From nobody@FreeBSD.org  Mon Apr 22 09:21:02 2002
Return-Path: <nobody@FreeBSD.org>
Received: from freefall.freebsd.org (freefall.FreeBSD.org [216.136.204.21])
	by hub.freebsd.org (Postfix) with ESMTP id 2249C37B435
	for <freebsd-gnats-submit@FreeBSD.org>; Mon, 22 Apr 2002 09:20:54 -0700 (PDT)
Received: (from nobody@localhost)
	by freefall.freebsd.org (8.11.6/8.11.6) id g3MG52g65859;
	Mon, 22 Apr 2002 09:05:02 -0700 (PDT)
	(envelope-from nobody)
Message-Id: <200204221605.g3MG52g65859@freefall.freebsd.org>
Date: Mon, 22 Apr 2002 09:05:02 -0700 (PDT)
From: Martin Perry <martin@raq.cx>
To: freebsd-gnats-submit@FreeBSD.org
Subject: Port Update Request: mail/imp: 2.2.7 -> 2.2.8 or 3.1
X-Send-Pr-Version: www-1.0

>Number:         37345
>Category:       ports
>Synopsis:       Port Update Request: mail/imp: 2.2.7 -> 2.2.8 or 3.1
>Confidential:   no
>Severity:       non-critical
>Priority:       medium
>Responsible:    freebsd-ports
>State:          closed
>Quarter:        
>Keywords:       
>Date-Required:  
>Class:          change-request
>Submitter-Id:   current-users
>Arrival-Date:   Mon Apr 22 09:30:01 PDT 2002
>Closed-Date:    Thu May 16 11:45:19 PDT 2002
>Last-Modified:  Thu May 16 11:45:19 PDT 2002
>Originator:     Martin Perry
>Release:        4.5-RELEASE-p4
>Organization:
>Environment:
FreeBSD dream.raq.cx 4.5-RELEASE-p4 FreeBSD 4.5-RELEASE-p4 #3: Mon Apr 22 14:39:08 BST 2002     martin@dream.raq.cx:/usr/obj/usr/src/sys/GENERIC  i386

>Description:
      Would it be possible to update the IMP port to the latest version, apparantely there is a security problem with 2.2.7 the current version in the ports tree. Here's a quote from the authors web site:

2002-04-06

IMP 2.2.8 and Horde 1.2.8 (SECURITY) have been released.

Download from ftp://ftp.horde.org/pub/horde/ and ftp://ftp.horde.org/pub/imp/ 
This version prevents some potential cross-site scripting (CSS) attacks. If an upgrade to IMP 3 is not possible, administrators of IMP 2.2.x production systems are encouraged to upgrade to prevent this attack against your systems. 

>How-To-Repeat:
      
>Fix:
      
>Release-Note:
>Audit-Trail:

From: Thierry Thomas <thierry@pompo.net>
To: Martin Perry <martin@raq.cx>
Cc: freebsd-gnats-submit@freebsd.org
Subject: Re: ports/37345: Port Update Request: mail/imp: 2.2.7 -> 2.2.8 or 3.1
Date: Mon, 22 Apr 2002 21:27:21 +0200

 Le 22 avr 02   9:05:02 +0000, Martin Perry crivait:
 > 
 > >Number:         37345
 > >Category:       ports
 > >Synopsis:       Port Update Request: mail/imp: 2.2.7 -> 2.2.8 or 3.1
 > >Confidential:   no
 > >Severity:       non-critical
 > >Priority:       medium
 > >Responsible:    freebsd-ports
 > >State:          open
 > >Quarter:        
 > >Keywords:       
 > >Date-Required:
 > >Class:          change-request
 > >Submitter-Id:   current-users
 > >Arrival-Date:   Mon Apr 22 09:30:01 PDT 2002
 > >Closed-Date:
 > >Last-Modified:
 > >Originator:     Martin Perry
 > >Release:        4.5-RELEASE-p4
 > >Organization:
 > >Environment:
 > FreeBSD dream.raq.cx 4.5-RELEASE-p4 FreeBSD 4.5-RELEASE-p4 #3: Mon Apr 22 14:39:08 BST 2002     martin@dream.raq.cx:/usr/obj/usr/src/sys/GENERIC  i386
 > 
 > >Description:
 >       Would it be possible to update the IMP port to the latest version, apparantely there is a security problem with 2.2.7 the current version in the ports tree. Here's a quote from the authors web site:
 > 
 > 2002-04-06
 > 
 > IMP 2.2.8 and Horde 1.2.8 (SECURITY) have been released.
 > 
 > Download from ftp://ftp.horde.org/pub/horde/ and ftp://ftp.horde.org/pub/imp/ 
 > This version prevents some potential cross-site scripting (CSS) attacks. If an upgrade to IMP 3 is not possible, administrators of IMP 2.2.x production systems are encouraged to upgrade to prevent this attack against your systems. 
 
 This upgrade has already been submitted: please see PR ports/36820.
 <URL:http://www.freebsd.org/cgi/query-pr.cgi?pr=36820>.
 -- 
 Th. Thomas.

From: Thierry Thomas <thierry@pompo.net>
To: Martin Perry <martin@raq.cx>
Cc: freebsd-gnats-submit@freebsd.org
Subject: Re: ports/37345: Port Update Request: mail/imp: 2.2.7 -> 2.2.8 or 3.1
Date: Thu, 16 May 2002 19:02:01 +0200

 Le 22 Apr 02   9:05:02 +0000, Martin Perry crivait:
 > 
 > >Number:         37345
 > >Category:       ports
 > >Synopsis:       Port Update Request: mail/imp: 2.2.7 -> 2.2.8 or 3.1
 
 PR ports/36820 has been committed, and this PR may be closed.
 Thanks.
 -- 
 Th. Thomas.
State-Changed-From-To: open->closed 
State-Changed-By: sada 
State-Changed-When: Thu May 16 11:42:22 PDT 2002 
State-Changed-Why:  
Submitter's request. 

http://www.freebsd.org/cgi/query-pr.cgi?pr=37345 
>Unformatted:
