notbugAs an Amazon Associate I earn from qualifying purchases.
Want a good read? Try FreeBSD Mastery: Jails (IT Mastery Book 15)
Want a good monitor light? See my photosAll times are UTC
Ukraine
Sanity Test Failure
Thursday, 17 Oct 2013
19:35 ohauer search for other commits by this committer
  • devel/bugzilla Bug-tracking system developed by Mozilla Project Deleted Refresh  This port version is marked as vulnerable. 
    • devel/bugzilla40 Bug-tracking system developed by Mozilla Project Deleted Refresh Forbidden Expired Ignore  This port version is marked as vulnerable. 
      • devel/bugzilla42 Bug-tracking system developed by Mozilla Project Deleted Refresh Forbidden Expired Ignore  This port version is marked as vulnerable. 
        • devel/bugzilla44 Bug-tracking system developed by Mozilla Project Refresh
          • german/bugzilla German localization for Bugzilla Deleted Refresh
            • german/bugzilla40 German localization for Bugzilla Deleted Refresh
              • german/bugzilla42 German localization for Bugzilla Deleted Refresh
                • german/bugzilla44 German localization for Bugzilla Refresh
                  • japanese/bugzilla Japanese localization for Bugzilla Deleted Refresh
                    • japanese/bugzilla40 Japanese localization for Bugzilla Deleted Refresh
                                (Only the first 10 of 16 items in this commit are shown above. View all ports for this commit)
                                - update to latest release [1]
                                - use PKGNAMESUFFIX instead LATEST_LINK
                                - whitespace cleanup
                                - svn mv */bugzilla to */bugzilla40
                                - add vuxml entry
                                
                                4.4.1, 4.2.7, and 4.0.11 Security Advisory
                                Wednesday Oct 16th, 2013
                                
                                Summary
                                =======
                                
                                Bugzilla is a Web-based bug-tracking system used by a large number of
                                software projects. The following security issues have been discovered
                                in Bugzilla:
                                
                                * A CSRF vulnerability in process_bug.cgi affecting Bugzilla 4.4 only
                                  can lead to a bug being edited without the user consent.
                                
                                * A CSRF vulnerability in attachment.cgi can lead to an attachment
                                  being edited without the user consent.
                                
                                * Several unfiltered parameters when editing flagtypes can lead to XSS.
                                
                                * Due to an incomplete fix for CVE-2012-4189, some incorrectly filtered
                                  field values in tabular reports can lead to XSS.
                                
                                All affected installations are encouraged to upgrade as soon as
                                possible.
                                
                                [1]  even bugzilla40 gets upstream fixes an upgrade to bugzilla42/44 is
                                recommend
                                
                                Security:	vid e135f0c9-375f-11e3-80b7-20cf30e32f6d
                                		CVE-2013-1733
                                		CVE-2013-1734
                                		CVE-2013-1742
                                		CVE-2013-1743
                                Original commitRevision:330666 

Sanity Test Results

japanese/bugzilla40:

This command (FreshPorts code 1):

/usr/local/bin/sudo /usr/sbin/chroot -u dan /usr/FreshPorts/ports-jail
/make-port.sh japanese/bugzilla40
2>/tmp/FreshPorts.japanese.bugzilla40.make-error.2013.10.17.19.44.19.70457

produced this error:

Error message is: "/usr/ports/japanese/bugzilla40/Makefile", line 18: Could
not find
/usr/ports/japanese/bugzilla40/../../devel/bugzilla/Makefile.common
make: fatal errors encountered -- cannot continue

german/bugzilla40:

This command (FreshPorts code 1):

/usr/local/bin/sudo /usr/sbin/chroot -u dan /usr/FreshPorts/ports-jail
/make-port.sh german/bugzilla40
2>/tmp/FreshPorts.german.bugzilla40.make-error.2013.10.17.19.44.19.70457

produced this error:

Error message is: "/usr/ports/german/bugzilla40/Makefile", line 17: Could
not find /usr/ports/german/bugzilla40/../../devel/bugzilla/Makefile.common
make: fatal errors encountered -- cannot continue

russian/bugzilla40:

This command (FreshPorts code 1):

/usr/local/bin/sudo /usr/sbin/chroot -u dan /usr/FreshPorts/ports-jail
/make-port.sh russian/bugzilla40
2>/tmp/FreshPorts.russian.bugzilla40.make-error.2013.10.17.19.44.20.70457

produced this error:

Error message is: "/usr/ports/russian/bugzilla40/Makefile", line 17: Could
not find /usr/ports/russian/bugzilla40/../../devel/bugzilla/Makefile.common
make: fatal errors encountered -- cannot continue