Commit graph

15090 commits

Author SHA1 Message Date
Matthias Andree
741cce9856 Update range to exclude nss 3.12.11 from vuln, as kwm@'s commit
to upgrade nss to 3.12.11 included the newer CKBI 1.87 that explicitly
distrusts DigiNotar.
2011-09-03 16:18:19 +00:00
Koop Mast
0080509bac Update to 3.12.11.
This update is based on the nss-3.12.11.with.ckbi.1.87 release.
The only change with the nss-3.12.11 release is that the certs from the
DigiNotar CA are marked a untrusted.
2011-09-03 15:58:50 +00:00
Matthias Andree
141b7bbd0b Add a security notice for the DigiNotar incident, listing nss/ca_root/nss. 2011-09-03 15:43:38 +00:00
Florian Smeets
bb5a89fd32 - only match vulnerable versions in the hlstats entry
- add additional CVEs
2011-09-03 12:49:12 +00:00
Doug Barton
31c7279fdb Mark vulnerable ports FORBIDDEN with EXPIRATION_DATE= 2011-09-30 2011-09-03 12:02:16 +00:00
Johan van Selst
508010664a - Update nettle to 2.3
The library is intended to be binary compatible with nettle-2.2
- Includes *.pc files for pkgconfig
2011-09-03 10:50:40 +00:00
Cy Schubert
49796f40f6 Bring COPS back from the dead. 2011-09-03 08:05:29 +00:00
Cy Schubert
84645c416e Bring this old-school tool back from the dead.
Assume maintainership of this port.
2011-09-03 08:03:36 +00:00
Doug Barton
2d9297a50f Add EXPIRATION to ports marked DEPRECATED that do not already have it. [1]
Date set to 2011-09-30 since that's > 1 month in all cases. Feel free to
change it to something more appropriate.

Change DEPRECATED to IGNORE for security/openvpn-beta to better fit the
intention.

Problem pointed out by:	linimon [1]
2011-09-03 07:55:32 +00:00
Chris Rees
cf411f9469 Final modification for apache22 vulnerability; include slave ports as well
Pointed out by:	flo
Reviewed by:	eadler
2011-09-02 17:15:58 +00:00
Chris Rees
1c2a1b2bc0 Correct range for apache22, 2.2.20 is fixed and 1.3 wasn't affected.
Submitted by:	Aleksandr Stankevic (sysmonk on IRC/Freenode##FreeBSD)
Security:	CVE-2011-3192
2011-09-01 19:06:27 +00:00
Sunpoet Po-Chuan Hsieh
834f365009 - Update to 0.9.9 2011-09-01 16:54:01 +00:00
Stefan Walter
34470f2ebe - remove dead mirror
- install license with LICENSE knob
- use USE_PYTHON instead of RUN_DEPENDS
- use DOS2UNIX instead of homemade commands
- use DATADIR instead of share/hmap
- use COPYTREE_SHARE for copying group of files
- fix plist
- bump PORTREVISION because of plist changes

PR:		156693
Submitted by:	Ruslan Mahmatkhanov <cvs-src@yandex.ru>
Approved by:	maintainer timeout (>4 months)
2011-09-01 13:11:46 +00:00
Ganael LAPLANCHE
23714f1687 - Update to 1.18
- Improve REINPLACE_CMD regexp for pthread patch
2011-09-01 06:35:34 +00:00
Cy Schubert
7fdc13c337 Fix build under 9.0-CURRENT. 2011-09-01 05:08:54 +00:00
Dennis Herrmann
ac3bd3351e - Update to 0.4.2.1
PR:		ports/160142
Submitted by:	KATO Tsuguru <tkato432@yahoo.com>
2011-08-31 22:01:46 +00:00
Sylvio Cesar Teixeira
8bf634d3b1 - Update to 0.21 2011-08-31 18:21:28 +00:00
Martin Matuska
770da65078 Update to 1.0.3 2011-08-31 08:18:12 +00:00
Shaun Amott
6f3d9abf71 Put a lower bound on the last php entry, as the bug was introduced in
5.3.7-RC5.

Submitted by:	"jaset" via #bsdports
2011-08-30 22:29:14 +00:00
Chris Rees
715ee5058b Update forgotten distinfo.
Pointyhat:	erwin -> crees
2011-08-30 22:17:14 +00:00
Matthias Andree
2a9cbca0a0 Use recently bugfixed rc script from ../openvpn port. 2011-08-30 17:12:31 +00:00
Matthias Andree
a2cf6822c5 Use required_modules rather than _precmd.
To fix failures with 'restart'.

Reported by: Miroslav Lachman
2011-08-30 17:11:57 +00:00
Brendan Fabeny
3ed506443b update to 0.2.2.32 2011-08-30 16:57:43 +00:00
Sofian Brabez
1efff13278 - Fix entry date and use two ranges
Reviewed by:	gahr@
Approved by:	jadawin@ (mentor)
2011-08-30 13:21:27 +00:00
Sofian Brabez
3b3c1eda00 - Document CVE-2011-3192 for recent apache DoS vulnerability
Approved by:	jadawin@ (mentor)
Security:	http://vuxml.org/freebsd/7f6108d2-cea8-11e0-9d58-0800279895ea.html
2011-08-30 12:01:13 +00:00
Andrey A. Chernov
45ba9805ed Remove myself from MAINTAINER 2011-08-30 07:57:26 +00:00
Pav Lucistnik
5dc02a69db - Extra verbosity for tracking down pointyhat build failure
PR:		ports/160281
Submitted by:	Sergei Vyshenski <svysh@pn.sinp.msu.ru> (maintainer)
2011-08-29 23:00:59 +00:00
Chris Rees
282d542da5 - Update to latest SVN
- While here, fix perl depends to use packages
- Use USERS and GROUPS
- Add some more OPTIONS
- Rename rc script to maiad

PR:		ports/159949
Submitted by:	Janky Jay III <ek@purplehat.org> (maintainer)
2011-08-29 15:57:19 +00:00
Frederic Culot
aac34abef3 - Update MASTER_SITES
- Undeprecate (distfile fetchable again)

PR:		ports/160143
Submitted by:	Kato Tsuguru <tkato432@yahoo.com>
2011-08-29 07:22:17 +00:00
Olli Hauer
86ce3173c6 - update to version 0.20
- unbreak port, (new CPAN maintainer)
2011-08-28 15:46:35 +00:00
Ashish SHUKLA
9d1247d864 Chase editors/emacs update.
PR:		ports/160196
2011-08-27 22:22:57 +00:00
Joe Marcus Clarke
85010d78d3 Update Pidgin and friends to 2.10.0. See
http://developer.pidgin.im/wiki/ChangeLog for a list of changes in this
release.
2011-08-27 17:28:25 +00:00
Sunpoet Po-Chuan Hsieh
e95493e4d0 - Update to 0.28
- Add BUILD_DEPENDS

Changes:	http://search.cpan.org/dist/Crypt-OpenSSL-RSA/Changes
2011-08-27 11:05:24 +00:00
Xin LI
2bcd156031 Upstream indicates that this only affects 4.40 and 4.41 so add a <ge> tag
to indicate that.
2011-08-26 18:12:00 +00:00
Xin LI
bd33b8a127 Document stunnel heap corruption vulnerability. 2011-08-26 18:10:39 +00:00
Anton Berezin
97d025f53c Update to 0.171.
Changes:	http://search.cpan.org/dist/Authen-Htpasswd/Changes
2011-08-26 13:46:12 +00:00
Ganael LAPLANCHE
a54ca5a9b8 Update to 1.17 2011-08-26 11:57:38 +00:00
Martin Wilke
b7b7664817 - Fix MASTER_SITES
- Cleanup

PR:		160145
Submitted by:	Ports Fury
2011-08-26 04:25:09 +00:00
Frederic Culot
9c69bf7580 - Update MASTER_SITES
- Undeprecate (distfile fetchable again)

PR:		ports/160144
Submitted by:	Kato Tsuguru <tkato432@yahoo.com>
2011-08-25 14:42:00 +00:00
Frederic Culot
2cfffc7263 - Update to 4.34 [1]
- Pet portlint(1) by moving LICENSE earlier

PR:		ports/160141 [1]
Submitted by:	Kato Tsuguru <tkato432@yahoo.com>
2011-08-25 12:36:49 +00:00
Baptiste Daroussin
68936a4987 Fix discovery date 2011-08-24 22:43:04 +00:00
Xin LI
0add101dd2 DOcument phpMyAdmin CVE-2011-3181 (multiple XSS). 2011-08-24 22:20:14 +00:00
Mathieu Arnold
2392555218 Update to 0.24
Add license

PR:		ports/159388
Submitted by:	Jase Thew <freebsd@beardz.net>
2011-08-24 12:27:42 +00:00
Stanislav Sedov
3b7e736c2a - Update to 1.0.2.
This is a bugfix release.  In particular it should ubreak build on
  PowerPC.
2011-08-24 07:56:59 +00:00
Koop Mast
fe61bf1eb4 Chase libnotify, libproxy and webkit-gtk2 shlib changes, and fix build where needed. 2011-08-23 18:39:19 +00:00
Rene Ladan
29d35d30a9 Document new Chromium vulnerabilities.
Obtained from:	http://google-chrome-browser.com/releases
Security:	CVE-2011-[2821, 2823-2829, 2839]
2011-08-23 17:02:34 +00:00
Xin LI
4d156302b0 Mark PHP5 < 5.3.7_2 as vulnerable to PHP bug #55439: crypt() returns only
the salt for MD5.
2011-08-23 00:58:34 +00:00
Martin Matuska
456d800955 Withdraw maintainership, pass back to ports@FreeBSD.org
Approved by:	maintainer (myself)
2011-08-22 21:30:53 +00:00
Steven Kreuzer
225393234e Delete the RandPasswd.orig file which is created during patching so that it does
not get copied to SITE_PERL/PERL_ARCH during install

Reported by:	pav@
2011-08-22 19:36:04 +00:00
Eitan Adler
e1f907bc92 - change the email address I use to maintain ports
Approved by:	bapt (mentor)
2011-08-21 20:51:40 +00:00
Roman Bogorodskiy
2c478db886 Update to 2.12.9. 2011-08-21 17:11:24 +00:00
Eitan Adler
74db235785 - change the email address I use to maintain ports
Approved by:	bapt (mentor)
2011-08-21 16:12:46 +00:00
Martin Matuska
cc646ccd0f Update to 1.0.5 2011-08-21 05:59:32 +00:00
Martin Matuska
750743b798 Update to 1.2.0 2011-08-21 05:59:08 +00:00
Olli Hauer
7a0bd31763 - bump PORTREVISION from ports if USE_APACHE=13+ or 20+ is defined 2011-08-20 17:27:52 +00:00
Xin LI
e9c0aeda71 Document multiple PHP vulnerabilities. 2011-08-20 00:43:48 +00:00
Doug Barton
a459b71ddd Remove direct dependency on mysqld, and replace it with conditionally
including USE_MYSQL= server if the option is chosen, or = yes if not
to preserve the old behavior.

PR:		ports/159542
Submitted by:	me
Approved by:	maintainer timeout (14 days)
2011-08-20 00:18:24 +00:00
Steven Kreuzer
1d4b4b920b Fix isse where if an external caller invokes the the method
Crypt::RandPasswd->random_chars_in_range(), Perl prepends the object
name to the function's argument list. This causes the local variables
$minlen, $maxlen, $lo_char, and $hi_char to be set incorrectly ($minlen
is set to the object name, $maxlen is set to what should have been the
minimum length, $lo_char is set to what should have been the maximum
length, and $hi_char is set to what should have been the first character
in the given range), so that the method returns an incorrect result.

PR:	ports/154207
Submitted by:	Matthew X. Economou <xenophon+fbsdports@irtnog.org>
2011-08-19 21:48:14 +00:00
Xin LI
2eeef0b019 Document Rails multiple vulnerabilities. 2011-08-19 18:42:12 +00:00
Xin LI
0b7f7a433d Document dovecot DoS vulnerability. 2011-08-19 17:46:10 +00:00
Ryan Steinmetz
6f1b281388 New port: security/duo
Duo provides simple two-factor authentication as a service via:

    1.  Phone callback
    2.  SMS-delivered one-time passcodes
    3.  Duo mobile app to generate one-time passcodes
    4.  Duo mobile app for smartphone push authentication
    5.  Duo hardware token to generate one-time passcodes

This package allows an admin (or ordinary user) to quickly add Duo
authentication to any Unix login without setting up secondary user
accounts, directory synchronization, servers, or hardware.

WWW: http://duosecurity.com

Approved by:	tabthorpe (mentor)
2011-08-19 17:14:07 +00:00
Ryan Steinmetz
b6ac688edd Add support for running multiple instances
Adjust whitespace in Makefile

PR:		ports/159892
Submitted by:	Paul Schmehl <pauls@utdallas.edu> (maintainer)
Approved by:	tabthorpe (mentor)
2011-08-19 13:02:39 +00:00
Ryan Steinmetz
dca16a54b6 Update to 2.03b
Pacify portlint(1)

Approved by: wxs, tabthorpe (mentors, implicit)
2011-08-19 11:06:10 +00:00
Sofian Brabez
ffbbeb4e91 - Update to 1.2.9
- Update pkg-descr
- Make happy portlint

Approved by:	miwi@ (mentor)
2011-08-18 22:38:48 +00:00
Sergey Skvortsov
7f6af2b8db Document "otrs" - vulnerabilities in OTRS-Core allows read access
to any file on local file system.
2011-08-18 19:06:26 +00:00
Gabor Kovesdan
6a3abba0b9 - Unbreak the build when libssh is not enabled but libidn is
- Add some LIB_DEPENDS

PR:		ports/159124
Submitted by:	Michael Scheidell <scheidell@secnap.net>
Reviewed by:	Helmut Schneider <jumper99@gmx.de>
Approved by:	Ruslan Mahmatkhanov <cvs-src@yandex.ru> (maintainer)
2011-08-18 18:57:14 +00:00
Johan van Selst
0ae7fe0c5b Fix nettle build with clang on i386: correct assembly
PR:		ports/159773
Submitted by:	rene
2011-08-18 08:39:56 +00:00
Chris Rees
ca01166ac9 Fix rc script to stop nfs hangs
PR:		ports/133563
Submitted by:	Thiemo Nordenholz <list@thiemo.net>, yar
2011-08-17 10:52:12 +00:00
Alex Dupre
dcc497c0bb Update to 1.09 release. 2011-08-17 07:12:33 +00:00
Matthias Andree
af6239f488 Fix skipping t_cltsrv when IP missing. Really this time.
Cause was a   trap "... ; exit 1" 0   shell construct that needs to be
cancelled for the exit 77 to take effect. trap 0 inserted to that end.
2011-08-16 22:33:30 +00:00
Ryan Steinmetz
f429cdbbd5 Improve interoperability with mysql-server 5.5
PR:		ports/159763
Submitted by:	Paul Schmehl <pauls@utdallas.edu> (maintainer)
Approved by:	wxs (mentor)
2011-08-16 21:50:58 +00:00
Jimmy Olgeni
812cc45fb9 Unbreak and bump PORTREVISION: rebuild cl-*-sbcl ports that depend
on devel/cl-asdf.
2011-08-16 21:00:30 +00:00
Jimmy Olgeni
16be896b77 Bump PORTREVISION: rebuild ports that depend on devel/cl-asdf. 2011-08-16 20:59:36 +00:00
Florian Smeets
2a83ea6191 document recent mozilla vulnerabilities 2011-08-16 18:12:50 +00:00
Xin LI
9e508b77ee Document samba vulnerabilities of SWAT web interface. 2011-08-16 17:36:06 +00:00
Wesley Shields
60ad1ce7b2 Adjust dates in 510b630e-c43b-11e0-916c-00e0815b8da8.
Noticed by:	kwm@
2011-08-15 20:00:37 +00:00
Gabor Pali
e9ea24974b - Update security/hs-SHA to 1.5.0.0
Obtained from:	FreeBSD Haskell
2011-08-14 15:30:07 +00:00
Steve Wills
ca56097f4f - Update to 1.6.1
PR:		ports/159711
Submitted by:	Janos Mohacsi <janos.mohacsi@bsd.hu> (maintainer)
2011-08-14 02:22:41 +00:00
Wesley Shields
2b13dd987d - Document ISC DHCP server DoS. 2011-08-14 01:41:10 +00:00
Sergey Skvortsov
dabcf20f07 Document "bugzilla" - multiple vulnerabilities. 2011-08-13 18:19:06 +00:00
Steve Wills
0ef44efb9c - Use xerces-c 3 [1]
- Pass maintainership back to Janos Mohacsi <janos.mohacsi@bsd.hu> [2]

PR:		ports/159715 [1]
Submitted by:	Janos Mohacsi <janos.mohacsi@bsd.hu> [1]
Approved by:	maintainer (me) [2]
2011-08-13 15:31:57 +00:00
Chris Rees
3fb14bc535 Document dtc security issues
PR:		ports/159736
Submitted by:	Ansgar Burchardt <ansgar@debian.org>
2011-08-13 15:02:29 +00:00
Koop Mast
b5762224ee Update to 3.12.10.
PR:		ports/159080
Submitted by:	flo@
2011-08-13 14:46:35 +00:00
Dirk Meyer
b4ce38fd98 - update to 1.0.0 2011-08-13 14:30:25 +00:00
Emanuel Haupt
809caaabc1 Update to 1.3.0
PR:		159729
Submitted by:	Jaap Akkerhuis <jaap@NLnetLabs.nl> (maintainer)
2011-08-12 23:51:08 +00:00
Koop Mast
0e682dded4 Remove USE_GNOME=gnometarget from ports. It has been a empty keyword since
mid 2008.

PR:		ports/159624
Submitted by:	Ruslan Mahmatkhanov <cvs-src@yandex.ru>
2011-08-11 19:20:17 +00:00
Alexey Dokuchaev
31ddc7b10d Remove now longer applicable warning and enable graph option by default as
qt-designer plugin was split some time ago; add LICENSE (GPLv2).
2011-08-11 14:18:57 +00:00
Koop Mast
89dc774c20 Document freetype2 and libXfont vulnabilities. 2011-08-11 08:37:56 +00:00
Juergen Lock
c6d7ced537 Update linux-f10-flashplugin to 10.3r183.5 .
Submitted by:	pointyhat via erwin
Security:	http://www.freebsd.org/ports/portaudit/2c12ae0c-c38d-11e0-8eb7-001b2134ef46.html
2011-08-10 20:27:26 +00:00
Baptiste Daroussin
5c8e32c5b9 Remove some expired ports
2011-08-08 deskutils/alexandria: Upcoming ruby-gnome removes dependencies
2011-08-06 security/drweb: fails to fetch (website rearranged)
2011-08-06 security/drweb-postfix: fails to fetch (website rearranged)
2011-08-06 security/drweb-qmail: fails to fetch (website rearranged)
2011-08-06 security/drweb-sendmail: fails to fetch (website rearranged)
2011-08-10 16:18:32 +00:00
Emanuel Haupt
4e134ef931 Update to 1.1
PR:		158443
Submitted by:	KATO Tsuguru <tkato432@yahoo.com>
2011-08-10 14:30:32 +00:00
Alexey Dokuchaev
bf974945ef - Sanitize port description and remove old-school attribution
- Remove defunct WWW address (redirects to www.symantec.com now; official
  L0phtCrack site no longer distributes open source version)
2011-08-09 16:36:46 +00:00
Martin Matuska
3f502c3647 Transfer maintainer back to ports@FreeBSD.org
Approved by:	maintainer (myself)
2011-08-09 15:41:30 +00:00
Alex Dupre
c51e069ded Update to 0.12.2 release. 2011-08-09 10:43:53 +00:00
Matthias Andree
20103c4245 Fix NOPORTDOCS support, though differently than suggested
Reported by: pgollucci
PR:          ports/159610
2011-08-08 22:38:44 +00:00
Emanuel Haupt
f82a5655ef - Fix MASTER_SITES
- Add LICENSE
- Use COPYTREE_SHARE instead of CP

PR:		159491
Submitted by:	KATO Tsuguru <tkato432@yahoo.com>
2011-08-08 16:08:42 +00:00
Gabor Kovesdan
34b256f438 - Update to 2.7.0
- Beautify OPTIONS
- Remove unnecessary patch

PR:		ports/158613
Submitted by:	sahil
2011-08-08 11:19:48 +00:00
Frederic Culot
4a3f7136b8 - Update to 0.6.2
PR:		ports/159573
Submitted by:	Douglas William Thrift <douglas@douglasthrift.net> (maintainer)
2011-08-08 07:19:41 +00:00
Matthias Andree
f62451dfef Skip self-test more readily without addresses. 2011-08-07 18:05:35 +00:00
Pav Lucistnik
de9a24e5a8 - Turn off self-tests on pointyhat, they fail
Reported by:	pointyhat
2011-08-07 17:23:39 +00:00