Commit graph

32 commits

Author SHA1 Message Date
Cheng-Lung Sung
6a5fb2dc6b - fix low risk vulnerability
(VuXML ID  4a0b334d-8d8d-11d9-afa0-003048705d5a)

PR:		78779
Submitted by:	Kang Liu (maintainer)
2005-03-14 02:32:56 +00:00
Cheng-Lung Sung
76d7c802da - The phpbb developer group announces there are 2 security problems
in phpbb 2.0.12, privilege elevatiIn my patch:disclosure.
  (VuXML ID: 53e711ed-8972-11d9-9ff8-00306e01dda2)
- 1. update www/phpbb to 2.0.13
- 2. use DATADIR in pkg-plist

PR:		78189
Submitted by:	Kang Liu (maintainre)
2005-03-01 06:48:45 +00:00
Cheng-Lung Sung
ee8da28d32 - Update to 2.0.12
- This release addresses a number of bugs and a couple of potential exploits.
- Release note: [http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=265423]

PR:		ports/77943
Submitted by:	clsung
Approved by:	Kang Liu (maintainer)
2005-02-23 07:00:51 +00:00
Edwin Groothuis
f186ee267a %%PREFIX%%/INDEX.html -> %%PREFIX%%/README.html 2004-12-03 12:01:38 +00:00
Daichi GOTO
adebaa87f9 Update www/phpbb to 2.0.11
It is a SECURITY update.

PR:		ports/74106
Submitted by:	Kang Liu <liukang@bjut.edu.cn> (maintainer)
2004-11-24 05:25:11 +00:00
Jeremy Messenger
4588473be9 Kill me, forgot to change the distinfo. 2004-07-24 01:51:21 +00:00
Jeremy Messenger
261c3bfe50 Update to 2.0.10, it is now compatible with PHP5.
PR:		ports/69237
Submitted by:	Xin LI <delphij@frontfree.net>
Approved by:	"Kang Liu" <liukang@bjpu.edu.cn> (maintainer)
2004-07-24 01:49:56 +00:00
Pav Lucistnik
55571c1c5d - Update to 2.0.9
PR:		ports/69042
Submitted by:	Xin LI <delphij@frontfree.net>
Approved by:	maintainer
2004-07-14 15:17:44 +00:00
Pav Lucistnik
802504d61c - Plug IP spoofing vulnerablity
http://www.vuxml.org/freebsd/cfe17ca6-6858-4805-ba1d-a60a61ec9b4d.html
- Plug sessions table exhaustion DoS attack
  http://www.securityfocus.com/archive/1/360931

PR:		ports/66150
Submitted by:	Xin LI <delphij@frontfree.net> (maintainer)
2004-05-06 10:07:06 +00:00
Pav Lucistnik
cd168f5792 - Update to 2.0.8a
PR:		ports/64939
Submitted by:	Kang Liu <liukang@bjpu.edu.cn> (maintainer)
2004-03-30 21:33:26 +00:00
Pav Lucistnik
fbfb1933d4 - Plug another SQL injection vulnerability
Exploit posted at:	http://www.securityfocus.com/archive/1/358708
Patch obtained from:	http://www.securityfocus.com/archive/1/358751

PR:		ports/64803
Submitted by:	Kang Liu <liukang@bjpu.edu.cn> (maintainer)
2004-03-27 15:07:16 +00:00
Pav Lucistnik
501a6c1622 - Update to 2.0.8 and plug security issue
PR:		ports/64770
Submitted by:	Kang Liu <liukang@bjpu.edu.cn> (maintainer)
2004-03-26 17:06:30 +00:00
Oliver Eikemeier
5e8bcbf91c mark FORBIDDEN: http://people.freebsd.org/~eik/portaudit/c551ae17-7f00-11d8-868e-000347dd607f.html 2004-03-26 09:01:41 +00:00
Pav Lucistnik
5f07531a36 - Update to 2.0.7a which fixes SQL injection vulnerability
- Bump PORTREVISION

http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=182281

PR:		ports/64679
Submitted by:	Kang Liu <liukang@bjpu.edu.cn> (maintainer)
2004-03-25 18:03:13 +00:00
Pav Lucistnik
d9a1ac83ac - Update to 2.0.7
PR:		ports/64239
Submitted by:	Kang Liu <liukang@bjpu.edu.cn> (maintainer)
2004-03-15 02:26:23 +00:00
Pav Lucistnik
012cd75b00 - Update checksum
New version (2.0.6d) was released without changing distfile name.
  Security vulnerability (sql injection) in viewtopic was fixed
  and some issues with login was fixed. I verified this by diffing
  old and new distfile.
- Add SIZE
- Bump PORTREVISION

PR:		ports/63641
Submitted by:	Kang Liu <liukang@bjpu.edu.cn> (maintainer)
2004-03-02 19:07:04 +00:00
Pav Lucistnik
cbda193121 - Update distinfo after tarball was changed to fix security issues, please see
http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=161943 for details.

PR:		ports/60921
Submitted by:	Kang Liu <liukang@bjpu.edu.cn> (maintainer)
2004-01-05 19:01:44 +00:00
Michael Haro
594b7a8ab1 Fix Potential security issue with search in phpbb
PR:		59741
Submitted by:	maintainer
2003-12-17 05:31:01 +00:00
Kirill Ponomarev
c0a9694bf6 - Fix BBCode vulnerability & pgsql problem in phpbb
PR:		56706
Submitted by:	maintainer
2003-09-17 18:14:52 +00:00
Kirill Ponomarev
7910bede2a - Fix typo NOPORTOCS -> NOPORTDOCS
- Fix install problem when NOPORTDOCS is defined
- Bump PORTREVISION

PR:		56189
Submitted by:	maintainer
2003-08-30 17:24:14 +00:00
Edwin Groothuis
9b21df6338 update ports/www/phpbb to 2.0.6
phpBB Group are pleased to announce the release of phpBB
	2.0.6 the "phew, it's way to hot to be furry" Edition. This
	release had been made to fix a number of potential security
	related issues and more annoying bugs.  (from:
	http://www.phpbb.com/phpBB/viewtopic.php?t=124245) Here is
	the patch made by me,I would like to be the maintainer of
	this port.

PR:		ports/55230
Submitted by:	Kang Liu <liukang@bjpu.edu.cn>
2003-08-24 11:37:24 +00:00
Norikatsu Shigemura
4020c357c0 o Fix two vulnerabilities.
http://www.phpbb.com/news.php?id=17

	* phpBB SQL Injection vulnerability
	http://www.phpbb.com/phpBB/viewtopic.php?t=112052

	* PHPBB Admin_Styles.PHP Theme_Info.CFG File Include Vulnerability
	http://www.securityfocus.com/bid/7932/credit/
	http://www.phpbb.com/phpBB/viewtopic.php?t=113826

o Bump PORTREVISION.
o Take MAINTAINERship to ports@.

PR:		ports/54165[1]
Submitted by:	Kang Liu <lazykang@hotmail.com> [1]
		Ivanchenko V. I. <webmaster@asiamusic.ru>
2003-07-07 08:04:49 +00:00
Norikatsu Shigemura
8a05761d31 Update to 2.0.5.
http://www.phpbb.com/phpBB/viewtopic.php?t=111156
It says "This edition includes a significant number of
fixes for bugs and a minor cross-site scripting issue."
The XSS exploit in phpBB viewtopic.php has been post in
bugtraq.

PR:		ports/53691
Submitted by:	Kang Liu <lazykang@hotmail.com>
Approved by:	for SECURITY UPDATE
2003-06-25 01:50:21 +00:00
Norikatsu Shigemura
bf4dc55c32 Bump PORTREVISION in last commit. 2003-06-08 06:30:27 +00:00
Norikatsu Shigemura
ddd32c3557 Fix dependency on php/pear system (follow up new PEAR strcture).
Submitted by:	Alex Dupre <sysadmin@alexdupre.com>
2003-06-08 06:27:26 +00:00
Ade Lovett
7e52725f2a Clear moonlight beckons.
Requiem mors pacem pkg-comment,
And be calm ports tree.

E Nomini Patri, E Fili, E Spiritu Sancti.
2003-03-07 06:14:21 +00:00
Sean Chittenden
4ed55b9e7f Update phpBB to 2.0.4.
Submitted by:	"Ivanchenko V. I." <webmaster@asiamusic.ru>
2003-03-05 22:13:57 +00:00
Sean Chittenden
69744be0ec Mark port as FORBIDDEN with the typical list of PHP security
vulnerabilities.

	http://online.securityfocus.com/archive/1/307212
	http://online.securityfocus.com/bid/6634
	http://online.securityfocus.com/archive/1/302199
2003-02-06 20:19:35 +00:00
Johann Visagie
5fbe508f8f - Ensure clean deinstallation if user had installed additional language
packs, styles or avatars.
2002-10-30 16:35:42 +00:00
Johann Visagie
4f51c79d52 - Update to version 2.0.3
- Use $TAR rather than cpio(1) to install
- $PERL -> $REINPLACE_CMD
- Install contributed code under $DATADIR
- Numerous small fixes
2002-10-29 19:54:47 +00:00
Johann Visagie
1cd8250a01 - Big cleanup - almost a complete rewrite of this port
- Add necessary dependency on www/mod_php4
- Structure port Makefile and $PLIST in such a way that configuration data is
  not overwritten upon reinstall
- Ensure that (de)installation as package also works correctly
- Install documentation under $DOCSDIR
- Bump $PORTREVISION
2002-05-10 09:54:03 +00:00
Johann Visagie
c20468019e Add phpbb 2.0.0, a PHP-based bulletin board / discussion forum system. 2002-04-25 14:20:18 +00:00