Johan van Selst
1bbe14e739
Update to libssh 0.7.4
...
https://www.libssh.org/2017/02/03/libssh-0-7-4/
PR: 218230
Submitted by: Iblis Lin
2017-03-30 19:41:05 +00:00
Jason Unovitch
d544c46db1
Document Xen Security Advisory (XSA 206)
...
CVE lists none (yet) assigned
While here, fix a typo on my last Xen entry
Security: https://vuxml.FreeBSD.org/freebsd/47873d72-14eb-11e7-970f-002590263bf5.html
2017-03-30 01:58:06 +00:00
Jason Unovitch
e61f6dcac2
Actually, let's refer to the original entries for these hostapd CVEs
...
Reflect CVE-2016-4476 / VID 967b852b-1e28-11e6-8dd3-002590263bf5 in cancelled
CVE-2015-5314 is in VID 976567f6-05c5-11e6-94fa-002590263bf5
PR: 217906
Security: https://vuxml.FreeBSD.org/freebsd/976567f6-05c5-11e6-94fa-002590263bf5.html
Security: https://vuxml.FreeBSD.org/freebsd/967b852b-1e28-11e6-8dd3-002590263bf5.html
2017-03-30 01:47:42 +00:00
Sunpoet Po-Chuan Hsieh
acd61b4661
Update to 0.18
...
Changes: http://search.cpan.org/dist/Net-SSH-AuthorizedKeysFile/Changes
2017-03-29 23:36:31 +00:00
Matthew Seaman
92aff0b4a8
phpMyAdmin: document PMASA-2017-8 -- bypass restrictions on 'no
...
password' accounts.
2017-03-29 16:47:39 +00:00
Mark Felder
bcbc95120f
Document hostapd vulnerabilities
...
PR: 217906
2017-03-28 23:19:47 +00:00
Sunpoet Po-Chuan Hsieh
6b18b88f36
Update to 1.81
...
Changes: http://search.cpan.org/dist/Net-SSLeay/Changes
2017-03-28 20:52:39 +00:00
Alan Somers
b9a543b963
security/sssd: upstream has moved from fedorahosted to pagure.io
...
PR: 218082
Reviewed by: lukas.slebodnik@intrak.sk (maintainer)
Approved by: brd (ports)
2017-03-27 20:48:27 +00:00
Shaun Amott
f74915b157
Update to 0.11.
...
PR: 217982
Submitted by: Anton Yuzhaninov <citrin+pr@citrin.ru>
Approved by: Thomas von Dein <freebsd@daemon.de> (maintainer)
2017-03-27 17:34:24 +00:00
Sunpoet Po-Chuan Hsieh
65fcde55df
Update to 1.6.1
...
Changes: https://github.com/nov/rack-oauth2/commits/master
2017-03-27 11:12:37 +00:00
Sunpoet Po-Chuan Hsieh
4d2d6736ea
Update to 0.26.0
...
Changes: https://gitlab.com/m2crypto/m2crypto/blob/master/CHANGES
https://gitlab.com/m2crypto/m2crypto/commits/master
2017-03-27 11:12:00 +00:00
Alex Dupre
551ec60b99
Change MASTER_SITES and unbreak.
2017-03-27 10:00:48 +00:00
Bartek Rutkowski
45314e8b77
security/snort2pfcd: update 1.2 -> 1.3
...
PR: 218149
Submitted by: Samee Shahzada <onestsam@gmail.com> (maintainer)
2017-03-27 09:52:38 +00:00
Sunpoet Po-Chuan Hsieh
1ec007b645
Update to 1.13.0
...
Changes: https://github.com/capistrano/sshkit/blob/master/CHANGELOG.md
2017-03-26 21:24:43 +00:00
Bernard Spil
9e7d5d132f
security/libp11: Fix build with LibreSSL
...
- Fix-up OPENSSL_VERSION_NUMBER checks
PR: 217006
Approved by: maintainer timeout
2017-03-26 18:55:21 +00:00
Shaun Amott
6c3212f7b2
Update to 0.2.9.10.
...
PR: 217830
Submitted by: Yuri Victorovich <yuri@rawbw.com> (maintainer)
2017-03-26 18:30:24 +00:00
Bernard Spil
914b2fb385
security/libressl-devel: Update to 2.5.1
...
- Update to 2.5.1 [1]
[1] Release Notes: https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-2.5.2-relnotes.txt
2017-03-26 18:01:27 +00:00
Kurt Jaeger
7da315e7b0
security/p5-Crypt-LE: add some depends and sort RUN_DEPENDS
...
Submitted by: des
2017-03-26 16:03:20 +00:00
Wen Heping
b100e87a5a
- Update to 1.209
...
Changes: http://cpansearch.perl.org/src/CAPOEIRAB/Digest-Bcrypt-1.209/Changes
2017-03-26 15:09:33 +00:00
Bernard Spil
969678376a
security/acme-client: Add run-time dep on ca_root_nss
...
- acme-client fails at runtime if CA roots not installed
PR: 215722
Reported by: pete@nomadlogic.org
2017-03-26 10:47:44 +00:00
Bernard Spil
b189f2aaef
security/certificate-transparency: Fix build issues with LibreSSL
...
- Fix OPENSSL_VERSION_NUMBER checks
- Fix LibreSSL detection
- Modify CMS disabling to BoringSSL and LibreSSL
PR: 217013
Obtained from: https://github.com/google/certificate-transparency/pull/1364
2017-03-26 10:40:48 +00:00
Lars Engels
591f45697c
security/lynis: Update to 2.4.7
2017-03-26 10:25:05 +00:00
Marcelo Araujo
ce49aa314d
- Update to 0.97.
...
- Take maintainership.
2017-03-26 04:49:02 +00:00
Antoine Brodin
8fb879105d
Switch default version of samba from 4.3 to 4.4
...
With hat: portmgr
Differential Revision: https://reviews.freebsd.org/D10131
2017-03-25 23:37:05 +00:00
Baptiste Daroussin
dd9ef4b511
Fix typo
2017-03-25 12:12:58 +00:00
Baptiste Daroussin
4a4ced5fad
Kickpass is a stupid simple password safe. It keep each password in a specific
...
safe, protected with modern cryptography. Its main user interface is command
line.
WWW: https://github.com/paulfariello/kickpass
2017-03-25 11:44:37 +00:00
Emanuel Haupt
a1cedd14e6
Add Math::Random::ISAAC as a dependency as it provides a more secure rand()
...
function.
PR: 217665
Approved by: maintainer timeout (alexander.4mail@gmail.com ; 16 days)
Differential Revision: D9923
2017-03-25 10:22:05 +00:00
Sunpoet Po-Chuan Hsieh
73719706cb
Update to 1.208
...
Changes: http://search.cpan.org/dist/Digest-Bcrypt/Changes
2017-03-25 04:37:58 +00:00
Timur I. Bakeyev
b4177f5dad
Add entry about Samba vulnerability CVE-2017-2619
...
Security: CVE-2017-2619
2017-03-25 00:01:54 +00:00
Sunpoet Po-Chuan Hsieh
90c3f32943
Update to 1.6.0
...
Changes: https://github.com/nov/rack-oauth2/commits/master
2017-03-24 17:48:07 +00:00
Sunpoet Po-Chuan Hsieh
760a519094
Update to 2.0.0
...
- Add LICENSE_FILE
Changes: https://github.com/net-ssh/net-ssh-gateway/blob/master/CHANGES.txt
2017-03-24 17:47:58 +00:00
Sunpoet Po-Chuan Hsieh
d6607f19d6
Add rubygem-net-ssh-gateway1 1.2.0 (copied from rubygem-net-ssh-gateway)
...
- Add PORTSCOUT
2017-03-24 17:47:54 +00:00
Baptiste Daroussin
965cf6d5fc
The Yubico Authenticator is a graphical desktop tool and command line tool for
...
generating Open AuTHentication (OATH) event-based HOTP and time-based TOTP
one-time password codes, with the help of a YubiKey that protects the shared
secrets.
WWW: https://developers.yubico.com/yubioath-desktop/
Sponsored by: Gandi.net
2017-03-24 12:42:20 +00:00
Matthias Andree
cca759b60e
Update to openvpn release 2.4.1
...
This contains predominently bugfixes and compatibility with
newer OpenSSL/LibreSSL.
Remove one patch that had been cherry-picked from upstream, no longer
needed.
Summary: https://github.com/OpenVPN/openvpn/blob/release/2.4/Changes.rst#version-241
Changes: https://community.openvpn.net/openvpn/wiki/ChangesInOpenvpn24
2017-03-23 21:53:58 +00:00
Kirill Ponomarev
16b03d1b4e
Add do-test target
...
Submitted by: Anton Yuzhaninov <citrin@citrin.ru>
Approved by: mat (mentor), maintainer
Differential Revision: https://reviews.freebsd.org/D10103
2017-03-23 13:26:02 +00:00
Joseph Mingrone
c0bc9257e9
security/py-pyaes: Pure-Python implementation of AES block-cipher and
...
common modes of operation.
WWW: https://github.com/ricmoo/pyaes
Approved by: swills (mentor, implicit)
2017-03-23 02:33:45 +00:00
Jason Unovitch
d87db865d6
Document Xen Security Advisory (XSA 211)
...
Security: CVE-2016-9603
Security: https://vuxml.FreeBSD.org/freebsd/af19ecd0-0f6a-11e7-970f-002590263bf5.html
2017-03-23 01:51:39 +00:00
Sunpoet Po-Chuan Hsieh
5a2dda6134
Add rubygem-omniauth-oauth2-generic 0.2.2
...
omniauth-oauth2-generic provides an OmniAuth strategy for authenticating with an
OAuth2 service using the authorization grant flow.
Most OmniAuth gems are written either as abstractions (omniauth-oauth2) or for a
specific provider (omniauth-github), but this one is designed to be configurable
enough to work with any basic OAuth2 provider. The primary differences between
OAuth2 provider strategies in OmniAuth are:
- The server's domain
- The URL paths used to authorize, request tokens and get user info
- The structure of the returned user information
These are all configurable options in this gem. There my be certain
requirements/features of some providers not covered by this gem's options, but
it was designed primarily so that if you are implementing your own OAuth2
provider for your service, you don't need to write an OmniAuth strategy as long
as it is compatible with the basic options provided by this gem.
WWW: https://gitlab.com/satorix/omniauth-oauth2-generic
2017-03-22 21:03:58 +00:00
Thomas Zander
1f57492fdd
Add CVE ID for recent irssi vulnerability
...
PR: 217878
Submitted by: dor.bsd@xm0.uk (irssi mainainer)
2017-03-22 19:14:32 +00:00
Kirill Ponomarev
4214cdc9a9
Update security/py-pynacl to 1.1.1
...
PR: 217938
Submitted by: maintainer
Approved by: mat (mentor)
Differential Revision: https://reviews.freebsd.org/D10077
2017-03-22 18:11:28 +00:00
Bartek Rutkowski
0be4152a36
security/zeronet: update 0.5.2 -> 0.5.3
...
PR: 217828
Submitted by: Yuri Victorovich <yuri@rawbw.com> (maintainer)
2017-03-22 12:26:59 +00:00
Dmitry Marakasov
0bd6fdcb2b
- Pass maintainership to submitter
...
PR: 217674
Submitted by: mshirk@daemon-security.com
2017-03-22 08:57:43 +00:00
Jason Unovitch
d406123dd2
Update hostapd on two older entries.
...
Fixes were not backported prior. Recent update is v2.6 as noted in advisory.
Security: CVE-2015-5310
Security: CVE-2015-5315
Security: CVE-2015-5316
Security: CVE-2016-4476
Security: CVE-2016-4477
Security: https://vuxml.FreeBSD.org/freebsd/967b852b-1e28-11e6-8dd3-002590263bf5.html
Security: https://vuxml.FreeBSD.org/freebsd/976567f6-05c5-11e6-94fa-002590263bf5.html
2017-03-22 03:01:06 +00:00
Matthias Andree
a01977335f
Fix build with LibreSSL 2.5.1.
...
PR: 217140
Submitted by: brnrd@
Obtained from: Olivier Wahrenberger, via upstream maintainers review
2017-03-21 23:04:59 +00:00
Antoine Brodin
7cfe69b584
- Add USES=samba to handle dependency on samba
...
Valid ARGS: build, env, lib, run (default: build,run)
- Add SAMBA_DEFAULT to bsd.default-versions.mk (default: 4.3)
- Remove obsolete samba36 ports
- Modify samba4x ports to install libsmbclient
- Convert the ports tree to USES=samba
Reviewed by: mat
Differential Revision: https://reviews.freebsd.org/D8919
2017-03-21 21:59:31 +00:00
Sunpoet Po-Chuan Hsieh
9d3e6fea5a
Update to 3.0.5
...
Changes: https://github.com/pbhogan/scrypt/blob/master/CHANGELOG.md
2017-03-21 20:39:28 +00:00
Vsevolod Stakhov
2e6f356fd4
- Update to 1.0.12
...
PR: 217979
Submitted by: Anton Yuzhaninov <citrin+pr@citrin.ru>
2017-03-21 16:21:19 +00:00
Steven Kreuzer
456c9da675
Fix issue preventing patch from applying cleanly
...
Reported by: pkg-fallout
2017-03-21 14:20:44 +00:00
Lars Engels
27a6509d4c
security/lynis: Update to 2.4.6
2017-03-21 13:55:23 +00:00
Ryan Steinmetz
0e25b5a72f
- Add the 'premerge' tag to the portscout ignore list
2017-03-21 12:46:39 +00:00