Subject: Re: CVS commit: pkgsrc/databases/gnats
To: grant beattie <grant@NetBSD.org>
From: Julio M. Merino Vidal <jmmv@menta.net>
List: pkgsrc-changes
Date: 11/15/2004 14:33:28
On Mon, 15 Nov 2004 22:49:58 +1100
grant beattie <grant@NetBSD.org> wrote:

> On Sun, Nov 14, 2004 at 01:50:49PM +0100, Julio M. Merino Vidal wrote:
> 
> > > Modified Files:
> > > 	pkgsrc/databases/gnats: Makefile PLIST distinfo
> > > 
> > > Log Message:
> > > Update to gnats 4.0.1.
> > > Fixes vulnerabilities described in
> > > http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0623 .
> > 
> > I guess this has to be pulled up to the 2004Q3 branch (don't have a
> > local copy of it to verify that the fix applies cleanly).
> 
> this vulnerability only applies to GNATS 4.0.0, and the branch is at
> GNATS 3.x, so no need for a pullup.

Well, I've just checked and 4.0 is in the branch, but known as gnats4
(soren@ moved gnats4 over gnats, as pointed out in another mail).  So the
fix still applies.

Cheers,

-- 
Julio M. Merino Vidal <jmmv@menta.net>
http://www.livejournal.com/users/jmmv/
The NetBSD Project - http://www.NetBSD.org/