwrapper-1.2.2_7
===> nspluginwrapper-1.2.2_7 depends on file: /compat/linux/bin/sh - found
===> nspluginwrapper-1.2.2_7 depends on file: /usr/local/libdata/pkgconfig/x11.pc - found
===> nspluginwrapper-1.2.2_7 depends on file: /usr/local/libdata/pkgconfig/xext.pc - found
===> nspluginwrapper-1.2.2_7 depends on file: /usr/local/libdata/pkgconfig/xt.pc - found
===> nspluginwrapper-1.2.2_7 depends on file: /compat/linux/usr/lib/libatk-1.0.so.0.2409.1 - found
===> nspluginwrapper-1.2.2_7 depends on file: /compat/linux/usr/lib/libcairo.so.2.10800.0 - found
===> nspluginwrapper-1.2.2_7 depends on file: /compat/linux/lib/libexpat.so.1 - found
===> nspluginwrapper-1.2.2_7 depends on file: /compat/linux/usr/lib/libfontconfig.so.1.3.0 - found
===> nspluginwrapper-1.2.2_7 depends on file: /compat/linux/usr/lib/libgtk-x11-2.0.so.0.1400.7 - not found
===> Verifying install for /compat/linux/usr/lib/libgtk-x11-2.0.so.0.1400.7 in /usr/ports/x11-toolkits/linux-f10-gtk2
===> Installing for linux-f10-gtk2-2.14.7_2
===> linux-f10-gtk2-2.14.7_2 depends on file: /compat/linux/bin/sh - found
===> linux-f10-gtk2-2.14.7_2 depends on file: /compat/linux/usr/lib/libatk-1.0.so.0.2409.1 - found
===> linux-f10-gtk2-2.14.7_2 depends on file: /compat/linux/usr/lib/libcairo.so.2.10800.0 - found
===> linux-f10-gtk2-2.14.7_2 depends on file: /compat/linux/lib/libexpat.so.1 - found
===> linux-f10-gtk2-2.14.7_2 depends on file: /compat/linux/usr/lib/libfontconfig.so.1.3.0 - found
===> linux-f10-gtk2-2.14.7_2 depends on file: /compat/linux/usr/lib/libjpeg.so.62.0.0 - found
===> linux-f10-gtk2-2.14.7_2 depends on file: /compat/linux/usr/lib/libpango-1.0.so.0.2203.0 - not found
===> Verifying install for /compat/linux/usr/lib/libpango-1.0.so.0.2203.0 in /usr/ports/x11-toolkits/linux-f10-pango
===> linux-f10-pango-1.22.3_1 has known vulnerabilities:
=> pango -- integer overflow.
Reference: <http://portaudit.FreeBSD.org/4b172278-3f46-11de-becb-001cc0377035.html>
=> Please update your ports tree and try again.
*** Error code 1
Stop in /usr/ports/x11-toolkits/linux-f10-pango.
*** Error code 1
Stop in /usr/ports/x11-toolkits/linux-f10-gtk2.
*** Error code 1
Stop in /usr/ports/www/nspluginwrapper.
Caliante said:Code:===> Verifying install for /compat/linux/usr/lib/libpango-1.0.so.0.2203.0 in /usr/ports/x11-toolkits/linux-f10-pango ===> linux-f10-pango-1.22.3_1 has known vulnerabilities: => pango -- integer overflow. Reference: <http://portaudit.FreeBSD.org/4b172278-3f46-11de-becb-001cc0377035.html> => Please update your ports tree and try again. *** Error code 1 Stop in /usr/ports/x11-toolkits/linux-f10-pango. *** Error code 1 Stop in /usr/ports/x11-toolkits/linux-f10-gtk2. *** Error code 1 Stop in /usr/ports/www/nspluginwrapper.
Would anybody happen to know a solution/workaround?
# cd /usr/ports/x11-toolkits/linux-f10-pango
# make DISABLE_VULNERABILITIES=yes install clean