If the port's source is already patched but it's just the port skeleton that needs updating then it shouldn't be a problem. Most of us are probably quite capable to change the port's Makefile. I know I am
It would also help to increase awareness of the bug, not only for the bad guys but for us good guys too. Everyone should be able to review the impact of said bug :e
BTW, if the vendor is lazy enough to not fix the vulnerability within a few weeks I think you can just go ahead: disclose details and mark the port FORBIDDEN.
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.