1
0
mirror of https://git.FreeBSD.org/ports.git synced 2025-01-08 06:48:28 +00:00
freebsd-ports/net-mgmt
Martin Wilke e1aff40d78 - Fix zabbix -- php frontend multiple vulnerabilities
Note:

	Input appended to and passed via the "extlang" parameter to the "calc_exp2()"
	function in include/validate.inc.php is not properly sanitised before being
	used. This can be exploited to inject and execute arbitrary PHP code.

	The application allows users to perform certain actions via HTTP requests
	without performing any validity checks to verify the requests. This can be
	exploited to e.g. create users by enticing a logged in administrator to
	visit a malicious web page.

	Input passed to the "srclang" parameter in locales.php (when "next" is set
	to a non-NULL value) is not properly verified before being used to include
	files. This can be exploited to include arbitrary files from local resources
	via directory traversal attacks and URL-encoded NULL bytes.

- Bump PORTREVISION

PR:		132944
Submitted by:	Eygene Ryabinkin <rea-fbsd@codelabs.ru> (many thanks!)
Approved by:	maintainer timeout (security 1 day)
Security:	http://www.vuxml.org/freebsd/03140526-1250-11de-a964-0030843d3802.html
2009-03-23 15:06:19 +00:00
..
aggregate Fix simultaneous use of -t and -p options. 2009-02-23 12:17:08 +00:00
aguri
aircrack-ng
airport
angst
annextools
ap-utils
argus Reset se@FreeBSD.org due to maintainer-timeouts and no response to email. 2008-12-18 02:33:39 +00:00
argus3 Reset se@FreeBSD.org due to maintainer-timeouts and no response to email. 2008-12-18 02:33:39 +00:00
argus3-clients Reset se@FreeBSD.org due to maintainer-timeouts and no response to email. 2008-12-18 02:33:39 +00:00
argus-clients Reset se@FreeBSD.org due to maintainer-timeouts and no response to email. 2008-12-18 02:33:39 +00:00
argus-monitor
arpalert
arpscan Reset dyeske@gmail.com at his request. 2009-02-02 23:44:01 +00:00
arpwatch
arts++
aspathtree
asused - Reset farrokhi@freebsd.org due to long period of inactivity. 2009-03-09 19:29:12 +00:00
bandwidthd
bgpq - Reset farrokhi@freebsd.org due to long period of inactivity. 2009-03-09 19:29:12 +00:00
bigsister
bpft
braa
bsd-airtools
bsnmp-regex - update to 0.3 version 2009-03-08 23:46:45 +00:00
bsnmp-ucd
bsnmptools - Remove conditional checks for FreeBSD 5.x and older 2009-01-06 17:59:31 +00:00
bwm-ng
cacti - Update to 0.8.7d 2009-02-16 16:43:39 +00:00
cacti-spine - Pass maintainership to submitter 2009-02-28 03:34:40 +00:00
cdpd
cdpr
cfgstoragemk
cflowd
check_multi - mirror distfile 2009-03-19 18:42:04 +00:00
check_snmp_pkgvuln
chillispot - Add conflicts with newly added net-mgmt/coovachilli 2009-01-20 11:58:02 +00:00
choparp
cidr
cisco_conf
ciscoconf
clog
collectd Bump the version of the curl shared library after the ftp/curl update 2009-01-23 15:43:14 +00:00
collectd5 Bump the version of the curl shared library after the ftp/curl update 2009-01-23 15:43:14 +00:00
confregdecode
coovachilli CoovaChilli is an access controller 2009-01-20 11:57:59 +00:00
cowpatty - Use my FreeBSD address on the ports I maintain 2009-03-06 18:14:36 +00:00
cricket Maintainer moved to ports@FreeBSD.org. 2008-11-20 11:06:24 +00:00
darkstat - Update to 3.0.712 2008-12-06 06:27:36 +00:00
disco
docsis
driftnet
echolot
ehnt
etherape
ettercap - Remove conditional checks for FreeBSD 5.x and older 2009-01-06 17:59:31 +00:00
ezradius
fetchconfig
flow-extract
flow-tools - Flow-tools conflicts with freshly-imported flow-tools-ng. 2008-11-16 22:39:21 +00:00
flow-tools-ng - Fix invocation of python and perl scripts by correcting path to env executable 2009-01-12 00:32:44 +00:00
flowd
flowscan
flowviewer
fprobe
fruity
gps - fix plist for -DNOPORTDOCS 2008-11-21 10:38:52 +00:00
grepcidr
grepip
gsnmp
horde-nic Bump PORTREVISION's after OpenLDAP update. 2009-01-05 19:04:45 +00:00
icmpmonitor
icmpquery
ifgraph
iftop
iog
ipacco - Reset farrokhi@freebsd.org due to long period of inactivity. 2009-03-09 19:29:12 +00:00
ipacctd
ipaudit Reset yinjieh@csie.nctu.edu.tw due to lack of time to work on ports 2008-12-25 03:13:51 +00:00
ipcad
ipcalc
ipfm
ipplan - Update to 4.91a 2009-03-19 15:52:17 +00:00
ipsectrace - Reset farrokhi@freebsd.org due to long period of inactivity. 2009-03-09 19:29:12 +00:00
ipv6calc Fix build of net-mgmt/ipv6calc 2009-03-06 23:19:58 +00:00
ipv6gen
irrtoolset
isic
jffnms - Reset farrokhi@freebsd.org due to long period of inactivity. 2009-03-09 19:29:12 +00:00
junipoll - Reset farrokhi@freebsd.org due to long period of inactivity. 2009-03-09 19:29:12 +00:00
kismet - Update ImageMagick to 6.4.9.2 2009-02-10 19:50:55 +00:00
knowlan
lanmap - Fix pkg-plist 2009-02-02 09:50:21 +00:00
libsmi
macroscope - Update to 1.0.3787 2008-12-25 18:08:52 +00:00
mbrowse
mrtg
mrtg-ping-probe fix regular expression for packet loss strings. 2009-03-09 23:10:05 +00:00
mtrace
nagcon
nagios Update to Nagios 3.0.6. 2008-12-10 00:31:50 +00:00
nagios2 - Add backport patches to fix CVE-2008-5027 and CVE-2008-5028 2009-01-16 00:00:22 +00:00
nagios12 - Mark as deprecated and schedule for removal in four weeks: last releases were back in 2004, neither of Nagios 1.x and NRPE 1.x are supported by the author. 2009-03-17 17:18:45 +00:00
nagios-certexp-plugin
nagios-check_bacula - Update to 2.4.4 2009-03-19 21:35:27 +00:00
nagios-check_ports - Update to 0.6.1 2009-03-13 16:22:35 +00:00
nagios-devel - Update to 3.1.0 2009-02-25 23:57:03 +00:00
nagios-geom - Update to 1.3 2008-12-23 20:14:48 +00:00
nagios-pf-plugin
nagios-plugins - Update to 1.4.43 2008-10-18 21:38:15 +00:00
nagios-portaudit
nagios-radauth-plugin
nagios-silfreed-plugins
nagios-snmp-plugins
nagios-spamd-plugin
nagiosgraph
nagiostat
nagircbot - Remove conditional checks for FreeBSD 5.x and older 2009-01-06 17:59:31 +00:00
nat
nav - USE_REINPLACE_CMD is nothing, remove 2009-01-08 16:59:24 +00:00
nbtscan
ndoutils - An rc.d script that actually works [1] 2008-12-25 14:42:24 +00:00
ndpmon
nedi
nefu - Reset farrokhi@freebsd.org due to long period of inactivity. 2009-03-09 19:29:12 +00:00
net-snmp Try to reduce errors/warnings within sctp area. 2009-03-07 15:51:25 +00:00
net-snmp4 Mark BROKEN on 8: does not build after arp-v2 import. 2009-01-08 17:11:33 +00:00
net-snmp53 Unbreak by merging RTL_LLINFO workaround from net-snmp. 2009-02-12 11:18:47 +00:00
net-snmp-devel Try to reduce errors/warnings within sctp area. 2009-03-07 15:51:25 +00:00
net-snmp-tkmib Upgrade to 4.2.7.1. 2009-03-12 14:09:37 +00:00
netams Replace last occurrence of BROKEN_WITH_MYSQL with IGNORE_WITH_MYSQL. 2009-03-04 14:33:11 +00:00
netdisco
netleak
netmask
netmond
netspoc
nettop
netustad
netwag
netwox
netxms - Update to 0.2.24 2009-01-13 03:08:02 +00:00
nfdump - Add the daylight saving patch 2009-03-10 23:41:08 +00:00
nfdump-devel
nfsen
ng_ipacct
nipper
nitpicker
nocol
nrg - Update maintainer mail 2009-03-20 17:49:26 +00:00
nrpe - Mark as deprecated and schedule for removal in four weeks: last releases were back in 2004, neither of Nagios 1.x and NRPE 1.x are supported by the author. 2009-03-17 17:18:45 +00:00
nrpe2 - Modify rc.d script to allow administrator to change PID file location 2008-12-25 20:24:43 +00:00
nrpep
nsca
nsca-client
nstreams
ocsinventory-agent
ocsinventory-ng - Roll back for the last revision, when you try to use USE_APACHE=2.0 2008-11-07 18:00:31 +00:00
openlldp
openvmps
oproute Mark for depreciation, since unmaintained, failing to work with current 2009-02-21 22:56:45 +00:00
ourmon
p0f - Reset farrokhi@freebsd.org due to long period of inactivity. 2009-03-09 19:29:12 +00:00
p5-Altoids
p5-Cflow - Reset farrokhi@freebsd.org due to long period of inactivity. 2009-03-09 19:29:12 +00:00
p5-Cisco-Reconfig
p5-Data-Validate-IP
p5-Mon
p5-MRTG-Parse
p5-Nagios-Plugin - Update to 0.32 2009-03-20 18:57:13 +00:00
p5-Nagios-Plugins-Memcached
p5-Net-Abuse-Utils - Update to 0.10 2009-02-15 17:24:16 +00:00
p5-Net-ACL
p5-Net-CIDR - Update to 0.13 2009-01-23 08:26:02 +00:00
p5-Net-IP
p5-Net-IP-Match-Regexp Bump version of the port to 1.01 2009-02-22 02:27:58 +00:00
p5-Net-IP-Match-XS
p5-Net-IP-Resolver
p5-Net-IPv4Addr
p5-Net-IPv6Addr
p5-Net-Netmask
p5-Net-SNMP
p5-Net-Telnet-Cisco-IOS
p5-NetAddr-IP Update to 4.024. 2009-02-09 13:05:28 +00:00
p5-NetAddr-IP-Lite
p5-NetApp This package provides a suite of modules for managing NetApp's NAS 2009-03-10 15:13:43 +00:00
p5-NSNMP
p5-POE-Component-SNMP Update to 1.1001 2009-02-15 20:02:29 +00:00
p5-SNMP
p5-SNMP_Session Update to version 1.12. 2008-12-04 13:28:54 +00:00
p5-SNMP-Info
p5-SNMP-MIB-Compiler
p5-SNMP-Simple
p5-SNMP-Util
p5-Telnet-Cisco
p5-Tie-NetAddr-IP
packit
pads - Added patch to fix a problem with the pidfile. 2009-02-21 21:23:32 +00:00
pancho
pftabled - Install a perl sample client and an option associated with it 2009-03-02 02:47:39 +00:00
php4-snmp
php5-snmp Update to 5.2.9 release and re-add pcre extension. 2009-03-06 10:08:35 +00:00
phpip - Take over maintainership 2009-03-09 19:14:20 +00:00
pixilate
pktstat
pmacct
pnp - Update to 0.4.12 2008-12-25 00:32:12 +00:00
portmon
py-flowtools
py-ipy - Update to 0.62 2008-12-22 21:20:13 +00:00
py-snmp
py-snmp2
py-snmp4
py-snmp4-apps
py-snmp4-mibs
py-twistedSNMP
py-yapsnmp CATEGORIES+= python for py- ports missing it 2008-12-28 10:54:08 +00:00
rancid
rancid-devel - Update to 2.3.2a9 2009-02-08 22:08:55 +00:00
rate
rcpd - Reset farrokhi@freebsd.org due to long period of inactivity. 2009-03-09 19:29:12 +00:00
remarp Use variables SITE_PERL and SITE_PERL_REL where appropriate. 2009-02-24 13:29:22 +00:00
rotorouter
routers2 - Update to 2.19 2008-11-18 23:25:18 +00:00
routers2-extensions - Update to 2.19 2008-11-18 23:25:18 +00:00
routers2-extras - Update to 2.19 2008-11-18 23:25:18 +00:00
rrdbot - Use my FreeBSD address on the ports I maintain 2009-03-06 18:14:36 +00:00
rubygem-snmp - Fix plist after ruby update by generating it dynamically. 2009-02-14 01:44:59 +00:00
satellite
sblim-wbemcli Bump the version of the curl shared library after the ftp/curl update 2009-01-23 15:43:14 +00:00
scdp
scli
scotty3
sdig
send - Remove conditional checks for FreeBSD 5.x and older 2009-01-06 17:59:31 +00:00
sendip
sing
sipcalc
sjitter - Reset farrokhi@freebsd.org due to long period of inactivity. 2009-03-09 19:29:12 +00:00
slate
smokeping - man pages installation is not conditioned by NOPORTDOCS (fix plist) 2008-11-21 10:37:10 +00:00
snmp4nagios
snmp++ Update to 3.2.23. 2009-03-05 14:48:50 +00:00
snmptt
softflowd
spectools - Chase libusb20 rename in r189585. 2009-03-09 17:15:43 +00:00
subcalc
sysmon
tcpreplay Update to 3.4.1 2009-03-09 13:58:32 +00:00
tcptrack
tknetmon - UNBREAK fix tktable dependency to 2.10 2008-11-30 20:55:25 +00:00
TkTopNetFlows - UNBREAK fix tktable dependency to 2.10 2008-11-30 20:55:25 +00:00
tork - Update to 0.30 2008-11-15 23:40:57 +00:00
torrus
trafd
vidalia - Update to 0.1.11 2009-02-23 23:06:28 +00:00
wdiag
weathermap
weplab
whatmask
wide-dhcp Mark BROKEN on 8: does not build after the arp-v2 import. 2009-01-08 17:59:41 +00:00
xymon-client - update to 4.2.3 2009-02-26 18:47:47 +00:00
xymon-server - update to 4.2.3 2009-02-26 18:54:32 +00:00
yabm
zabbix - Fix zabbix -- php frontend multiple vulnerabilities 2009-03-23 15:06:19 +00:00
zabbix2 - Fix zabbix -- php frontend multiple vulnerabilities 2009-03-23 15:06:19 +00:00
zabbix2-agent - Fix zabbix -- php frontend multiple vulnerabilities 2009-03-23 15:06:19 +00:00
zabbix-agent - Fix zabbix -- php frontend multiple vulnerabilities 2009-03-23 15:06:19 +00:00
Makefile check_multi is kind of a wrapper plugin which takes benefit of the 2009-03-18 06:21:13 +00:00