Subject: CVS commit: [pkgsrc-2012Q2] pkgsrc/graphics/png
From: Matthias Scheler
Date: 2012-07-13 10:51:00
Message id: 20120713085100.A6F45175DD@cvs.netbsd.org

Log Message:
Pullup ticket #3858 - requested by wiz
graphics/png: security update

Revisions pulled up:
- graphics/png/Makefile                                         1.150
- graphics/png/distinfo                                         1.97

---
   Module Name:	pkgsrc
   Committed By:	wiz
   Date:		Wed Jul 11 09:00:42 UTC 2012

   Modified Files:
   	pkgsrc/graphics/png: Makefile distinfo

   Log Message:
   Update to 1.5.12:
     Removed scripts/makefile.cegcc from the *.zip and *.7z distributions; it
       depends on configure, which is not included in those archives.
     Changed "a+w" to "u+w" in Makefile.in to fix CVE-2012-3386.

   I don't see CVS-2012-3386 as a vulnerability that applies to pkgsrc,
   since to trigger it, you have to run 'make distcheck', and pkgsrc
   never does that.

Files:
RevisionActionfile
1.149.2.1modifypkgsrc/graphics/png/Makefile
1.96.2.1modifypkgsrc/graphics/png/distinfo