[#] http://marc.info/?l=openbsd-ports-cvs&m=140909568415792&w=2
openbsd-ports-cvs(obsdave,2) — All
2014-08-27 03:55:16


Module name: ports
Changes by: zhuk@cvs.openbsd.org 2014/08/26 17:27:42

Modified files:
x11/kde4/krfb : Tag: OPENBSD_5_5 Makefile
Added files:
x11/kde4/krfb/patches: Tag: OPENBSD_5_5
patch-libvncserver_lzoconf_h
patch-libvncserver_lzodefs_h
patch-libvncserver_minilzo_c
patch-libvncserver_minilzo_h

Log message:
Security fix for krfb 4.11 branch, CVE-2014-4607:

krfb embeds libvncserver which embeds liblzo2, it contains various flaws
that result in integer overflow problems.

This commit actually updates bundled lzo library, as suggested by upstream.

testing and okay jca@, "I trust you" naddy@