Commit graph

22360 commits

Author SHA1 Message Date
Dmitry Marakasov
6ab1c00766 - Add LICENSE_FILE
- Switch to options helpers
2015-11-12 14:42:01 +00:00
Dmitry Marakasov
f49f981849 - Switch to options helpers
- Switch to new testing framework
2015-11-12 14:40:38 +00:00
Jimmy Olgeni
0ced111be8 Add security/elixir-comeonin_i18n, an internationalization library for
security/elixir-comeonin.
2015-11-12 14:27:38 +00:00
Ryan Steinmetz
c39c1ec545 - Update to 1.2-alpha4 2015-11-12 13:53:22 +00:00
Ryan Steinmetz
18aa9be4ab - Update to 1.9.17 2015-11-12 12:34:59 +00:00
Sunpoet Po-Chuan Hsieh
0f5c9201db - Update to 1.1.1
Changes:	https://github.com/onelogin/ruby-saml/releases
2015-11-12 11:58:57 +00:00
Hajimu UMEMOTO
2dd87a10a5 Use OPTIONS helper. 2015-11-12 11:21:48 +00:00
Hajimu UMEMOTO
01d64fe98c Use OPTIONS helper. 2015-11-12 11:16:30 +00:00
Rene Ladan
b08bc93a51 Document new vulnerabilities in www/chromium < 46.0.2490.86
Obtained from:	http://googlechromereleases.blogspot.nl/2015/11/stable-channel-update.html
2015-11-11 22:43:58 +00:00
Bryan Drewery
3f7ae3c03a Make portlint stop spamming me. It's gotten quite silly.
There's no reason to regenerate these for the sake of having 'UTC' in the patch
and it also considers patches with comments to be invalid.

WARN: /root/svn/ports/security/openssh-portable/files/patch-auth.c: patch was not generated using ``make makepatch''.  It is recommended to use ``make makepatch'' when you need to [re-]generate a patch to ensure proper patch format.
WARN: /root/svn/ports/security/openssh-portable/files/patch-auth2.c: patch was not generated using ``make makepatch''.  It is recommended to use ``make makepatch'' when you need to [re-]generate a patch to ensure proper patch format.
WARN: /root/svn/ports/security/openssh-portable/files/patch-readconf.c: patch was not generated using ``make makepatch''.  It is recommended to use ``make makepatch'' when you need to [re-]generate a patch to ensure proper patch format.
WARN: /root/svn/ports/security/openssh-portable/files/patch-regress__test-exec.sh: patch was not generated using ``make makepatch''.  It is recommended to use ``make makepatch'' when you need to [re-]generate a patch to ensure proper patch format.
WARN: /root/svn/ports/security/openssh-portable/files/patch-servconf.c: patch was not generated using ``make makepatch''.  It is recommended to use ``make makepatch'' when you need to [re-]generate a patch to ensure proper patch format.
WARN: /root/svn/ports/security/openssh-portable/files/patch-session.c: patch was not generated using ``make makepatch''.  It is recommended to use ``make makepatch'' when you need to [re-]generate a patch to ensure proper patch format.
WARN: /root/svn/ports/security/openssh-portable/files/patch-ssh-agent.1: patch was not generated using ``make makepatch''.  It is recommended to use ``make makepatch'' when you need to [re-]generate a patch to ensure proper patch format.
WARN: /root/svn/ports/security/openssh-portable/files/patch-ssh-agent.c: patch was not generated using ``make makepatch''.  It is recommended to use ``make makepatch'' when you need to [re-]generate a patch to ensure proper patch format.
WARN: /root/svn/ports/security/openssh-portable/files/patch-ssh.c: patch was not generated using ``make makepatch''.  It is recommended to use ``make makepatch'' when you need to [re-]generate a patch to ensure proper patch format.
WARN: /root/svn/ports/security/openssh-portable/files/patch-ssh_config: patch was not generated using ``make makepatch''.  It is recommended to use ``make makepatch'' when you need to [re-]generate a patch to ensure proper patch format.
WARN: /root/svn/ports/security/openssh-portable/files/patch-ssh_config.5: patch was not generated using ``make makepatch''.  It is recommended to use ``make makepatch'' when you need to [re-]generate a patch to ensure proper patch format.
WARN: /root/svn/ports/security/openssh-portable/files/patch-sshconnect.c: patch was not generated using ``make makepatch''.  It is recommended to use ``make makepatch'' when you need to [re-]generate a patch to ensure proper patch format.
WARN: /root/svn/ports/security/openssh-portable/files/patch-sshd.8: patch was not generated using ``make makepatch''.  It is recommended to use ``make makepatch'' when you need to [re-]generate a patch to ensure proper patch format.
WARN: /root/svn/ports/security/openssh-portable/files/patch-sshd.c: patch was not generated using ``make makepatch''.  It is recommended to use ``make makepatch'' when you need to [re-]generate a patch to ensure proper patch format.
WARN: /root/svn/ports/security/openssh-portable/files/patch-sshd_config: patch was not generated using ``make makepatch''.  It is recommended to use ``make makepatch'' when you need to [re-]generate a patch to ensure proper patch format.
WARN: /root/svn/ports/security/openssh-portable/files/patch-sshd_config.5: patch was not generated using ``make makepatch''.  It is recommended to use ``make makepatch'' when you need to [re-]generate a patch to ensure proper patch format.
2015-11-11 21:21:44 +00:00
Bryan Drewery
7c7778bb96 Fix the NONECIPHER not actually being offered by the server.
Upstream issue: https://github.com/rapier1/openssh-portable/issues/3
2015-11-11 21:04:48 +00:00
Bernard Spil
a45c2247bc Document CVE's in MySQL/MariaDB/Percona
PR:		204410
Submitted by:	Sevan Janiyan <venture37@geeklan.co.uk>
Reviewed by:	feld
Approved by:	feld
Security:	CVE-2015-4802
Security:	CVE-2015-4807
Security:	CVE-2015-4815
Security:	CVE-2015-4826
Security:	CVE-2015-4830
Security:	CVE-2015-4836
Security:	CVE-2015-4858
Security:	CVE-2015-4861
Security:	CVE-2015-4870
Security:	CVE-2015-4913
Security:	CVE-2015-4792
2015-11-11 20:39:13 +00:00
Dirk Meyer
5d9fc1b8dc This is a fast and Secure Tunnelling Daemon.
WWW: http://git.universe-factory.net/fastd
PR:		204473
Submitted by:	Jan Bramkamp
2015-11-11 18:42:24 +00:00
Dirk Meyer
0699735966 This is a fast and Secure Tunnelling Daemon.
WWW: http://git.universe-factory.net/fastd
PR:		204472
Submitted by:	Jan Bramkamp
2015-11-11 18:34:21 +00:00
Bryan Drewery
70381a9f0d Update advice to disable ChallengeResponseAuthentication for key usage.
PR:		204475
Reported by:	Mark.Martinec@ijs.si
2015-11-11 18:04:40 +00:00
Dirk Meyer
5ef4e86434 This is a very small Elliptic Curve Cryptography library.
WWW: http://git.universe-factory.net/libuecc
PR:		204471
Submitted by:	Jan Bramkamp
2015-11-11 17:40:45 +00:00
Steve Wills
70a10de92f Document RCE in jenkins 2015-11-11 16:26:40 +00:00
Guido Falsi
1df9f4df9c Document owncloudclient vulnerability
PR:		204407
Submitted by:	Sevan Janiyan <venture37 at geeklan.co.uk>
Security:	CVE-2015-7298
2015-11-11 11:19:17 +00:00
Jason Unovitch
8ff9fb91a4 Document Xen XSAs-{142,148,149,150,151,152,153}
Security:	CVE-2015-7311
Security:	CVE-2015-7835
Security:	CVE-2015-7969
Security:	CVE-2015-7970
Security:	CVE-2015-7971
Security:	CVE-2015-7972
Security:	https://vuxml.FreeBSD.org/freebsd/301b04d7-881c-11e5-ab94-002590263bf5.html
Security:	https://vuxml.FreeBSD.org/freebsd/3d9f6260-881d-11e5-ab94-002590263bf5.html
Security:	https://vuxml.FreeBSD.org/freebsd/83350009-881e-11e5-ab94-002590263bf5.html
Security:	https://vuxml.FreeBSD.org/freebsd/c0e76d33-8821-11e5-ab94-002590263bf5.html
Security:	https://vuxml.FreeBSD.org/freebsd/e3792855-881f-11e5-ab94-002590263bf5.html
Security:	https://vuxml.FreeBSD.org/freebsd/e4848ca4-8820-11e5-ab94-002590263bf5.html
Security:	https://vuxml.FreeBSD.org/freebsd/fc1f8795-881d-11e5-ab94-002590263bf5.html
2015-11-11 03:22:07 +00:00
Jason Unovitch
5d91b7a259 Document p5-HTML-Scrubber XSS vulnerability
PR:		204416
Reported by:	Sevan Janiyan <venture37@geeklan.co.uk>
Security:	CVE-2015-5667
Security:	https://vuxml.FreeBSD.org/freebsd/2f7f4db2-8819-11e5-ab94-002590263bf5.html
2015-11-11 02:16:23 +00:00
Jan Beich
252ac7fdab Document MFSA 2015-101 affects multimedia/libvpx as well
PR:		203410
2015-11-10 22:26:13 +00:00
Jason Unovitch
ff9a094d22 Document CVE assignment on wpa_supplicant 2015-5 advisory
PR:		201432
Security:	CVE-2015-8041
Security:	https://vuxml.FreeBSD.org/freebsd/c93c9395-25e1-11e5-a4a5-002590263bf5.html
2015-11-10 03:25:27 +00:00
Jason Unovitch
3c8503c967 Revise lldpd entry to cover denial of service CVE and add references.
PR:		204044
Security:	CVE-2015-8012
Security:	CVE-2015-8011
Security:	https://vuxml.FreeBSD.org/freebsd/2a4a112a-7c1b-11e5-bd77-0800275369e2.html
2015-11-10 03:18:50 +00:00
Mark Felder
a5573f5fb3 Document dns/powerdns denial of service vulnerability
Security:	CVE-2015-5311
2015-11-09 20:57:50 +00:00
Sunpoet Po-Chuan Hsieh
e72adbae31 - Mark IGNORE on FreeBSD 9.x 2015-11-09 18:43:08 +00:00
Sunpoet Po-Chuan Hsieh
dd77cb5575 - Update to 2.5.0
- Add LICENSE_FILE
- Convert to new options target helper
- Convert to new options variable helper
- Use = instead of += for PLIST_SUB
- Cleanup Makefile

Changes:	https://github.com/rubygems/rubygems/blob/master/History.txt
PR:		204328
Exp-run by:	antoine
2015-11-09 18:42:51 +00:00
Renato Botelho
effa54ec4c Backport a couple of commits from master, that will be present in 5.3.4:
- dff2d05bb9 [1]: kernel-pfKey: Enable AES-CTR
- 04f22cdabc [2]: VICI: add NAT information

Bump PORTREVISION

[1] dff2d05bb9
[2] 04f22cdabc

PR:		204398
Approved by:	maintainer
Obtained from:	pfSense
Sponsored by:	Rubicon Communications (Netgate)
2015-11-09 16:56:08 +00:00
Tijl Coosemans
c17e62e0b6 - Update polarssl/mbedtls ports
- Mark polarssl 1.2.x deprecated
- Fix sparc64 build by removing -fpic (leaving only -fPIC)

MFH:		2015Q4
Security:	https://tls.mbed.org/tech-updates/releases/mbedtls-2.2.0-2.1.3-1.3.15-and-polarssl.1.2.18-released
2015-11-09 15:58:20 +00:00
Ryan Steinmetz
68483f4505 - Bump PORTEPOCH as 1.26b1 > 1.26 2015-11-09 13:31:37 +00:00
Antoine Brodin
496ac41eab Mark a few ports BROKEN: unfetchable 2015-11-09 12:59:03 +00:00
Ryan Steinmetz
52b33aef84 - Update to 5.26 2015-11-09 12:31:29 +00:00
Matthias Andree
6c2d5afdf8 Update to new upstream release 0.66 (security fix).
Switch to USES=gssapi:mit.

Security:	CVE-2015-5309
Security:	0cb0afd9-86b8-11e5-bf60-080027ef73ec
2015-11-09 09:18:22 +00:00
Matthias Andree
73e069adbd Record PuTTY vuln' CVE-2015-5309 (Erase char handling). 2015-11-09 08:06:55 +00:00
Lars Engels
437912ad49 Forced commit. PR ID was 204360 not 162881
PR:		204360
2015-11-07 16:33:07 +00:00
Lars Engels
8853d8cf15 Update to 2.1.1
PR:		162881
Submitted by:	Enrique Ayesta Perojo
2015-11-07 16:30:52 +00:00
Jimmy Olgeni
eda90894c9 Upgrade security/elixir-comeonin to version 1.4. 2015-11-07 14:01:04 +00:00
Pawel Pekala
6100c598ae Fix plist when DOCS=off
PR:		200013
Reported by:	yuri@rawbw.com
2015-11-06 20:14:00 +00:00
Tijl Coosemans
ac0075c2b5 Update the Linphone stack.
Linphone 3.9.0
Ortp 0.25.0 + bump PORTREVISION on dependent ports (devel/libosmo-abis)
Libbzrtp 1.0.3
Belle-sip (fix files/patch-src-belle_sip_headers_impl.c)
Mediastreamer 2.12.0
MS plugins (msbcg729 1.0.1, msilbc 2.1.2, msopenh264 1.1.1, msx264 1.5.2)
2015-11-06 16:24:13 +00:00
Sunpoet Po-Chuan Hsieh
9501ea1f32 - Fix MASTER_SITES
- Use USES=tar:tgz

Approved by:	portmgr (blanket)
2015-11-06 13:12:32 +00:00
Kubilay Kocak
17efc87c42 [NEW] security/py-letsencrypt: Welcome Let's Encrypt client!
In short: getting and installing SSL/TLS certificates made easy.

The Let's Encrypt Client is a tool to automatically receive and install
X.509 certificates to enable TLS on servers. The client will
interoperate with the Let's Encrypt CA which will be issuing
browser-trusted certificates for free.

It's all automated:

The tool will prove domain control to the CA and submit a CSR
(Certificate Signing Request).

If domain control has been proven, a certificate will get issued and
the tool will automatically install it.

WWW: https://github.com/letsencrypt/letsencrypt

PR:		203405
2015-11-06 08:38:34 +00:00
Kubilay Kocak
72d5c4667e security/py-acme: Update to 0.0.0.dev20151104
- Update version and distinfo checksum (0.0.0.dev20151104)
- Switch to DISTVERSION (illegal PORTVERSION) and DISTVERSIONPREFIX
- Use github version tags rather than a direct commit

PR:		204303
Approved by:	Carlos J Puga Medina <cpm fbsd es> (maintainer)
2015-11-06 08:29:10 +00:00
Sunpoet Po-Chuan Hsieh
fc22a9e780 - Use USES=pathfix
- While I'm here, pet portlint

Approved by:	portmgr (blanket)
2015-11-06 03:40:35 +00:00
Don Lewis
79d59d9010 Add openoffice-devel version information to entry
18b3c61b-83de-11e5-905b-ac9e174be3af
Apache OpenOffice 4.1.1 -- multiple vulnerabilities.
2015-11-05 22:26:19 +00:00
Dmitry Marakasov
2f9f592fbd - Add LICENSE
- Fix pkgconfig file location

Approved by:	portmgr blanket
MFH:		2015Q4 (blanket)
2015-11-05 20:57:25 +00:00
Don Lewis
5983dc2090 Apache OpenOffice 4.1.1 -- multiple vulnerabilities. 2015-11-05 17:03:03 +00:00
Mathieu Arnold
065c026fe5 Fix ports that confused the meaning of WRKDIR and WRKSRC.
PR:		204056
Submitted by:	mat
Reviewed by:	bapt
Sponsored by:	Absolight
Differential Revision:	https://reviews.freebsd.org/D2735
2015-11-05 12:36:25 +00:00
Dmitry Marakasov
c5c6314a6c - Mark MAKE_JOBS_UNSAFE, fails in parallel build:
/usr/bin/ld: cannot find -lpcre

(bundled pcre library is used before it's built)

- Use options helpers

Approved by:	portmgr blanket
2015-11-05 11:50:19 +00:00
Bartek Rutkowski
5b00bbd716 security/govpn: update 4.0 -> 4.1
PR:		204279
Submitted by:	Sergey Matveev <stargrave@stargrave.org> (maintainer)
2015-11-05 04:49:49 +00:00
Sunpoet Po-Chuan Hsieh
34aabcc302 - Update TEST_DEPENDS: remove redundant LOCALBASE/bin 2015-11-04 20:15:09 +00:00
Sunpoet Po-Chuan Hsieh
fbec6d8cfb - Add LICENSE_FILE
- Update RUN_DEPENDS: remove redundant LOCALBASE/bin
- Remove PKGMESSAGE from SUB_FILES
2015-11-04 20:15:05 +00:00
Sunpoet Po-Chuan Hsieh
331aef55a4 - Update to 0.22.5
- Update BUILD_DEPENDS: remove redundant LOCALBASE/bin and use newer swig
- Strip shared library
- Update WWW

Changes:	https://gitlab.com/m2crypto/m2crypto/tags
2015-11-04 20:11:35 +00:00
Sunpoet Po-Chuan Hsieh
fb4243736a - Move devel/py-parsing to devel/py-pyparsing
- Change MASTER_SITES to CHEESESHOP
- Remove DISTNAME
- While I'm here, remove duplicate PORTREVISION for security/py-crits/Makefile
2015-11-04 20:11:00 +00:00
Niclas Zeising
b224fe5d39 Add CVE for xscreensaver lock bypass. 2015-11-04 19:36:01 +00:00
Dmitry Marakasov
2c9532f09f - Add LICENSE
- Switch to options helpers
- Drop @dirrm* from plist
- Pet portlint
- Fix WWW:

Approved by:	portmgr blanket
2015-11-04 17:54:59 +00:00
Olli Hauer
d521b0af5e - update to 6.49BETA6
- use new OPTIONS targes

Parts from Changelog [1]
==========================
Nmap 6.49BETA6
o Integrated all of your IPv6 OS fingerprint submissions from April to October
  (only 9 of them!). We are steadily improving the IPv6 database, but we need
  your submissions. The classifier added 3 new groups, bringing the new total
  to 93. Highlights: http://seclists.org/nmap-dev/2015/q4/61 [Daniel Miller]

o Integrated all of your IPv4 OS fingerprint submissions from February to
  October (1065 of them). Added 219 fingerprints, bringing the new total to
  4985. Additions include Linux 4.1, Windows 10, OS X 10.11, iOS 9, FreeBSD
  11.0, Android 5.1, and more. Highlights:
  http://seclists.org/nmap-dev/2015/q4/60 [Daniel Miller]

o Integrated all of your service/version detection fingerprints submitted from
  February to October (800+ of them). The signature count went up 2.5% to
  10293. We now detect 1089 protocols, from afp, bitcoin, and caldav to
  xml-rpc, yiff, and zebra. Highlights: http://seclists.org/nmap-dev/2015/q4/62
  [Daniel Miller]

o [NSE] Added 10 NSE scripts from 5 authors, bringing the total up to 509!
  They are all listed at http://nmap.org/nsedoc/, and the summaries are below
  (authors are listed in brackets):

...

[1] https://nmap.org/changelog.html
2015-11-04 17:30:00 +00:00
Cy Schubert
e8ab409d89 Simplify and standardize port structure.
Submitted by:	hrs
2015-11-04 02:29:38 +00:00
Ryan Steinmetz
b5e8d74067 - Update to 5.26b1 (5.25 contains a build breaking bug, 5.26b1 resolves this) 2015-11-03 12:31:59 +00:00
Renato Botelho
5ebc099a79 - Update security/sudo to 1.8.15
- Remove patch-plugins__sudoers__Makefile.in, unnecessary on stagedir days
- Remove patch-plugins__sudoers__audit.c, sudo_gettext.h is already included
  by sudoers.h
- Rework patch-plugins__sudoers__sudoers.in to replace pkg_* utilities by
  pkg on message
2015-11-03 09:44:23 +00:00
Cy Schubert
b9d5e43fe0 As of r399238, when the heimdal port option was selected, this port did
not build properly. Prior to r399238, even if the heimdal port was
installed, the base krb5 libraries and include files were used. This is
because ports/security/heimdal places its libraries in
${LOCALBASE}/lib/heimdal and include files in ${LOCALBASE}/include/heimdal,
which this port does not look for (unless told to do so... by this commit).

Discovered by:	marino
2015-11-03 04:55:58 +00:00
Kubilay Kocak
a8fe7b23c5 security/py-cryptography: Add missing run-time dependencies
Add py-idna and conditionally (For Python < 3.3) py-ipaddress to
RUN_DEPENDS

While I'm here:

- Update minimum versions requirement for py-cffi
- Update test target since the framework supports TEST_DEPENDS et al.

Noticed by:	brnrd
2015-11-02 16:39:53 +00:00
Philippe Audeoud
b89bb2ad80 - Update to 0.020 2015-11-02 14:29:32 +00:00
Kurt Jaeger
9085b33fdc security/softether: fix USES
PR:		204184
Submitted by:	marino
Approved by:	maintainer (implicit)
2015-11-02 14:11:09 +00:00
Kurt Jaeger
4811858357 security/softether: fixes
- iconv build
- build with No-SSLv3
- MAKE_JOBS_UNSAFE=yes unconditionally

PR:		203688, 204184
Submitted by:	net@arrishq.net (maintainer)
2015-11-02 11:59:59 +00:00
Jimmy Olgeni
0fb5922be2 Upgrade security/elixir-comeonin to version 1.3.1. 2015-11-02 08:39:46 +00:00
Jason Unovitch
7f715d5501 Document multiple vulnerabilities fixed in CodeIgniter
PR:		203403
Security:	https://vuxml.FreeBSD.org/freebsd/bdd57272-803c-11e5-ab94-002590263bf5.html
2015-11-01 02:10:37 +00:00
Antoine Brodin
3f67b68ab7 Update to 2.1.0.12 2015-10-31 21:46:50 +00:00
Olli Hauer
fa64224f89 - update patches to match latest git rev (v0.7.2)
- add ca_root_nss as direct runtime dependency
- use new option target to install docs

Download URL has changed from s3.amazonaws to snort.org!
Please adjust your pulledpork.conf

MFH:		2015Q4
2015-10-31 13:08:49 +00:00
Cy Schubert
72f9f8117a Fix Kerberos selection option and USES. 2015-10-31 05:58:27 +00:00
Sunpoet Po-Chuan Hsieh
bb2b83b72f - Convert to new options helper
- Convert to new options target helper

Approved by:	portmgr (blanket)
2015-10-30 11:26:47 +00:00
Sunpoet Po-Chuan Hsieh
16a0be9b6f - Fix gemspec for rubygem-ruby-saml 1.1.0 update
- Bump PORTREVISION for package change
2015-10-30 11:26:24 +00:00
Sunpoet Po-Chuan Hsieh
e8abe935a2 - Update to 1.1.0
- Add LICENSE

Changes:	https://github.com/onelogin/ruby-saml/blob/master/changelog.md
2015-10-30 11:26:20 +00:00
Sean Bruno
343a083fb9 Enable the building and installation of the .a version of the library
for static linking.  This affects emulators/qemu-user-static primarily
but will help anyone trying to statically link their applications.

Reviewed by:	tijl cpm@fbsd.es (Maintainer)
2015-10-29 14:30:24 +00:00
Roman Bogorodskiy
62a14d310a security/libgpg-error: enable static lib
Enable static lib as it's needed by QEMU for static
linking (qemu-user-static) and bump PORTREVISION.

Submitted by:	sbruno
2015-10-29 14:29:06 +00:00
Renato Botelho
9c90e69933 - Add a new option, SWANCTL, to install swanctll utility
- When VICI option is selected, install libvici.h to include directory,
  it's useful when you need to build a custom code linked to libvici
- Pass path to USE_LDCONFIG otherwise libraries will not be visible

PR:		204098
Approved by:	maintainer
Obtained from:	pfSense
Sponsored by:	Rubicon Communications (Netgate)
2015-10-29 12:42:30 +00:00
Antoine Brodin
e44b020d61 Update to 2.5
Announce:	http://www.volatilityfoundation.org/#!25/c1f29
2015-10-29 12:14:38 +00:00
Jason Unovitch
23503a93fa Document additional CVE assigned for the last Wordpress update
Security:	CVE-2015-7989
Security:	https://vuxml.FreeBSD.org/freebsd/f4ce64c2-5bd4-11e5-9040-3c970e169bc2.html
2015-10-29 01:51:05 +00:00
Mark Felder
d5bb164515 Document information disclosure in net/openafs
Security:	CVE-2015-7762
Security:	CVE-2015-7763
2015-10-28 20:59:22 +00:00
Pawel Pekala
33eb4d6ebb Framework to connect any number of virtual machines to the
tor anonymity network.

WWW: https://github.com/yurivict/vm-to-tor

PR:		200333
Submitted by:	Yuri Victorovich <yuri@rawbw.com>
2015-10-28 20:30:13 +00:00
Renato Botelho
48f7ab060b - Add a new option (VICI) to build VICI management protocol
- Change SMP option description to show users it's deprecated

PR:		204090
Approved by:	maintainer
2015-10-28 14:27:28 +00:00
Niclas Zeising
8bcc103ea0 Add entry for x11/xscreensaver for a lock bypass vulnerability 2015-10-27 20:53:54 +00:00
Dmitry Marakasov
c78fd04ab5 - Fix shebangs
- Add NO_ARCH

Approved by:	portmgr blanket
2015-10-27 18:52:44 +00:00
Sunpoet Po-Chuan Hsieh
d929b71224 - Update to 1.8.4
Changes:	http://lists.gnupg.org/pipermail/gnupg-announce/2015q3/000375.html
PR:		204003
Submitted by:	Carlos J Puga Medina <cpm@fbsd.es> (maintainer)
2015-10-27 15:54:54 +00:00
Sunpoet Po-Chuan Hsieh
28e56989fe - Update to 0.22
Changes:	http://search.cpan.org/dist/Unix-Passwd-File/Changes
2015-10-27 15:51:58 +00:00
Sunpoet Po-Chuan Hsieh
c0425b4793 - Add LICENSE_FILE 2015-10-27 15:50:06 +00:00
Sunpoet Po-Chuan Hsieh
949aa01893 - Update to 1.055
Changes:	http://search.cpan.org/dist/Net-SSLGlue/Changes
2015-10-27 15:49:42 +00:00
Mathieu Arnold
91f933b2cb Document lldpd security vunlnerability.
PR:		204044
Submitted by:	maintainer
Sponsored by:	Absolight
2015-10-27 13:44:07 +00:00
Renato Botelho
1f33e7ef35 strongSwan can be beuit using 3 different printf hooks: builtin, glibc
(compatible with FreeBSD's libc) and vstr (devel/vstr). Since it's not
selected any of them on CONFIGURE_ARGS, it uses auto, and end up using
glibc.

pfSense users reported memory leaks on strongSwan [2] [3] and a it was
reported to upstream [1].

Add a single option and let user choose which printf hook to use, and
change default to use builtin. Bump PORTREVISION due to default change

[1] https://wiki.strongswan.org/issues/1106
[2] https://forum.pfsense.org/index.php?topic=96767.0
[3] https://redmine.pfsense.org/issues/5149

PR:		204051
Approved by:	maintainer
Obtained from:	pfSense
MFH:		2015Q4
Sponsored by:	Rubicon Communications (Netgate)
2015-10-27 13:27:17 +00:00
Thomas Zander
30bf7ffd51 Update to upstream version 0.3.8
PR:		204022
Submitted by:	christer.edwards@gmail.com (maintainer)
2015-10-26 18:44:23 +00:00
Mark Felder
320c35ac14 Update range for libressl vulnerability
Range was entered incorrectly as <2.2.3

Security:	e75a96df-73ca-11e5-9b45-b499baebfeaf
2015-10-26 13:45:27 +00:00
Steve Wills
bcbd6e9e1e security/py-python-gnupg: create port
The gnupg module allows Python programs to make use of the functionality
provided by the GNU Privacy Guard (abbreviated GPG or GnuPG). Using this
module, Python programs can encrypt and decrypt data, digitally sign documents
and verify digital signatures, manage (generate, list and delete) encryption
keys, using proven Public Key Infrastructure (PKI) encryption technology based
on OpenPGP.

WWW: http://packages.python.org/python-gnupg/index.html

PR:		199551
Submitted by:	Christer Edwards <christer.edwards@gmail.com>
2015-10-26 01:20:21 +00:00
Jason Unovitch
d8c079f57d security/webfwlog: update 1.00 -> 1.01 [1]
- While here add trailing slash to WWW:

PR:		203955 [1]
Submitted by:	Torsten Zuhlsdorff <ports@toco-domains.de>
Approved by:	zeus@ix.netcom.com (maintainer)
2015-10-25 20:11:51 +00:00
Joe Marcus Clarke
99d9c2bd22 Add an entry for wireshark-1.12.8 for CVE-2015-7830. 2015-10-25 17:37:12 +00:00
Jason Unovitch
76779cc5bd Document the recent remote site takeover via SQL injection vuln in Joomla
While here, document all missing Joomla security vulnerabilities since the
last entry in March 2014

Security:	CVE-2014-6631
Security:	CVE-2014-6632
Security:	CVE-2014-7228
Security:	CVE-2014-7229
Security:	CVE-2015-5397
Security:	CVE-2015-5608
Security:	CVE-2015-6939
Security:	CVE-2015-7297
Security:	CVE-2015-7857
Security:	CVE-2015-7858
Security:	CVE-2015-7859
Security:	CVE-2015-7899
Security:	https://vuxml.FreeBSD.org/freebsd/0ebc6e78-7ac6-11e5-b35a-002590263bf5.html
Security:	https://vuxml.FreeBSD.org/freebsd/03e54e42-7ac6-11e5-b35a-002590263bf5.html
Security:	https://vuxml.FreeBSD.org/freebsd/f8c37915-7ac5-11e5-b35a-002590263bf5.html
Security:	https://vuxml.FreeBSD.org/freebsd/ec2d1cfd-7ac5-11e5-b35a-002590263bf5.html
Security:	https://vuxml.FreeBSD.org/freebsd/deaba148-7ac5-11e5-b35a-002590263bf5.html
Security:	https://vuxml.FreeBSD.org/freebsd/cec4d01a-7ac5-11e5-b35a-002590263bf5.html
Security:	https://vuxml.FreeBSD.org/freebsd/beb3d5fc-7ac5-11e5-b35a-002590263bf5.html
Security:	https://vuxml.FreeBSD.org/freebsd/adbb32d9-7ac5-11e5-b35a-002590263bf5.html
2015-10-25 03:26:58 +00:00
Thomas Zander
a8d0d986c6 Un-break build on systems where cxx does not support c++11
PR:		203992
Submitted by:	eric@camachat.org (maintainer)
2015-10-24 13:10:50 +00:00
Matthias Andree
70092ef822 Handle OpenSSL/PolarSSL options in the right way,
such that it is maintainable if we add more SSL libs in the future.

To fix fall-out from r399858 and r399982.
2015-10-24 11:18:04 +00:00
Jason Unovitch
f919e6acd7 Document redirect vulnerability in the drupal7 overlay module
PR:		203977
Security:	CVE-2015-7943
Security:	https://vuxml.FreeBSD.org/freebsd/75f39413-7a00-11e5-a2a1-002590263bf5.html
2015-10-24 03:55:25 +00:00
Danilo Egea Gondolfo
75f6a10389 - New port: security/s2n
s2n is a C99 implementation of the TLS/SSL protocols that
is designed to be simple, small, fast, and with security as
a priority. It is released and licensed under the Apache Software License 2.0.

WWW: https://github.com/awslabs/s2n
2015-10-23 22:48:34 +00:00
Matthew Seaman
1cf82dbf08 Record phpMyAdmin -- content spoofing vulnerability. 2015-10-23 20:39:41 +00:00
Thomas Zander
6f1821384b Update to upstream version 2.4.1, add BROKER OPTION
PR:		203849
Submitted by:	leres@ee.lbl.gov (maintainer)
2015-10-23 19:04:50 +00:00
Dmitry Marakasov
d0e4a5817f - Add NO_ARCH
- Drop @dirrm* from plist

Approved by:	portmgr blanket
2015-10-23 18:36:52 +00:00
Thomas Zander
8e02189b35 Adopt broccoli version numbering, update to 1.97
The gist from maintainer's explanation of the situation:
Upon creation of the port, the version number of the bro
distribution broccoli was packaged with was used. But it
makes more sense to use broccoli's actual version number.

PR:		203848
Submitted by:	leres@ee.lbl.gov (maintainer)
2015-10-23 18:12:26 +00:00
Xin LI
08f34c37a2 Add CVE references to the NTP entry. 2015-10-23 11:59:59 +00:00
Jason Unovitch
fc111cf1ce Document Mediawiki security vulnerabilities for 1.25.3, 1.24.4, and 1.23.11
Security:	https://vuxml.FreeBSD.org/freebsd/b973a763-7936-11e5-a2a1-002590263bf5.html
2015-10-23 03:43:36 +00:00
Martin Matuska
f927ae941d Horde package update:
comms/pear-Horde_ActiveSync 2.29.2 -> 2.30.0
devel/pear-Horde_Core 2.22.0 -> 2.22.1
devel/pear-Horde_Nls 2.0.5 -> 2.1.0
devel/pear-Horde_Notification 2.0.2 -> 2.0.3
textproc/pear-Horde_Pdf 2.0.5 -> 2.0.6
devel/pear-Horde_Queue 1.1.2 -> 1.1.3
security/pear-Horde_Secret 2.0.4 -> 2.0.5
www/pear-Horde_SessionHandler 2.2.4 -> 2.2.5
devel/pear-Horde_Token 2.0.6 -> 2.0.7
devel/horde-content 2.0.4 -> 2.0.5
ftp/horde-gollem 3.0.5 -> 3.0.6
www/horde-base 5.2.7 -> 5.2.8
mail/horde-imp 6.2.10 -> 6.2.11
mail/horde-ingo 3.2.6 -> 3.2.7
deskutils/horde-kronolith 4.2.9 -> 4.2.11
deskutils/horde-mnemo 4.2.7 -> 4.2.8
deskutils/horde-nag 4.2.5 -> 4.2.6
www/horde-passwd 5.0.3 -> 5.0.4
www/horde-trean 1.1.2 -> 1.1.3
mail/horde-turba 4.2.8 -> 4.2.10
mail/horde-webmail 5.2.10 -> 5.2.11
deskutils/horde-groupware 5.2.10 -> 5.2.11
2015-10-22 16:00:30 +00:00
Mathieu Arnold
89d49eb53f Fix build without POLARSSL.
Pointy hat to:	mat
Sponsored by:	Absolight
2015-10-22 14:07:10 +00:00
Kubilay Kocak
ce8374460e security/suricata: Update to 2.0.9
- Update PORTVERSION and distinfo checksum (2.0.9)

Changes:

  https://github.com/inliniac/suricata/blob/suricata-2.0.9/ChangeLog

While I'm here,

- Standardize the length of pkg-message separators and add spaces
  between them and the text body. <idea> It would be cool if the ports
  framework could wrap these pkg-message's in standard formatting for
  all ports automagically</idea>

Requested by:	Martin Olsson (via email)
2015-10-22 11:56:31 +00:00
Cy Schubert
898655c0cb Document October 2015 NTP Security Vulnerability Announcement (Medium) 2015-10-22 03:03:30 +00:00
Dan Langille
395599811e - Update to 2.9.7.6
Reviewed by: zi (maintainer)
Differential Revision: https://reviews.freebsd.org/D3963
2015-10-21 17:59:38 +00:00
Mathieu Arnold
4cb8340ae5 Update to 2.0-beta2.
- Bump PORTEPOCH as version goes backwards
- Remove unneeded variables
- Pet portlint

PR:		203913
Submitted by:	maintainer
Sponsored by:	Absolight
2015-10-21 14:16:25 +00:00
Mathieu Arnold
4597301bdf Update to 201541. [1]
Convert to options helpers.

PR:		203823 [1]
Submitted by:	maintainer
Sponsored by:	Absolight
2015-10-21 14:16:18 +00:00
Tijl Coosemans
fd89eecc7a Update to 4.1.8 2015-10-21 11:53:36 +00:00
Cy Schubert
fa0fbc575d Add sonames and minor versioned library names.
PR:             203882
2015-10-21 06:59:10 +00:00
Kubilay Kocak
d9484b7997 security/py-cryptography: Add enum43 to RUN_DEPENDS
Refactor *_DEPENDS to match setup.py's less than obvious dependencies

cffi is both a build/run dependency, the rest are only run dependencies.

This was causing a build failure for net-im/papyon:

  ImportError: No module named enum

Reported by:	kwm, pkg-fallout
Assisted by:	antoine
2015-10-20 15:14:08 +00:00
Mathieu Arnold
ca0156916b Use options helpers.
Sponsored by:	Absolight
2015-10-20 15:03:44 +00:00
Jason Unovitch
379ee526f4 Document multiple XSS vulnerabilities fixed in CodeIgniter
PR:		203403
Security:	https://vuxml.FreeBSD.org/freebsd/95602550-76cf-11e5-a2a1-002590263bf5.html
2015-10-20 02:33:47 +00:00
Sunpoet Po-Chuan Hsieh
2743e8d9cf - Add NO_ARCH
- While I'm here, use "yes" instead of "YES"

Approved by:	portmgr (blanket)
2015-10-19 20:22:29 +00:00
Sunpoet Po-Chuan Hsieh
5b9e9cd2dc - Use USES=localbase
- Pet portlint: fix diff header of patch files
2015-10-19 20:21:10 +00:00
Renato Botelho
b5f8054f06 Add new VuXML entry for git arbitrary code execution bug on versions before
2.6.1
2015-10-19 17:04:02 +00:00
Dmitry Marakasov
67971bd0fb Improve shebangfix framework
- Support multiple values in *_OLD_CMD, i.e. we can now fix both "/usr/bin/python" and "/usr/bin/env python" at the same time
- Default *_OLD_CMD values are now always appended, so you don't need to specify them in individual ports
- Add lua support (depends on USES=lua)
- Add more default values, such as "/usr/bin/env foo" for python, perl, bash, ruby and lua
- Shebangfix now matches whole words, e.g. we will no longer (erroneously) replace "/usr/bin/perl5.005" with "${perl_CMD}5.005" (but "/usr/bin/perl -tt" is still (correctly) replaced with "${perl_CMD} -tt")

Note that *_OLD_CMD items containing spaces must now be quoted (e.g. perl_OLD_CMD=/bin/perl /usr/bin/perl "/usr/bin/env perl")

Update shebangfix usage according to new rules in many ports:

- Remove *_OLD_CMD for patterns now replaced by default
- Quote custom *_OLD_CMD which contain spaces

Fix shebangfix usage in many ports (irrelevant to infrastructure change):

- Remove redundant SHEBANG_LANG (no need to duplicate default langs)
- Remove redundant *_CMD (such as python_CMD=${LOCALBASE}/bin/python${PYTHON_VER} when USES=python is present)
- Never use *_OLD_CMD in REINPLACE_CMD matchers, these should always look for exact string

Approved by:	portmgr (bapt)
Differential Revision:	D3756
2015-10-19 14:50:52 +00:00
Antoine Brodin
b49bc725a0 Finish removing yubikey-personalization 2015-10-19 13:59:03 +00:00
Ryan Steinmetz
e5c19fce71 - Update variable name in previous commit
- Bump PORTREVISION
2015-10-19 13:42:11 +00:00
Ryan Steinmetz
622c375809 - Add additional instances variable for puppet/chef/cfengine/etc use
- Bump PORTREVISION
2015-10-19 13:30:28 +00:00
Jimmy Olgeni
1ff7395d51 Upgrade security/elixir-comeonin to version 1.3.0. 2015-10-19 08:14:23 +00:00
Cy Schubert
ba44c33bf8 Bump PORTREVISION. 2015-10-19 07:29:08 +00:00
Cy Schubert
f43d2cea80 Fix READLINE option.
Add support for libedit (LIBEDIT option).
Both command line editing options now supported by RADIO button.

Fix typo in gssapi: bootstrap.
2015-10-19 07:17:47 +00:00
Cy Schubert
86da5965d8 Fix READLINE option.
Add support for libedit (LIBEDIT option).
Both command line editing options now supported by RADIO button.
2015-10-19 07:13:33 +00:00
Guido Falsi
2f90775268 - Update to 1.3.2
- Add QT4 and QT5 options, to choose toolkit.

PR:		203804
Submitted by:	Ports Fury
2015-10-18 13:41:15 +00:00
Romain Tartière
d4119bd942 Remove security/yubikey-personalization (duplicate of security/ykpers)
PR:		203835
Submitted by:	cmt@burggraben.net
2015-10-18 09:55:55 +00:00
Kubilay Kocak
8b7f69106a security/py-cryptography: Update to 1.0.2
- Update to 1.0.2
- Strip shared libraries
- Add patch to support building with LibreSSL
- Remove ALPN patch (upstreamed)

Changes:

  https://github.com/pyca/cryptography/blob/1.0.2/CHANGELOG.rst

PR:		203819
Submitted by:	Ralf van der Enden <tremere cainites net>
2015-10-18 03:13:53 +00:00
Sunpoet Po-Chuan Hsieh
d791a4add6 - Document Salt multiple vulnerabilities 2015-10-17 18:16:56 +00:00
Sunpoet Po-Chuan Hsieh
b8dd7bfcf0 - Update to 1.4.0
- Add LICENSE
- Add NO_ARCH
- Fix indent

Changes:	http://pear.php.net/package/Crypt_GPG/download/
2015-10-17 18:10:31 +00:00
Sunpoet Po-Chuan Hsieh
5943262277 - Add LICENSE_FILE
- Use USES=localbase
2015-10-17 18:08:22 +00:00
Romain Tartière
f35d4877c1 The YubiKey Personalization Tool is a Qt based Cross-Platform utility designed
to facilitate re-configuration of YubiKeys on Windows, Linux and Mac platforms.
The tool provides a same simple step-by-step approach to make configuration of
YubiKeys easy to follow and understand, while still being powerful enough to
exploit all functionality both of the YubiKey 1 and YubiKey 2 generation of
keys. The tool provides the same functionality and user interface on Windows,
Linux and Mac platforms.

The Cross-Platform YubiKey Personalization Tool provides the following main
functions:
  - Programming the YubiKey in "Yubico OTP" mode;
  - Programming the YubiKey in "OATH-HOTP" mode;
  - Programming the YubiKey in "Static Password" mode;
  - Programming the YubiKey in "Challenge-Response" mode;
  - Programming the NDEF feature of the YubiKey NEO;
  - Testing the challenge-response functionality of a YubiKey;
  - Deleting the configuration of a YubiKey;
  - Checking type and firmware version of the YubiKey.

WWW: https://github.com/Yubico/yubikey-personalization-gui
2015-10-17 12:59:34 +00:00
Romain Tartière
4e001bf384 The YubiKey Personalization package contains a library and command line tool
used to personalize (i.e., set a AES key) YubiKeys.

WWW: https://github.com/Yubico/yubikey-personalization
2015-10-17 12:58:50 +00:00
Steve Wills
f880925a41 Document CVE-2015-7184 in firefox 2015-10-16 18:57:28 +00:00
Steve Wills
dcfa462ca6 security/quantis: fix build with OpenJDK8
PR:		203513
Approved by:	maintainer timeout (ale, >2 weeks)
2015-10-16 18:17:58 +00:00
Koop Mast
82f203006a Document flash 0-day, remove code execution.
Security:	CVE-2015-7645, CVE-2015-7647, CVE-2015-7648
2015-10-16 16:11:19 +00:00
Kubilay Kocak
91364fbc63 security/fwknop: Update to 2.6.7
* Update to 2.6.7
* Update and sort pkg-plist
* Group/sort sections
* Convert to OPTIONS helpers
* Use install-strip target so binaries/libraries are stripped

PR:		203168
Submitted by:	Sean Greven <sean.greven gmail com> (maintainer)
2015-10-16 12:25:21 +00:00
Peter Wemm
e4482bc1e2 Fix the vuxml build caused by a multitude of errors in r399425 (libressl). 2015-10-16 07:44:55 +00:00
Bernard Spil
3dba139b7a security/libressl: Fix memory leak and buffer overflow DoS vulnerability
* Update to 2.2.4 (fixing vulnerabilities)
  * Create vuxml entry

Differential Revision: https://reviews.freebsd.org/D3916
Submitted by:	Bernard Spil <brnrd@freebsd.org>
Reviewed by:	delphij
Approved by:	delphij (secteam)
MFC after:	2015Q4
Security:	e75a96df-73ca-11e5-9b45-b499baebfeaf
Security:	CVE-2015-5333, CVE-2015-5334
2015-10-16 07:13:03 +00:00
Bernard Spil
eac75ec131 security/libressl: Fix memory leak and buffer overflow DoS vulnerability
* Update to 2.2.4 (fixing vulnerabilities)
  * Create vuxml entry

Differential revision: https://reviews.freebsd.org/D3916
Submitted by:	Bernard Spil <brnrd@freebsd.org>
Reviewed by:	delphij (secteam)
Approved by:	delphij
MFC after:	2015Q4
Security:	CVE-2015-5333, CVE-2015-533
2015-10-16 07:08:40 +00:00
Dmitry Marakasov
bf3bcf82ea - Handle permissions in plist
- Unsilence install

Approved by:	portmgr blanket
2015-10-15 21:00:20 +00:00
Sunpoet Po-Chuan Hsieh
41b5b48741 - Add LICENSE_FILE
- Move LICENSE upward
- Add NO_ARCH

Approved by:	portmgr (blanket)
2015-10-15 20:18:56 +00:00
Sunpoet Po-Chuan Hsieh
edd8a382b7 - Update to 0.19
Changes:	http://search.cpan.org/dist/IO-Async-SSL/Changes
2015-10-15 20:17:32 +00:00
Tijl Coosemans
fe28aa632f Security update to 2.1.2
MFH:		2015Q4
Security:	07a1a76c-734b-11e5-ae81-14dae9d210b8
Security:	CVE-2015-5291
2015-10-15 15:26:33 +00:00
Tijl Coosemans
98688b18e1 Security update to 1.3.14
MFH:		2015Q4
Security:	07a1a76c-734b-11e5-ae81-14dae9d210b8
Security:	CVE-2015-5291
2015-10-15 15:25:32 +00:00
Mathieu Arnold
7f0f664d7e Drop 8 support.
With hat:	portmgr
Sponsored by:	Absolight
Differential Revision:	https://reviews.freebsd.org/D3694
2015-10-15 14:55:14 +00:00
Mark Felder
b3175cfda7 security/polarssl: Update to 1.2.17
Changelog:	https://tls.mbed.org/tech-updates/releases/mbedtls-2.1.2-and-1.3.14-and-polarssl-1.2.17-released

Security:	07a1a76c-734b-11e5-ae81-14dae9d210b8
Security:	CVE-2015-5291
2015-10-15 14:51:05 +00:00
Mark Felder
1fdbc58c42 Document vulnerability in polarssl, polarssl13, and mbedtls
Security:	CVE-2015-5291
2015-10-15 14:48:51 +00:00
Lev A. Serebryakov
3535651a1b Update devel/subversion to 1.9.2.
PR:		203713
Submitted by:	Peter Wemm <peter@FreeBSD.org>
2015-10-15 10:43:15 +00:00
Jason Unovitch
086688b059 Document multiple vulnerabilities in the Magento platform
While here, update an older entry to reflect Magento was vulnerable

PR:		201709
Security:	https://vuxml.FreeBSD.org/freebsd/ea1d2530-72ce-11e5-a2a1-002590263bf5.html
Security:	https://vuxml.FreeBSD.org/freebsd/ec34d0c2-1799-11e2-b4ab-000c29033c32.html
Security:	CVE-2012-3363
2015-10-14 23:59:01 +00:00
Dmitry Marakasov
a311f3e214 - Drop 8.x support
- Add LICENSE

Approved by:	portmgr blanket
2015-10-14 23:52:30 +00:00
Dmitry Marakasov
6000b270e0 - Add LICENSE_FILE
- Regenerate patches with `make makepatch`
2015-10-14 23:51:30 +00:00
Jan Beich
6286222db5 net/miniupnpc: improve TALOS-2015-0035 entry in VuXML
- Add "reserved" CVE link
- Adjust version range to include a few previous snapshots
  and different fix in /branches/2015Q4

PR:		203705
2015-10-14 19:02:28 +00:00
Kurt Jaeger
a1b9350920 security/binwalk: 2.0.1 -> 2.0.2 (or so)
- old version did not work
- current github head does work (tested)
- new from head sees itself as 2.1.0, but not yet released, so...

PR:		203774
Requested by:	emaste
2015-10-14 18:12:58 +00:00
Jan Beich
899edfd9f7 net/miniupnpc: reference TALOS-2015-0035 fix
It maybe easier to backport to the quaterly branch than the development
snapshot that caused fallout in most consumers.

PR:		203705
2015-10-14 17:05:18 +00:00
Mark Felder
7d0ce5c47b Document www/pear-twig remote code execution
Security:	CVE-2015-7809
2015-10-14 16:53:25 +00:00
Mark Felder
41d6fa567f Document assigned CVE for graphics/optipng
Security:	CVE-2015-7801
2015-10-14 16:47:15 +00:00
Mark Felder
52ef750fc0 net/miniupnpc: Document buffer overflow
PR:		203705
Security:	TALOS-2015-0035
2015-10-14 16:21:20 +00:00
Koop Mast
34794030bd Document latest flash vulnabilities.
Security:	CVE-2015-5569, CVE-2015-7625, CVE-2015-7626, CVE-2015-7627,
		CVE-2015-7628, CVE-2015-7629, CVE-2015-7630, CVE-2015-7631,
		CVE-2015-7632, CVE-2015-7633, CVE-2015-7634, CVE-2015-7643,
		CVE-2015-7644
2015-10-14 12:21:59 +00:00
Frederic Culot
1d0b9d3e31 - Reassign lippe@'s ports after his commit bit was taken in for safekeeping 2015-10-14 11:04:10 +00:00
Cy Schubert
1e0fd5f376 Replace HEIMDAL option with HEIMDAL_PORTS and HEIMDAL_BASE. 2015-10-14 03:46:52 +00:00
Cy Schubert
96f80c1899 Update 4.6 --> 4.7 2015-10-14 03:44:52 +00:00
Rene Ladan
46a3cede8a Forgot two vulnerabilities in the previous commit. 2015-10-13 19:31:43 +00:00
Rene Ladan
5a62cc722a Document new vulnerabilities in www/chromium < 46.0.2490.71
Obtained from:	http://googlechromereleases.blogspot.nl/2015/10/stable-channel-update.html
2015-10-13 19:28:44 +00:00
Kurt Jaeger
86cadbb07d security/py-acme: 0.0.b1 -> 0.0.0.dev20151008
Changes: For now, see
	https://github.com/letsencrypt/letsencrypt/commits/master

PR:		203405
2015-10-13 19:12:17 +00:00
Mark Felder
cb8c677412 security/sshgaurd: Update to 1.6.2
* Remove recommendation of using syslog pipes
* IPFW support has been rewritten and entries now are added to table 22

PR:		203452
2015-10-13 01:14:26 +00:00
Jason Unovitch
b22b3543a4 Add CVE assignment to r398701 Zend Framework 1 entry
PR:		203462
Security:	CVE-2015-7695
Security:	https://vuxml.FreeBSD.org/freebsd/d3324fdb-6bf0-11e5-bc5e-00505699053e.html
2015-10-12 14:19:25 +00:00
Jason Unovitch
f1813f99c1 Add CVE assignment to r398626 PHP entry
PR:		203541
Security:	CVE-2015-7804
Security: 	CVE-2015-7803
Security: 	https://vuxml.FreeBSD.org/freebsd/c1da8b75-6aef-11e5-9909-002590263bf5.html
2015-10-12 14:11:12 +00:00
John Marino
16f7d87a0d security/wpa_supplicant: Upgrade version 2.4 => 2.5 2015-10-11 22:52:59 +00:00
Dmitry Marakasov
3b49e4c544 - Switch to options helpers
- Drop 8.x support

Approved by:	portmgr blanket
2015-10-11 15:13:52 +00:00
Ryan Steinmetz
8bbd9b2d43 - Reset MAINTAINER due to fatal bounce
Reported by:	portscout
2015-10-11 13:19:10 +00:00
Alex Kozlov
93d153234f - Pass maintainership to submitter
Submitted by:	Piotr Kubaj <pkubaj@riseup.net>
2015-10-11 12:02:38 +00:00
Alex Kozlov
6d78fb007a - Update to 2015.68 [1]
- Drop maintainership

PR:	203694 [1]
Submitted by:	pkubaj@riseup.net
2015-10-11 11:42:27 +00:00
Sunpoet Po-Chuan Hsieh
0d5efed076 - Update to 0.11
- Add LICENSE
- Strip shared library
- Sort PLIST

Changes:	http://search.cpan.org/dist/Crypt-OpenSSL-Random/Changes
2015-10-10 23:11:48 +00:00
Sunpoet Po-Chuan Hsieh
504dd069ea - Add rubygem-sshkey 1.7.0
SSHKey generates private and public SSH keys (RSA and DSA supported) using pure
Ruby.

WWW: https://github.com/bensie/sshkey
2015-10-10 23:11:03 +00:00
Jason Unovitch
4229f5003d Document shell command execution via improper escaping in p5-UI-Dialog
PR:		203667
Security:	CVE-2008-7315
Security:	https://vuxml.FreeBSD.org/freebsd/00dadbf0-6f61-11e5-a2a1-002590263bf5.html
2015-10-10 15:27:11 +00:00
Jason Unovitch
dcbe0f47eb Document iPython vulnerabilities fixed in 3.2.2
PR:		203668
Security:	CVE-2015-6938
Security:	CVE-2015-7337
Security:	https://vuxml.FreeBSD.org/freebsd/290351c9-6f5c-11e5-a2a1-002590263bf5.html
2015-10-10 15:01:54 +00:00
Hajimu UMEMOTO
a7dcb78228 - Use USES=gssapi.
- OPTIONSfy Kerberos.
2015-10-09 14:35:09 +00:00
Hajimu UMEMOTO
14e92b7732 Fix build with clang and MIT Kerberos.
Reported by:	Beat Siegenthaler <beat.siegenthaler__at__beatsnet.com>
2015-10-09 14:22:37 +00:00
Tijl Coosemans
c4e12a20bf New port: security/esteidfirefoxplugin
A Firefox plugin that enables in-browser digital signing with Estonian ID
cards.

PR:		194300
Submitted by:	toomas.aas@raad.tartu.ee
Reviewed by:	marino
2015-10-09 09:06:16 +00:00
Palle Girgensohn
ea97aed20c Add entry for two security problems in PostgreSQL
CVE-2015-5289: json or jsonb input values constructed from arbitrary
user input can crash the PostgreSQL server and cause a denial of
service.

CVE-2015-5288: The crypt() function included with the optional pgCrypto
extension could be exploited to read a few additional bytes of memory.
No working exploit for this issue has been developed.
2015-10-08 21:18:53 +00:00
Antoine Brodin
55f070c203 Unbreak INDEX 2015-10-08 19:52:00 +00:00
Bernard Spil
8af8503214 security/stunnel: Update to 5.24
- Supports building without EGD
  - Order options alphabetical

Reviewed by:	koobs (mentor), zi (maintainer)
Approved by:	zi (maintainer)
PR:	198997
Differential Revision:	https://reviews.freebsd.org/D2694
2015-10-08 19:38:53 +00:00
Jimmy Olgeni
eb8748beda Remove trailing whitespace from Makefiles, M-X. 2015-10-08 15:12:22 +00:00
Dmitry Marakasov
efe60d6b89 - Move file owner handling to plist, fix stage as non-root
PR:		203287
Submitted by:	amdmi3
Approved by:	maintainer timeout (ek@purplehat.org, 2 weeks)
2015-10-08 13:19:42 +00:00
Dmitry Marakasov
63d66740c9 - Optionize DOCS
Approved by:	kwm
2015-10-07 18:04:03 +00:00
Emanuel Haupt
f0a121e8c4 Update to 0.16 2015-10-07 12:22:33 +00:00
Dag-Erling Smørgrav
b43a2bc820 r398691 placed the patch in the wrong directory, where it had no effect.
Move it to the master port and bump the subport again.

Reviewed by:	ume@
2015-10-07 07:19:26 +00:00
William Grzybowski
bb9f4237d7 security/vuxml: Document Zend Framework 1 vulnerability
PR:		203462
Security:	d3324fdb-6bf0-11e5-bc5e-00505699053e
Security:	CVE-2014-8089
2015-10-06 15:02:38 +00:00
Dag-Erling Smørgrav
a428eb2978 Silence debugging message.
Approved by:	maintainer silence
2015-10-06 08:55:46 +00:00
Jason Unovitch
e9f4ccdda9 Document OpenSMTPD vulnerabilities (5.7.3)
Revise pkg name, add PORTEPOCH, add more detail to earlier entry (5.7.2)

Security:	42852f72-6bd3-11e5-9909-002590263bf5
Security:	ee7bdf7f-11bb-4eea-b054-c692ab848c20
Security:	CVE-2015-7687
2015-10-06 02:54:49 +00:00
Jason Unovitch
b695e42b60 Document recent mbed TLS/PolarSSL security releases
PR:		203544
Security:	5d280761-6bcf-11e5-9909-002590263bf5
Security:	953aaa57-6bce-11e5-9909-002590263bf5
2015-10-06 02:24:46 +00:00
Koop Mast
dc0f431bb0 GNOME 3 expects pinentry to have libsecret support. so instead of offering
a options change always build it with libsecret support.

Approved by:	maintainer (implicit)
2015-10-05 20:18:23 +00:00
Steve Wills
1e96f2755d security/vault: update to 0.3.0, add LICENSE
PR:		203548
Submitted by:	Dave Cottlehuber <dch@skunkwerks.at>
2015-10-05 18:58:12 +00:00
Vanilla I. Shu
45e99b72eb define DOCSDIR to avoid file conflict with security/erlang-jose. 2015-10-05 15:13:09 +00:00
Vanilla I. Shu
e2680f5b78 define DOCDIRS to avoid file conflict with security/elixir-jose. 2015-10-05 15:11:35 +00:00
Dmitry Marakasov
d33a1b4d3b - Regenerate python bytecode to fix references to stagedir
- Remove USES=desktop-file-utils as suggested by stage-qa
- Add NO_ARCH

Approved by:	portmgr blanket
2015-10-05 13:19:44 +00:00
Koop Mast
b62752ffb6 Unbreak vuxml, woops. 2015-10-05 11:56:43 +00:00
Koop Mast
cdc4fb8019 Document heap overflows and a DoS in gdk-pixbuf2.
Security:	CVE-2015-7673, CVE-2015-7674
2015-10-05 11:46:56 +00:00
Tijl Coosemans
54605fdfbd Update to 2.1.1
PR:		203546
Submitted by:	takefu@airport.fm
MFH:		2015Q4
Security:	https://tls.mbed.org/tech-updates/releases/mbedtls-2.1.1-and-1.3.13-and-polarssl-1.2.16-released
2015-10-05 09:13:58 +00:00
Tijl Coosemans
faf3c23c3c - Update to 1.3.13
- Take maintainership

PR:		203545
Submitted by:	takefu@airport.fm
MFH:		2015Q4
Security:	https://tls.mbed.org/tech-updates/releases/polarssl-1.2.15-and-mbedtls-1.3.12-released
Security:	https://tls.mbed.org/tech-updates/releases/mbedtls-2.1.1-and-1.3.13-and-polarssl-1.2.16-released
2015-10-05 09:11:45 +00:00
Jason Unovitch
e8566ce038 Document 20150910 Plone advisories
PR:		203255
Security:	6b3374d4-6b0b-11e5-9909-002590263bf5
2015-10-05 03:09:24 +00:00
Jason Unovitch
0b27f0b023 Document PHP multiple security advisories in phar plugin
PR:		203541
Security:	c1da8b75-6aef-11e5-9909-002590263bf5
2015-10-05 00:00:11 +00:00
Jason Unovitch
323aa15dc7 Add CVE reference to Apache James entry
PR:		203461
Security:	CVE-2015-7611
Security:	be3069c9-67e7-11e5-9909-002590263bf5
2015-10-04 21:27:55 +00:00
Sunpoet Po-Chuan Hsieh
5c0a38f92e - Convert to new options target helper
Approved by:	portmgr (blanket)
2015-10-04 18:01:34 +00:00
Steve Wills
2d9053c65d Document mail/opensmtpd vulnerability 2015-10-04 14:23:03 +00:00
Sunpoet Po-Chuan Hsieh
2eed519680 - Add NO_ARCH 2015-10-03 17:12:02 +00:00
Sunpoet Po-Chuan Hsieh
efff28dc5b - Add NO_ARCH 2015-10-03 17:11:57 +00:00
Sunpoet Po-Chuan Hsieh
7bb252677f - Add NO_ARCH 2015-10-03 17:11:53 +00:00
Sunpoet Po-Chuan Hsieh
4dab170ebe - Add NO_ARCH 2015-10-03 17:11:49 +00:00
Sunpoet Po-Chuan Hsieh
c12f71e706 - Add NO_ARCH 2015-10-03 17:11:45 +00:00
Sunpoet Po-Chuan Hsieh
38598eb703 - Add NO_ARCH 2015-10-03 17:11:40 +00:00
Sunpoet Po-Chuan Hsieh
9630e1ea3b - Update to 2.0.1
- Add LICENSE_FILE

Changes:	https://github.com/tinfoil/devise-two-factor/commits/master
2015-10-03 17:10:51 +00:00
Rodrigo Osorio
79bc9b413e Upgrade TOR port to 0.2.6.10
PR:		201540
Submitted by:	Neel Chauhan <neel@neelc.org>
Approved by:	bf@ (maintainer)
2015-10-03 07:32:41 +00:00
Dmitry Marakasov
bc79ec9140 - Add empty directory to plist
- Drop @dirrm* from plist

Approved by:	portmgr blanket
2015-10-02 11:19:22 +00:00
Mathieu Arnold
7f5ef38c3f Backout r398328 and r398370, they break packages depending on them.
With hat:	portmgr
MFH:		2015Q4
Sponsored by:	Absolight, The FreeBSD Foundation
2015-10-02 10:41:09 +00:00
Vanilla I. Shu
55ebba7bbd Move 'elirix-' to PKGNAMEPREFIX to make portlint happy. 2015-10-02 02:40:31 +00:00
Vanilla I. Shu
24e2752adc Move 'erlang-' to PKGNAMEPREFIX. 2015-10-02 02:39:57 +00:00
Hajimu UMEMOTO
f571a16345 Use SUB_FILES. 2015-10-01 17:08:36 +00:00
Hajimu UMEMOTO
d4d22ea900 Fix DOCSDIR. 2015-10-01 16:52:45 +00:00
Hajimu UMEMOTO
d2c500d787 Sync package name with origin.
PR:		202756
2015-10-01 15:58:07 +00:00
Jason Unovitch
48375c0b2a Document security advisory for the Apache James server
PR:		203461
Security:	be3069c9-67e7-11e5-9909-002590263bf5
2015-10-01 03:14:14 +00:00
Dmitry Marakasov
33ad4e44e4 - Convert pkg-install script to @dir
- Use options helpers
- Remove unneeded @dir's from plist

PR:		203045
Submitted by:	amdmi3
Approved by:	maintainer timeout (gabor, 2 weeks)
2015-09-30 18:31:32 +00:00
Carlo Strub
f4b1502edf Report OTRS vulnerability
Security:	CVE-2015-6842, CVE-2013-7135
2015-09-30 06:18:37 +00:00
Vanilla I. Shu
de804b218e Add elixir-jose. 2015-09-29 13:30:49 +00:00
Vanilla I. Shu
8a7c423ef2 Fix RUN_DEPENDS. 2015-09-29 12:48:39 +00:00
Vanilla I. Shu
1f0e322af4 add erlang-jose. 2015-09-29 12:15:47 +00:00
Jimmy Olgeni
e80d2fc541 Upgrade security/elixir-comeonin to version 1.2.2. 2015-09-29 03:39:42 +00:00
Ruslan Makhmatkhanov
ce9699179a security/py-flask-httpauth: update to 2.7.0 2015-09-28 18:24:34 +00:00
Jimmy Olgeni
864dd06a77 Upgrade security/elixir-comeonin to version 1.2.1. 2015-09-28 15:41:19 +00:00
Martin Matuska
58376c0f6d Horde package update:
comms/pear-Horde_ActiveSync 2.28.6 -> 2.29.2
devel/pear-Horde_Core 2.20.8 -> 2.22.0
security/pear-Horde_Crypt 2.6.0 -> 2.6.1
graphics/pear-Horde_Image 2.3.2 -> 2.3.3
mail/pear-Horde_Imap_Client 2.29.1 -> 2.29.3
mail/pear-Horde_Mime 2.9.1 -> 2.9.2
2015-09-28 13:45:10 +00:00
Koop Mast
e04f8d76fe Document newest flash vulnabilities. 2015-09-28 09:29:05 +00:00
Kubilay Kocak
ab6c592026 security/suricata: Disable -march=native
Suricata currently builds with GCC -march=native by default.

This can create problems if, for example, packages of this port are
built on ATOM servers but installed on AMD processors. In these and
other cases where the build host is not equal to the target host,
suricata can generate an Illegal instruction and refuse
to start.

It is ultimately preferable to explicitly cross-build and/or optimize
compilation for target architectures and processors. See: PEP20.

PR:		203296
Submitted by:	Olivier Cochard <olivier cochard me>
Tested by:	Olivier Cochard <olivier cochard me>
MFH:		2015Q3
2015-09-28 08:25:44 +00:00
Sunpoet Po-Chuan Hsieh
1a32af02ec - Add LICENSE_FILE 2015-09-28 06:20:36 +00:00
Jason Unovitch
76d899e7d9 Fix <freebsdpr> syntax on several entries
Without ports/ prepended to the PR number, the http://www.vuxml.org links
go to https://bugs.FreeBSD.org and not the actual PR.

While here, "trongSwan" -> "StrongSwan" spelling correction

PR:		200777
2015-09-28 02:54:41 +00:00
Jason Unovitch
aebbbabec4 Document multiple vulnerabilities in CodeIgniter
PR:		203401
Security:	5114cd11-6571-11e5-9909-002590263bf5
Security:	01bce4c6-6571-11e5-9909-002590263bf5
Security:	c21f4e61-6570-11e5-9909-002590263bf5
Security:	f838dcb4-656f-11e5-9909-002590263bf5
Security:	b7d785ea-656d-11e5-9909-002590263bf5
2015-09-28 01:09:11 +00:00
Dmitry Marakasov
90d5e0a5d8 - Switch to @sample 2015-09-27 22:33:21 +00:00
Olli Hauer
e48f1b3666 - update to 6.49BETA5
- use DOCS instead PORTDOCS
- remove gcc workaround [1]
- (hopefully) use the correct __FreeBSD_version for SOCK_RAW

Changelog:
https://nmap.org/changelog.html

PR:		196065 [1]
PR:		200558 [2]
PR:		202139 [3]

Submitted by:	sbruno@ , mikael.urankar@gmail.com [1]
Submitted by:	truckman@ [2]
Submitted by:	trasz@ [3]
2015-09-27 10:32:29 +00:00
Rene Ladan
9ca5987077 Document new vulnerabilities in www/chromium < 45.0.2454.101
Obtained from:	http://googlechromereleases.blogspot.nl/2015/09/stable-channel-update_24.html
2015-09-27 08:38:32 +00:00
Kurt Jaeger
5ae0e54915 security/py-acme: simplify WRKSRC
PR:		203364
Submitted by:	mat
2015-09-27 08:31:28 +00:00
Antoine Brodin
a5ad8641b4 - Convert to @sample
- Cleanup plist
2015-09-26 21:02:09 +00:00
Mark Linimon
144bbb306f Mark as broken on sparc64: fails to link.
Approved by:	portmgr (sparc64 blanket)
2015-09-26 16:56:32 +00:00
Koop Mast
7b97259096 Update gstreamer1 ports to 1.6.0.
* gstreamer1-libav now uses ffmpeg from ports.
* New ports:
  * gstreamer1-validate: Tools to detect if elements are not behaving
    as expected, mainly aimed at developers, or advanced debugging.
  * gstreamer1-rtsp-server: Base foundation for building a rtsp
    server ontop of GStreamer
 * Bunch of new plugins like: mpg123, rsvg, libde265, openh264, x265 and dtls.

Release announcement:
  http://lists.freedesktop.org/archives/gstreamer-announce/2015-September/000357.html

Obtained from:	gnome devel repo
2015-09-26 14:36:23 +00:00
Kurt Jaeger
78cfb29cbd security/py-acme: add PYTHON_PKGNAMEPREFIX
PR:		203364
Pointy hat to:	pi
2015-09-26 12:46:39 +00:00
Kurt Jaeger
75a44b60a1 New port: security/py-acme
Implements the Automated Certificate Management Environment (ACME)

WWW: https://github.com/letsencrypt/letsencrypt/tree/master/acme

PR:		203364
Submitted by:	Carlos J Puga Medina <cpm@fbsd.es>, pi
2015-09-26 12:37:43 +00:00
Antoine Brodin
89a6caf641 Remove @exec/@unexec redundant with USES=desktop-file-utils 2015-09-26 09:17:40 +00:00
Jimmy Olgeni
43bc8abccf Upgrade security/elixir-comeonin to version 1.2.0. 2015-09-26 07:58:17 +00:00
Baptiste Daroussin
460ab80d2a Replace plist entries with proper USES 2015-09-26 00:35:41 +00:00
Mark Linimon
bd0822160f Mark as broken on sparc64: these ports fail to link with boost.
Approved by:	portmgr (sparc64 blanket)
2015-09-25 22:00:40 +00:00