Commit graph

9518 commits

Author SHA1 Message Date
Alejandro Pulver
1762f5f1ad - Reformat pkg-descr.
- Take maintainership.

PR:		ports/104233
Submitted by:	Thomas Abthorpe <thomas@goodking.ca>
2006-10-31 02:11:25 +00:00
James E. Housley
3065300a3e * Upgrade to version 5.10
* When package building, don't automatically fetch the newest DAT
2006-10-31 00:22:39 +00:00
Renato Botelho
16fc551b11 Update to 20061029 to fix vulnerability
Approved by:	portmgr (erwin)
Security:	http://www.vuxml.org/freebsd/8012a79d-5d21-11db-bb8d-00123ffe8333.html
2006-10-30 13:52:36 +00:00
Vasil Dimov
4d81bd32df Add a <modified> tag with the current date to reflect my previous change.
I knew I should ask someone before committing, however trivial was the change.

Spotted by:	remko
Approved by:	portmgr (implicit)
2006-10-30 07:34:06 +00:00
Vasil Dimov
c359213b8a Fix typo: "Dmitri Lenev reports reports a privilege ..."
Approved by:	portmgr (implicit)
2006-10-30 07:04:38 +00:00
Simon L. B. Nielsen
11ce17521a Document screen -- combined UTF-8 characters vulnerability.
Approved by:	portmgr (secteam blanket)
2006-10-29 19:07:08 +00:00
Simon L. B. Nielsen
04ee71b7ac Document two MySQL privilege escalations.
PR:		ports/104890
Submitted by:	Henrik Brix Andersen <henrik@brixandersen.dk>
Approved by:	portmgr (secteam blanket)
2006-10-29 13:50:01 +00:00
Martin Wilke
100c045e82 - Add entry for www/serendipity and www/serendipity-devel
Reviewed by:	markus@
Approved by:	portmgr (implicit VuXML), secteam (Remko (not reviewed yet))
2006-10-23 13:15:30 +00:00
Markus Brueffer
925b0719f1 Document an integer overflow vulnerability in Qt and kdelibs, based on an
entry by sat

Approved by:	portmgr (erwin)
2006-10-23 11:15:11 +00:00
Simon L. B. Nielsen
7af8fd8980 Add reference, which I missed the first time around, from Opera
Software to opera -- URL parsing heap overflow vulnerability entry,

Approved by:	portmgr (secteam blanket)
2006-10-20 22:59:39 +00:00
Simon L. B. Nielsen
a889bdb46b Document opera -- URL parsing heap overflow vulnerability.
Approved by:	portmgr (secteam blanket)
2006-10-20 22:56:04 +00:00
Simon L. B. Nielsen
8c9c1b0930 Minor correction to last commit; the NVIDIA driver version 1.0.8762
was also affected, so mark it as such.

Approved by:		portmgr (secteam blanket)
2006-10-20 22:45:27 +00:00
Simon L. B. Nielsen
83d2fc7202 Update entry for nvidia-driver -- arbitrary root code execution
vulnerability:

- Add new info about vulnerable versions from NVIDIA.
- Add workaround.
- Add more references.
- Remove suggestion to move to "nv" driver now that we have a simpler
  workaround.

Approved by:		portmgr (secteam blanket)
Parts submitted by:	mnag
2006-10-20 22:32:30 +00:00
Marcus Alves Grando
e4f21a09c1 - Mark as forbidden
Approved by:	portmgr (secteam blanket)
Security:	http://www.vuxml.org/freebsd/8012a79d-5d21-11db-bb8d-00123ffe8333.html
2006-10-20 14:53:54 +00:00
Remko Lodder
7ef185e45c Document asterisk -- remote heap overwrite vulnerability
Approved by:		portmgr (VuXML blanket)
Submitted by:		Thomas Sandford
Facilitated by:		Snow B.V.
2006-10-20 08:13:06 +00:00
Remko Lodder
0546f23a3c Some style changes to the plone entry.
Previous commit was also reviewed by myself.

Approved by:		portmgr (Blanket VuXML)
Facilitated by:		Snow B.V.
2006-10-20 07:44:01 +00:00
Ion-Mihai Tetcu
2a9d3078c5 Fix plist.
PR:		ports/104405
Submitted by:	Fabian Keil<fk@fabiankeil.de>
Approved by:	portmgr (erwin), Peter Thoenen (maintainer)
2006-10-20 07:20:21 +00:00
Martin Wilke
2a7ec3a7c1 - Add a entry for www/plone
Approved by:	portmgr (erwin)
2006-10-19 22:47:49 +00:00
Shaun Amott
e54712d17f Document:
drupal -- HTML attribute injection
  drupal -- cross site request forgeries
  drupal -- multiple XSS vulnerabilities

Submitted by:	brooks
Reviewed by:	remko
Approved by:	portmgr (erwin)
2006-10-19 13:48:59 +00:00
Shaun Amott
cce7554a1c Document "ingo -- local arbitrary shell command execution"
Submitted by:	thierry
Reviewed by:	remko
Approved by:	portmgr (erwin)
2006-10-19 13:19:44 +00:00
Simon L. B. Nielsen
a0a4a2fb88 Update php -- _ecalloc Integer Overflow Vulnerability entry with
details from Steffan Essers advisory about the implications of this
issue.  The advisory was not public when this issue was initially
fixed.

Approved by:	portmgr (secteam blanket)
2006-10-17 20:45:55 +00:00
Marcus Alves Grando
3d5fa7b997 - Update HPN patch. Patch are renamed, the only content differences are two rows now enclosed in an "else" block.
Submitted by:	ale
Approved by:	portmgr (erwin)
2006-10-17 13:27:18 +00:00
Erwin Lansing
a2eb0bd472 Mark multimedia/win32-codecs as not-vulnerable after the quicktime codecs
were optional. The quicktime codecs are still vulnerable though, but we
rely on the conditional FORBIDDEN statement in the ports Makefile for this.

Approved by:	portmgr (self), secteam (simon)
2006-10-17 09:20:59 +00:00
Simon L. B. Nielsen
346b79b908 Document "nvidia-driver -- arbitrary root code execution vulnerability".
Note that I haven't actually had time to make a test system to reproduce
this on FreeBSD, but due to the nature of this issue and that there is a
PoC exploit in the advisory, I'm adding this entry due to "better safe
than sorry"...

Approved by:	portmgr (secteam blanket)
2006-10-16 21:54:38 +00:00
Andrew Pantyukhin
a02c9e0237 - Mark php open_basedir fixed
Reviewed by:	secteam (simon)
Approved by:	portmgr (secteam blanket)
2006-10-16 17:44:32 +00:00
Marcus Alves Grando
26c48dc2d6 - clamav -- CHM unpacker and PE rebuilding vulnerabilities
Approved by:	portmgr (mnag with secteam hat)
2006-10-16 14:32:54 +00:00
Marcus Alves Grando
ec97343ab6 - Update to 0.88.5
- portlint(1)

Approved by:	portmgr (mnag with secteam hat), garga (maintainer)
Security:	http://lurker.clamav.net/message/20061016.015114.dc6a8930.en.html,
		http://secunia.com/advisories/22370/
2006-10-16 14:18:52 +00:00
Martin Wilke
72f4c4414b - Add missing depends
PR:             ports/104362
Submitted by:   Joshua Abraham<jabra@ccs.neu.edu> (maintainer)
Approved by:    portmgr (clement)
2006-10-16 12:13:03 +00:00
Andrew Pantyukhin
3fc4ea54a0 - Add some references
Reviewed by:	secteam (simon)
Approved by:	portmgr (secteam blanket)
2006-10-15 19:43:00 +00:00
Andrew Pantyukhin
4658ca81a7 - Document temporary file symlink privilege escalation in tkdiff
- Correct Javier's name spelling in an old advisory

Reviewed by:	secteam (simon)
Approved by:	portmgr (secteam blanket)
2006-10-15 16:04:57 +00:00
Andrew Pantyukhin
a838b78a3b - Document multiple remote file inclusion vulnerabilities in vtiger
Reviewed by:	secteam (simon)
Approved by:	portmgr (secteam blanket)
2006-10-15 11:31:33 +00:00
Andrew Pantyukhin
2e6d88f123 - Document heap overflow in the KML engine in google-earth
Reviewed by:	secteam (simon)
Approved by:	portmgr (implicit)
2006-10-14 12:32:43 +00:00
Jeremy Messenger
70cd04b258 Simple commandline wrapper around gpg that makes it store its passphrase
in gnome-keyring.  It is a direct competitor to (the unmaintained)
quintuple-agent.

Submitted by:	ahze
Approved by:	portmgr (kris and marcus)
2006-10-14 09:10:57 +00:00
Joe Marcus Clarke
29747f458a Chase the GNOME X11BASE to LOCALBASE move, and fix the build with the
new freetype2 where needed.

Submitted by:	mezz, ahze, pav, and many others
Approved by:	portmgr (implicit, kris)
2006-10-14 08:54:54 +00:00
Joe Marcus Clarke
f1bb12de8e Presenting GNOME 2.16.1 for FreeBSD. This release represents a massive
amount of work by the FreeBSD GNOME Team and our testers.

On top of the usual GNOME update, we have taken this opportunity to move
GNOME from X11BASE to LOCALBASE.  This means roughly 600 ports NOT part of
the GNOME Desktop also need to be changed.  The bulk of the move was carried
out by ahze, mezz, and pav, but it would not have been possible without
cooperation from the FreeBSD KDE team who worked with us to make sure
GNOME and KDE can still coexist happily.  We would also like to send a
shout out to kris and pointyhat for putting up with multiple test runs
until we got something that was solid.

Back to GNOME 2.16.  This release brings a huge amount of new functionality
to FreeBSD.  The standard release notes can be read at
http://www.gnome.org/start/2.16/ .  But on top of what you will read there,
jylefort and marcus have completed work on a port of HAL to FreeBSD.  This
will allow FreeBSD to take advantage of closer hardware interaction such
as auto-mounting CD-ROMs, USB drives, and music players; auto-playing
audio CDs; and managing laptop power consumption.

But where would this all be without our loyal testers and contributors?
Therefore, the FreeBSD GNOME team would like to thank the following users:

Phillip Neumann <pneumann@gmail.com>
tmclaugh
mux
Yuri Pankov <yuri.pankov@gmail.com>
chinsan
Thomas <freebsdlists@bsdunix.ch>
Brian Gruber <knightbg@yahoo.com>
Franz Klammer <klammer@webonaut.com>
Dominique Goncalves <dominique.goncalves@gmail.com>
Pascal Hofstee <caelian@gmail.com>
Yasuda Keisuke <kysd@po.harenet.ne.jp>
backyard <backyard1454-bsd@yahoo.com>
Andris Raugulis <endrju@null.lv> <endrju@null.lv>
Eric L. Chen <d9364104@mail.nchu.edu.tw>
Pawel Worach <pawel.worach@gmail.com>
QuiRK on #freebsd-gnome
Shane Bell <decept0@gmail.com>
luigi
sajd on #freebsd-gnome
sat
Chris Coleman <chrisc@vmunix.com>
kaeru on #freebsd-gnome
crsd_ via irc.freenode.org/#FreeBSD-GNOME
Joel Diaz <joeldiaz@mac.com>

Enjoy!

Approved by:	portmgr (implicit, kris)
2006-10-14 08:35:50 +00:00
Kris Kennaway
1db4e32391 Revert previous commit; it still conflicts but CONFLICTS checking was
broken at the time.

Approved by:	portmgr (self)
2006-10-12 03:35:56 +00:00
Shaun Amott
8227c1bcf2 Update distinfo to reflect re-rolled distfile, and unbreak the port. The
differences between the old and new files were entirely cosmetic. The
full diff is available in the Audit-Trail of the PR below.

PR:		ports/104307
Submitted by:	Frank J. Laszlo <laszlof@vonostingroup.com>
Approved by:	portmgr (marcus)
2006-10-12 00:36:00 +00:00
Erwin Lansing
0f30452066 devel/cscope was fixed in version 15.6 so use lt instead of le.
Submitted by:	joerg
Pointyhat to:	erwin
Approved by:	portmgr (self)
2006-10-11 08:32:04 +00:00
Andrew Pantyukhin
bcb02aab56 - Update to 20061009 fingerprints 2006-10-09 20:36:50 +00:00
Boris Samorodov
800e4e5443 Sguil (pronounced "sgweel") is a graphical interface to snort
(www.snort.org), an open source intrusion detection system.
The actual interface and GUI server are written in tcl/tk
(www.tcl.tk). Sguil also relies on other open source software
in order to function properly.

The sensor list includes security/barnyard, security/snort,
security/sancp, tcpdump (a part of the OS) and devel/tcltls as
well as lang/tcl84 and lang/tclX.  Care has been taken to ensure
that everything you need to build a working sguil operation is
in the FreeBSD ports system or part of the OS already.

Sguil currently functions as an analysis interface and has
no snort sensor or rule management capabilities.

WWW: http://sguil.sourceforge.net/index.php
pauls@utdallas.edu

PR:		ports/95018
Submitted by:	Paul Schmehl <pauls at utdallas.edu>
2006-10-09 19:04:38 +00:00
Cheng-Lung Sung
139f582ed9 - Update to 0.1.2.2
PR:		ports/104211
Submitted by:	maintainer (Peter Thoenen)
2006-10-09 16:10:58 +00:00
Simon L. B. Nielsen
c89423ae3d Mark zgv as fixed wrt. "zgv, xzgv -- heap overflow vulnerability". 2006-10-09 15:45:02 +00:00
Sergei Kolobov
b6c24fd127 - Add dependency on libtool; we cannot simply add USE_AUTOTOOLS
as that implies GNU_CONFIGURE which this port does NOT use
- Bump PORTREVISION

Noticed by:	pointyhat via kris
2006-10-09 15:41:47 +00:00
Martin Wilke
8257f2d5d1 - Update to 0.9.6.1
PR:		ports/104202
Submitted by:	Robin Gruyters <r.gruyters@yirdis.nl> (maintainer)
2006-10-09 13:38:02 +00:00
Cheng-Lung Sung
03b4a853af - Update to 0.9.10
libpreludedb Changelog:
- Fix PostgreSQL schema update version 5.
- Only export symbol starting with preludedb_.
- Verbose error reporting in case of libpreludedb initialization failure.

PR:		ports/104201
Submitted by:	maintainer (Robin Gruyters)
2006-10-09 09:51:12 +00:00
Andrew Pantyukhin
42ab9bb812 - Require gcc 3.4+
Reported by:	pointyhat via kris
2006-10-09 08:22:19 +00:00
Peter Pentchev
ef0ecb1c36 Fix the problem with unattended deinstallation by not even attempting
to remove the stunnel user and group at all - just kill the package
deinstall script.

PR:		104028
Reported by:	jan grant <jan.grant@bristol.ac.uk>,
		Stephen Hurd <shurd@sasktel.net> (in private mail a while ago),
		and, I think, many others
2006-10-08 18:06:54 +00:00
Andrew Pantyukhin
9bfb513347 - Add php-suhosin to edabe438-542f-11db-a5ae-00508d6a62df
as per original advisory

Discussed with:	ale
2006-10-08 16:41:50 +00:00
Pav Lucistnik
13c2c88c2e - Remove symlinks created by mtree target from plists
Pointy hats to:	rafan 6x, droso 2x, pav 2x, alepulve, clsung, glewis, itetcu,
		miwi
2006-10-08 14:59:46 +00:00
Roman Bogorodskiy
32e98c797b - Update to 1.5.2
- Add WITHOUT_CXX knob to disable C++ wrapper library
2006-10-08 13:46:32 +00:00