[Bug 213792] www/axis2: Update to 1.7.4, Security Vulnerability

bugzilla-noreply at freebsd.org bugzilla-noreply at freebsd.org
Wed Oct 26 00:55:55 UTC 2016


https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=213792

            Bug ID: 213792
           Summary: www/axis2: Update to 1.7.4, Security Vulnerability
           Product: Ports & Packages
           Version: Latest
          Hardware: Any
                OS: Any
            Status: New
          Keywords: patch, security
          Severity: Affects Some People
          Priority: ---
         Component: Individual Port(s)
          Assignee: freebsd-ports-bugs at FreeBSD.org
          Reporter: dbaio at bsd.com.br
             Flags: merge-quarterly?

Created attachment 176171
  --> https://bugs.freebsd.org/bugzilla/attachment.cgi?id=176171&action=edit
axis2-1.7.4.patch

- Update to 1.7.4
- Resolve CVE-2012-6153 and CVE-2014-3577 [1]
- Not necessary axis2.war anymore. Updated upstream [2]

[1]  http://axis.apache.org/axis2/java/core/release-notes/1.7.4.html
     https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6153
     https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3577

[2]  https://issues.apache.org/jira/browse/AXIS2-5816


Please, hold this issue for a while, my tests on poudriere are still running
(devel/llvm37 is taking too long). 

[Q/A]

portlint: OK (looks fine.)
testport: 
        poudriere: i386,  9.3   (waiting)
        poudriere: amd64, 9.3   (waiting)
        poudriere: i386,  10.3  (waiting)
        poudriere: amd64, 10.3  (not tested, still building all dependencies)
        poudriere: i386,  11    (waiting)
        poudriere: amd64, 11    (waiting)
        poudriere: i386,  12    (waiting)
        poudriere: amd64, 12    (OK)

-- 
You are receiving this mail because:
You are the assignee for the bug.


More information about the freebsd-ports-bugs mailing list