In general, this sort of security flagging is done via portaudit's own database
which is derived mostly from VuXML.  To get around the lockout imposed by 
you can do:


but a) this doesn't disable any actual vulnerabilities, just the checking
for their presence, and b) on your own head be it.

Now, in the case of the win32-codecs port, it is done differently.  The port
Makefile says this:

.if defined(WITH_QUICKTIME)
FORBIDDEN=      Remote code execution:
ADDITIONAL_CODECS_DISTFILES+=   qt63dlls-20050115.tar.bz2 \
PLIST_SUB+=     QUICKTIME="@comment "

ie. selecting the Quicktime plugins in the OPTIONS dialog, which causes
WITH_QUICKTIME to be defined, means that the port will be marked forbidden,
and any attempt to install it will be blocked.

A simple 'make config' and unchecking that option will let you install
the port with all of the other codecs.

Freshports parses the VuXML database to mark ports as vulnerable -- the VuXML
data contains a listing of the vulnerable package names and ranges of version
numbers.  VuXML doesn't actually have a way of distinguishing what options are
enabled for the port, although the textual note in the entry explains the 
fairly clearly.  It doesn't say "Users are advised to reinstall the port with 
Quicktime support turned off" which might be a nice addition.  The system will
however prompt users to upgrade to a version of the port after the code to
forbid installation with Quicktime stuff enabled was added.



