Joe Marcus Clarke
a075d031b2
Change the wireshark version for the DRDA fix.
2012-09-05 16:02:11 +00:00
Dag-Erling Smørgrav
dbc36c9345
Remove useless metadata from ports I created.
2012-09-05 15:43:33 +00:00
Cy Schubert
60236bdbd9
Update 0.13.1 --> 0.15.1
2012-09-05 14:26:25 +00:00
Frederic Culot
48d9d6c9ba
- Update to 0.23
...
Changes: http://search.cpan.org/dist/Authen-TacacsPlus/Changes
2012-09-05 10:56:26 +00:00
Eygene Ryabinkin
1213e0634b
VuXML: document XSS in MoinMoin before 1.9.4 via RST parser
2012-09-05 10:42:38 +00:00
Eygene Ryabinkin
bf6426a1fb
VuXML: document wrong group ACL processing in MoinMoin
2012-09-05 09:47:35 +00:00
Eygene Ryabinkin
1b3ec36058
PHP 5.x: document header splitting vulnerability
...
There is a related CVE number (CVE-2012-4388), but there is no current
consensus about it:
http://article.gmane.org/gmane.comp.security.oss.general/8303
2012-09-05 06:29:38 +00:00
Matthias Andree
84f7423f73
Modify fetchmail vuln' URLs to established site.
...
While at it, adjust the two oldest topics to current format, for uniformity,
on, for instance, http://www.vuxml.org/freebsd/pkg-fetchmail.html .
2012-09-04 21:05:15 +00:00
Ashish SHUKLA
4b9fb5608c
Chase Emacs updates
2012-09-04 17:05:43 +00:00
Eygene Ryabinkin
e4591b9585
security/squidclamav: fix DoS and XSS vulnerabilities
...
Apply upstream patches for CVE-2012-3501 and CVE-2012-4667.
Security: http://www.vuxml.org/freebsd/ce680f0a-eea6-11e1-8bd8-0022156e8794.html
Security: http://www.vuxml.org/freebsd/8defa0f9-ee8a-11e1-8bd8-0022156e8794.html
PR: 171022
QA page: http://codelabs.ru/fbsd/ports/qa/security/squidclamav/5.7_1
Approved by: maintainer timeout (1 week)
2012-09-04 13:45:28 +00:00
Mark Linimon
8e65c59121
Mark as broken on powerpc and sparc64 (and, presumably, ia64).
...
Hat: portmgr
2012-09-04 06:57:36 +00:00
Johan van Selst
fb5118b613
- Add patch to fix getsubopt() parsing
...
Fixes setting of "realm-kdc" and "server-realm"
http://lists.gnu.org/archive/html/help-shishi/2012-08/msg00073.html
- Bump PORTREVISION
- Reduce Makefile header
Submitted by: Mats Erik Andersson <openbsd@gisladisker.se>
2012-09-02 09:04:01 +00:00
Eitan Adler
fc7b0bc22c
Inform the community about a recent bitcoin DoS vuln.
...
Reviewed by: swills
2012-09-02 02:57:37 +00:00
Olli Hauer
3c8085b82e
- update bugzilla bugzilla3 and bugzilla42
...
- use new bugzilla@ address (members skv@, tota@, ohauer@)
- patch russian/japanese/german bugzilla and bugzilla templates
so the reflect the security updates in the original templates
- patch german/bugzilla42 templates
- adopt new Makefile header
vuxml: 6ad18fe5-f469-11e1-920d-20cf30e32f6d
CVE: CVE-2012-3981
https://bugzilla.mozilla.org/show_bug.cgi?id=785470
https://bugzilla.mozilla.org/show_bug.cgi?id=785522
https://bugzilla.mozilla.org/show_bug.cgi?id=785511
2012-09-01 20:16:06 +00:00
Eygene Ryabinkin
98d2a83482
VuXML: document CVE-2012-3534, DoS via large number of connections
2012-09-01 18:50:14 +00:00
Eitan Adler
1503d3f928
vuxml matches on PKGNAME, not on the port directory.
...
mediawiki118 has PKGNAME mediawiki-1.18.4
2012-09-01 17:40:16 +00:00
Eygene Ryabinkin
39ee691a71
Add "modified" tag to the Java 7 entry
...
Forgot to do it at r303435.
Spotted by: wxs
Pointyhat to: rea
2012-09-01 17:16:50 +00:00
Wen Heping
3ca103d238
- Update www/mediawiki to 1.19.2
...
- Update www/mediawiki118 to 1.18.5
- Document the security bugs
2012-09-01 12:44:33 +00:00
Eygene Ryabinkin
73839b622e
VuXML: update Java 7 entry with Oracle-provided details
...
Oracle's Java 7 update 7 fixes CVE-2012-4681.
2012-08-31 16:58:41 +00:00
Matthias Andree
bc4796d9ea
Tidy up paragraph formatting (it passed "make validate" before).
...
Suggested by: wxs
2012-08-31 15:17:13 +00:00
Eygene Ryabinkin
3fab9832c2
VuXML: document CVE-2012-3548, DoS in Wireshark
2012-08-31 10:59:18 +00:00
Rene Ladan
c8cff29ed9
Document vulnerabilities in www/chromium < 21.0.1180.89
...
Obtained from: http://googlechromereleases.blogspot.nl/search/label/Stable%20updates
2012-08-30 23:08:54 +00:00
Florian Smeets
b306f9876d
- Update net/asterisk to 1.8.15.1
...
- Update net/asterisk10 to 10.7.1
- Document vulnerabilities in vuln.xml
- Fix URLs in the pervious asterisk vuln.xml entry
Security: http://www.vuxml.org/freebsd/4c53f007-f2ed-11e1-a215-14dae9ebcf89.html
2012-08-30 22:14:10 +00:00
Steven Kreuzer
18f446f31b
Update to 1.11
...
PR: ports/171129
Submitted by: Steve Wills <swills@freebsd.org>
2012-08-30 19:28:59 +00:00
Florian Smeets
2f4c3550c5
- update firefox and thunderbird to 15.0
...
- update firefox-esr, thunderbird-esr, linux-thunderbird and linux-firefox to 10.0.7
- update seamonkey and linux-seamonkey to 2.12
- update nss to 3.13.6
- update bsdipc code (posix_spawn, SysV shared memory)
- rename patches to easily track those not (yet) submitted upstream
- reduce package size, except for www/libxul[1]
- restore default objdir to what it was in 13.0
- fix mail/enigmail after thunderbird build changes
- don't accidentally pick up headers from installed ports[3]
- add support for PREFIX != LOCALBASE to Makefile.webplugins [4]
- document vulnerabilities in vuln.xml
- *miscellaneous cleanups and fixups*
Obtained from: OpenBSD ports[1]
PR: ports/159831, ports/160933, ports/170467[3], ports/170236 [4]
Submitted by: avilla [4]
In collaboration with: Jan Beich <jbeich@tormail.net> Who did most of the hard
work.
2012-08-30 14:54:17 +00:00
Jase Thew
d313dc8481
- Update to 1.5.20
...
- Update MASTER_SITES
- Convert to optionsNG and add DOCS option
- Document security vulnerabilities [1]
PR: ports/169558
Requested by: Alexey <alexey@kouznetsov.com> (submitter)
Security: 6dd5e45c-f084-11e1-8d0f-406186f3d89d [1]
Approved by: flo (mentor)
2012-08-30 11:40:20 +00:00
Eygene Ryabinkin
5a241795eb
VuXML: document CVE-2012-4681, security manager bypass in Java 7.x
2012-08-30 09:03:22 +00:00
Matthias Andree
38ee66a4ac
Add a vuln' entry for fetchmail's CVE-2011-3389 vulnerability.
2012-08-30 06:23:21 +00:00
Sofian Brabez
5e7369feb3
- Fix duplicated flags
...
PR: ports/171117
Submitted by: Lung-Pin Chang <changlp at cs.nctu.edu.tw>
2012-08-29 10:54:47 +00:00
Steve Wills
9f4eb9f533
- Update to 0.04
...
PR: ports/170929
Approved by: Frank Wall <fw@moov.de> (maintainer)
2012-08-27 21:45:58 +00:00
Matthias Andree
6b9d75c6d6
Update fetchmail to 6.3.21_1, fixing CVE-2012-3482.
...
Adjust VuXML database entry from < 6.3.22 to < 6.3.21_1.
PR: ports/170613
Approved by: maintainer timeout (14 days)
Security: http://www.vuxml.org/freebsd/83f9e943-e664-11e1-a66d-080027ef73ec.html
Security: CVE-2012-3482
2012-08-27 17:44:23 +00:00
Dirk Meyer
2e5654f50a
- fix comment
...
PR: 171006
Submitted by: Nick Hibma
2012-08-27 05:06:01 +00:00
Eygene Ryabinkin
61a4acdb03
VuXML entry c906e0a4-efa6-11e1-8fbf-001b77d09812: fix port epoch
...
Pointyhat to: rea
2012-08-26 21:31:11 +00:00
Eygene Ryabinkin
7b229e281e
VuXML: document XSS in RoundCube Web-mail application
...
Branch 0.8.x before 0.8.1 is prone to XSS attack via incoming
HTML messages.
2012-08-26 21:26:57 +00:00
Steve Wills
09573f4343
- Update to 0.121930
...
PR: ports/171064
Approved by: Victor Popov <v.a.popov@gmail.com> (maintainer)
2012-08-26 18:16:55 +00:00
Eygene Ryabinkin
f7b99adb95
news/inn: fix plaintext command injection, CVE-2012-3523
...
Relevant only for INN installations that are using encryption.
PR: 171013
Approved by: fluffy@FreeBSD.org (maintainer)
Security: http://www.vuxml.org/freebsd/a7975581-ee26-11e1-8bd8-0022156e8794.html
2012-08-26 17:33:12 +00:00
Brendan Fabeny
c8b37f6406
update security/tor to 0.2.2.38 and security/tor-devel to 0.2.3.20-rc
...
Security: Tor bugs 6480, 6530, 6537
2012-08-26 15:36:30 +00:00
Alberto Villa
f1f5da0da2
- Document Calligra input validation failure.
2012-08-26 01:44:43 +00:00
Bryan Drewery
c073ee94ec
- Document that CVE-2012-3386 only affects automake >= 1.5.0
...
Verified this by inspecting the automake14 source, as well as
official release tarballs and git history.
Approved by: bapt (mentor)
2012-08-25 22:17:28 +00:00
Eygene Ryabinkin
ba15cdb935
VuXML: document cross-site scripting in SquidClamav
2012-08-25 11:37:59 +00:00
Eygene Ryabinkin
dceeb16c74
VuXML: document DoS in SquidGuard
...
SquidGuard can be crashed via the specially-crafted URL
when external URL checker is used.
2012-08-25 10:07:39 +00:00
Roman Bogorodskiy
898c7be42e
- Properly define deprecated functions to remove warnings in other
...
ports
- Avoid installing multiple copies of the GPLv2 and LGPL21 licenses
- Bump PORTREVISION
PR: 170488
Submitted by: Jason E. Hale <bsdkaffee@gmail.com>
Approved by: Hirohisa Yamaguchi (maintainer)
2012-08-25 08:33:55 +00:00
Eygene Ryabinkin
4a6a3e8277
VuXML: document INN plaintext command injection vulnerability
2012-08-24 20:13:53 +00:00
Thomas Abthorpe
7a49f28845
- Reset maintainer due to mail bounces
...
With hat: portmgr
2012-08-24 12:44:52 +00:00
Alex Dupre
78814883e7
Update to 1.12.5 release.
2012-08-23 14:56:42 +00:00
Tom Judge
fbdf0baff1
Upgrade to 4.41.
...
Changes: http://clamtk.sourceforge.net/CHANGES
Approved by: eadler (mentor)
2012-08-23 03:09:32 +00:00
Eygene Ryabinkin
cfe35f60ca
VuXML: document CVE-2012-3525 in jabberd 2.x
2012-08-22 21:10:10 +00:00
Eygene Ryabinkin
c810204482
VuXML: fix whitespace in my previous rssh entry
2012-08-22 20:01:19 +00:00
Eygene Ryabinkin
d000b2b27d
VuXML: document rssh vulnerabilities fixed in version 2.3.3
2012-08-22 20:00:31 +00:00
Doug Barton
235e0c0890
Fix problem introduced in r302141. The directory for the unpacked source
...
files is unversioned, so it conflicts with the name of the rc.d script in
WRKDIR after SUB_FILES is applied.
2012-08-21 21:00:33 +00:00