1
0
mirror of https://git.FreeBSD.org/ports.git synced 2024-12-28 05:29:48 +00:00
Mirror of the FreeBSD ports git repo https://git.FreeBSD.org/ports.git .
Go to file
Martin Wilke e1aff40d78 - Fix zabbix -- php frontend multiple vulnerabilities
Note:

	Input appended to and passed via the "extlang" parameter to the "calc_exp2()"
	function in include/validate.inc.php is not properly sanitised before being
	used. This can be exploited to inject and execute arbitrary PHP code.

	The application allows users to perform certain actions via HTTP requests
	without performing any validity checks to verify the requests. This can be
	exploited to e.g. create users by enticing a logged in administrator to
	visit a malicious web page.

	Input passed to the "srclang" parameter in locales.php (when "next" is set
	to a non-NULL value) is not properly verified before being used to include
	files. This can be exploited to include arbitrary files from local resources
	via directory traversal attacks and URL-encoded NULL bytes.

- Bump PORTREVISION

PR:		132944
Submitted by:	Eygene Ryabinkin <rea-fbsd@codelabs.ru> (many thanks!)
Approved by:	maintainer timeout (security 1 day)
Security:	http://www.vuxml.org/freebsd/03140526-1250-11de-a964-0030843d3802.html
2009-03-23 15:06:19 +00:00
accessibility Release these ports into wild. I don't have time for these ports anymore. I am 2009-03-18 20:06:38 +00:00
arabic Update KDE to 4.2.1. 2009-03-09 00:55:48 +00:00
archivers - Update to 1.5.1 2009-03-23 01:59:59 +00:00
astro - Do not run depend on moc. 2009-03-21 12:15:34 +00:00
audio - Fix multiple vulnerabilities 2009-03-23 14:24:22 +00:00
benchmarks - Mark port MAKE_JOBS_SAFE 2009-03-23 12:18:31 +00:00
biology - Update to 1.6.1 2009-03-19 20:54:05 +00:00
cad - Add missing plist 2009-03-23 06:03:56 +00:00
chinese Update KDE to 4.2.1. 2009-03-09 00:55:48 +00:00
comms - Add MAKE_JOBS_SAFE variable 2009-03-23 13:06:09 +00:00
converters - Update to 0.29 2009-03-23 04:12:16 +00:00
databases - Mark port MAKE_JOBS_SAFE 2009-03-23 12:18:31 +00:00
deskutils PlayWolf is a plasma applet for KDE4 that allows you to control Amarok 2.x from 2009-03-20 23:30:32 +00:00
devel Update to 0.07 2009-03-23 13:24:26 +00:00
dns - Mark port MAKE_JOBS_SAFE 2009-03-23 12:18:31 +00:00
editors - Remove IGNORE line 2009-03-23 06:05:03 +00:00
emulators - Fix build on CURRENT: rename dprintf macro to not conflict with one from stdio.h 2009-03-22 23:06:45 +00:00
finance - Update to 6.02 2009-03-22 18:34:18 +00:00
french Upgrade SeaMonkey's FLP to 1.1.15. 2009-03-22 17:21:57 +00:00
ftp - Fix build after strndup(3) MFC 2009-03-21 17:26:35 +00:00
games Update to 1.5.14. 2009-03-22 19:03:41 +00:00
german - add LICENSE: 2009-03-19 21:09:05 +00:00
graphics - Update to 6.5.0-5 2009-03-23 12:25:33 +00:00
hebrew Update KDE to 4.2.1. 2009-03-09 00:55:48 +00:00
hungarian Update KDE to 4.2.1. 2009-03-09 00:55:48 +00:00
irc - Mark port MAKE_JOBS_SAFE 2009-03-23 12:18:31 +00:00
japanese Follow the version number of databases/namazu2. 2009-03-22 16:11:51 +00:00
java Welcome to the new linux ports infrastructure which allows using 2009-03-19 17:28:51 +00:00
korean - Fix install and deinstall procedure 2009-03-22 21:15:03 +00:00
lang - Update to snapshot r5519. 2009-03-23 13:46:42 +00:00
mail Reset barner@FreeBSD.org due to several months of inactivity. 2009-03-23 01:01:14 +00:00
math R-cran-sm is a R module for smoothing methods for nonparametric 2009-03-22 13:32:38 +00:00
mbone - externd support for tcl/tk 8.3 2009-03-14 18:50:25 +00:00
misc - update to 0.05 2009-03-22 23:36:25 +00:00
Mk R-cran-sm is a R module for smoothing methods for nonparametric 2009-03-22 13:32:38 +00:00
multimedia Reset barner@FreeBSD.org due to several months of inactivity. 2009-03-23 01:01:14 +00:00
net Remove net/penguintv-devel since the development version has not 2009-03-23 04:10:01 +00:00
net-im - Mark port MAKE_JOBS_SAFE 2009-03-23 12:18:31 +00:00
net-mgmt - Fix zabbix -- php frontend multiple vulnerabilities 2009-03-23 15:06:19 +00:00
net-p2p Update to 2.2.3. 2009-03-22 05:45:49 +00:00
news - Update WWW 2009-03-22 18:47:07 +00:00
palm - Update to 0.13 2009-03-20 23:21:00 +00:00
polish Fix build on 6-STABLE after adding --with-pthread to polish/libgadu 2009-03-22 10:56:44 +00:00
ports-mgmt Update to 2.11.0. 2009-03-22 17:54:19 +00:00
portuguese Welcome to the new linux ports infrastructure which allows using 2009-03-19 17:28:51 +00:00
print - Mark BROKEN: does not fetch 2009-03-20 21:22:11 +00:00
russian Update KDE to 4.2.1. 2009-03-09 00:55:48 +00:00
science - Fix Fortran linking 2009-03-22 22:09:27 +00:00
security - Fix spelling 2009-03-23 14:22:46 +00:00
shells - Update to R36b 2009-03-21 01:02:58 +00:00
sysutils Reset barner@FreeBSD.org due to several months of inactivity. 2009-03-23 01:01:14 +00:00
Templates
textproc Use DOCSDIR consistently and repect NOPORTDOCS. 2009-03-23 08:15:51 +00:00
Tools
ukrainian Update KDE to 4.2.1. 2009-03-09 00:55:48 +00:00
vietnamese
www Has been gone from CPAN for ages, so can't build anyway. Use 2009-03-23 14:09:14 +00:00
x11 Move oclock from x11 to x11-clocks category. 2009-03-23 11:36:19 +00:00
x11-clocks Move oclock from x11 to x11-clocks category. 2009-03-23 11:36:19 +00:00
x11-drivers Update to 6.12.1 2009-03-19 02:40:00 +00:00
x11-fm - udpate to 0.4.1 2009-03-20 09:15:46 +00:00
x11-fonts Welcome to the new linux ports infrastructure which allows using 2009-03-19 17:28:51 +00:00
x11-servers Add the patch that I missed in the last commit. 2009-03-08 23:07:06 +00:00
x11-themes - Fix clearlooks-themes slave port for people with gtk-engines2 installed 2009-03-22 18:13:31 +00:00
x11-toolkits - Update to 2.12.8 2009-03-22 19:34:49 +00:00
x11-wm - Remove excessive @dirrmtrys 2009-03-20 21:04:49 +00:00
.cvsignore
CHANGES - Change the wording a bit to point to UPDATING as well 2009-03-02 18:53:31 +00:00
COPYRIGHT
GIDs - Register uid and gid for mail/prayer 2009-03-17 15:10:39 +00:00
KNOBS Add PSYCO knob: "Adds Python Psyco optimization support" 2009-03-06 02:01:27 +00:00
LEGAL
Makefile
MOVED Has been gone from CPAN for ages, so can't build anyway. Use 2009-03-23 14:09:14 +00:00
README
UIDs - Register uid and gid for mail/prayer 2009-03-17 15:10:39 +00:00
UPDATING - Add notes for www/suphp updating from 0.6.x to 0.7.x 2009-03-20 07:36:17 +00:00

This is the FreeBSD Ports Collection.  For an easy to use
WEB-based interface to it, please see:

	http://www.FreeBSD.org/ports

For general information on the Ports Collection, please see the
FreeBSD Handbook ports section which is available from:

	http://www.FreeBSD.org/doc/en_US.ISO8859-1/books/handbook/ports.html
		for the latest official version
	or:
	The ports(7) manual page (man ports).

These will explain how to use ports and packages.

If you would like to search for a port, you can do so easily by
saying (in /usr/ports):


	make search name="<name>"
	or:
	make search key="<keyword>"

which will generate a list of all ports matching <name> or <keyword>.
make search also supports wildcards, such as:

	make search name="gtk*"

For information about contributing to FreeBSD ports, please see the Porter's
Handbook, available at:

	http://www.FreeBSD.org/doc/en_US.ISO8859-1/books/porters-handbook/

NOTE:  This tree will GROW significantly in size during normal usage!
The distribution tar files can and do accumulate in /usr/ports/distfiles,
and the individual ports will also use up lots of space in their work
subdirectories unless you remember to "make clean" after you're done
building a given port.  /usr/ports/distfiles can also be periodically
cleaned without ill-effect.