Re: [UPDATE] CVE-2017-16248: www/p5-Catalyst-Plugin-Static-Simple

2019-01-08 Thread Andrew Hewus Fresh
On Mon, Jan 07, 2019 at 09:08:44AM +0200, Paul Irofti wrote: > > Same here, but i still made a diff for -stable as an exercise when it > > happened, if needed :) > > OK for the -stable diff. Andrew, will you commit this bit as well? If > not, I will commit it myself when/if someone commits the upd

Re: [UPDATE] CVE-2017-16248: www/p5-Catalyst-Plugin-Static-Simple

2019-01-06 Thread Paul Irofti
> Same here, but i still made a diff for -stable as an exercise when it > happened, if needed :) OK for the -stable diff. Andrew, will you commit this bit as well? If not, I will commit it myself when/if someone commits the update to -current. > Index: Makefile > =

Re: [UPDATE] CVE-2017-16248: www/p5-Catalyst-Plugin-Static-Simple

2019-01-06 Thread Daniel Jakots
On Sun, 6 Jan 2019 22:11:28 -0500, Daniel Jakots wrote: > On Sun, 6 Jan 2019 19:51:25 -0700, Andrew Hewus Fresh > wrote: > > > On Mon, Dec 17, 2018 at 03:21:27AM +0100, Charlene Wendling wrote: > > > Hi, > > > > > > I'm adding the quirks info as well. Can someone check this out > > > please

Re: [UPDATE] CVE-2017-16248: www/p5-Catalyst-Plugin-Static-Simple

2019-01-06 Thread Daniel Jakots
On Sun, 6 Jan 2019 19:51:25 -0700, Andrew Hewus Fresh wrote: > On Mon, Dec 17, 2018 at 03:21:27AM +0100, Charlene Wendling wrote: > > Hi, > > > > I'm adding the quirks info as well. Can someone check this out > > please? > > OK afresh1@, although I don't have a firm enough grasp on Quirks t

Re: [UPDATE] CVE-2017-16248: www/p5-Catalyst-Plugin-Static-Simple

2019-01-06 Thread Charlene Wendling
On Sun, 6 Jan 2019 19:51:25 -0700 Andrew Hewus Fresh wrote: > On Mon, Dec 17, 2018 at 03:21:27AM +0100, Charlene Wendling wrote: > > Hi, > > > > I'm adding the quirks info as well. Can someone check this out > > please? > > OK afresh1@, although I don't have a firm enough grasp on Quirks to >

Re: [UPDATE] CVE-2017-16248: www/p5-Catalyst-Plugin-Static-Simple

2019-01-06 Thread Andrew Hewus Fresh
On Mon, Dec 17, 2018 at 03:21:27AM +0100, Charlene Wendling wrote: > Hi, > > I'm adding the quirks info as well. Can someone check this out please? OK afresh1@, although I don't have a firm enough grasp on Quirks to know for sure this is right. I also don't know whether it should be backported

Re: [UPDATE] CVE-2017-16248: www/p5-Catalyst-Plugin-Static-Simple

2018-12-16 Thread Charlene Wendling
Hi, I'm adding the quirks info as well. Can someone check this out please? Charlène. Index: devel/quirks/Makefile === RCS file: /cvs/ports/devel/quirks/Makefile,v retrieving revision 1.670 diff -u -p -r1.670 Makefile --- devel/q

[UPDATE] CVE-2017-16248: www/p5-Catalyst-Plugin-Static-Simple

2018-12-07 Thread Charlene Wendling
Hi ports, I'm proposing here an update for www/p5-Catalyst-Plugin-Static-Simple, from 0.29 to 0.36, that also fixes CVE-2017-16248 [1] (directory traversal) by the way. What's new upstream (full changelog there [2]): - Fix installation for Perl 5.26+ - Relax/fix some tests - Change configuratio