notbugAs an Amazon Associate I earn from qualifying purchases.
Want a good read? Try FreeBSD Mastery: Jails (IT Mastery Book 15)
Want a good monitor light? See my photosAll times are UTC
Ukraine
This referral link gives you 10% off a Fastmail.com account and gives me a discount on my Fastmail account.

Get notified when packages are built

A new feature has been added. FreshPorts already tracks package built by the FreeBSD project. This information is displayed on each port page. You can now get an email when FreshPorts notices a new package is available for something on one of your watch lists. However, you must opt into that. Click on Report Subscriptions on the right, and New Package Notification box, and click on Update.

Finally, under Watch Lists, click on ABI Package Subscriptions to select your ABI (e.g. FreeBSD:14:amd64) & package set (latest/quarterly) combination for a given watch list. This is what FreshPorts will look for.

non port: x11-toolkits/pango/files/CVE-20191010238

Number of commits found: 2

Saturday, 26 Sep 2020
13:06 zeising search for other commits by this committer
x11/toolcits-pango: Actually apply security patch

Rename the patch that fixes CVE-2010-1010238 so that it is actually applied
when  building pango.
Regenerate it using make makepatch
bump portrevision

Reported by:	tobik
MFH:		2020Q3 (implicit, security fix)
Security:	456375e1-cd09-11ea-9172-4c72b94353b5
Original commitRevision:550179 
Thursday, 23 Jul 2020
18:34 joneum search for other commits by this committer
SECURITY UPDATE: Buffer overflow

Gnome Pango 1.42 and later is affected by: Buffer Overflow. The impact is: The
heap based buffer overflow can be used to get code execution. The component is:
function name: pango_log2vis_get_embedding_levels, assignment of nchars and the
loop condition. The attack vector is: Bug can be used when application pass
invalid utf-8 strings to functions like pango_itemize.

PR:		239563
Reported by:	Miyashita Touka <imagin8r@protonmail.com>
Approved by:	gnome (maintainer timeout)
MFH:		2020Q3
Security:	456375e1-cd09-11ea-9172-4c72b94353b5
Sponsored by:	Netzkommune GmbH
Original commitRevision:542951 

Number of commits found: 2