Commit graph

389574 commits

Author SHA1 Message Date
Mark Felder
007e8ab72d net-im/ricochet: Update to 1.1.2
This update resolves an information disclosure vulnerability.

Changelog:	https://github.com/ricochet-im/ricochet/releases/tag/v1.1.2

PR:		207536
Security:	http://www.vuxml.org/freebsd/d71831ef-e6f8-11e5-85be-14dae9d210b8.html
2016-03-10 19:52:12 +00:00
Sunpoet Po-Chuan Hsieh
f3af6f58a3 - Remove USES=tar:bzip2 2016-03-10 19:51:31 +00:00
Mark Felder
e714095ac5 net-im/ricochet: Document vulnerability
PR:		207536
2016-03-10 19:50:28 +00:00
Matthias Andree
d2a065da18 Avoid patch-LP1551075 when HTDIG is enabled. [1]
This patch is part of the HTDIG integration patch already. [1]

Also correct namazurc file path in pkg-message, bumping PORTREVISION.

PR:		207876 [1]
Submitted by:	David Siebörger [1]
2016-03-10 19:50:12 +00:00
John Marino
f44a99d51b audio/deadbeef-musical-spectrum-plugin is not jobs safe
As seen in similar deadbeef plugins, this port is unsafe because it
starts building assemble object files before confirming the build
directory (gtk3) has been created.
2016-03-10 19:41:06 +00:00
John Marino
ca1136fc7a lang/gcc6-aux: Upgrade version 20160214 => 20160306 2016-03-10 19:25:55 +00:00
Antoine Brodin
0d83b5b634 Fix MOVED 2016-03-10 19:02:46 +00:00
Mark Felder
5bc6192955 net/exabgp: Update to 3.4.15
Changelog:	https://github.com/Exa-Networks/exabgp/releases/tag/3.4.15

Approved by:	zi
2016-03-10 18:56:45 +00:00
Emanuel Haupt
edb2e3c786 Fix format of elasticsearch-plugin-marvel2 2016-03-10 18:44:18 +00:00
Christian Weisgerber
ac7e1b3132 Do not include _POSIX_SOURCE in CPPFLAGS. It removes much termios(4)
functionality, resulting in broken tty settings.

Approved by:	ehaupt
2016-03-10 18:26:20 +00:00
Mathieu Arnold
c1d9f32b40 Fix fetch-list.
PR:		207875
Sponsored by:	Absolight
2016-03-10 16:48:22 +00:00
Dan Langille
506a4bbae7 Move this port to where it should live, based on existing ports for
Elasticsearch 2
2016-03-10 16:40:46 +00:00
Raphael Kubo da Costa
4e84a1c4aa Update to 16.0.0.
PR:		207789
Submitted by:	jochen@jochen-neumeister.de (first version),
		Axel.Rau@Chaos1.DE (later version)
Approved by:	Axel.Rau@Chaos1.DE (maintainer)
2016-03-10 16:30:32 +00:00
Raphael Kubo da Costa
9a5ea2d5cc New port: devel/py-attrs.
attrs is an MIT-licensed Python package with class decorators
that ease the chores of implementing the most common attribute-related
object protocols without writing dull boilerplate code again and again.

WWW: https://github.com/hynek/attrs

PR:		207853
Submitted by:	Axel.Rau@Chaos1.DE
2016-03-10 16:23:24 +00:00
Mark Felder
572f7e6dce comms/qtel: Fix packaging issue 2016-03-10 15:42:14 +00:00
Jan Beich
a5f9d886e2 gecko: enable DTRACE probes by default 2016-03-10 15:38:57 +00:00
Mark Felder
bbf94ea27a security/pidgin-otr: Update to 4.0.2
Changes:

- Fix use-after-free issue during SMP
- Updated Spanish, German, Norwegian Bokmål translations
- New Danish translation
- The Windows binary has been linked with updated versions of libotr,
    libgcrypt, libgpg-error, and other supporting libraries

MFH:		2016Q1
Security:	CVE-2015-8833
Security:	http://www.vuxml.org/freebsd/77e0b631-e6cf-11e5-85be-14dae9d210b8.html
2016-03-10 15:06:51 +00:00
Mark Felder
515d586b1c Document security/pidgin-otr vulnerability
Security:	CVE-2015-8833
2016-03-10 15:03:39 +00:00
Mathieu Arnold
f8d35a1d15 Update to 2.2.8
PR:		206898
Submitted by:	tkato432 yahoo com
Sponsored by:	Absolight
2016-03-10 14:46:15 +00:00
Mathieu Arnold
1fc580cf0a Update to 1.9.5
PR:		205211
Submitted by:	tkato432 yahoo com
Sponsored by:	Absolight
2016-03-10 14:46:10 +00:00
Mathieu Arnold
9885f8ca04 Update to 1.2.6
PR:		204195
Submitted by:	tkato432 yahoo com
Sponsored by:	Absolight
2016-03-10 14:45:59 +00:00
Tilman Keskinoz
3fdc839ad0 Switch to libotr instead of libotr3
PR:		207880
Submitted by:	Sascha Holzleiter
2016-03-10 14:12:07 +00:00
Raphael Kubo da Costa
bb736d2290 qt4 sqldrivers: Switch to a proper qmake build, use Makefile.sqldrivers.
We've recently started receiving pkg-fallout emails because qt4-mysql-plugin
is failing to build in HEAD. It turns out we were using some custom-made
Makefile.bsd files to drive the builds, and they did not always register all
dependencies between the files correctly.

Fix it by switching to a proper qmake build that uses the .pro files shipped
with Qt4 itself: they can be used without running the `configure' script
almost as if they were not part of the Qt distribution itself. By doing this
we can stop having our own Makefiles and also stop setting a lot of
variables in the port Makefiles.

While here, consolidate most of the variable setting into a single
Makefile.sqldrivers in devel/qt4 (like we already do for devel/qt5) so that
each of the qt4-*-plugin ports only need to set a few values such as the
plugin name and additional USES or includes that might be necessary.

Bump PORTREVISION because we now include the debug versions of the plugins
in PLIST_FILES when the ports are built with WITH_DEBUG=yes (they were
already shipped before, but not registered in the plists).
2016-03-10 14:11:16 +00:00
John Marino
c18bc18524 ports-mgmt/synth: Upgrade version 1.22 => 1.30
This is an enhancement release that contains a bug fix.

Description of bug:
  If synth is launched from mountpoint of the ports directory
  (e.g. /usr/ports), it may malfunction with strange messages such
  as "invalid origins" and printing strange symbols to the screen
  along with parts of a directory.

  As a result, Synth now detects this launch location (as it already
  did with /usr/local) and refuses to run until the current directory
  is changed outside of the ports tree.

Enhancement 1:
  It is now possible to remove alternate profiles.  When more than
  one profile exists, a menu option "<" appears that provides the
  user with an opportunity to remove one to all inactive profiles
  from the configuration.  The man page has been updated as well.

Enhancement 2:
  Synth will automatically convert any directory inputs on the
  configure command to the true path.  For example, if somebody types
  in "/usr/xports" for the ports directory, but that's just a
  symbolic link to /vcs/freebsd-ports", the entry will automatically
  convert to its true resolved path (e.g. /vcs/freebsd-ports). This
  enables the cwd detection of the bug fix above to always work.
2016-03-10 13:25:54 +00:00
Kurt Jaeger
b5f752f55b net/3proxy: 0.8.5 -> 0.8.6
Changes:
  https://github.com/z3APA3A/3proxy/releases/tag/3proxy-0.8.6

PR:		207816
Submitted by:	timp87@gmail.com (maintainer)
2016-03-10 11:43:44 +00:00
Jan Beich
95b8773461 gecko: build as position-independent executable 2016-03-10 10:45:46 +00:00
Jan Beich
4efc900e34 mail/thunderbird, www/seamonkey: update enigmail to 1.9.1 2016-03-10 10:44:56 +00:00
Philippe Audeoud
c18b8d62d5 - Update to 1.700 2016-03-10 10:32:05 +00:00
Philippe Audeoud
de98e60965 - Update to 0.12 2016-03-10 10:29:38 +00:00
Philippe Audeoud
e235572ce2 - Update to 1.34 2016-03-10 09:16:00 +00:00
Philippe Audeoud
ab151d0807 - Update to 2.55 2016-03-10 09:09:16 +00:00
Wen Heping
75e7b17c5f - Add missing depends
PR:		207841
Spotted by:	admin@vladiom.com.ua
2016-03-10 08:11:05 +00:00
Stephen Montgomery-Smith
527a6d685c - Update to 2.12.0. 2016-03-10 02:59:39 +00:00
Brooks Davis
389d61317a Upgrade to 3.8.0 release. 2016-03-10 02:23:44 +00:00
Jan Beich
11f121af96 www/firefox{,-esr}: drop obsolete note after r403852
MFH:		2016Q1
2016-03-10 01:19:56 +00:00
Jan Beich
dceef331b5 security/nss: refresh patch with version approved upstream 2016-03-10 00:18:31 +00:00
Jan Beich
c9e338009b audio/sdl{,2}_mixer: sync and add missing option descriptions
PR:		202689
2016-03-10 00:17:59 +00:00
Jan Beich
82865e1e1d audio/sdl{,2}_mixer: fix VORBIS=on logic after r410689
PR:		202689
Reported by:	antoine
2016-03-10 00:17:26 +00:00
Mark Felder
2cb1dfe780 Update libotr vulnerability information
Correct description is "integer overflow"

libotr3 has also been added as vulnerable. It appears vulnerable as it
also has datalen defined as unsigned int and identical functions.

Security:	http://www.vuxml.org/freebsd/c2b1652c-e647-11e5-85be-14dae9d210b8.html
2016-03-09 22:58:44 +00:00
Antoine Brodin
db3d43f7e0 Set an expiration date for 2 ports deprecated since February 2014 2016-03-09 22:51:03 +00:00
Mark Felder
c54823e66a Document security/libotr vulnerability
It is not clear at this time if security/libotr3 is also affected.

Security:	CVE-2016-2851
2016-03-09 22:42:39 +00:00
Mark Felder
23cc40478d security/libotr: Update to 4.1.1
Changes:
* Fix an integer overflow bug that can cause a heap buffer overflow (and
from there remote code execution) on 64-bit platforms
* Fix possible free() of an uninitialized pointer
* Be stricter about parsing v3 fragments
* Add a testsuite ("make check" to run it), but only on Linux for now,
since it uses Linux-specific features such as epoll
* Fix a memory leak when reading a malformed instance tag file
* Protocol documentation clarifications

MFH:		2016Q1
Security:	CVE-2016-2851
2016-03-09 22:37:52 +00:00
Muhammad Moinur Rahman
947e5fd48d devel/p5-File-BOM: Update version 0.14=>0.15
- Mark NO_ARCH
2016-03-09 22:25:56 +00:00
Mathieu Arnold
f6d0673391 Update to 9.9.8-P4, 9.10.3-P4 and latest snapshot.
MFH:		2016Q1 (obviously)
Security:	CVE-2016-1285
Security:	CVE-2016-1286
Security:	CVE-2016-2088
Sponsored by:	Absolight
2016-03-09 21:16:31 +00:00
Kurt Jaeger
f37d2b7cd0 audio/teamspeak3-server: 3.0.12.2 -> 3.0.12.3
- fixed an other server crashes on malicious input

PR:		207826
Submitted by:	Ultima1252@gmail.com
Approved by:	hirner@bitfire.at (maintainer)
2016-03-09 21:14:55 +00:00
Muhammad Moinur Rahman
4818c44adb devel/p5-File-Append-TempFile: Update version 0.05=>0.07
- Mark NO_ARCH
- Build framework changed to modbuildtiny
- Added OPTIONSNG for post-install
2016-03-09 21:03:33 +00:00
Dmitry Marakasov
128243116e - Add LICENSE_FILE
- Add NO_ARCH
- Don't install LICENSE with PORTDOCS
- Install bash completion where it belongs

PR:		207817
Submitted by:	amdmi3
Approved by:	lme (maintainer)
2016-03-09 20:46:17 +00:00
Kurt Jaeger
694cdca38e math/geogebra: 5.0.208.0 -> 5.0.212.0, change RUN_DEPENDS to USE_LINUX
Changes:
  http://www.geogebra.org/wiki/en/Reference:Changelog_5.0

PR:		207852
Submitted by:	Zsolt Udvari <udvzsolt@gmail.com> (maintainer)
Reported by:	marino
2016-03-09 19:51:11 +00:00
Muhammad Moinur Rahman
03653cf3f5 textproc/groonga: Update version 5.1.0=>6.0.0
- Remove bsd.poprt.options.mk as no longer required
2016-03-09 19:39:47 +00:00
Antoine Brodin
1eff39459f - Remove OPENPYXL1 option from py-pandas
- Set an EXPIRATION_DATE for py-openpyxl1 (deprecated since May 2014)
2016-03-09 19:34:03 +00:00