Re: Alpha release of Maia Mailguard 1.0.5

"Janky Jay, III" <[email protected]> Thu, 2 Oct 2025 10:53:33 -0600
Newsgroups gmane.mail.virus.maiamailguard
Message-ID <[email protected]>
This is a multi-part message in MIME format.
--===============3405053878869400111==
Content-Type: multipart/alternative;
 boundary="------------77N4l0sqmTWyESTWOhjOzbAV"
Content-Language: en-US

This is a multi-part message in MIME format.
--------------77N4l0sqmTWyESTWOhjOzbAV
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit

Hi Bubba,

On 10/2/25 10:35AM, Bubba Brown wrote:
>
> My build ended here: has anyone else seen this? If so, did you proceed 
> with make DISABLE_VULNERABILITIES=yes?
>
> ===>  libxslt-1.1.43_1 has known vulnerabilities:
> libxslt-1.1.43_1 is vulnerable:
>  libxslt -- unmaintained, with multiple unfixed vulnerabilities
>  CVE: CVE-2025-7425
>  CVE: CVE-2025-7424
>  WWW: 
> https://vuxml.FreeBSD.org/freebsd/b0a3466f-5efc-11f0-ae84-99047d0a6bcc.html
>
> 1 problem(s) in 1 package(s) found.
> => Please update your ports tree and try again.
> => Note: Vulnerable ports are marked as such even if there is no 
> update available.
> => If you wish to ignore this vulnerability rebuild with 'make 
> DISABLE_VULNERABILITIES=yes'
> *** Error code 1
>
> Stop.
> make[13]: stopped making 
> "/usr/ports/textproc/libxslt/work/.install_done.libxslt._usr_local" in 
> /usr/ports/t
> extproc/libxslt
> *** Error code 1
>
> <...>
>
> Stop.
> make: stopped making "all install" in /usr/ports/security/maia-mailguard
> root@wintermute:/usr/ports/security/maia-mailguard #
>

Unfortunately, yes. This old code is going to leave the system 
vulnerable. I'd recommend just disabling vulnerability checks for this 
single port (if you're okay with it) and continuing the rest of the 
build with checks enabled so you're made aware of any other possibly 
vulnerable software.

# cd /usr/ports/textproc/libxslt && make all install clean 
DISABLE_VULNERABILITIES=yes

Then, just continue with the security/maia-mailguard build.

-- 
Regards,
Janky Jay, III


--------------77N4l0sqmTWyESTWOhjOzbAV
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit

<!DOCTYPE html>
<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body>
    Hi Bubba,<br>
    <br>
    <div class="moz-cite-prefix">On 10/2/25 10:35AM, Bubba Brown wrote:<br>
    </div>
    <blockquote type="cite"
cite="mid:fe636ecc-3522-486f-94e0-14c748a1f3d8-UmgsxY/[email protected]">
      <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
      <p><span style="font-family:monospace"><span
            style="color:#000000;background-color:#ffffff;"> </span>My
          build ended here: has anyone else seen this? If so, did you
          proceed with </span><span style="font-family:monospace">make
          DISABLE_VULNERABILITIES=yes?</span><br>
        <span style="font-family:monospace"><br>
          ===&gt;  libxslt-1.1.43_1 has known vulnerabilities: <br>
          libxslt-1.1.43_1 is vulnerable: <br>
           libxslt -- unmaintained, with multiple unfixed
          vulnerabilities <br>
           CVE: CVE-2025-7425 <br>
           CVE: CVE-2025-7424 <br>
           WWW:
          <a class="moz-txt-link-freetext"
href="https://vuxml.FreeBSD.org/freebsd/b0a3466f-5efc-11f0-ae84-99047d0a6bcc.html"
            moz-do-not-send="true">https://vuxml.FreeBSD.org/freebsd/b0a3466f-5efc-11f0-ae84-99047d0a6bcc.html</a><br>
          <br>
          1 problem(s) in 1 package(s) found. <br>
          =&gt; Please update your ports tree and try again. <br>
          =&gt; Note: Vulnerable ports are marked as such even if there
          is no update available. <br>
          =&gt; If you wish to ignore this vulnerability rebuild with
          'make DISABLE_VULNERABILITIES=yes' <br>
          *** Error code 1 <br>
          <br>
          Stop. <br>
          make[13]: stopped making
          "/usr/ports/textproc/libxslt/work/.install_done.libxslt._usr_local"
          in /usr/ports/t<br>
          extproc/libxslt <br>
          *** Error code 1 <br>
          <br>
          &lt;...&gt; <br>
          <br>
          Stop. <br>
          make: stopped making "all install" in
          /usr/ports/security/maia-mailguard <br>
          root@wintermute:/usr/ports/security/maia-mailguard #</span></p>
    </blockquote>
    <br>
    Unfortunately, yes. This old code is going to leave the system
    vulnerable. I'd recommend just disabling vulnerability checks for
    this single port (if you're okay with it) and continuing the rest of
    the build with checks enabled so you're made aware of any other
    possibly vulnerable software.<br>
    <br>
    # cd /usr/ports/textproc/libxslt &amp;&amp; make all install clean <span
      style="font-family:monospace">DISABLE_VULNERABILITIES=yes<br>
      <br>
      Then, just continue with the security/maia-mailguard build.<br>
    </span><br>
    <pre class="moz-signature" cols="72">-- 
Regards,
Janky Jay, III</pre>
    <br>
  </body>
</html>

--------------77N4l0sqmTWyESTWOhjOzbAV--

--===============3405053878869400111==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KTWFpYS11c2Vy
cyBtYWlsaW5nIGxpc3QKTWFpYS11c2Vyc0ByZW5haXNzb2Z0LmNvbQpodHRwOi8vd3d3LnJlbmFp
c3NvZnQuY29tL2NnaS1iaW4vbWFpbG1hbi9saXN0aW5mby9tYWlhLXVzZXJzCg==

--===============3405053878869400111==--