Re: Alpha release of Maia Mailguard 1.0.5
"Janky Jay, III" <[email protected]> Thu, 2 Oct 2025 10:53:33 -0600
| Newsgroups | gmane.mail.virus.maiamailguard |
|---|---|
| Message-ID | <[email protected]> |
This is a multi-part message in MIME format.
--===============3405053878869400111==
Content-Type: multipart/alternative;
boundary="------------77N4l0sqmTWyESTWOhjOzbAV"
Content-Language: en-US
This is a multi-part message in MIME format.
--------------77N4l0sqmTWyESTWOhjOzbAV
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit
Hi Bubba,
On 10/2/25 10:35AM, Bubba Brown wrote:
>
> My build ended here: has anyone else seen this? If so, did you proceed
> with make DISABLE_VULNERABILITIES=yes?
>
> ===> libxslt-1.1.43_1 has known vulnerabilities:
> libxslt-1.1.43_1 is vulnerable:
> libxslt -- unmaintained, with multiple unfixed vulnerabilities
> CVE: CVE-2025-7425
> CVE: CVE-2025-7424
> WWW:
> https://vuxml.FreeBSD.org/freebsd/b0a3466f-5efc-11f0-ae84-99047d0a6bcc.html
>
> 1 problem(s) in 1 package(s) found.
> => Please update your ports tree and try again.
> => Note: Vulnerable ports are marked as such even if there is no
> update available.
> => If you wish to ignore this vulnerability rebuild with 'make
> DISABLE_VULNERABILITIES=yes'
> *** Error code 1
>
> Stop.
> make[13]: stopped making
> "/usr/ports/textproc/libxslt/work/.install_done.libxslt._usr_local" in
> /usr/ports/t
> extproc/libxslt
> *** Error code 1
>
> <...>
>
> Stop.
> make: stopped making "all install" in /usr/ports/security/maia-mailguard
> root@wintermute:/usr/ports/security/maia-mailguard #
>
Unfortunately, yes. This old code is going to leave the system
vulnerable. I'd recommend just disabling vulnerability checks for this
single port (if you're okay with it) and continuing the rest of the
build with checks enabled so you're made aware of any other possibly
vulnerable software.
# cd /usr/ports/textproc/libxslt && make all install clean
DISABLE_VULNERABILITIES=yes
Then, just continue with the security/maia-mailguard build.
--
Regards,
Janky Jay, III
--------------77N4l0sqmTWyESTWOhjOzbAV
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit
<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
</head>
<body>
Hi Bubba,<br>
<br>
<div class="moz-cite-prefix">On 10/2/25 10:35AM, Bubba Brown wrote:<br>
</div>
<blockquote type="cite"
cite="mid:fe636ecc-3522-486f-94e0-14c748a1f3d8-UmgsxY/[email protected]">
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
<p><span style="font-family:monospace"><span
style="color:#000000;background-color:#ffffff;"> </span>My
build ended here: has anyone else seen this? If so, did you
proceed with </span><span style="font-family:monospace">make
DISABLE_VULNERABILITIES=yes?</span><br>
<span style="font-family:monospace"><br>
===> libxslt-1.1.43_1 has known vulnerabilities: <br>
libxslt-1.1.43_1 is vulnerable: <br>
libxslt -- unmaintained, with multiple unfixed
vulnerabilities <br>
CVE: CVE-2025-7425 <br>
CVE: CVE-2025-7424 <br>
WWW:
<a class="moz-txt-link-freetext"
href="https://vuxml.FreeBSD.org/freebsd/b0a3466f-5efc-11f0-ae84-99047d0a6bcc.html"
moz-do-not-send="true">https://vuxml.FreeBSD.org/freebsd/b0a3466f-5efc-11f0-ae84-99047d0a6bcc.html</a><br>
<br>
1 problem(s) in 1 package(s) found. <br>
=> Please update your ports tree and try again. <br>
=> Note: Vulnerable ports are marked as such even if there
is no update available. <br>
=> If you wish to ignore this vulnerability rebuild with
'make DISABLE_VULNERABILITIES=yes' <br>
*** Error code 1 <br>
<br>
Stop. <br>
make[13]: stopped making
"/usr/ports/textproc/libxslt/work/.install_done.libxslt._usr_local"
in /usr/ports/t<br>
extproc/libxslt <br>
*** Error code 1 <br>
<br>
<...> <br>
<br>
Stop. <br>
make: stopped making "all install" in
/usr/ports/security/maia-mailguard <br>
root@wintermute:/usr/ports/security/maia-mailguard #</span></p>
</blockquote>
<br>
Unfortunately, yes. This old code is going to leave the system
vulnerable. I'd recommend just disabling vulnerability checks for
this single port (if you're okay with it) and continuing the rest of
the build with checks enabled so you're made aware of any other
possibly vulnerable software.<br>
<br>
# cd /usr/ports/textproc/libxslt && make all install clean <span
style="font-family:monospace">DISABLE_VULNERABILITIES=yes<br>
<br>
Then, just continue with the security/maia-mailguard build.<br>
</span><br>
<pre class="moz-signature" cols="72">--
Regards,
Janky Jay, III</pre>
<br>
</body>
</html>
--------------77N4l0sqmTWyESTWOhjOzbAV--
--===============3405053878869400111==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline
X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KTWFpYS11c2Vy
cyBtYWlsaW5nIGxpc3QKTWFpYS11c2Vyc0ByZW5haXNzb2Z0LmNvbQpodHRwOi8vd3d3LnJlbmFp
c3NvZnQuY29tL2NnaS1iaW4vbWFpbG1hbi9saXN0aW5mby9tYWlhLXVzZXJzCg==
--===============3405053878869400111==--