Commit graph

14440 commits

Author SHA1 Message Date
Emanuel Haupt
5cee224d7b Include a patchset that solves a problem with phase2 re-keying. That is, when
phase2 lifetime (either in seconds or bytes) expires, then vpnc either silently
stops passing traffic or that plus consuming CPU time by running a tight loop.

This issue have experienced this issue on various platforms.

Example of a bug report:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=496718

Bump PORTREVISION and while we're here remove MD5 sums.

Submitted by:   avg
Obtained from:  http://www.gossamer-threads.com/lists/vpnc/devel/3442, with
                slight adjustments to apply to our patchlevel by avg
2011-02-25 19:42:32 +00:00
Xin LI
c0da877e99 Add two OpenLDAP security by-pass vulnerabilities. 2011-02-25 18:39:16 +00:00
Brooks Davis
5e1bb82021 Chase nss revision and update to 3.12.9.
PR:		ports/154961
Submitted by:	Niclas Zeising
2011-02-25 17:19:01 +00:00
Johan van Selst
8a43efc266 - Update GNU SASL to version 1.6.0
- This includes shlib bump
- Grab maintainership
2011-02-25 14:06:15 +00:00
Matthias Andree
81da014c29 Fix broken linux-sun-jdk vulndb entries.
VuXML:		18e5428f-ae7c-11d9-837d-000e0c2e438a
VuXML:		c93e4d41-75c5-11dc-b903-0016179b2dd5
PR:		ports/154918
2011-02-25 14:01:14 +00:00
Martin Wilke
3e8d73e14d - Part 1 of python24 removal
- Clean up bsd.python.mk (remove PYWSGIREF, PYHASHLIB, PYCTYPES and PYEXPAT) all these is now part of python
	  since python25

Remove:
	textproc/py-expat
	devel/py-ctypes
	security/py-hashlib
	www/py-wsgiref
2011-02-25 09:46:39 +00:00
Martin Wilke
3fc2da5cbc - Get rid (RUN|BUILD) PYCTYPES since py25 is default in python 2011-02-25 08:46:07 +00:00
Ade Lovett
e0d39220da Update to libtool 2.4
Tested by:	pav (multiple -exp runs)
2011-02-25 06:15:44 +00:00
Martin Wilke
729d9d232f - Move over to py25 or above
- While here get rid FreeBSD 6.X and md5 support
2011-02-25 03:19:29 +00:00
Xin LI
03b42818c9 Chase after net/openldap24-server update.
Reminded by:	miwi
2011-02-25 01:32:17 +00:00
Dirk Meyer
40161454f3 - update to 0.14.1 2011-02-24 13:49:49 +00:00
Roman Bogorodskiy
c09ac60c23 Update to 2.11.6. 2011-02-23 19:05:33 +00:00
Wesley Shields
5b5cf8e237 Add CONFLICTS_INSTALL on audio/csound. There is a PR to update audio/csound
to 5.13 and I've asked miwi@ to add the conflict when he does the update.

While here drop MD5 from distinfo.

Submitted by:	atom@smasher.org
2011-02-23 17:49:41 +00:00
Renato Botelho
77b710064d - Update to 20110223
- Align with clamav port new option to use llvm from ports
2011-02-23 15:32:46 +00:00
Renato Botelho
3254e6b917 Add a new option to build JIT bytecode compiler using llvm installed from ports
instead of build clamav's own llvm. The option is off by default, so, no
PORTREVISION bum is required

PR:		ports/154900
Submitted by:	Denny Lin <dennylin93@hs.ntnu.edu.tw>
2011-02-23 15:14:35 +00:00
Martin Wilke
aaf8e0c47c - Cleanup previous entry 2011-02-23 14:43:41 +00:00
Florian Smeets
8b5a0e6344 - add asterisk -- Exploitable Stack and Heap Array Overflows 2011-02-22 21:30:18 +00:00
Renato Botelho
eb8d173c48 Fix detection if python was built with threads support and run make check
accordingly

PR:		ports/154848
Submitted by:	Martin Simmons <martin@lispworks.com>
2011-02-21 11:35:52 +00:00
Cheng-Lung Sung
b5b9e94db8 - Update to 2.0.24 2011-02-20 11:32:58 +00:00
Xin LI
4443818f1f Document PivotX administrator password reset vulnerability. 2011-02-20 05:04:28 +00:00
Martin Wilke
a9d926beb4 - Update to 3.5.1
PR:		154588
Submitted by:	Cezary Morga <cm@therek.net>
Approved by:	maintainer timeout
2011-02-19 12:49:34 +00:00
Wesley Shields
c3765ac8e1 Apply two patches:
- Fix build when --enable-dynamicplugins is not given to configure. [1]
- Fix a segfault in HttpInspect

PR:		ports/154868
Submitted by:	Dean Freeman <wfreeman@sourcefire.com> (maintainer)
		[1]: Michael Scheidell
2011-02-18 20:06:36 +00:00
Wen Heping
8c6e637343 - Update to 0.5.29 2011-02-17 03:25:42 +00:00
Thomas Abthorpe
7387137ea8 Reassign ports to the pool, thanks for your service, we hope to see you
back.
2011-02-16 03:46:50 +00:00
Martin Wilke
9fb10a5d3e - Update lastest tomcat entry (tomcat6/7 have the same problem)
Note: Please ask for review at ports-security@  THX!
2011-02-15 08:18:21 +00:00
Wen Heping
b6bcb75050 - Document tomcat vulnerability 2011-02-15 08:00:38 +00:00
Johan van Selst
8e72fed5ce - Update libecc 0.13.0
- Includes shlib bump
2011-02-14 22:01:30 +00:00
Pav Lucistnik
0b40fb1da6 - Remove stray cmd from plist that created bogus file on pkg_add
Reported by:	pointyhat
2011-02-13 22:17:19 +00:00
Olli Hauer
997592b8db - fix leftover if APACHE_VERSION > 13
PR:		ports/147009
2011-02-13 22:06:37 +00:00
Olli Hauer
8d8c954d31 - update to version 5.51
Nmap 5.51 [2011-02-11]

o [Ndiff] Added support for prerule and postrule scripts. [David]

o [NSE] Fixed a bug which caused some NSE scripts to fail due to the
  absence of the NSE SCRIPT_NAME environment variable when loaded.
  Michael Pattrick reported the problem. [Djalal]

o [Zenmap] Selecting one of the scan targets in the left pane is
  supposed to jump to that host in the Nmap Output in the right pane
  (but it wasn't).  Brian Krebs reported this bug. [David]

o Fixed an obscure bug in Windows interface matching. If the MAC
  address of an interface couldn't be retrieved, it might have been
  used instead of the correct interface. Alexander Khodyrev reported
  the problem.  [David]

o [NSE] Fixed portrules in dns-zone-transfer and ftp-proftpd-backdoor
  that used shortport functions incorrectly and always returned
  true. [Jost Krieger]

o [Ndiff] Fixed ndiff.dtd to include two elements that can be diffed:
  status and address. [Daniel Miller]

o [Ndiff] Fixed the ordering of hostscript-related elements in XML
  output. [Daniel Miller]

o [NSE] Fixed a bug in the nrpe-enum script that would make it run for
  every port (when it was selected--it isn't by default).  Daniel
  Miller reported the bug. [Patrick]

o [NSE] When an NSE script sets a negative socket timeout, it now
  causes a controlled Lua stack trace instead of a fatal error.
  Vlatko Kosturjak reported the bug. [David]

o [Zenmap] Worked around an error that caused the py2app bootstrap
  executable to be non-universal even when the rest of the application
  was universal. This prevented the binary .dmg from working on
  PowerPC. Yxynaxen reported the problem. [David]

o [Ndiff] Fixed an output line that wasn't being redirected to a file
  when all other output was. [Daniel Miller]
2011-02-13 19:36:36 +00:00
Alexey Dokuchaev
616b037062 - Update jumbo patch to version 11
- Add LICENSE (GPLv2)
2011-02-13 14:12:21 +00:00
Sahil Tandon
034342f190 Expand the range of supported Python versions and
pacify portlint(1).

PR:		ports/154374
Submitted by:	Jase Thew <freebsd@beardz.net>
Approved by:	maintainer timeout
2011-02-13 07:01:53 +00:00
Frederic Culot
e74b252d55 - Update to 5.7
Changes:	http://squidclamav.darold.net/news.html
PR:		ports/154691
Submitted by:	Laurent Levier <llevier AT argosnet.com> (maintainer)
2011-02-12 09:38:53 +00:00
Andrej Zverev
85b13ac345 Fix WWW in pkg-descr to http://search.cpan.org/dist/<MODULE> for unification.
No functional changes.

Sponsored by:	p5 namespace
2011-02-12 09:30:23 +00:00
Xin LI
57763c8ea6 Document two phpMyAdmin vulnerabilities. 2011-02-11 22:23:47 +00:00
Juergen Lock
4edd8ea987 Update to 10.2r152.
PR:		ports/154630
Submitted by:	Tsurutani Naoki <turutani@scphys.kyoto-u.ac.jp>
Security:	http://www.freebsd.org/ports/portaudit/4a3482da-3624-11e0-b995-001b2134ef46.html
Feature safe:	yes
2011-02-11 21:39:03 +00:00
Xin LI
802d02a1b7 Document mupdf PDF handling remote code execution vulnerability.
Submitted by:	Tim Zingelman <tez netbsd.org>
2011-02-11 19:59:48 +00:00
Xin LI
7adbdc82a2 Document rubygem-mail Remote Arbitrary Shell Command Injection Vulnerability.
Submitted by:	Tim Zingelman <tez netbsd.org>
2011-02-11 19:51:20 +00:00
Xin LI
7fb7de0219 Document plone remote security bypass vulnerability.
Submitted by:	Tim Zingelman <tez netbsd.org>
2011-02-11 19:48:03 +00:00
Xin LI
daf58256ad Document exim local privilege escalasion vulnerability.
Submitted by:	Tim Zingelman <tez netbsd.org>
2011-02-11 19:40:12 +00:00
Xin LI
5664bbedc9 Document OpenOffice multiple vulnerabilities.
Submitted by:	Tim Zingelman <tez netbsd.org>
2011-02-11 19:36:45 +00:00
Brooks Davis
7eeab3d6e6 Update to 2.2.2
PR:		ports/154568
Submitted by:	Ruslan Mahmatkhanov
2011-02-11 18:12:28 +00:00
Sunpoet Po-Chuan Hsieh
846198cc68 - Update MAINTAINER address 2011-02-11 08:27:24 +00:00
Sunpoet Po-Chuan Hsieh
058c615405 - Update to 2.9.0.4
- Update snortsam checksum
- Fix LIBNET_CONFIG issue
- Pet portlint

Changes:	http://www.snort.org/downloads/740
PR:		ports/154668
Submitted by:	Dean Freeman <wfreeman@sourcefire.com> (maintainer)
2011-02-11 08:01:39 +00:00
Cy Schubert
2d5c97dc53 Apply fixes for kpropd denial of service (MITKRB5-SA-2011-001) and KDC
denial of service (MITKRB5-SA-2011-002).

Security:	MITKRB5-SA-2011-001 (CVE-2010-4022),
		MITKRB5-SA-2011-002 (CVE-2011-0281)
2011-02-11 01:04:09 +00:00
Dirk Meyer
74bfc0300e - Security update to 1.0.0d
Security: http://openssl.org/news/secadv_20110208.txt
Security: CVE-2011-0014
Feature safe:	yes
2011-02-10 18:30:34 +00:00
Martin Wilke
4f067e03ce - Cleanup previous commit 2011-02-10 16:44:00 +00:00
Koop Mast
f089b1925b Document multiple webkit-gtk2 security vulnabilities, fixed in 1.2.7. 2011-02-10 10:41:58 +00:00
Peter Pentchev
5bafc9702d Update to stunnel-4.35:
- drop the transparent proxying patch, integrated upstream
- while I'm here, fix the very first master site URL -
  the download page on stunnel.org just links to the sites now,
  and does not contain downloadable source

PR:		154631
Submitted by:	Tsurutani Naoki <turutani@scphys.kyoto-u.ac.jp>
2011-02-10 09:34:59 +00:00
Xin LI
1683ca14df Document awstat multiple vulnerability.
Notified by:    Tim Zingelman <tez netbsd.org>
2011-02-10 00:44:26 +00:00