Re: Is apache24-2.4.54 vulnerable ?

2022-06-10 Thread Jochen Neumeister
Am 10.06.22 um 16:36 schrieb Peter Blok: I think the question is this a typo in the vuln-2022.xml, because the changelog shows the CVE are fixed in 2.4.54 See: https://cgit.freebsd.org/ports/commit/?id=0bb1abdb20498df239e15e7f9e9eec33e2eec499 On 10 Jun 2022, at 15:20, Wall, Stephen

Re: current SA in vuxml

2020-03-20 Thread Jochen Neumeister
For you, Gordon ;-) Am 20.03.20 um 10:17 schrieb Miroslav Lachman: I don't know who is responsible for adding March entries in to vuxml at the same time as published it on the website but I really would like to say THANK YOU. Kind regards Miroslav Lachman

Re: PEAR packages potentially contain malicious code

2019-01-21 Thread Jochen Neumeister
Hi all, I just took net/pear-Net_SMTP as an example and compared it with "make makesum" SHA256 and SIZE. The values are the same. So the packages are not compromised. But today I will start testing all PEAR ports for different values. This can unfortunately take time. If a port has different v