Re: Portaudit claims nginx 1.2.x vulnerable

2013-05-16 Thread Michael Gmelin
On Thu, 16 May 2013 15:36:28 -0700 Xin Li wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA512 > > Hi, Michael, > > On 05/16/13 15:04, Michael Gmelin wrote: > > Hi, > > > > I just noticed that portaudit considers www/nginx >=1.2.0,1 > > <1.4.1,1 to be affected by CVE-2013-2028, creating

Re: Portaudit claims nginx 1.2.x vulnerable

2013-05-16 Thread Xin Li
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Hi, Michael, On 05/16/13 15:04, Michael Gmelin wrote: > Hi, > > I just noticed that portaudit considers www/nginx >=1.2.0,1 > <1.4.1,1 to be affected by CVE-2013-2028, creating noise and > preventing installation: > > http://portaudit.freebsd.org/

Portaudit claims nginx 1.2.x vulnerable

2013-05-16 Thread Michael Gmelin
Hi, I just noticed that portaudit considers www/nginx >=1.2.0,1 <1.4.1,1 to be affected by CVE-2013-2028, creating noise and preventing installation: http://portaudit.freebsd.org/efaa4071-b700-11e2-b1b9-f0def16c5c1b.html According to the announcement on the nginx mailing list, only versions of n