1
0
mirror of https://git.FreeBSD.org/ports.git synced 2024-12-02 01:20:54 +00:00
Commit Graph

16468 Commits

Author SHA1 Message Date
Joe Marcus Clarke
a075d031b2 Change the wireshark version for the DRDA fix. 2012-09-05 16:02:11 +00:00
Dag-Erling Smørgrav
dbc36c9345 Remove useless metadata from ports I created. 2012-09-05 15:43:33 +00:00
Cy Schubert
60236bdbd9 Update 0.13.1 --> 0.15.1 2012-09-05 14:26:25 +00:00
Frederic Culot
48d9d6c9ba - Update to 0.23
Changes:	http://search.cpan.org/dist/Authen-TacacsPlus/Changes
2012-09-05 10:56:26 +00:00
Eygene Ryabinkin
1213e0634b VuXML: document XSS in MoinMoin before 1.9.4 via RST parser 2012-09-05 10:42:38 +00:00
Eygene Ryabinkin
bf6426a1fb VuXML: document wrong group ACL processing in MoinMoin 2012-09-05 09:47:35 +00:00
Eygene Ryabinkin
1b3ec36058 PHP 5.x: document header splitting vulnerability
There is a related CVE number (CVE-2012-4388), but there is no current
consensus about it:
  http://article.gmane.org/gmane.comp.security.oss.general/8303
2012-09-05 06:29:38 +00:00
Matthias Andree
84f7423f73 Modify fetchmail vuln' URLs to established site.
While at it, adjust the two oldest topics to current format, for uniformity,
on, for instance, http://www.vuxml.org/freebsd/pkg-fetchmail.html.
2012-09-04 21:05:15 +00:00
Ashish SHUKLA
4b9fb5608c Chase Emacs updates 2012-09-04 17:05:43 +00:00
Eygene Ryabinkin
e4591b9585 security/squidclamav: fix DoS and XSS vulnerabilities
Apply upstream patches for CVE-2012-3501 and CVE-2012-4667.

Security:	http://www.vuxml.org/freebsd/ce680f0a-eea6-11e1-8bd8-0022156e8794.html
Security:	http://www.vuxml.org/freebsd/8defa0f9-ee8a-11e1-8bd8-0022156e8794.html
PR:		171022
QA page:	http://codelabs.ru/fbsd/ports/qa/security/squidclamav/5.7_1
Approved by:	maintainer timeout (1 week)
2012-09-04 13:45:28 +00:00
Mark Linimon
8e65c59121 Mark as broken on powerpc and sparc64 (and, presumably, ia64).
Hat:		portmgr
2012-09-04 06:57:36 +00:00
Johan van Selst
fb5118b613 - Add patch to fix getsubopt() parsing
Fixes setting of "realm-kdc" and "server-realm"
  http://lists.gnu.org/archive/html/help-shishi/2012-08/msg00073.html
- Bump PORTREVISION
- Reduce Makefile header

Submitted by:	Mats Erik Andersson <openbsd@gisladisker.se>
2012-09-02 09:04:01 +00:00
Eitan Adler
fc7b0bc22c Inform the community about a recent bitcoin DoS vuln.
Reviewed by:	swills
2012-09-02 02:57:37 +00:00
Olli Hauer
3c8085b82e - update bugzilla bugzilla3 and bugzilla42
- use new bugzilla@ address (members skv@, tota@, ohauer@)
- patch russian/japanese/german bugzilla and bugzilla templates
  so the reflect the security updates in the original templates
- patch german/bugzilla42 templates
- adopt new Makefile header

	vuxml: 6ad18fe5-f469-11e1-920d-20cf30e32f6d
	CVE: CVE-2012-3981
	https://bugzilla.mozilla.org/show_bug.cgi?id=785470
	https://bugzilla.mozilla.org/show_bug.cgi?id=785522
	https://bugzilla.mozilla.org/show_bug.cgi?id=785511
2012-09-01 20:16:06 +00:00
Eygene Ryabinkin
98d2a83482 VuXML: document CVE-2012-3534, DoS via large number of connections 2012-09-01 18:50:14 +00:00
Eitan Adler
1503d3f928 vuxml matches on PKGNAME, not on the port directory.
mediawiki118 has PKGNAME mediawiki-1.18.4
2012-09-01 17:40:16 +00:00
Eygene Ryabinkin
39ee691a71 Add "modified" tag to the Java 7 entry
Forgot to do it at r303435.

Spotted by:	wxs
Pointyhat to:	rea
2012-09-01 17:16:50 +00:00
Wen Heping
3ca103d238 - Update www/mediawiki to 1.19.2
- Update www/mediawiki118 to 1.18.5
- Document the security bugs
2012-09-01 12:44:33 +00:00
Eygene Ryabinkin
73839b622e VuXML: update Java 7 entry with Oracle-provided details
Oracle's Java 7 update 7 fixes CVE-2012-4681.
2012-08-31 16:58:41 +00:00
Matthias Andree
bc4796d9ea Tidy up paragraph formatting (it passed "make validate" before).
Suggested by:	wxs
2012-08-31 15:17:13 +00:00
Eygene Ryabinkin
3fab9832c2 VuXML: document CVE-2012-3548, DoS in Wireshark 2012-08-31 10:59:18 +00:00
Rene Ladan
c8cff29ed9 Document vulnerabilities in www/chromium < 21.0.1180.89
Obtained from:	http://googlechromereleases.blogspot.nl/search/label/Stable%20updates
2012-08-30 23:08:54 +00:00
Florian Smeets
b306f9876d - Update net/asterisk to 1.8.15.1
- Update net/asterisk10 to 10.7.1
- Document vulnerabilities in vuln.xml
- Fix URLs in the pervious asterisk vuln.xml entry

Security:	http://www.vuxml.org/freebsd/4c53f007-f2ed-11e1-a215-14dae9ebcf89.html
2012-08-30 22:14:10 +00:00
Steven Kreuzer
18f446f31b Update to 1.11
PR:		ports/171129
Submitted by:	Steve Wills <swills@freebsd.org>
2012-08-30 19:28:59 +00:00
Florian Smeets
2f4c3550c5 - update firefox and thunderbird to 15.0
- update firefox-esr, thunderbird-esr, linux-thunderbird and linux-firefox to 10.0.7
- update seamonkey and linux-seamonkey to 2.12
- update nss to 3.13.6
- update bsdipc code (posix_spawn, SysV shared memory)
- rename patches to easily track those not (yet) submitted upstream
- reduce package size, except for www/libxul[1]
- restore default objdir to what it was in 13.0
- fix mail/enigmail after thunderbird build changes
- don't accidentally pick up headers from installed ports[3]
- add support for PREFIX != LOCALBASE to Makefile.webplugins [4]
- document vulnerabilities in vuln.xml
- *miscellaneous cleanups and fixups*

Obtained from:	OpenBSD ports[1]
PR:		ports/159831, ports/160933, ports/170467[3], ports/170236 [4]
Submitted by:	avilla [4]
In collaboration with:	Jan Beich <jbeich@tormail.net> Who did most of the hard
			work.
2012-08-30 14:54:17 +00:00
Jase Thew
d313dc8481 - Update to 1.5.20
- Update MASTER_SITES
- Convert to optionsNG and add DOCS option
- Document security vulnerabilities [1]

PR:		ports/169558
Requested by:	Alexey <alexey@kouznetsov.com> (submitter)
Security:	6dd5e45c-f084-11e1-8d0f-406186f3d89d [1]
Approved by:	flo (mentor)
2012-08-30 11:40:20 +00:00
Eygene Ryabinkin
5a241795eb VuXML: document CVE-2012-4681, security manager bypass in Java 7.x 2012-08-30 09:03:22 +00:00
Matthias Andree
38ee66a4ac Add a vuln' entry for fetchmail's CVE-2011-3389 vulnerability. 2012-08-30 06:23:21 +00:00
Sofian Brabez
5e7369feb3 - Fix duplicated flags
PR:		ports/171117
Submitted by:	Lung-Pin Chang <changlp at cs.nctu.edu.tw>
2012-08-29 10:54:47 +00:00
Steve Wills
9f4eb9f533 - Update to 0.04
PR:		ports/170929
Approved by:	Frank Wall <fw@moov.de> (maintainer)
2012-08-27 21:45:58 +00:00
Matthias Andree
6b9d75c6d6 Update fetchmail to 6.3.21_1, fixing CVE-2012-3482.
Adjust VuXML database entry from < 6.3.22 to < 6.3.21_1.

PR:		ports/170613
Approved by:	maintainer timeout (14 days)
Security:	http://www.vuxml.org/freebsd/83f9e943-e664-11e1-a66d-080027ef73ec.html
Security:	CVE-2012-3482
2012-08-27 17:44:23 +00:00
Dirk Meyer
2e5654f50a - fix comment
PR:		171006
Submitted by:	Nick Hibma
2012-08-27 05:06:01 +00:00
Eygene Ryabinkin
61a4acdb03 VuXML entry c906e0a4-efa6-11e1-8fbf-001b77d09812: fix port epoch
Pointyhat to: rea
2012-08-26 21:31:11 +00:00
Eygene Ryabinkin
7b229e281e VuXML: document XSS in RoundCube Web-mail application
Branch 0.8.x before 0.8.1 is prone to XSS attack via incoming
HTML messages.
2012-08-26 21:26:57 +00:00
Steve Wills
09573f4343 - Update to 0.121930
PR:		ports/171064
Approved by:	Victor Popov <v.a.popov@gmail.com> (maintainer)
2012-08-26 18:16:55 +00:00
Eygene Ryabinkin
f7b99adb95 news/inn: fix plaintext command injection, CVE-2012-3523
Relevant only for INN installations that are using encryption.

PR:		171013
Approved by:	fluffy@FreeBSD.org (maintainer)
Security:	http://www.vuxml.org/freebsd/a7975581-ee26-11e1-8bd8-0022156e8794.html
2012-08-26 17:33:12 +00:00
Brendan Fabeny
c8b37f6406 update security/tor to 0.2.2.38 and security/tor-devel to 0.2.3.20-rc
Security:	Tor bugs 6480, 6530, 6537
2012-08-26 15:36:30 +00:00
Alberto Villa
f1f5da0da2 - Document Calligra input validation failure. 2012-08-26 01:44:43 +00:00
Bryan Drewery
c073ee94ec - Document that CVE-2012-3386 only affects automake >= 1.5.0
Verified this by inspecting the automake14 source, as well as
official release tarballs and git history.

Approved by:	bapt (mentor)
2012-08-25 22:17:28 +00:00
Eygene Ryabinkin
ba15cdb935 VuXML: document cross-site scripting in SquidClamav 2012-08-25 11:37:59 +00:00
Eygene Ryabinkin
dceeb16c74 VuXML: document DoS in SquidGuard
SquidGuard can be crashed via the specially-crafted URL
when external URL checker is used.
2012-08-25 10:07:39 +00:00
Roman Bogorodskiy
898c7be42e - Properly define deprecated functions to remove warnings in other
ports
- Avoid installing multiple copies of the GPLv2 and LGPL21 licenses
- Bump PORTREVISION

PR:		170488
Submitted by:	Jason E. Hale <bsdkaffee@gmail.com>
Approved by:	Hirohisa Yamaguchi (maintainer)
2012-08-25 08:33:55 +00:00
Eygene Ryabinkin
4a6a3e8277 VuXML: document INN plaintext command injection vulnerability 2012-08-24 20:13:53 +00:00
Thomas Abthorpe
7a49f28845 - Reset maintainer due to mail bounces
With hat:	portmgr
2012-08-24 12:44:52 +00:00
Alex Dupre
78814883e7 Update to 1.12.5 release. 2012-08-23 14:56:42 +00:00
Tom Judge
fbdf0baff1 Upgrade to 4.41.
Changes: http://clamtk.sourceforge.net/CHANGES

Approved by:	eadler (mentor)
2012-08-23 03:09:32 +00:00
Eygene Ryabinkin
cfe35f60ca VuXML: document CVE-2012-3525 in jabberd 2.x 2012-08-22 21:10:10 +00:00
Eygene Ryabinkin
c810204482 VuXML: fix whitespace in my previous rssh entry 2012-08-22 20:01:19 +00:00
Eygene Ryabinkin
d000b2b27d VuXML: document rssh vulnerabilities fixed in version 2.3.3 2012-08-22 20:00:31 +00:00
Doug Barton
235e0c0890 Fix problem introduced in r302141. The directory for the unpacked source
files is unversioned, so it conflicts with the name of the rc.d script in
WRKDIR after SUB_FILES is applied.
2012-08-21 21:00:33 +00:00