Sat Mar 29 10:25:19 2014 UTC ()
We already have fix for CVE-2014-2525 in libyaml-0.1.5nb1.
Thanks to wiz@ noted via private e-mail.


(taca)
diff -r1.13115 -r1.13116 pkgsrc/doc/TODO

cvs diff -r1.13115 -r1.13116 pkgsrc/doc/TODO (expand / switch to unified diff)

--- pkgsrc/doc/TODO 2014/03/29 09:39:37 1.13115
+++ pkgsrc/doc/TODO 2014/03/29 10:25:19 1.13116
@@ -1,14 +1,14 @@ @@ -1,14 +1,14 @@
1$NetBSD: TODO,v 1.13115 2014/03/29 09:39:37 taca Exp $ 1$NetBSD: TODO,v 1.13116 2014/03/29 10:25:19 taca Exp $
2 2
3Suggested new packages 3Suggested new packages
4====================== 4======================
5 5
6 Any unresolved PRs (if you have commit access) 6 Any unresolved PRs (if you have commit access)
7 http://gnats.NetBSD.org/summary/category/pkg.html 7 http://gnats.NetBSD.org/summary/category/pkg.html
8 8
9 Any complete, polished packages in pkgsrc-wip (ditto) 9 Any complete, polished packages in pkgsrc-wip (ditto)
10 http://pkgsrc-wip.sourceforge.net/ 10 http://pkgsrc-wip.sourceforge.net/
11 11
12 bacula-rescue 12 bacula-rescue
13 Scripts used to help create rescue boot CDs for bare metal 13 Scripts used to help create rescue boot CDs for bare metal
14 restores with Bacula. Scripts exist for Linux, Solaris, and 14 restores with Bacula. Scripts exist for Linux, Solaris, and
@@ -767,27 +767,27 @@ For possible Perl packages updates, see  @@ -767,27 +767,27 @@ For possible Perl packages updates, see
767 o libssh2-1.4.2 767 o libssh2-1.4.2
768 o libstree-0.4.3pre2 [pkg/43748] 768 o libstree-0.4.3pre2 [pkg/43748]
769 o libtar-1.2.20 769 o libtar-1.2.20
770 o libtcl-nothread-8.5.1 770 o libtcl-nothread-8.5.1
771 o libthrift-0.8.0 771 o libthrift-0.8.0
772 o libusb-1.0.18 772 o libusb-1.0.18
773 o libusbx-1.0.18 [but actually obsolete, switch to libusb] 773 o libusbx-1.0.18 [but actually obsolete, switch to libusb]
774 o libuuid-2.24.1 774 o libuuid-2.24.1
775 o libv4l-0.8.5 775 o libv4l-0.8.5
776 o libvdpau-0.7 776 o libvdpau-0.7
777 o libwildmidi-0.3.5 777 o libwildmidi-0.3.5
778 o libxdg-basedir-1.2.0 778 o libxdg-basedir-1.2.0
779 o libxklavier-5.3 779 o libxklavier-5.3
780 o libyaml-0.1.6 [CVE-2014-2525] 780 o libyaml-0.1.6 [CVE-2014-2525, already fixed in libyaml-0.1.5nb1]
781 o licq-1.3.8 781 o licq-1.3.8
782 o liferea-1.10.7 782 o liferea-1.10.7
783 o lighttpd-1.4.35 783 o lighttpd-1.4.35
784 o lincvs-2.1.4 [now called CrossVC] 784 o lincvs-2.1.4 [now called CrossVC]
785 o liquidwar-6.0.0.11 785 o liquidwar-6.0.0.11
786 o lldpd-0.7.7 [wip, perl module path] 786 o lldpd-0.7.7 [wip, perl module path]
787 o lmbench-2.5 [http://lmbench.sourceforge.net/] 787 o lmbench-2.5 [http://lmbench.sourceforge.net/]
788 o lottanzb-0.5.3 788 o lottanzb-0.5.3
789 o lq-sp-1.3.4.13 789 o lq-sp-1.3.4.13
790 o lsh-2.1 790 o lsh-2.1
791 o ltris-1.0.19 791 o ltris-1.0.19
792 o lwm-1.2.3 792 o lwm-1.2.3
793 o m17n-db-1.6.5 793 o m17n-db-1.6.5