Commit graph

25134 commits

Author SHA1 Message Date
Johan van Selst
1bbe14e739 Update to libssh 0.7.4
https://www.libssh.org/2017/02/03/libssh-0-7-4/

PR:		218230
Submitted by:	Iblis Lin
2017-03-30 19:41:05 +00:00
Jason Unovitch
d544c46db1 Document Xen Security Advisory (XSA 206)
CVE lists none (yet) assigned

While here, fix a typo on my last Xen entry

Security:	https://vuxml.FreeBSD.org/freebsd/47873d72-14eb-11e7-970f-002590263bf5.html
2017-03-30 01:58:06 +00:00
Jason Unovitch
e61f6dcac2 Actually, let's refer to the original entries for these hostapd CVEs
Reflect CVE-2016-4476 / VID 967b852b-1e28-11e6-8dd3-002590263bf5 in cancelled

CVE-2015-5314 is in VID 976567f6-05c5-11e6-94fa-002590263bf5

PR:		217906
Security:	https://vuxml.FreeBSD.org/freebsd/976567f6-05c5-11e6-94fa-002590263bf5.html
Security:	https://vuxml.FreeBSD.org/freebsd/967b852b-1e28-11e6-8dd3-002590263bf5.html
2017-03-30 01:47:42 +00:00
Sunpoet Po-Chuan Hsieh
acd61b4661 Update to 0.18
Changes:	http://search.cpan.org/dist/Net-SSH-AuthorizedKeysFile/Changes
2017-03-29 23:36:31 +00:00
Matthew Seaman
92aff0b4a8 phpMyAdmin: document PMASA-2017-8 -- bypass restrictions on 'no
password' accounts.
2017-03-29 16:47:39 +00:00
Mark Felder
bcbc95120f Document hostapd vulnerabilities
PR:		217906
2017-03-28 23:19:47 +00:00
Sunpoet Po-Chuan Hsieh
6b18b88f36 Update to 1.81
Changes:	http://search.cpan.org/dist/Net-SSLeay/Changes
2017-03-28 20:52:39 +00:00
Alan Somers
b9a543b963 security/sssd: upstream has moved from fedorahosted to pagure.io
PR:		218082
Reviewed by:	lukas.slebodnik@intrak.sk (maintainer)
Approved by:	brd (ports)
2017-03-27 20:48:27 +00:00
Shaun Amott
f74915b157 Update to 0.11.
PR:		217982
Submitted by:	Anton Yuzhaninov <citrin+pr@citrin.ru>
Approved by:	Thomas von Dein <freebsd@daemon.de> (maintainer)
2017-03-27 17:34:24 +00:00
Sunpoet Po-Chuan Hsieh
65fcde55df Update to 1.6.1
Changes:	https://github.com/nov/rack-oauth2/commits/master
2017-03-27 11:12:37 +00:00
Sunpoet Po-Chuan Hsieh
4d2d6736ea Update to 0.26.0
Changes:	https://gitlab.com/m2crypto/m2crypto/blob/master/CHANGES
		https://gitlab.com/m2crypto/m2crypto/commits/master
2017-03-27 11:12:00 +00:00
Alex Dupre
551ec60b99 Change MASTER_SITES and unbreak. 2017-03-27 10:00:48 +00:00
Bartek Rutkowski
45314e8b77 security/snort2pfcd: update 1.2 -> 1.3
PR:		218149
Submitted by:	Samee Shahzada <onestsam@gmail.com> (maintainer)
2017-03-27 09:52:38 +00:00
Sunpoet Po-Chuan Hsieh
1ec007b645 Update to 1.13.0
Changes:	https://github.com/capistrano/sshkit/blob/master/CHANGELOG.md
2017-03-26 21:24:43 +00:00
Bernard Spil
9e7d5d132f security/libp11: Fix build with LibreSSL
- Fix-up OPENSSL_VERSION_NUMBER checks

PR:		217006
Approved by:	maintainer timeout
2017-03-26 18:55:21 +00:00
Shaun Amott
6c3212f7b2 Update to 0.2.9.10.
PR:		217830
Submitted by:	Yuri Victorovich <yuri@rawbw.com> (maintainer)
2017-03-26 18:30:24 +00:00
Bernard Spil
914b2fb385 security/libressl-devel: Update to 2.5.1
- Update to 2.5.1 [1]

[1] Release Notes: https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-2.5.2-relnotes.txt
2017-03-26 18:01:27 +00:00
Kurt Jaeger
7da315e7b0 security/p5-Crypt-LE: add some depends and sort RUN_DEPENDS
Submitted by:	des
2017-03-26 16:03:20 +00:00
Wen Heping
b100e87a5a - Update to 1.209
Changes: http://cpansearch.perl.org/src/CAPOEIRAB/Digest-Bcrypt-1.209/Changes
2017-03-26 15:09:33 +00:00
Bernard Spil
969678376a security/acme-client: Add run-time dep on ca_root_nss
- acme-client fails at runtime if CA roots not installed

PR:		215722
Reported by:	pete@nomadlogic.org
2017-03-26 10:47:44 +00:00
Bernard Spil
b189f2aaef security/certificate-transparency: Fix build issues with LibreSSL
- Fix OPENSSL_VERSION_NUMBER checks
  - Fix LibreSSL detection
  - Modify CMS disabling to BoringSSL and LibreSSL

PR:		217013
Obtained from:	https://github.com/google/certificate-transparency/pull/1364
2017-03-26 10:40:48 +00:00
Lars Engels
591f45697c security/lynis: Update to 2.4.7 2017-03-26 10:25:05 +00:00
Marcelo Araujo
ce49aa314d - Update to 0.97.
- Take maintainership.
2017-03-26 04:49:02 +00:00
Antoine Brodin
8fb879105d Switch default version of samba from 4.3 to 4.4
With hat:	portmgr
Differential Revision:	https://reviews.freebsd.org/D10131
2017-03-25 23:37:05 +00:00
Baptiste Daroussin
dd9ef4b511 Fix typo 2017-03-25 12:12:58 +00:00
Baptiste Daroussin
4a4ced5fad Kickpass is a stupid simple password safe. It keep each password in a specific
safe, protected with modern cryptography. Its main user interface is command
line.

WWW: https://github.com/paulfariello/kickpass
2017-03-25 11:44:37 +00:00
Emanuel Haupt
a1cedd14e6 Add Math::Random::ISAAC as a dependency as it provides a more secure rand()
function.

PR:		217665
Approved by:	maintainer timeout (alexander.4mail@gmail.com; 16 days)
Differential Revision:	D9923
2017-03-25 10:22:05 +00:00
Sunpoet Po-Chuan Hsieh
73719706cb Update to 1.208
Changes:	http://search.cpan.org/dist/Digest-Bcrypt/Changes
2017-03-25 04:37:58 +00:00
Timur I. Bakeyev
b4177f5dad Add entry about Samba vulnerability CVE-2017-2619
Security:	CVE-2017-2619
2017-03-25 00:01:54 +00:00
Sunpoet Po-Chuan Hsieh
90c3f32943 Update to 1.6.0
Changes:	https://github.com/nov/rack-oauth2/commits/master
2017-03-24 17:48:07 +00:00
Sunpoet Po-Chuan Hsieh
760a519094 Update to 2.0.0
- Add LICENSE_FILE

Changes:	https://github.com/net-ssh/net-ssh-gateway/blob/master/CHANGES.txt
2017-03-24 17:47:58 +00:00
Sunpoet Po-Chuan Hsieh
d6607f19d6 Add rubygem-net-ssh-gateway1 1.2.0 (copied from rubygem-net-ssh-gateway)
- Add PORTSCOUT
2017-03-24 17:47:54 +00:00
Baptiste Daroussin
965cf6d5fc The Yubico Authenticator is a graphical desktop tool and command line tool for
generating Open AuTHentication (OATH) event-based HOTP and time-based TOTP
one-time password codes, with the help of a YubiKey that protects the shared
secrets.

WWW: https://developers.yubico.com/yubioath-desktop/

Sponsored by:	Gandi.net
2017-03-24 12:42:20 +00:00
Matthias Andree
cca759b60e Update to openvpn release 2.4.1
This contains predominently bugfixes and compatibility with
newer OpenSSL/LibreSSL.

Remove one patch that had been cherry-picked from upstream, no longer
needed.

Summary: https://github.com/OpenVPN/openvpn/blob/release/2.4/Changes.rst#version-241
Changes: https://community.openvpn.net/openvpn/wiki/ChangesInOpenvpn24
2017-03-23 21:53:58 +00:00
Kirill Ponomarev
16b03d1b4e Add do-test target
Submitted by:	Anton Yuzhaninov <citrin@citrin.ru>
Approved by:	mat (mentor), maintainer
Differential Revision: https://reviews.freebsd.org/D10103
2017-03-23 13:26:02 +00:00
Joseph Mingrone
c0bc9257e9 security/py-pyaes: Pure-Python implementation of AES block-cipher and
common modes of operation.

WWW: https://github.com/ricmoo/pyaes

Approved by:	swills (mentor, implicit)
2017-03-23 02:33:45 +00:00
Jason Unovitch
d87db865d6 Document Xen Security Advisory (XSA 211)
Security:	CVE-2016-9603
Security:	https://vuxml.FreeBSD.org/freebsd/af19ecd0-0f6a-11e7-970f-002590263bf5.html
2017-03-23 01:51:39 +00:00
Sunpoet Po-Chuan Hsieh
5a2dda6134 Add rubygem-omniauth-oauth2-generic 0.2.2
omniauth-oauth2-generic provides an OmniAuth strategy for authenticating with an
OAuth2 service using the authorization grant flow.

Most OmniAuth gems are written either as abstractions (omniauth-oauth2) or for a
specific provider (omniauth-github), but this one is designed to be configurable
enough to work with any basic OAuth2 provider. The primary differences between
OAuth2 provider strategies in OmniAuth are:
- The server's domain
- The URL paths used to authorize, request tokens and get user info
- The structure of the returned user information

These are all configurable options in this gem. There my be certain
requirements/features of some providers not covered by this gem's options, but
it was designed primarily so that if you are implementing your own OAuth2
provider for your service, you don't need to write an OmniAuth strategy as long
as it is compatible with the basic options provided by this gem.

WWW: https://gitlab.com/satorix/omniauth-oauth2-generic
2017-03-22 21:03:58 +00:00
Thomas Zander
1f57492fdd Add CVE ID for recent irssi vulnerability
PR:		217878
Submitted by:	dor.bsd@xm0.uk (irssi mainainer)
2017-03-22 19:14:32 +00:00
Kirill Ponomarev
4214cdc9a9 Update security/py-pynacl to 1.1.1
PR:		217938
Submitted by:	maintainer
Approved by:	mat (mentor)
Differential Revision:	https://reviews.freebsd.org/D10077
2017-03-22 18:11:28 +00:00
Bartek Rutkowski
0be4152a36 security/zeronet: update 0.5.2 -> 0.5.3
PR:		217828
Submitted by:	Yuri Victorovich <yuri@rawbw.com> (maintainer)
2017-03-22 12:26:59 +00:00
Dmitry Marakasov
0bd6fdcb2b - Pass maintainership to submitter
PR:		217674
Submitted by:	mshirk@daemon-security.com
2017-03-22 08:57:43 +00:00
Jason Unovitch
d406123dd2 Update hostapd on two older entries.
Fixes were not backported prior. Recent update is v2.6 as noted in advisory.

Security:	CVE-2015-5310
Security:	CVE-2015-5315
Security:	CVE-2015-5316
Security:	CVE-2016-4476
Security:	CVE-2016-4477
Security:	https://vuxml.FreeBSD.org/freebsd/967b852b-1e28-11e6-8dd3-002590263bf5.html
Security:	https://vuxml.FreeBSD.org/freebsd/976567f6-05c5-11e6-94fa-002590263bf5.html
2017-03-22 03:01:06 +00:00
Matthias Andree
a01977335f Fix build with LibreSSL 2.5.1.
PR:		217140
Submitted by:	brnrd@
Obtained from:	Olivier Wahrenberger, via upstream maintainers review
2017-03-21 23:04:59 +00:00
Antoine Brodin
7cfe69b584 - Add USES=samba to handle dependency on samba
Valid ARGS:  build, env, lib, run (default: build,run)
- Add SAMBA_DEFAULT to bsd.default-versions.mk (default: 4.3)
- Remove obsolete samba36 ports
- Modify samba4x ports to install libsmbclient
- Convert the ports tree to USES=samba

Reviewed by:	mat
Differential Revision:	https://reviews.freebsd.org/D8919
2017-03-21 21:59:31 +00:00
Sunpoet Po-Chuan Hsieh
9d3e6fea5a Update to 3.0.5
Changes:	https://github.com/pbhogan/scrypt/blob/master/CHANGELOG.md
2017-03-21 20:39:28 +00:00
Vsevolod Stakhov
2e6f356fd4 - Update to 1.0.12
PR:		217979
Submitted by:	Anton Yuzhaninov <citrin+pr@citrin.ru>
2017-03-21 16:21:19 +00:00
Steven Kreuzer
456c9da675 Fix issue preventing patch from applying cleanly
Reported by:	pkg-fallout
2017-03-21 14:20:44 +00:00
Lars Engels
27a6509d4c security/lynis: Update to 2.4.6 2017-03-21 13:55:23 +00:00
Ryan Steinmetz
0e25b5a72f - Add the 'premerge' tag to the portscout ignore list 2017-03-21 12:46:39 +00:00