Re: portsdb output and portaudit question



jan gestre wrote:
i was trying to portupgrade ruby coz portaudit is complaining of
vulnerabilities, i did run cvsup and portsdb -Uu before portupgrade, at
first i couldn't upgrade ruby coz portupgrade is complaining maybe coz
portaudit but someone in the list suggested this:

# portupgrade -Rr -m DISABLE_VULNERABILITIES="yes" ruby

whoala it installed the ruby package but still portaudit complains even
though the installed version is current which has no vulnerability. is this
normal? any way to fix these?


This is expected behavior. The ports system will let you upgrade a
vulnerable port without complaint. It will however complain if you try
to install (or upgrade to) a version that has vulnerabilities. Since
portupgrade complained, it's no surprise that portaudit also complains
after the forced upgrade.

This means that either the version in ports aren't fixed yet (the
existence of a vulnerability of a prior version does not imply that said
vulnerability is fixed in the current version), or that your ports tree
is out of date. Seeing that the latter is not true, I would say you
just have to wait for an updated version to appear in ports.

You can create an account at freshports and ad ruby to your "watch
list". That means you'll get notified when new versions arrive.


Svein Halvor

Attachment: signature.asc
Description: OpenPGP digital signature



Relevant Pages

  • Re: Bad sectors... how bad?
    ... > complexity contains bugs and software written to fix bugs will contain ... >> and the $100 upgrade is that the upgrade looks for previous installs. ... online to fully update all the patches. ... > So when a vulnerability is found you want to remain vulnerable for 6 ...
    (alt.comp.hardware.pc-homebuilt)
  • [Full-disclosure] [SECURITY] [DSA 746-1] New packages fix remote command execution in phpgroupware
    ... Vulnerability: remote command execution ... execution of arbitrary commands on the server running phpgroupware. ... We recommend that you upgrade your phpgroupware package. ... If you are using the apt-get package manager, ...
    (Full-Disclosure)
  • RE: ALOM Question
    ... The Upgrade worked great and now I can connect remotely via ssh. ... You are running a version of OpenSSH older than OpenSSH 3.2.1 ... vulnerability may be avoided by enabling UsePrivilegeSeparation. ...
    (SunManagers)
  • [SECURITY] [DSA 746-1] New packages fix remote command execution in phpgroupware
    ... Vulnerability: remote command execution ... execution of arbitrary commands on the server running phpgroupware. ... We recommend that you upgrade your phpgroupware package. ... If you are using the apt-get package manager, ...
    (Bugtraq)
  • [CLA-2003:614] Conectiva Security Announcement - sendmail
    ... SUMMARY: Buffer overflow vulnerability ... All sendmail users should upgrade immediately. ... UPDATED PACKAGES ... Detailed instructions reagarding the use of apt and upgrade examples ...
    (Bugtraq)