From matthias.andree@gmx.de  Thu Jan  8 17:50:22 2004
Return-Path: <matthias.andree@gmx.de>
Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125])
	by hub.freebsd.org (Postfix) with ESMTP id 81B4616A4CE
	for <FreeBSD-gnats-submit@freebsd.org>; Thu,  8 Jan 2004 17:50:22 -0800 (PST)
Received: from mail.dt.e-technik.uni-dortmund.de (krusty.dt.E-Technik.Uni-Dortmund.DE [129.217.163.1])
	by mx1.FreeBSD.org (Postfix) with ESMTP id D6A0A43D1D
	for <FreeBSD-gnats-submit@freebsd.org>; Thu,  8 Jan 2004 17:50:20 -0800 (PST)
	(envelope-from matthias.andree@gmx.de)
Received: from m2a2.dyndns.org (krusty.dt.e-technik.uni-dortmund.de [129.217.163.1])
	by mail.dt.e-technik.uni-dortmund.de (Postfix) with ESMTP id 6DB611927E
	for <FreeBSD-gnats-submit@freebsd.org>; Fri,  9 Jan 2004 02:50:19 +0100 (CET)
Received: from libertas.emma.line.org (libertas.emma.line.org [192.168.0.2])
	by merlin.emma.line.org (Postfix) with ESMTP id AD2B3A0EEB;
	Fri,  9 Jan 2004 02:50:17 +0100 (CET)
Received: from emma by libertas.emma.line.org with local (Exim 4.30; FreeBSD)
	id 1Aelmz-0001kI-D7; Fri, 09 Jan 2004 02:50:17 +0100
Message-Id: <E1Aelmz-0001kI-D7@libertas.emma.line.org>
Date: Fri, 09 Jan 2004 02:50:17 +0100
From: Matthias Andree <matthias.andree@gmx.de>
Sender: Matthias Andree <matthias.andree@gmx.de>
To: FreeBSD-gnats-submit@freebsd.org
Cc:
Subject: [MAINTAINER] news/leafnode: SECURITY update to 1.9.48
X-Send-Pr-Version: 3.113
X-GNATS-Notify:

>Number:         61105
>Category:       ports
>Synopsis:       [MAINTAINER] news/leafnode: SECURITY update to 1.9.48
>Confidential:   no
>Severity:       serious
>Priority:       low
>Responsible:    freebsd-ports-bugs
>State:          closed
>Quarter:        
>Keywords:       
>Date-Required:  
>Class:          maintainer-update
>Submitter-Id:   current-users
>Arrival-Date:   Thu Jan 08 18:00:34 PST 2004
>Closed-Date:    Thu Jan 08 18:15:48 PST 2004
>Last-Modified:  Thu Jan 08 18:15:48 PST 2004
>Originator:     Matthias Andree
>Release:        FreeBSD 4.9-STABLE i386
>Organization:
>Environment:
System: FreeBSD libertas.emma.line.org 4.9-STABLE FreeBSD 4.9-STABLE #70: Sat Jan  3 13:14:20 CET
>Description:
- Update to 1.9.48, security fixes inside.

Upstream NEWS:

### SECURITY BUGFIX
- Fetchnews: when a. minlines=0 (default) and b. delaybody=0 (default) and
  either c. no filterfile is configured (default) or a. and b. and d.
  article_despite_filter=1 are configured, an article with missing mandatory
  headers and without body can hang fetchnews and/or prevent the fetch of
  further articles from the current group or server.
  Reported by Toni Viemer, SourceForge bug 873149.
  This was a denial-of-service bug, not one that could lead to local or remote
  privilege escalation.

### BUGFIX
- Fetchnews: log group name when articles are skipped that match the minlines,
  maxlines, maxbytes or age filters, for more consistent logging.

### CHANGES
- Rebuilt with autoconf 2.59.

Generated with FreeBSD Port Tools 0.50
>How-To-Repeat:
>Fix:

--- leafnode-1.9.48.patch begins here ---
diff -ruN --exclude=CVS /usr/ports/news/leafnode/Makefile /root/ports/news/leafnode/Makefile
--- /usr/ports/news/leafnode/Makefile	Wed Jan  7 15:56:30 2004
+++ /root/ports/news/leafnode/Makefile	Fri Jan  9 02:34:01 2004
@@ -6,7 +6,7 @@
 #
 
 PORTNAME=	leafnode
-PORTVERSION=	1.9.47
+PORTVERSION=	1.9.48
 CATEGORIES=	news
 MASTER_SITES=	${MASTER_SITE_SOURCEFORGE:S/$/:sourceforge/} \
 		http://osdn.dl.sourceforge.net/sourceforge/${PORTNAME}/ \
diff -ruN --exclude=CVS /usr/ports/news/leafnode/distinfo /root/ports/news/leafnode/distinfo
--- /usr/ports/news/leafnode/distinfo	Wed Jan  7 15:56:30 2004
+++ /root/ports/news/leafnode/distinfo	Fri Jan  9 02:33:47 2004
@@ -1 +1 @@
-MD5 (leafnode-1.9.47.rel.tar.bz2) = 4c83fc265f34aa1a42dc90599101b4fe
+MD5 (leafnode-1.9.48.rel.tar.bz2) = 629f5d4cd8eb6c2140ac7b3684c3085a
--- leafnode-1.9.48.patch ends here ---

>Release-Note:
>Audit-Trail:
State-Changed-From-To: open->closed 
State-Changed-By: clement 
State-Changed-When: Thu Jan 8 18:15:23 PST 2004 
State-Changed-Why:  
Committed, thanks ! 

http://www.freebsd.org/cgi/query-pr.cgi?pr=61105 
>Unformatted:
