Commit graph

22345 commits

Author SHA1 Message Date
Olli Hauer
2c50b7407b - document Bugzilla security issues 2015-12-23 11:14:07 +00:00
Jun Kuriyama
8ad3cbf243 - Upgrade to 1.4.20 (minor fixes). 2015-12-23 03:25:52 +00:00
Jason Unovitch
04708aced2 security/keepass: fix XSEL option dependency
- Switch x11/xsel -> x11/xsel-conrad. This resolves a run time issue
  when copying passwords to the clipboard.

PR:		204397
Reported by:	Alex Zhukov <baron.pampa@gmail.com>
Submitted by:	Ben Woods <woodsb02@gmail.com> (maintainer)
MFH:		2015Q4
2015-12-23 00:40:32 +00:00
Jason Unovitch
59e2c648ea security/keepassx: update 0.4.3 -> 0.4.4
- Update MASTER_SITES. Upstream no longer uses SVN or SourceForge
  infrastructure. See http://sourceforge.net/p/keepassx/code/387/
- USES: Add desktop-file-utils

PR:		205105
Approved by:	maintainer timeout (2 weeks)
Security:	CVE-2015-8378
Security:	https://vuxml.FreeBSD.org/freebsd/918a5d1f-9d40-11e5-8f5c-002590263bf5.html
MFH:		2015Q4
2015-12-23 00:22:31 +00:00
Jason Unovitch
fcb50bb32f Document two librsvg2 vulnerabilities
PR:		205502
Security:	CVE-2015-7557
Security:	CVE-2015-7558
Security:	https://vuxml.FreeBSD.org/freebsd/da634091-a84a-11e5-8f5c-002590263bf5.html
Security:	https://vuxml.FreeBSD.org/freebsd/d6c51737-a84b-11e5-8f5c-002590263bf5.html
2015-12-22 01:43:44 +00:00
Sunpoet Po-Chuan Hsieh
7f62f953dc - Sort SUBDIRs 2015-12-21 16:15:40 +00:00
Mathieu Arnold
970c34a2dc Fix build as a user.
While there, merge do-install and post-install, and use an option
target helper.

Sponsored by:	Absolight
2015-12-21 16:02:55 +00:00
Mark Felder
896a330f0e irc/quassel: Document vulnerability
Security:	CVE-2015-8547
2015-12-21 15:39:40 +00:00
Jason Unovitch
c0cde21162 Revise Moodle multiple security vulnerabilities from r401745 to reflect
recently published advisory

Security:	https://vuxml.FreeBSD.org/freebsd/82b3ca2a-8c07-11e5-bd18-002590263bf5.html
2015-12-21 00:41:29 +00:00
Roman Bogorodskiy
b9470c68c6 Document libvirt vulnerability
Security:	CVE-2015-5313
2015-12-20 23:44:59 +00:00
Dmitry Marakasov
0b5828572f - Switch to options helpers
- Remove always false condition

Approved by:	portmgr blanket
2015-12-20 15:28:49 +00:00
Matthias Andree
b771610ca8 Update to new upstream release 2.3.9.
Removes the PW_SAVE option, the upstream code always permits saving
passwords to files now (so the feature is always enabled).

ChangeLog: <https://community.openvpn.net/openvpn/wiki/ChangesInOpenvpn23#OpenVPN2.3.9>
2015-12-20 14:35:13 +00:00
Timur I. Bakeyev
b72a236f01 Add entry for multiple Samba vulnerabilities 2015-12-19 23:42:25 +00:00
Jan Beich
c40f7d5a82 security/nss: enable NSSLOWHASH_* API support
Possible consumers:
  - net/chrony (autodetected)
  - security/p11-kit (--with-hash-impl=freebl)

PR:		205171
Submitted by:	John Hein <z7dr6ut7gs@snkmail.com>
2015-12-19 10:48:06 +00:00
Jan Beich
8ea39122c9 security/nss: update to 3.20.2
Changes:	https://hg.mozilla.org/projects/nss/rev/891676aa0d85
MFH:		2015Q4
2015-12-19 10:47:23 +00:00
Antoine Brodin
72a8dc0cd3 Fix make patch 2015-12-19 07:03:51 +00:00
Rene Ladan
ddf4aeac9d Document new vulnerabilities in www/chromium < 47.0.2526.106
Obtained from:	http://googlechromereleases.blogspot.nl/2015/12/stable-channel-update_15.html
2015-12-18 19:54:40 +00:00
Mark Felder
6456e07736 security/isakmpd: Fix building with libressl
PR:		198535
2015-12-18 17:53:40 +00:00
Jimmy Olgeni
1fa71dc23f Upgrade security/elixir-comeonin to version 2.0. 2015-12-18 14:51:34 +00:00
Raphael Kubo da Costa
a924b9c755 Add upstream commit to fix build errors with -pedantic.
This fixes at least devel/ccrtp's build on 9.3, which is currently broken:

  In file included from ccrtp/crypto/gcrypt/gcrypthmac.cpp:23:
  /usr/local/include/gcrypt.h:509: error: comma at end of enumerator list
  /usr/local/include/gcrypt.h:1346: error: comma at end of enumerator list
  Makefile:571: recipe for target 'gcrypthmac.lo' failed

MFH'ing this is not necessary, this bug is only present in libgcrypt 1.6.4.

PR:		205000
Approved by:	maintainer timeout (15 days)
2015-12-18 12:25:01 +00:00
Jason Unovitch
94a87762a1 Add PHP 5.6 package name to an earlier PHP VuXML entry
PR:		200779
Security:	CVE-2015-5590
Security:	CVE-2015-5589
Security:	https://vuxml.FreeBSD.org/freebsd/8b1f53f3-2da5-11e5-86ff-14dae9d210b8.html
2015-12-18 01:34:02 +00:00
Baptiste Daroussin
0a19021d44 Fix URL 2015-12-18 01:23:52 +00:00
Dmitry Marakasov
903f0b2f60 - Fix build when CC contains slashes
Approved by:	portmgr blanket
2015-12-17 18:46:14 +00:00
Dmitry Marakasov
8fe2c14615 - Switch to options helpers 2015-12-17 18:45:17 +00:00
Mark Felder
c48d611c78 Document vulns in cups-filters and foomatic-filters
Security:	CVE-2015-8560
Security:	CVE-2015-8327
2015-12-17 18:14:47 +00:00
Mark Felder
aee44a5313 Document py-amf vulnerability
Security:	CVE-2015-8549
2015-12-17 17:36:21 +00:00
Mathieu Arnold
7c47779cb9 Fix usage of ${PERL5}.
${PERL5} points to a specific version of perl, say, perl5.22.1, it is
fine to use it in a ports Makefile to do Perly things, but ports using
it must use ${PERL}, that points to /usr/local/bin/perl so that if the
minor version is updated, the shebang keep working.

While there, make some ports use shebangfix, regen a few patches, and
bump PORTREVISION where a shebang went from PERL5 to PERL.

PR:		205367
With hat:	portmgr
Sponsored by:	Absolight
2015-12-17 17:19:48 +00:00
Mark Felder
6bb642b982 Document multiple joomla vulnerabilities
Security:	CVE-2015-8562
Security:	CVE-2015-8563
Security:	CVE-2015-8564
Security:	CVE-2015-8565
2015-12-17 17:13:03 +00:00
Dmitry Marakasov
81a9a555ef - Update to 0.2.7.6
PR:		204123, 204806, 205252
Submitted by:	neel@neelc.org
Approved by:	maintainer timeout (bf, >1 month)
2015-12-17 16:16:51 +00:00
Dmitry Marakasov
8ff2ca1457 - Don't override/force logfile configuration
PR:		204739
Submitted by:	amdmi3
Approved by:	bf (maintainer)
2015-12-17 10:58:13 +00:00
Dmitry Marakasov
8a052b4f78 - Fix build with TCMALLOC and STATIC_TOR
PR:		204739
Submitted by:	amdmi3
Approved by:	portmgr blanket
MFH:		2015Q4 (blanket)
2015-12-17 10:36:53 +00:00
Cy Schubert
621e682f72 Update 1.12.4 --> 1.12.5 2015-12-17 01:36:46 +00:00
Olli Hauer
3167034399 - use GHL instead old GOOGLE archives plus bigger local patches
- sync pkg-descr
2015-12-16 19:17:01 +00:00
Mark Felder
5b11508dbb Document bind vulnerabilities
Security:	CVE-2015-3193
Security:	CVE-2015-8000
Security:	CVE-2015-8461
2015-12-16 02:15:12 +00:00
Dmitry Marakasov
e6d97701e3 - Switch to options helpers 2015-12-16 02:02:18 +00:00
Jan Beich
df15463625 Document recent mozilla vulnerabilities 2015-12-16 01:56:33 +00:00
Mark Felder
360dfb47be Document openjdk8 vulnerabilities
PR:		204269
Security:	CVE-2015-4908
Security:	CVE-2015-4916
Security:	CVE-2015-4906
Security:	CVE-2015-4872
Security:	CVE-2015-4911
Security:	CVE-2015-4893
Security:	CVE-2015-4803
Security:	CVE-2015-4903
Security:	CVE-2015-4734
Security:	CVE-2015-4842
Security:	CVE-2015-4882
Security:	CVE-2015-4840
Security:	CVE-2015-4902
Security:	CVE-2015-4871
Security:	CVE-2015-4806
Security:	CVE-2015-4810
Security:	CVE-2015-4868
Security:	CVE-2015-4901
Security:	CVE-2015-4844
Security:	CVE-2015-4805
Security:	CVE-2015-4860
Security:	CVE-2015-4883
Security:	CVE-2015-4843
Security:	CVE-2015-4881
Security:	CVE-2015-4835
2015-12-15 22:06:12 +00:00
Mark Felder
7934c78497 security/sshguard-pf Fix documentation URL in pkg-message
Submitted by:	Johan <johan jails se>
2015-12-15 21:18:52 +00:00
Olli Hauer
76fb0987f1 - fix Additional tests command
o use ./vuln.xml for the sample to work on every location
2015-12-15 20:42:56 +00:00
Olli Hauer
15e5449fea - document subversion CVE entry
o CVE-2015-5259
  o CVE-2015-5343

- adopt new pkg notation on howto check new VID entry
2015-12-15 20:37:05 +00:00
Martin Wilke
b24555fba0 - Update to 1.2.0
PR:		204986
Submitted by:	maintainer
Approved by:	mat (mentor)
Differential Revision:	D4576
2015-12-15 14:41:01 +00:00
Martin Wilke
b44961b1fc - Update to 1.2.0
- Switch to options helper

PR:		204987
Submitted by:	maintainer
Approved by:	mat (mentor)
Differential Revision:	D4575
2015-12-15 14:36:15 +00:00
Martin Wilke
5b2cf02256 A small command line utility for parsing PKCS#10 certificate signing
requests to perl data structure and provides accessor methods to
supported elements.

It is based on the generic ASN.1 module by Graham Barr and on the
x509decode example by Norbert Klasen. It is also based upon the
works of Duncan Segrests Crypt-X509-CRL module. The module parses
common fields and extensions. Some fields might be missing.

WWW: http://search.cpan.org/dist/Crypt-PKCS10/

PR:		204814
Submitted by:	Sergei Vyshenski <svysh.fbsd@gmail.com>
Approved by:    mat (mentor)
Differential Revision:  D4574
2015-12-15 14:33:33 +00:00
Cy Schubert
c675356816 This is the second part of two commits, the first being r403749.
Adopt the same port structure as used by the cfengine family of ports:

security/krb5 is renamed to security/krb5-114.

A brand new security/krb5 now becomes a master port for the family of
security/krb5-* ports. The default installs krb5-1.14. There is no
functional change to the port build nor does the name of the latest krb5
port and package change. Users can continue to install security/krb5
to track the latest major version of security/krb5.

Users wishing to install a specific version branch of krb5 can continue
to install any of the security/krb5-* ports or by setting KRB5_VERSION
in make.conf make.conf or including the branch on the make command line
during build:

	make KRB5_VERSIN=NNN

make -V VERSIONS lists available versions.

security/krb5-appl has been updated to support this change (also fixing
a typo in the krb5-appl/Makefile).

Inspired by:            sysutils/cfengine
2015-12-15 05:02:21 +00:00
Cy Schubert
05fc46624d Move security/krb5 to security/krb5-114 in preparation for restructuring
of the krb5 faimily of ports.

Inspired by:	the cfengine family of ports
2015-12-15 04:57:48 +00:00
Dmitry Marakasov
654518ff1c - Drop @dirrm* from plist
Approved by:	portmgr blanket
2015-12-15 01:21:43 +00:00
Kubilay Kocak
8d288bf5db security/py-fail2ban: Modernize and cleanup
- Use autoplist, update pkg-plist accordingly, deprecate py3kplist
- Remove unnecessary PYDISTUTILS_PKGVERSION and --install-purelib args
- Cleanup a REINPLACE to be more explicit
- Add do-test target
- Regenerate patches (makepatch compatible)
- Add NO_ARCH
- Sort and group USE{S,_*} entries

PR:		204373
Approved by:	maintainer <theis gmx at>
2015-12-14 10:52:47 +00:00
Rene Ladan
3d96ca1252 Document new vulnerabilities in www/chromium < 47.0.2526.80
Obtained from:	http://googlechromereleases.blogspot.nl/2015/12/stable-channel-update_8.html
2015-12-13 21:34:24 +00:00
Koop Mast
3970d847b0 * Update the freeimage entry in the dcraw vulnability.
* Document integer overflow in freeimage.
2015-12-13 20:23:41 +00:00
Olli Hauer
5f8c55ba37 - update to 7.01
FreeBSD related changes:
========================
Nmap 7.01 [2015-12-09]

o [NSE] [GH#254] Update the TLSSessionRequest probe in ssl-enum-ciphers to
  match the one in nmap-service-probes, which was fixed previously to correct a
  length calculation error. [Daniel Miller]

o [NSE] [GH#251] Correct false positives and unexpected behavior in http-*
  scripts which used http.identify_404 to determine when a file was not found
  on the target. The function was following redirects, which could be an
  indication of a soft-404 response. [Tom Sellers]

o [NSE] [GH#241] Fix a false-positive in hnap-info when the target responds
  with 200 OK to any request. [Tom Sellers]

o [NSE] [GH#244] Fix an error response in xmlrpc-methods when run against a
  non-HTTP service. The expected behavior is no output. [Niklaus Schiess]

o [NSE] Fix SSN validation function in http-grep, reported by Bruce Barnett.
2015-12-13 15:49:09 +00:00