port maintenance

  • Thread starter Thread starter Anonymous
  • Start date Start date
A

Anonymous

Guest
When I run portaudit -a I got:


Affected package: mDNSResponder-214
Type of problem: mDNSResponder -- corrupted stack crash when parsing bad
resolv.conf.
Reference:
<http://portaudit.FreeBSD.org/1cd87e2a-81e3-11df-81d8-00262d5ed8ee.html>

Affected package: opera-10.10.20091120_2
Type of problem: opera -- Data URIs can be used to allow cross-site
scripting. Reference:
<http://portaudit.FreeBSD.org/77b9f9bc-7fdf-11df-8a8d-0008743bf21a.html>

Affected package: linux-f10-pango-1.22.3_1
Type of problem: pango -- integer overflow.
Reference: <http://portaudit.FreeBSD.org/4b172278-3f46-11de-
becb-001cc0377035.html>

3 problem(s) in your installed packages found.

You are advised to update or deinstall the affected package(s)
immediately.

It is sad that port mDNSResponse is without maintainer:

mDNSResponder 214 net
This port version is marked as vulnerable.
Apple's mDNSResponder

There is no maintainer for this port.

Opera has problem more or one month, update 10.11 was available long time ago but not in the FreeBSD ports.
For linux pango I understand because it is an old version which Fedora doesn't use anymore (other Linux distros too).

Thanks.
 
So what are you saying?

As for opera, I think opera itself is maintaining opera port, btw, zloidemon update opera port to lates and submitted it to opera port maintainer (freebsd-maintainer at opera.com)

so I hope to see opera in port updated soon
 
killasmurf86 said:
So what are you saying?

As for opera, I think opera itself is maintaining opera port, btw, zloidemon update opera port to lates and submitted it to opera port maintainer (freebsd-maintainer at opera.com)

so I hope to see opera in port updated soon

...that keeping ports which has problems without maintainer is VERY bad and it is not responsible to users.
 
lumiwa said:
...that keeping ports which has problems without maintainer is VERY bad and it is not responsible to users.

Do I hear someone volunteering?
 
SirDice said:
Do I hear someone volunteering?

I am sorry, no. I don't know enough but it is bad and there are no responsibility to the users anywhere.
 
actually, you can download a freeBSD version from opera itself!
yes really. from the website. v10.6 for freebsd.

I tried it but it always crashed on closing -
invoking a bugzilla type dialog.

but I only did a local install.
I just installed the latest port instead.
 
bigearsbilly said:
actually, you can download a freeBSD version from opera itself!
yes really. from the website. v10.6 for freebsd.

I tried it but it always crashed on closing -
invoking a bugzilla type dialog.

but I only did a local install.
I just installed the latest port instead.

Opera is not a problem, IMO a bigger problem is
Affected package: mDNSResponder-214
Type of problem: mDNSResponder -- corrupted stack crash when parsing bad
resolv.conf.
Reference:
<http://portaudit.FreeBSD.org/1cd87e2a-81e3-11df-81d8-00262d5ed8ee.html>
 
Back
Top