Commit graph

22360 commits

Author SHA1 Message Date
Antoine Brodin
278351948b Allow use a regular user, some files were unreadable 2015-12-25 22:35:43 +00:00
Carlo Strub
f6810e0ee9 Update to 0.2.13 2015-12-25 21:35:26 +00:00
Carlo Strub
59100de785 Update to 0.21 2015-12-25 21:16:53 +00:00
Raphael Kubo da Costa
01bc556cb3 Add an entry for CVE-2015-0860 in archivers/dpkg. 2015-12-25 15:57:54 +00:00
Alex Kozlov
c84369de65 - Remove no longer used USE_RUBY_FEATURES knob
Approved by:	ruby, portmgr (swills)
2015-12-25 07:12:18 +00:00
Adam Weinberger
861a3a88ef Fix signature. The signature cannot have been correct; it was 50% the size of
all other signatures.
2015-12-24 17:27:47 +00:00
Martin Wilke
d7945e3244 - Adjust latest py*-django entry
Discussed with: feld
2015-12-24 17:09:18 +00:00
Jason Unovitch
a8ec954225 Document information disclosure vulnerability in the Mantis Bug Tracker
PR:		201106
Security:	CVE-2015-5059
Security:	https://vuxml.FreeBSD.org/freebsd/e1b5318c-aa4d-11e5-8f5c-002590263bf5.html
2015-12-24 14:57:58 +00:00
Jason Unovitch
f602a86a7d Update earlier MediaWiki entry (r394240) with CVE assignment information
PR:		202328
Security:	CVE-2013-7444
Security:	CVE-2015-6727
Security:	CVE-2015-6728
Security:	CVE-2015-6729
Security:	CVE-2015-6730
Security:	CVE-2015-6731
Security:	CVE-2015-6733
Security:	CVE-2015-6734
Security:	CVE-2015-6735
Security:	CVE-2015-6736
Security:	CVE-2015-6737
Security:       https://vuxml.FreeBSD.org/freebsd/6241b5df-42a1-11e5-93ad-002590263bf5.html
2015-12-24 14:08:42 +00:00
Jason Unovitch
438d4532e9 Update earlier MediaWiki entry (r400007) with CVE assignment information
Security:	CVE-2015-8001
Security:	CVE-2015-8002
Security:	CVE-2015-8003
Security:	CVE-2015-8004
Security:	CVE-2015-8005
Security:	CVE-2015-8006
Security:	CVE-2015-8007
Security:	CVE-2015-8008
Security:	CVE-2015-8009
Security:	https://vuxml.FreeBSD.org/freebsd/b973a763-7936-11e5-a2a1-002590263bf5.html
2015-12-24 14:02:39 +00:00
Jason Unovitch
4462ea194b Document recent MediaWiki vulnerabilities
Security:	CVE-2015-8628
Security:	CVE-2015-8627
Security:	CVE-2015-8626
Security:	CVE-2015-8625
Security:	CVE-2015-8624
Security:	CVE-2015-8623
Security:	CVE-2015-8622
Security:	https://vuxml.FreeBSD.org/freebsd/f36bbd66-aa44-11e5-8f5c-002590263bf5.html
2015-12-24 13:54:41 +00:00
Kubilay Kocak
c11a20df8f security/suricata: Update to 3.0 RC3
- Update DISTVERSION and distinfo checksum (3.0RC3)
- Pet portlint (makepatch: patch UTC time)

Merry Christmas All! HO HO HO

PR:		205306
Submitted by:	Franco Fichtner <franco opnsense org>
2015-12-24 13:31:53 +00:00
Sunpoet Po-Chuan Hsieh
cd24f70ea4 - Fix r404311: incomplete version range leads to false positive 2015-12-24 13:17:42 +00:00
Alex Kozlov
f15516c296 - Fix various distinfo issues
Approved by:	portmgr blanket
2015-12-24 11:41:32 +00:00
Sunpoet Po-Chuan Hsieh
21480756ee - Document Ruby vulnerability 2015-12-23 19:07:57 +00:00
Olli Hauer
2c50b7407b - document Bugzilla security issues 2015-12-23 11:14:07 +00:00
Jun Kuriyama
8ad3cbf243 - Upgrade to 1.4.20 (minor fixes). 2015-12-23 03:25:52 +00:00
Jason Unovitch
04708aced2 security/keepass: fix XSEL option dependency
- Switch x11/xsel -> x11/xsel-conrad. This resolves a run time issue
  when copying passwords to the clipboard.

PR:		204397
Reported by:	Alex Zhukov <baron.pampa@gmail.com>
Submitted by:	Ben Woods <woodsb02@gmail.com> (maintainer)
MFH:		2015Q4
2015-12-23 00:40:32 +00:00
Jason Unovitch
59e2c648ea security/keepassx: update 0.4.3 -> 0.4.4
- Update MASTER_SITES. Upstream no longer uses SVN or SourceForge
  infrastructure. See http://sourceforge.net/p/keepassx/code/387/
- USES: Add desktop-file-utils

PR:		205105
Approved by:	maintainer timeout (2 weeks)
Security:	CVE-2015-8378
Security:	https://vuxml.FreeBSD.org/freebsd/918a5d1f-9d40-11e5-8f5c-002590263bf5.html
MFH:		2015Q4
2015-12-23 00:22:31 +00:00
Jason Unovitch
fcb50bb32f Document two librsvg2 vulnerabilities
PR:		205502
Security:	CVE-2015-7557
Security:	CVE-2015-7558
Security:	https://vuxml.FreeBSD.org/freebsd/da634091-a84a-11e5-8f5c-002590263bf5.html
Security:	https://vuxml.FreeBSD.org/freebsd/d6c51737-a84b-11e5-8f5c-002590263bf5.html
2015-12-22 01:43:44 +00:00
Sunpoet Po-Chuan Hsieh
7f62f953dc - Sort SUBDIRs 2015-12-21 16:15:40 +00:00
Mathieu Arnold
970c34a2dc Fix build as a user.
While there, merge do-install and post-install, and use an option
target helper.

Sponsored by:	Absolight
2015-12-21 16:02:55 +00:00
Mark Felder
896a330f0e irc/quassel: Document vulnerability
Security:	CVE-2015-8547
2015-12-21 15:39:40 +00:00
Jason Unovitch
c0cde21162 Revise Moodle multiple security vulnerabilities from r401745 to reflect
recently published advisory

Security:	https://vuxml.FreeBSD.org/freebsd/82b3ca2a-8c07-11e5-bd18-002590263bf5.html
2015-12-21 00:41:29 +00:00
Roman Bogorodskiy
b9470c68c6 Document libvirt vulnerability
Security:	CVE-2015-5313
2015-12-20 23:44:59 +00:00
Dmitry Marakasov
0b5828572f - Switch to options helpers
- Remove always false condition

Approved by:	portmgr blanket
2015-12-20 15:28:49 +00:00
Matthias Andree
b771610ca8 Update to new upstream release 2.3.9.
Removes the PW_SAVE option, the upstream code always permits saving
passwords to files now (so the feature is always enabled).

ChangeLog: <https://community.openvpn.net/openvpn/wiki/ChangesInOpenvpn23#OpenVPN2.3.9>
2015-12-20 14:35:13 +00:00
Timur I. Bakeyev
b72a236f01 Add entry for multiple Samba vulnerabilities 2015-12-19 23:42:25 +00:00
Jan Beich
c40f7d5a82 security/nss: enable NSSLOWHASH_* API support
Possible consumers:
  - net/chrony (autodetected)
  - security/p11-kit (--with-hash-impl=freebl)

PR:		205171
Submitted by:	John Hein <z7dr6ut7gs@snkmail.com>
2015-12-19 10:48:06 +00:00
Jan Beich
8ea39122c9 security/nss: update to 3.20.2
Changes:	https://hg.mozilla.org/projects/nss/rev/891676aa0d85
MFH:		2015Q4
2015-12-19 10:47:23 +00:00
Antoine Brodin
72a8dc0cd3 Fix make patch 2015-12-19 07:03:51 +00:00
Rene Ladan
ddf4aeac9d Document new vulnerabilities in www/chromium < 47.0.2526.106
Obtained from:	http://googlechromereleases.blogspot.nl/2015/12/stable-channel-update_15.html
2015-12-18 19:54:40 +00:00
Mark Felder
6456e07736 security/isakmpd: Fix building with libressl
PR:		198535
2015-12-18 17:53:40 +00:00
Jimmy Olgeni
1fa71dc23f Upgrade security/elixir-comeonin to version 2.0. 2015-12-18 14:51:34 +00:00
Raphael Kubo da Costa
a924b9c755 Add upstream commit to fix build errors with -pedantic.
This fixes at least devel/ccrtp's build on 9.3, which is currently broken:

  In file included from ccrtp/crypto/gcrypt/gcrypthmac.cpp:23:
  /usr/local/include/gcrypt.h:509: error: comma at end of enumerator list
  /usr/local/include/gcrypt.h:1346: error: comma at end of enumerator list
  Makefile:571: recipe for target 'gcrypthmac.lo' failed

MFH'ing this is not necessary, this bug is only present in libgcrypt 1.6.4.

PR:		205000
Approved by:	maintainer timeout (15 days)
2015-12-18 12:25:01 +00:00
Jason Unovitch
94a87762a1 Add PHP 5.6 package name to an earlier PHP VuXML entry
PR:		200779
Security:	CVE-2015-5590
Security:	CVE-2015-5589
Security:	https://vuxml.FreeBSD.org/freebsd/8b1f53f3-2da5-11e5-86ff-14dae9d210b8.html
2015-12-18 01:34:02 +00:00
Baptiste Daroussin
0a19021d44 Fix URL 2015-12-18 01:23:52 +00:00
Dmitry Marakasov
903f0b2f60 - Fix build when CC contains slashes
Approved by:	portmgr blanket
2015-12-17 18:46:14 +00:00
Dmitry Marakasov
8fe2c14615 - Switch to options helpers 2015-12-17 18:45:17 +00:00
Mark Felder
c48d611c78 Document vulns in cups-filters and foomatic-filters
Security:	CVE-2015-8560
Security:	CVE-2015-8327
2015-12-17 18:14:47 +00:00
Mark Felder
aee44a5313 Document py-amf vulnerability
Security:	CVE-2015-8549
2015-12-17 17:36:21 +00:00
Mathieu Arnold
7c47779cb9 Fix usage of ${PERL5}.
${PERL5} points to a specific version of perl, say, perl5.22.1, it is
fine to use it in a ports Makefile to do Perly things, but ports using
it must use ${PERL}, that points to /usr/local/bin/perl so that if the
minor version is updated, the shebang keep working.

While there, make some ports use shebangfix, regen a few patches, and
bump PORTREVISION where a shebang went from PERL5 to PERL.

PR:		205367
With hat:	portmgr
Sponsored by:	Absolight
2015-12-17 17:19:48 +00:00
Mark Felder
6bb642b982 Document multiple joomla vulnerabilities
Security:	CVE-2015-8562
Security:	CVE-2015-8563
Security:	CVE-2015-8564
Security:	CVE-2015-8565
2015-12-17 17:13:03 +00:00
Dmitry Marakasov
81a9a555ef - Update to 0.2.7.6
PR:		204123, 204806, 205252
Submitted by:	neel@neelc.org
Approved by:	maintainer timeout (bf, >1 month)
2015-12-17 16:16:51 +00:00
Dmitry Marakasov
8ff2ca1457 - Don't override/force logfile configuration
PR:		204739
Submitted by:	amdmi3
Approved by:	bf (maintainer)
2015-12-17 10:58:13 +00:00
Dmitry Marakasov
8a052b4f78 - Fix build with TCMALLOC and STATIC_TOR
PR:		204739
Submitted by:	amdmi3
Approved by:	portmgr blanket
MFH:		2015Q4 (blanket)
2015-12-17 10:36:53 +00:00
Cy Schubert
621e682f72 Update 1.12.4 --> 1.12.5 2015-12-17 01:36:46 +00:00
Olli Hauer
3167034399 - use GHL instead old GOOGLE archives plus bigger local patches
- sync pkg-descr
2015-12-16 19:17:01 +00:00
Mark Felder
5b11508dbb Document bind vulnerabilities
Security:	CVE-2015-3193
Security:	CVE-2015-8000
Security:	CVE-2015-8461
2015-12-16 02:15:12 +00:00
Dmitry Marakasov
e6d97701e3 - Switch to options helpers 2015-12-16 02:02:18 +00:00