Commit graph

5841 commits

Author SHA1 Message Date
Jacques Vidrine
7f5388e9d6 Note a symlink vulnerability in getmail.
Submitted by:	Shane Kinney <mod6@freebsdhackers.net>
Approved by:	portmgr
2004-10-04 19:59:35 +00:00
Jacques Vidrine
a0e0b140b1 Fill in empty topic from previous commit.
Noticed by:	Shane Kinney <mod6@freebsdhackers.net>
Approved by:	portmgr
2004-10-04 17:30:00 +00:00
Jacques Vidrine
75a8348c4c Record FreeBSD-SA-04:15.syscons.
Approved by:	portmgr
2004-10-04 17:09:55 +00:00
Jacques Vidrine
1ea5847470 Add missing PORTEPOCH for samba.
Noticed by:	dinoex
Approved by:	portmgr
2004-10-04 14:01:45 +00:00
Jacques Vidrine
796de6c0ad Note racoon certificate verification bug.
Submitted by:	Jon Passki <cykyc@yahoo.com>
Approved by:	portmgr
2004-10-03 22:49:55 +00:00
Jacques Vidrine
b3829c3922 Note distcc IP address ACL bug.
Submitted by:	Jon Passi <cykyc@yahoo.com>
Approved by:	portmgr
2004-10-03 15:51:49 +00:00
Jacques Vidrine
0a516d0900 Remove a duplicate entry.
Submitted by:	Jon Passki <cykyc@yahoo.com>
Approved by:	portmgr
2004-10-03 15:38:27 +00:00
Jacques Vidrine
17fd0dac46 Correct the version number for latest Mozilla entry.
(cut-n-paste damage)

Approved by:	portmgr
2004-10-01 01:40:54 +00:00
Jacques Vidrine
444816916c Document the last few of the relatively recent Mozilla vulnerabilities.
Approved by:	portmgr
2004-10-01 01:37:52 +00:00
Jacques Vidrine
f3cbac7e5e Correct mangled CVE name: s/8983/0903/
Approved by:	portmgr
2004-09-30 23:32:10 +00:00
Jacques Vidrine
890f7d6ec7 Add another two older vulnerabilities affecting Mozilla & co.
Continue to try hard to cover past package names:
  - I missed el-linux-mozillafirebird previously.
  - Move all the `obsolete' package names into one place
    for clarity.

Approved by:	portmgr
2004-09-30 23:29:22 +00:00
Jacques Vidrine
75afc26d33 Don't forget `ja-samba' also.
Approved by:	portmgr
2004-09-30 22:30:26 +00:00
Jacques Vidrine
1ecf1ca2c8 Note samba file disclosure vulnerability.
Approved by:	portmgr
2004-09-30 22:26:01 +00:00
Kris Kennaway
84e8d56ed5 Increase USE_GCC to 3.4 for those ports which compile with it.
Approved by:	portmgr
2004-09-30 05:32:00 +00:00
Tom Rhodes
42aca1ba75 Fix apache version number entry, bump modified date for apache as well.
Approved by:	portmgr
2004-09-29 16:48:15 +00:00
Kris Kennaway
825afd6dc3 BROKEN on 5.x: Does not compile
Approved by:    portmgr (self)
2004-09-29 06:00:57 +00:00
Kris Kennaway
90abb24f53 BROKEN on 5.x: Does not compile
Approved by:    portmgr (self)
2004-09-29 05:45:34 +00:00
Jacques Vidrine
87c8e299b9 Make an initial attempt at covering all Mozilla/Firefox/Thunderbird
package names that we've had.  Similar changes need to be made to many
other entries, but let's use this one as a test subject first.

Approved by:	portmgr
2004-09-28 18:02:03 +00:00
Jacques Vidrine
d1c098e865 Correct spelling of phpnuke package name.
Reported by:	Dan Langille
Approved by:	portmgr
2004-09-28 15:06:18 +00:00
Jacques Vidrine
28bec85248 Note BMP decoder flaws in Mozilla/Firefox/Thunderbird.
Approved by:	portmgr
2004-09-28 14:31:41 +00:00
Jacques Vidrine
216d6ce8d1 Note stack buffer overflow in Mozilla mail.
Approved by:	portmgr
2004-09-28 14:28:03 +00:00
Jacques Vidrine
311d5d5ef7 Document Mozilla/Firefox/Thunderbird heap buffer overflows.
Approved by:	portmgr
2004-09-28 14:22:34 +00:00
Jacques Vidrine
4a5c4d0cdb Correct the package name for phpMyAdmin.
Reported by:	Matthew Seaman <m.seaman@infracaninophile.co.uk>
Approved by:	portmgr
2004-09-28 13:36:53 +00:00
Kris Kennaway
c3bbf8ee3b Correct another typo. :-(
Spotted by:	eik
Approved by:	portmgr (self)
XL pointy hat to: self
2004-09-28 02:07:03 +00:00
Kris Kennaway
c1481d696e Correct typo in previous
Approved by:	portmgr (self)
Pointy hat to:	self
2004-09-28 01:42:41 +00:00
Kris Kennaway
02b58eff4a Now builds on amd64
Approved by:	portmgr (self)
2004-09-27 23:44:03 +00:00
Jacques Vidrine
64a5200854 Add CERT Vulnerability Note references to xpm entry.
Approved by:	portmgr
2004-09-27 15:15:21 +00:00
Jacques Vidrine
49af9c28f0 Note two older vulnerabilities in PHP.
Submitted by:	Jon Passki <cykyc@yahoo.com>
Approved by:	portmgr
2004-09-27 02:57:31 +00:00
Jacques Vidrine
32bd453eb6 Note subversion information disclosure vulnerability.
Submitted by:	lev
Approved by:	portmgr
2004-09-26 18:17:36 +00:00
Jacques Vidrine
d2894c398c Add missing PORTEPOCH in a mozilla entry.
Correct package name in an apache entry.

Reported by:	Dan Langille <dan@langille.org>
Approved by:	portmgr
2004-09-26 18:04:52 +00:00
Kris Kennaway
82f9e5ad55 BROKEN on 5.x: Does not compile
Approved by:    portmgr (self)
2004-09-26 03:11:57 +00:00
Kris Kennaway
ca09d17d22 BROKEN: Does not build
Approved by:	portmgr (self)
2004-09-26 02:52:32 +00:00
Kris Kennaway
149b3e7f85 BROKEN on 5.x: Does not compile
Approved by:    portmgr (self)
2004-09-26 02:43:13 +00:00
Jacques Vidrine
c41b8c1e2b Forgot to add <modified> element for last commit.
Approved by:	portmgr
2004-09-25 00:59:48 +00:00
Jacques Vidrine
9f43a46e43 Add missing PORTEPOCH on one of the mozilla entries.
Noticed by:	Dan Langille <dan@langille.org>
Approved by:	portmgr
2004-09-25 00:58:58 +00:00
Jacques Vidrine
0fb3c87dfe Document vulnerabilities in lha.
Reviewed by:	dinoex
Approved by:	portmgr
2004-09-23 15:07:39 +00:00
Jacques Vidrine
8ed099096a Lately it seems I like to use dashes in topics... but I should at
least be consistent with how many.  s/---/--/

Approved by:	portmgr
2004-09-23 14:16:16 +00:00
Jacques Vidrine
e7c6d5e304 Document mysql buffer overflow.
Reported by:	ale
Approved by:	portmgr
2004-09-23 14:10:58 +00:00
Brian Feldman
a3963f0f8c Update to pam_alreadyloggedin-0.3 to unbreak. There should be no
visible changes.

This work was done by Jeremie Le Hen; thanks!

Submitted by:	Jeremie Le Hen <jeremie@le-hen.org>
Approved by:	portmgr
2004-09-22 17:42:45 +00:00
Jacques Vidrine
458849a587 Document Mozilla security icon spoofing vulnerability.
Approved by:	portmgr
2004-09-22 16:39:58 +00:00
Jacques Vidrine
d1b0ba75fb Document Mozilla vulnerability involving NULL bytes in FTP URLs.
Also, correct s/firebird/firefox/ in a previously documented issue.

Approved by:	portmgr
2004-09-22 16:16:30 +00:00
Jacques Vidrine
dfaa8e2391 Document Mozilla automatic file upload vulnerability.
Approved by:	portmgr
2004-09-22 15:59:56 +00:00
Jacques Vidrine
03eeeb2a99 Document mozilla certificate import denial-of-service vulnerability.
Approved by:	portmgr
2004-09-22 15:44:03 +00:00
Jacques Vidrine
3fbdc7e460 Note a file name disclosure issue in rssh.
Reported by:	leeym
Approved by:	portmgr
2004-09-21 22:04:54 +00:00
Yen-Ming Lee
04a4a7825c - replace "@dirrm ..." with "@unexec rmdir ..."
(p5-IO-INET6 will install files in SITE_PERL/PERL_ARCH/auto/IO/Socket/INET6)

PR:		70640
Submitted by:	leeym
Approved by:	portmgr (marcus)
2004-09-21 17:48:17 +00:00
Jacques Vidrine
14a4d02444 Add entry describe GNU Radius denial-of-service vulnerability.
Approved by:	portmgr
2004-09-20 20:13:11 +00:00
Jacques Vidrine
424b8857eb Add sudoedit vulnerability.
Approved by:	portmgr
2004-09-20 20:06:44 +00:00
Jacques Vidrine
8dba5f120c In latest CVS entry, remove the reference to the exploit. It does
not apply to any of these vulnerabilities, but to the previous CVS
vulnerability (CAN-2004-0396).

Approved by:	portmgr
2004-09-19 23:36:42 +00:00
Jacques Vidrine
9d5b3878ff Oh yeah, add affected FreeBSD versions for CVS issues.
Approved by:	portmgr
2004-09-19 23:32:05 +00:00
Jacques Vidrine
e368c4afbc Update CVS entry with some details.
Approved by:	portmgr
2004-09-19 23:23:49 +00:00