Commit graph

16 commits

Author SHA1 Message Date
Olli Hauer
5e7bd302a1 - update to 4.0.5
Vulnerability Details
=====================

Class:       Cross-Site Request Forgery
Versions:    4.0.2 to 4.0.4, 4.1.1 to 4.2rc2
Fixed In:    4.0.5, 4.2
Description: Due to a lack of validation of the enctype form
             attribute when making POST requests to xmlrpc.cgi,
             a possible CSRF vulnerability was discovered. If a user
             visits an HTML page with some malicious HTML code in it,
             an attacker could make changes to a remote Bugzilla installation
             on behalf of the victim's account by using the XML-RPC API
             on a site running mod_perl. Sites running under mod_cgi
             are not affected. Also the user would have had to be
             already logged in to the target site for the vulnerability
             to work.
References:  https://bugzilla.mozilla.org/show_bug.cgi?id=725663
CVE Number:  CVE-2012-0453

Approved by:	skv (implicit)
2012-04-10 05:15:47 +00:00
Sergey Skvortsov
f2adc1c379 Update to latest 20110808 translation. 2011-08-20 17:10:12 +00:00
Olli Hauer
d399de5688 - create missing (empty) directory (bugzilla) so checksetup does not fail
- use DIST_SUBDIR for bugzilla and all translations
- sort pkg-plist (genplist)

OK from bugzilla maintainers per PM.

PR:		ports/158766
Submitted by:	ohauer
2011-07-18 21:56:02 +00:00
Sergey Skvortsov
7bd02d2b01 - Copy devel/bugzilla to devel/bugzilla3; russian/bugzilla-ru to russian/bugzilla3-ru
- Update devel/bugzilla, russian/bugzilla-ru to 4.0.1
- Update devel/bugzilla3, russian/bugzilla3-ru to 3.6.5

Changes:	http://www.bugzilla.org/releases/4.0.1/release-notes.html
		http://www.bugzilla.org/releases/3.6.5/release-notes.html
2011-06-07 13:30:01 +00:00
TAKATSU Tomonari
b6d62e1d1f - Update to 3.6.3-ru-20101117
Submitted by:	ohauer (via private e-mail)
2010-12-12 06:00:16 +00:00
Sergey Skvortsov
7f5e8b5d95 Update to 3.6.2-ru-20100809 2010-10-23 12:52:10 +00:00
Dirk Meyer
de78af3ac5 - update to 1.4.1
Reviewed by:	exp8 run on pointyhat
Supported by:	miwi
2010-03-28 06:47:48 +00:00
TAKATSU Tomonari
34281ff693 - Update to 3.4.6 [1]
- Remove ja-bugzilla-2.* from CONFLICT entries of devel/bugzilla,
 devel/bugzilla2 and russian/bugzilla-ru [2]
- Change MAINTAINER address from tota@rtfm.jp to tota@FreeBSD.org

 [1] This port has been updated from the bugzilla Japanized patch to
    bugzilla Japanese language pack installation, both of which are
    maintained differently.
     * Japanized patch is not actively maintained anymore.
     * More sophisticated language pack framework has been introduced since
       Bugzilla 3.0.
 [2] This port no longer conflicts with those ports due to the new language
    pack framework.

Approved by:	maho (mentor)
2010-03-25 13:25:48 +00:00
Sergey Skvortsov
80877671bc Update to 3.4.3-ru-20091115 2010-02-12 15:34:49 +00:00
Dirk Meyer
ca9c60461c - update to jpeg-8 2010-02-05 11:46:55 +00:00
Sergey Skvortsov
2641998467 Update to 3.4.2-ru-20090923
Feature safe:	yes
2009-09-23 11:56:07 +00:00
Dmitry Marakasov
3eb168f46b - Switch SourceForge ports to the new File Release System: categories starting with P,R,S 2009-08-22 00:35:32 +00:00
Sergey Skvortsov
87dfe18224 Update to 3.2rc2-ru-1.0 2008-12-01 15:40:15 +00:00
Pietro Cerutti
cb339c9b5f - Fix depends list after devel/bugzilla update
Reported by:	QA Tindie
Approved by:	portmgr
2008-09-09 20:32:03 +00:00
Sergey Skvortsov
19f2c81fd5 * fix condition operation in RUN_DEPENDS from "=" to "=="
* set PORTSCOUT variable
2008-08-30 09:12:39 +00:00
Sergey Skvortsov
03eb7331ed Add bugzilla-ru , russian localization for Bugzilla. 2008-07-28 15:44:14 +00:00