[Bug 251141] databases/mantis: update to 2.24.3 [3 CVEs fixed]

bugzilla-noreply at freebsd.org bugzilla-noreply at freebsd.org
Sat Nov 14 18:56:28 UTC 2020


https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=251141

            Bug ID: 251141
           Summary: databases/mantis: update to 2.24.3 [3 CVEs fixed]
           Product: Ports & Packages
           Version: Latest
          Hardware: Any
                OS: Any
            Status: New
          Severity: Affects Some People
          Priority: ---
         Component: Individual Port(s)
          Assignee: ports-bugs at FreeBSD.org
          Reporter: zab at zltech.eu

Created attachment 219687
  --> https://bugs.freebsd.org/bugzilla/attachment.cgi?id=219687&action=edit
update to 2.24.3

There is a new version available:
https://mantisbt.org/bugs/changelog_page.php?project=mantisbt&version=2.24.3

This is a security release fixing:
- CVE-2020-25781
- CVE-2020-25288
- CVE-2020-25830
(no VuXML entry yet)

I created a patch for version update.
Changes:
- version to 2.24.3
- added files/patch-.imgbotconfig (its original exists in git repo but not
included in official 2.24.3 package, there might be some users with configured
imgbot depending on it + there is a PLIST_FILES entry in Makefile)
- adopt maintainership

QA:
- portlint: no new warns/errors (actual repo has 15)
- poudriere: ok (13-CURRENT, with/without my,pg,plugins)
- fresh install: works similar to previous version (12.2-RELEASE)
- update existing mantis 2.24.2 system to 2.24.3: works like 2.24.2, no changes
seen in user flows (except fixed errors :)
- database schema: unchanged (checked on pg-12)

-- 
You are receiving this mail because:
You are the assignee for the bug.


More information about the freebsd-ports-bugs mailing list