1
0
mirror of https://git.FreeBSD.org/ports.git synced 2025-01-24 09:25:01 +00:00
Commit Graph

518753 Commits

Author SHA1 Message Date
Tobias C. Berner
1f4b5d0926 misc/cave: fix build on recent current and deprecate 2020-08-28 11:35:51 +00:00
Tobias C. Berner
6825ce59e3 x11-fm/caja: fix build on recent current
Obtained from:	6bf49f348d
2020-08-28 11:32:26 +00:00
Tobias C. Berner
e054843f35 deskutils/cairo-dock-plugins: fix build on recent current
Obtained from:	d08541a0af
2020-08-28 11:24:57 +00:00
Tobias C. Berner
8be18b0565 games/bygfoot: fix build on recent current and deprecate 2020-08-28 11:19:52 +00:00
Tobias C. Berner
6b8c279e7b biology/bwa: fix build on recent current
Obtained from:	2a1ae7b6f3
2020-08-28 11:17:13 +00:00
Tobias C. Berner
5beefb1c76 devel/buildtool: fix build on current and deprecate 2020-08-28 11:11:58 +00:00
Tobias C. Berner
67b4ede2a2 security/bugs: fix build on current and deprecate 2020-08-28 11:06:43 +00:00
Tobias C. Berner
f849872d7f graphics/bsd-plotutils: fix build on recent current 2020-08-28 11:02:20 +00:00
Tobias C. Berner
2604ea22f3 audio/bristol: fix build on recent current 2020-08-28 10:59:56 +00:00
Tobias C. Berner
5ab37f4c09 x11/bricons: fix build on recent current and deprecate 2020-08-28 10:49:14 +00:00
Tobias C. Berner
68a88f6561 games/bomberinstinct: fix build with recent current and deprecate 2020-08-28 10:45:17 +00:00
Max Brazhnikov
7dbd093d10 math/scilab: fix build with -fno-common 2020-08-28 10:04:24 +00:00
Dmitry Marakasov
ccb27bc9a4 - Update WWW
- Fix testing and flavor usage in TEST_DEPENDS

Approved by:	portmgr blanket
2020-08-28 09:36:39 +00:00
Frederic Culot
343057825c devel/p5-Future: update to 0.45
Changes:	https://metacpan.org/source/PEVANS/Future-0.45/Changes
2020-08-28 09:19:15 +00:00
Frederic Culot
a41bc00361 net/p5-XML-RPC: update to 1.1
Changes:	https://metacpan.org/source/CAVAC/XML-RPC-1.1/Changes
2020-08-28 09:02:07 +00:00
Jimmy Olgeni
afdb2f8b95 Update devel/etcd34 to version 3.4.13. 2020-08-28 08:49:16 +00:00
Gerald Pfeifer
e99fd9443c Update to the 20200827 snapshot of GCC 8.4.1.
This brings a few improvements for aarch64 and arm.
2020-08-28 08:03:42 +00:00
Alexey Dokuchaev
4ba80f827f Allow to build against contemporary versions of OpenSSL. 2020-08-28 06:53:53 +00:00
Alexey Dokuchaev
fdf265074b - Reorder #include's to unbreak the build against Qt versions 5.14+
- Do not include <X11/Xcm/Xcm.h> twice (included from "qcmsevents.h")
2020-08-28 06:09:24 +00:00
Tobias C. Berner
054311d725 archivers/ark: fix vulnerability in tar extraction
KDE Project Security Advisory
=============================

Title:           Ark: maliciously crafted TAR archive with symlinks can install files outside the extraction directory.
Risk Rating:     Important
CVE:             CVE-2020-24654
Versions:        ark <= 20.08.0
Author:          Elvis Angelaccio <elvis.angelaccio@kde.org>
Date:            27 August 2020

Overview
========

A maliciously crafted TAR archive containing symlink entries
would install files anywhere in the user's home directory upon extraction.

Proof of concept
================

For testing, an example of malicious archive can be found at
https://github.com/jwilk/traversal-archives/releases/download/0/dirsymlink.tar

Impact
======

Users can unwillingly install files like a modified .bashrc, or a malicious
script placed in ~/.config/autostart.

Workaround
==========

Before extracting a downloaded archive using the Ark GUI, users should inspect it
to make sure it doesn't contain symlink entries pointing outside the extraction folder.

The 'Extract' context menu from the Dolphin file manager shouldn't be used.

Solution
========

Ark 20.08.1 skips maliciously crafted symlinks when extracting TAR archives.

Alternatively, 8bf8c5ef07 can be applied to previous
releases.

Credits
=======

Thanks to Fabian Vogt for reporting this issue and for fixing it.

MFH:		2020Q3
Security:	CVE-2020-24654
2020-08-28 05:47:31 +00:00
Tobias C. Berner
fc5c7433e8 security/vuxml: document vulnerability in ark 2020-08-28 05:15:49 +00:00
Jung-uk Kim
59a19c1c98 - Unbreak. The FTP server was restored recently.
- Fix build with Clang 11 (-fno-common).
2020-08-28 04:17:41 +00:00
Jung-uk Kim
f0802eb0f3 Re-add korean/hpscat. The FTP server was restored recently. 2020-08-28 04:13:19 +00:00
Jung-uk Kim
9601984bf4 Remove korean/hpscat to properly repo-copy. 2020-08-28 04:12:26 +00:00
Jung-uk Kim
bdf6ecf9bf - Re-add korean/hpscat. The FTP server was restored recently.
- Fix build with Clang 11.
2020-08-28 03:46:41 +00:00
Alexey Dokuchaev
8c09cea9bf Revert r546386 now that better fix had been committed in r546699. 2020-08-28 03:39:25 +00:00
Alexey Dokuchaev
9ed27dded0 Unbreak the build with -fno-common (Clang 11, GCC 10).
Reported by:	pkg-fallout
2020-08-28 02:39:38 +00:00
Jan Beich
d5cdb69eb7 x11/nwg-launchers: update to 0.3.2
Changes:	https://github.com/nwg-piotr/nwg-launchers/releases/tag/v0.3.2
Reported by:	GitHub (watch releases)
2020-08-28 00:04:01 +00:00
Johannes M Dieterich
ffa26e3926 math/sleef: update to 3.4.1
While there, fix LLVM11 introduced breakage on HEAD
2020-08-27 23:23:33 +00:00
Sergey A. Osokin
24c3408056 Add the corresponding library path to the patch for the
third-party http_auth_spnego module.

The third-party http_auth_spnego module may not work with
in-base Kerberos implementation because of gss_locaname()
function usage, so remove the GSSAPI_BASE option from the
GSSAPI radio button.

Bump PORTREVISION.
2020-08-27 23:03:40 +00:00
TAKATSU Tomonari
7466b00b38 - Update to 2020.4 2020-08-27 22:54:55 +00:00
TAKATSU Tomonari
a33f7b88d5 - Update to 1.1.9 2020-08-27 22:53:08 +00:00
TAKATSU Tomonari
95c462fac6 - Update to 1.0-2 2020-08-27 22:40:09 +00:00
Steve Wills
123a995d9f net-im/chatterino2: create port
Chatterino is a chat client for twitch chat. It aims to be an improved/extended
version of the twitch web chat.

WWW: https://chatterino.com/
2020-08-27 21:22:04 +00:00
Craig Leres
1eab12760e security/vuxml: Mark php72, php73, and php74 vulnerable as per:
https://www.php.net/ChangeLog-7.php#PHP_7_4
    https://www.php.net/ChangeLog-7.php#PHP_7_3
    https://www.php.net/ChangeLog-7.php#PHP_7_2

The phar_parse_zipfile function had [a] use-after-free vulnerability
because of [a] mishandling of the actual_alias variable.

Security:	CVE-2020-7068
2020-08-27 20:50:21 +00:00
Tobias C. Berner
18782e8107 devel/blame: fix build with recent current 2020-08-27 20:47:12 +00:00
Tobias C. Berner
197bc77acd comms/bladrf: fix build on recent current 2020-08-27 20:38:36 +00:00
Tobias C. Berner
fcb88e6e71 comms/birda: fix build on recent current 2020-08-27 20:36:04 +00:00
Tobias C. Berner
b974172440 games/biniax2: fix build on recent current 2020-08-27 20:34:48 +00:00
Tobias C. Berner
0ff563c818 games/biloba: fix build on recent current 2020-08-27 20:33:30 +00:00
Tobias C. Berner
c62d24f613 x11/bbrun: fix build on recent current 2020-08-27 20:26:24 +00:00
Tobias C. Berner
8827b9fc75 net/bandwidthd: fix build on recent current 2020-08-27 20:21:04 +00:00
Tobias C. Berner
905a3a6e4a games/awele: fix build on recent current 2020-08-27 20:04:02 +00:00
Tobias C. Berner
04673929a6 multimedia/avinfo: fix build with recent current 2020-08-27 20:01:19 +00:00
Adam Weinberger
c0fac3c2a0 security/gnupg: Update to 2.2.22
Also, sort plist. The new gpgsplit binary is getting installed as
gpgsplit2 to avoid a conflict with security/gnupg1.

Noteworthy changes in version 2.2.22
====================================

  * gpg: Change the default key algorithm to rsa3072.

  * gpg: Add regular expression support for Trust Signatures on all
    platforms.  [#4843]

  * gpg: Fix regression in 2.2.21 with non-default --passphrase-repeat
    option.  [#4991]

  * gpg: Ignore --personal-digest-prefs for ECDSA keys.  [#5021]

  * gpgsm: Make rsaPSS a de-vs compliant scheme.

  * gpgsm: Show also the SHA256 fingerprint in key listings.

  * gpgsm: Do not require a default keyring for --gpgconf-list.  [#4867]

  * gpg-agent: Default to extended key format and record the creation
    time of keys.  Add new option --disable-extended-key-format.

  * gpg-agent: Support the WAYLAND_DISPLAY envvar.  [#5016]

  * gpg-agent: Allow using --gpgconf-list even if HOME does not
    exist.  [#4866]

  * gpg-agent: Make the Pinentry work even if the envvar TERM is set
    to the empty string.  [#4137]

  * scdaemon: Add a workaround for Gnuk tokens <= 2.15 which wrongly
    incremented the error counter when using the "verify" command of
    "gpg --edit-key" with only the signature key being present.

  * dirmngr: Better handle systems with disabled IPv6.  [#4977]

  * gpgpslit: Install tool.  It was not installed in the past to avoid
    conflicts with the version installed by GnuPG 1.4.  [#5023]
    (We're installing it as gpgsplit2 to avoid conflict with security/gnupg1)

  * gpgtar: Handle Unicode file names on Windows correctly (requires
    libgpg-error 1.39).  [#4083]

  * gpgtar: Make --files-from and --null work as documented.  [#5027]

  * Build the Windows installer with the new Ntbtls 0.2.0 so that TLS
    connections succeed for servers demanding GCM.

  Release-info: https://dev.gnupg.org/T5030
2020-08-27 19:58:01 +00:00
Tobias C. Berner
c47060ce3b mail/avenger: fix build on recent current 2020-08-27 19:56:15 +00:00
Tobias C. Berner
0257e2ef8b scecurity/autossh: fix build with recent current 2020-08-27 19:49:07 +00:00
Tobias C. Berner
46119761be audio/aumix: fix build with recent current 2020-08-27 19:42:55 +00:00
Tobias C. Berner
e0777ded3b editors/atom: fix build with recent current
Obtained from:	89a306bca9.patch
2020-08-27 19:41:48 +00:00
Tobias C. Berner
c78f5a9473 games/atris: fix build on recent current 2020-08-27 19:40:27 +00:00