Commit graph

561116 commits

Author SHA1 Message Date
Jan Beich
465a1177ab net/wayvnc: update to 0.4.1
Changes:	https://github.com/any1/wayvnc/releases/tag/v0.4.1
Reported by:	GitHub (watch releases)

(cherry picked from commit c7dbfbd90d)
2021-12-17 04:02:30 +00:00
Jan Beich
4c3fced875 www/youtube_dl: update to 2021.12.17
Changes:	https://github.com/ytdl-org/youtube-dl/releases/tag/2021.12.17
Reported by:	GitHub (watch releases)

(cherry picked from commit 347de090b9)
2021-12-17 04:02:30 +00:00
Matthias Fechner
44e1143696 textproc/apache-solr: security update to 8.11.1
Updates bundled log4j2 dependencies to address CVE-2021-44228 (SOLR-15843)
Upgrade jaegertracing to 1.6.0 and libthrift to 0.14.1 to address CVE-2020-13949 (SOLR-15324)

Changelog:
https://cwiki.apache.org/confluence/display/SOLR/ReleaseNote8_11_1

PR:		260373
MFH:		2021Q4
Security:	66cf7c43-5be3-11ec-a587-001b217b3468
(cherry picked from commit bbfc927ee0)
2021-12-16 23:54:44 +01:00
Juraj Lutter
108a7ce68e net-mgmt/unifi6: Update to 6.5.55
This is a security release, bundling the latest log4j library.

Release notes: https://community.ui.com/releases/r/network/6.5.55

(cherry picked from commit b5068e3392)
2021-12-16 17:19:02 +01:00
Christoph Moench-Tegeder
37dcf180ca www/firefox-esr: update to 91.4.1
Release Notes (soon):
  https://www.mozilla.org/en-US/firefox/91.4.1/releasenotes/

(cherry picked from commit e5ff61315b)
2021-12-16 14:33:25 +01:00
Christoph Moench-Tegeder
107e16bf4c www/firefox: update to 95.0.1
Release Notes (soon):
  https://www.mozilla.org/en-US/firefox/95.0.1/releasenotes/

(cherry picked from commit 01ec19a5fd)
2021-12-16 14:09:47 +01:00
Kyle Evans
dde2a8ee71 games/gzdoom: bump PORTREVISION after 446e0f2e6c
Pointy hat:	kevans
2021-12-15 23:46:12 -06:00
Kyle Evans
446e0f2e6c games/gzdoom: fix wildmidi crash
get_patch_data() may recurse on itself, which is not OK to do while
using std::lock_guard<>.  Move the contents of get_patch_data() to a
get_patch_data_locked() that may recurse on itself.

This is a direct commit to quarterly, as this has since been fixed by
the version present in main.  Specifically, a later refactoring ends up
dropping the patch_lock entirely after get_patch_data() and friends are
pushed into an Instruments class anyways.

Based on triage work and an initial patch by wpaul@.
2021-12-15 23:40:55 -06:00
Daniel O'Connor
0a7ee2e927
sysutils/pefs-kmod: Add aarch64 to the list of supported architectures
PR:		260463
(cherry picked from commit 39829be244)
2021-12-16 09:03:25 +07:00
Jan Beich
24eccd506b emulators/rpcs3: update to 0.0.19.13104
Changes:	2f93df480...43b7d1fe9
(cherry picked from commit 314e01781b)
2021-12-16 00:32:34 +00:00
Jan Beich
31301a26ed x11-servers/xwayland-devel: update to 21.0.99.1.149
Changes:	d189102c7...6c1a1fcc4
(cherry picked from commit 58f041b842)
2021-12-15 21:46:36 +03:00
Jan Beich
1765f0ae85 x11-servers/xwayland-devel: unbreak fetch due to repo shrink
fetch: https://github.com/freedesktop/xorg-xserver/commit/42e34498f87a.patch: size mismatch: expected 10310, actual 10298

-index 37c39497c3..f0f9d748aa 100644
+index 37c39497c..f0f9d748a 100644
-index 0000000000..1668dda570
+index 000000000..1668dda57
-index 0000000000..be8fb39d92
+index 000000000..be8fb39d9
-index b249dbb083..ddf6336565 100644
+index b249dbb08..ddf633656 100644
-index f04d431c74..e1e610f87d 100644
+index f04d431c7..e1e610f87 100644
-index 21587dbb64..7a02515044 100644
+index 21587dbb6..7a0251504 100644
-index 16c13fb64e..508294c6c6 100644
+index 16c13fb64..508294c6c 100644
-index 672647f713..bb0a71f8db 100644
+index 672647f71..bb0a71f8d 100644
-index d2fa4e0bb2..9c3ab32d2a 100644
+index d2fa4e0bb..9c3ab32d2 100644
-index 74a46994fe..919a227680 100644
+index 74a46994f..919a22768 100644
-index ddf6336565..3dd8446b31 100644
+index ddf633656..3dd8446b3 100644
-index e1e610f87d..594140301f 100644
+index e1e610f87..594140301 100644
-index 00f161eda0..1b2487c077 100644
+index 00f161eda..1b2487c07 100644
-index 508294c6c6..a88a3d3116 100644
+index 508294c6c..a88a3d311 100644
-index 69c02dce42..6a06708924 100644
+index 69c02dce4..6a0670892 100644
-index 1b2487c077..ed3903853f 100644
+index 1b2487c07..ed3903853 100644

(cherry picked from commit 4055fc841f)
2021-12-15 21:46:35 +03:00
Jan Beich
5506c30b63 x11-servers/xwayland-devel: update to 21.0.99.1.143
Changes:	089e7f98f...d189102c7
(cherry picked from commit 38afa36fcb)
2021-12-15 21:46:35 +03:00
Jan Beich
1d5fa1a815 x11-servers/xwayland-devel: update to 21.0.99.1.142
Changes:	0146fd6d3...089e7f98f
(cherry picked from commit 2f71913be4)
2021-12-15 21:46:35 +03:00
Jan Beich
42273dfcd6 x11-servers/xwayland-devel: update to 21.0.99.1.136
Changes:	04c93b98e...0146fd6d3
(cherry picked from commit 0207e5a408)
2021-12-15 21:46:35 +03:00
Jan Beich
2d2c722d14 x11-servers/xwayland-devel: update to 21.0.99.1.133
Changes:	80eeff3eb...04c93b98e
(cherry picked from commit d684832c1a)
2021-12-15 21:46:35 +03:00
Jan Beich
dc70366390 devel/sdl12-compat: update to s20211214
Changes:	8743305...8f54fd8
(cherry picked from commit f3127bd16f)
2021-12-15 18:43:43 +00:00
Jan Beich
7c2c2c0b9a x11/swaync: update to s20211214
Changes:	75894f5...f0c3918
(cherry picked from commit 5d56a8c6b6)
2021-12-15 18:43:43 +00:00
Jan Beich
4c50eda2cc games/openra: update IP2Location LITE to October snapshot
(cherry picked from commit 9505d5d44f)
2021-12-15 18:43:30 +00:00
Jan Beich
05735c1f46 games/openra: unbreak fetch due to repo shrink
fetch: https://github.com/openra/OpenRA/commit/e13fd693c386.patch: size mismatch: expected 71620, actual 71562

This reverts commit d5ecb8f8af.

(cherry picked from commit 8e8ef5a07c)
2021-12-15 18:43:29 +00:00
Jan Beich
1128782f31 games/openbor*: unbreak fetch due to repo shrink
fetch: https://github.com/DCurrent/openbor/commit/794ba23189a3.patch: size mismatch: expected 1278, actual 1276
fetch: https://github.com/DCurrent/openbor/commit/731d96887795.patch: size mismatch: expected 1293, actual 1291

This reverts commit aab0ad0d4a.

(cherry picked from commit dda2183658)
2021-12-15 18:43:29 +00:00
Mathieu Arnold
ea81d41cfb
dns/bind916: fix runnaway memory leak
Obtained from:	https://gitlab.isc.org/isc-projects/bind9/-/merge_requests/5626

(cherry picked from commit 925b730fbf)
2021-12-15 17:02:39 +01:00
Mathieu Arnold
f1581521a0
dns/bind916: update to 9.16.24
(cherry picked from commit 0090b81b1f)
2021-12-15 17:02:31 +01:00
Mathieu Arnold
9bc7725a63
dns/bind916: update to 9.16.23
Changes:	https://downloads.isc.org/isc/bind9/9.16.23/doc/arm/html/notes.html#notes-for-bind-9-16-23
(cherry picked from commit 72c2245218)
2021-12-15 17:02:22 +01:00
Fabian Keil
62a44ce069 www/privoxy: Update to 3.0.33 stable
This update fixes a couple of security issues. Quoting the ChangeLog:

    - Security/Reliability:
      - cgi_error_no_template(): Encode the template name to prevent
        XSS (cross-side scripting) when Privoxy is configured to servce
        the user-manual itself.
        Commit 0e668e9409c. OVE-20211102-0001. CVE-2021-44543.
        Reported by: Artem Ivanov
      - get_url_spec_param(): Free memory of compiled pattern spec
        before bailing.
        Reported by Joshua Rogers (Opera) who also provided the fix.
        Commit 652b4b7cb0. OVE-20211201-0003. CVE-2021-44540.
      - process_encrypted_request_headers(): Free header memory when
        failing to get the request destination.
        Reported by Joshua Rogers (Opera) who also provided the fix.
        Commit 0509c58045. OVE-20211201-0002. CVE-2021-44541.
      - send_http_request(): Prevent memory leaks when handling errors
        Reported by Joshua Rogers (Opera) who also provided the fix.
        Commit c48d1d6d08. OVE-20211201-0001. CVE-2021-44542.

The complete list of changes is available at:
https://lists.privoxy.org/pipermail/privoxy-announce/2021-December/000009.html

PR:		260290
MFH:		2021Q4
Security:	897e1962-5d5a-11ec-a3ed-040e3c3cf7e7
(cherry picked from commit dec093e215)
2021-12-14 20:04:55 -08:00
Kirill Ponomarev
de8b1d4f6c sysutils/cbsd: Update to 13.0.20
Changes: https://github.com/cbsd/cbsd/releases/tag/v13.0.20

Reported by:	maintainer

(cherry picked from commit 4d5e4fb9de)
2021-12-14 18:11:58 +01:00
Franco Fichtner
d4f4088955 security/suricata: Update to 6.0.4
While here pet portfmt.

Changes:		https://forum.suricata.io/t/suricata-6-0-4-and-5-0-8-released/1942
PR:			260250
Approved by:		0mp (mentor)
MFH:			2021Q4
Differential Revision:	https://reviews.freebsd.org/D33335

(cherry picked from commit 3571a07d68)
2021-12-14 12:10:42 +01:00
Matthias Andree
c222755ca7 mail/mailman: regression fix update to 2.1.39
Mark Sapiro announced Mailman 2.1.39 "[...] fixes
https://bugs.launchpad.net/mailman/+bug/1954694
[...]
The fix for CVE-2021-42097 was case sensitive and should not be.
The fix for CVE-2021-44227 introduced a potential NameError in logging.

This could cause a user's changes to the option's page to not be
accepted and perhaps cause a 'We hit a bug' response if the user visited
the page with a mixed- or upper-case email address."

URL:		https://bugs.launchpad.net/mailman/+bug/1954694
MFH:		2021Q4
(cherry picked from commit 9449a10c3d)
2021-12-13 23:33:51 +01:00
Ashish SHUKLA
72e94c4bc4
www/cinny: Update to 1.6.0
MFH:		2021Q4
Security:	0dcf68fa-5c31-11ec-875e-901b0e9408dc
(cherry picked from commit a367a9d74e)
2021-12-13 17:20:48 +00:00
Ashish SHUKLA
cba275f3dd
www/cinny: Update to 1.5.1
(cherry picked from commit 0f1667fbaa)
2021-12-13 17:20:42 +00:00
Ashish SHUKLA
85e1493ff7
www/cinny: Update to 1.5.0
- Designate configuration file as such, there is now one

(cherry picked from commit c594388688)
2021-12-13 17:20:38 +00:00
Ashish SHUKLA
bd230202ff
www/cinny: Update to 1.4.0
(cherry picked from commit c4540ba5db)
2021-12-13 17:20:33 +00:00
Ashish SHUKLA
18c10023c3
www/cinny: Update to 1.3.2
(cherry picked from commit 5afcb83dcc)
2021-12-13 17:20:28 +00:00
Ashish SHUKLA
ec2fa47c47
www/element-web: Update to 1.9.7
Approved by:	maintainer (implicit, version bump, as per PR 258262)
MFH:		2021Q4
Security:	0dcf68fa-5c31-11ec-875e-901b0e9408dc

(cherry picked from commit ff439c0005)
2021-12-13 17:15:30 +00:00
Ashish SHUKLA
f722c33d41
www/element-web: Update to 1.9.6
Approved by:	maintainer (implicit, version bump, as per PR 258262)

(cherry picked from commit 0ccc5aabe3)
2021-12-13 17:15:25 +00:00
Ashish SHUKLA
be4e95d516
www/element-web: Update to 1.9.5
Approved by:	maintainer (implicit, version bump, as per PR 258262)

(cherry picked from commit e4a6d525d2)
2021-12-13 17:15:20 +00:00
Ashish SHUKLA
031e6257ee
www/element-web: Update to 1.9.4
Approved by:	maintainer (implicit, version bump, as per PR 258262)

(cherry picked from commit 399a954253)
2021-12-13 17:15:15 +00:00
Ashish SHUKLA
e15036dcaf
www/element-web: Update to 1.9.3
Approved by:	maintainer (implicit, version bump, as per PR 258262)

(cherry picked from commit 8dcfe73b5b)
2021-12-13 17:15:11 +00:00
Ashish SHUKLA
c89d55abd3
www/element-web: Update to 1.9.2
(cherry picked from commit 9e8b1a213d)
2021-12-13 17:15:06 +00:00
Ashish SHUKLA
0da3f83e71
www/element-web: Update to 1.9.1
Approved by:	maintainer (implicit, version bump, as per PR 258262)

(cherry picked from commit 11f7005347)
2021-12-13 17:14:37 +00:00
Matthias Fechner
c0f35eb181 textproc/apache-solr: disable format lookup for log4j
As recommended here:
https://solr.apache.org/news.html#apache-solr-affected-by-apache-log4j-cve-2021-44228
disable lookup that opens a security vulnerability with log4j < 2.15.0.
This is a mitigation for CVE-2021-44228.

PR:		260373
(cherry picked from commit 7604d31e30)
2021-12-13 16:11:42 +01:00
Matthias Fechner
d709612f9c textproc/apache-solr: Security update to 8.11.0
Changelog:
https://solr.apache.org/security.html
https://solr.apache.org/docs/8_11_0/changes/Changes.html

PR:		260373
Reported by:	ari@ish.com.au
Security:	66cf7c43-5be3-11ec-a587-001b217b3468

(cherry picked from commit 1b3a85f97e)
2021-12-13 08:27:19 +01:00
Christoph Moench-Tegeder
96f4c70e70 mail/thunderbird: use libc for res_* functions
thunderbird's javascript code needs more than basic DNS resolution
(e.g. SRV, TXT, MX lookups) - more than javascript natively has
(welcome to the web) and builds it's own bindings for libc to use
the resolver(3) interface. Unlike linux, where the resolver routines
live in libresolv, FreeBSD has these routines in libc.
I'm referencing libc.so.7 directly, as this is enough to make this
code work on 13/amd64 (others should work too) - the official way
of using libc.so would be much more work (and reimplementing parts
of the dynamic linker in javascript takes the cake, or something).

This is enough to make adding and using new CalDAV calendars possible;
other problems might linger and possibly require a better solution.

(cherry picked from commit 9a2174d4e0)
2021-12-12 23:20:46 +01:00
Yuri Victorovich
d885cb58c8 audio/calf-lv2: Unbreak by updating to the intermediate commit fixing clang compilation: 0.90.3 -> 0.90.3.20210427
gcc-compiled libcalf.so was crashing due to mix of gcc- and base-provided libc++.so and libstdc++.so

PR:		258051
Original patch submitted by:	 Florian Walpen <dev@submerge.ch>

(cherry picked from commit 866b394fc6)
2021-12-12 14:06:09 -08:00
Yuri Victorovich
f2b9853a5e audio/calf-lv2: Broken.
(cherry picked from commit da7c8ee010)
2021-12-12 14:06:09 -08:00
Benjamin Takacs
ce8e04db8b java/openjfx14: fix build with non-default CCACHE_DIR
In the build of openjfx14 CCACHE_DIR gets lost leading to build failures e.g.
when building as nobody, so add it into ccwrapper and cxxwrapper.

While here remove redundant ${SETENV} in do-build (${_GRADLE_RUN}
already contains ${SETENV})

PR:		260215
(cherry picked from commit 4ddd25225a)
2021-12-12 19:29:40 +01:00
Charlie Li
a7a31a598c
deskutils/gucharmap: update to 14.0.1
Chase textproc/UCD update.

Approved by: arrowd (mentor)
Differential Revision: https://reviews.freebsd.org/D32928

(cherry picked from commit f2b7e61817)
2021-12-12 12:03:06 -05:00
Matthias Andree
8963d93509 security/openvpn: sort OPTIONS_{DEFAULT|DEFINE}
(cherry picked from commit 42d7350924)
2021-12-12 12:29:24 +01:00
Matthias Andree
0a512a27a1 security/openvpn: deprecate tunnelblick
While here, shorten LZO_DESC to fit 80x24 dialogs.

(cherry picked from commit bedfd042b9)
2021-12-12 12:29:23 +01:00
Alex
a34084d590 games/omega: Fix inventory display crash and take maintainership
PR:		259786
Reported by:	Alex <r7st.guru@gmail.com> (new maintainer)
Approved by:	portmgr (blanket: bugfix, unmaintained port)
MFH:		2021Q4

(cherry picked from commit dfc806ae70)
2021-12-12 16:57:45 +09:00