Commit graph

20582 commits

Author SHA1 Message Date
Guido Falsi
79ede1bfbe Document asterisk security issues.
While here, add CVE number to a previous asterisk entry.
2015-01-29 11:20:51 +00:00
Dmitry Marakasov
e5f034214d - Add missing plist files and empty dirs, drop @dirrm*
PR:		197147
Submitted by:	amdmi3
Approved by:	eric@camachat.org (maintainer)
2015-01-29 02:17:29 +00:00
Renato Botelho
4e6332642c Update to 0.98.6 2015-01-28 14:24:48 +00:00
Johannes Jost Meixner
b94dece6fd Add CVE-2015-0235.
- Affects linux_base-*

Approved by:	so@ (des)
2015-01-28 08:39:20 +00:00
Dmitry Marakasov
d694e148e6 - Drop @dirrm* from and add empty directories to pkg-plists
Approved by:	portmgr blanket
2015-01-28 01:41:25 +00:00
Sunpoet Po-Chuan Hsieh
cd528e3870 - Update to 1.68
Changes:	http://search.cpan.org/dist/Net-SSLeay/Changes
2015-01-27 11:26:54 +00:00
Kubilay Kocak
62abfe3028 devel/libhtp, security/suricata: Use iconv:translit
Use translit for USES=iconv, fixing a build error on specific (10-STABLE r???)
versions of FreeBSD that dont contain a libiconv implementation with certain
features [1] in base.

PR:		196720 [1]
Reported by:	<trond.endrestol ximalas info>
2015-01-27 10:47:48 +00:00
Vanilla I. Shu
5cedef19bd Add p5-Crypt-Sodium 0.06, perl bindings for portable NaCL (libsodium).
PR:		197088
Submitted by:	Thomas von Dein <freebsd@daemon.de>
2015-01-27 06:32:33 +00:00
Tijl Coosemans
20ebd85bff Document critical Adobe Flash Player vulnerability (CVE-2015-0311) 2015-01-26 21:20:43 +00:00
Olli Hauer
dad6a4f07c - document bugzilla security issues 2015-01-26 20:24:08 +00:00
Antoine Brodin
aa49f292d4 Fix DEPENDS 2015-01-24 21:49:41 +00:00
Antoine Brodin
a0e397213e Fix a typo in DEPENDS 2015-01-24 20:30:13 +00:00
Antoine Brodin
bd63b368ac Fix some _DEPENDS 2015-01-24 19:27:27 +00:00
Li-Wen Hsu
8ad3597657 - Fix description of 9c7b6c20-a324-11e4-879c-00e0814cab4e 2015-01-24 17:58:07 +00:00
Antoine Brodin
364abe76fd Switch some dependencies from a directory name or a file generated by pkg-install
to a package name,  as the former can't be attributed to a package
2015-01-24 15:07:39 +00:00
Alexey Dokuchaev
62b818217f Sanitize port description (obtained upstream) and kill EOL whitespace. 2015-01-24 10:25:21 +00:00
Koop Mast
268c173ab8 Install vala "bindings"
Add LICENSE
Update WWW
2015-01-24 10:09:10 +00:00
Mark Felder
ff76b3eb0c Patch parser to fix matching for Cyrus IMAP login attempts which are not
plaintext.

PR:		196943
Submitted by:	jakob.alvermark@bsdlabs.com
2015-01-23 20:15:34 +00:00
Tijl Coosemans
86c6fc4c0d - Update devel/automake to 1.15
- Update devel/gettext to 0.19.4
- Update devel/libtool and devel/libltdl to 2.4.5
- This version of libtool has been fixed to pass -fstack-protector to the
  compiler during linking.  Add the same fix to USES=libtool.  This should
  improve SSP support on FreeBSD/i386 8 and 9.
- databases/libmemcached, security/sssd: patch configure.ac so
  AC_CONFIG_AUX_DIR appears earlier.
  For databases/libmemcached changing configure.ac causes manpages to be
  regenerated which requires extra dependencies so patch a makefile to
  prevent that.
- devel/xfce4-dev-tools: only depend on recent versions of autoconf and
  automake

PR:		196938
Exp-run by:	antoine
Approved by:	portmgr (antoine)
2015-01-23 18:54:01 +00:00
Li-Wen Hsu
f3324ced2c Document Django 2014-01-13 vulnerabilty 2015-01-23 17:47:00 +00:00
Ryan Steinmetz
d67d09e2ba - Update to 5.10 2015-01-22 23:33:14 +00:00
Mikhail Teterin
af56c7fc52 Add a note about the just-fixed vulnerability of applications using net/libutp.
PR:		196351
Differential Revision:	D1575
Submitted by:	Jan Beich
Approved by:	bapt
2015-01-22 17:43:47 +00:00
Jase Thew
4a3017391b security/polarssl13:
- Add upstream patch to address crafted certificates vulnerability
- Add USES cpe

MFH:		2015Q1
Security:	CVE-2015-1182
Security:	a5856eba-a015-11e4-a680-1c6f65c3c4ff
Approved by:	maintainer (chris@bsdjunk.com)
2015-01-22 17:28:10 +00:00
Johannes Jost Meixner
128d64ac67 security/linux-c6-openssl: upgrade to 1.0.1e_3
- Upgrade to 1.0.1e_3
- Fixes CVEs from 2015-01-08.

Differential Revision:	https://reviews.freebsd.org/D1597
Security:	4e536c14-9791-11e4-977d-d050992ecde8
Approved by:	swills (mentor)
2015-01-22 17:10:25 +00:00
Johannes Jost Meixner
2925c75bbb Amend linux-c6-openssl version in OpenSSL entry from 2015-01-08.
Approved by:	swills (mentor)
2015-01-22 17:09:22 +00:00
Vsevolod Stakhov
a91fe34f1e Add CVE-2015-0206 description for LibreSSL port. 2015-01-22 17:02:40 +00:00
Vsevolod Stakhov
469e0c88d8 - Update to 2.1.3
PR:		197005
Submitted by:	Bernard Spil <spil.oss at gmail.com>
2015-01-22 16:48:37 +00:00
Tijl Coosemans
96f7bce425 Document Adobe Flash Player vulnerabilities 2015-01-22 12:54:13 +00:00
David Thiel
cd4ac85168 Update to 1.31.
PR:		196529
Submitted by: lightside
2015-01-22 00:42:35 +00:00
Rene Ladan
3872f5cc79 Document new vulnerabilities in www/chromium < 40.0.2214.91
Also affects FFmpeg, ICU, DOM but the links on the webpage all result in a 403.

Obtained from:	http://googlechromereleases.blogspot.nl
2015-01-21 22:09:38 +00:00
Frederic Culot
39557796a8 - Update to 1.12
- Shorten COMMENT

Changes:	http://search.cpan.org/dist/Data-Password/Changes
2015-01-21 15:03:22 +00:00
Anton Berezin
b874fcc48e Update to 1.73. 2015-01-21 12:57:27 +00:00
Max Brazhnikov
4e6233d1c5 security/pinentry:
- Make it apparent that Qt 4 frontend is broken on 10.x and greater

PR:		196681
Submitted by:	Gerard Seibert
2015-01-21 10:38:38 +00:00
John Marino
3fcf85f9b8 security/p5-Mcrypt: strip Mcrypt.so upon installation
PR:		196416
Submitted by:	maintainer (Tatsuki Makino)
2015-01-20 20:57:46 +00:00
Jase Thew
f57e5d76bd security/polarssl:
- Add upstream patch to address crafted certificates vulnerability
- Add USES cpe

MFH:		2015Q1
Security:	CVE-2015-1182
Security:	a5856eba-a015-11e4-a680-1c6f65c3c4ff
2015-01-19 21:19:31 +00:00
Jase Thew
d0fe2da51c security/vuxml:
- Document security/polarssl and security/polarssl13 crafted certificates
  vulnerability (CVE-2015-1182)
2015-01-19 20:52:53 +00:00
Matthias Andree
a202dc8d67 Grab maintainership and unmark BROKEN.
Bump PORTREVISION for the benefit of those that used TRYBROKEN=*.

PR: 190497
2015-01-19 20:37:32 +00:00
Matthias Andree
9d0ba19501 Fix crash when configuration file is not EOL-terminated. 2015-01-19 20:36:42 +00:00
Matthias Andree
0dff9e6c89 Fix warnings due to missing #import. 2015-01-19 20:36:21 +00:00
Matthias Andree
64325337c3 work around missing deps in src/Makefile[.in] 2015-01-19 16:45:47 +00:00
Sunpoet Po-Chuan Hsieh
f45b356a16 - Fix *_DEPENDS: parent is already in all supported Perl releases
- Bump PORTREVISION for dependency change
- While I'm here, move LICENSE upward

With hat:	perl
2015-01-19 13:06:16 +00:00
Koop Mast
bb89f80c35 Update ImageMagick to 6.9.0.4.
- Normalize the ImageMagick library name so it stays the same regardless of
  what the 16-bit and HDRI option are set to [1]. Teach cmake to look for
  the new name. Bump ports that link to the libraries due to this.
- As a result do away with the "HALFSUPPORTED" option block, and list
  16-bit and HDRI with the other options.
- ImageMagick ships a basic SVG plugin when not using librsvg2 for SVG
  support. This basic SVG plugin needs libxml2 to work [2]. Make libxml2
  a mandatory dependency (instead of only when the SVG option was selected).
- Don't touch .keep files in the modules directory, there files there so
  it useless.

PR:		194949 [1]
PR:		195227 [2]
Requested by:	many [1]
Submitted by:	software-freebsd@interfasys.ch [2]
2015-01-18 21:12:42 +00:00
Thomas Zander
ab68814eff Update to upstream version 1.11b
PR:		196765
Submitted by:	fk@fabiankeil.de (maintainer)
2015-01-18 19:27:00 +00:00
Kurt Jaeger
68aae0b0e7 New port: security/p5-Digest-GOST
Digest::GOST provides an interface to the GOST R 34.11-94
message digest algorithm, also defined in RFC 5831.

WWW: http://search.cpan.org/dist/Digest-GOST/
2015-01-18 11:20:54 +00:00
Sunpoet Po-Chuan Hsieh
3580345a42 - Update to 1.67
- Sort PLIST

Changes:	http://search.cpan.org/dist/Net-SSLeay/Changes
2015-01-18 10:34:43 +00:00
Kubilay Kocak
43650faa38 security/py-cryptography: Update to 0.7.2, Fix LibreSSL
- Update to 0.7.2
- Update BUILD_DEPENDS and TEST_DEPENDS
- Patch upstream sources to fix LibreSSL:

  * Remove EGD (Perl Entropy Gathering Daemon) support. This hasn't
    been needed on FreeBSD since FreeBSD 4.2
  * Disable compression conditionally using OPENSSL_NO_COMP
  * Check features, not version for x509_vfy

[1] https://github.com/pyca/cryptography/issues/928

PR:		196827
Submitted by:	Bernard Spil <spil.oss gmail com>
2015-01-18 09:38:15 +00:00
Kubilay Kocak
4658660b42 security/suricata: Update to 2.0.6, add lots of OPTIONS
- Update to 2.0.6
- Update pkg-plist
- Add LICENSE_FILE
- Add OPTIONS for:

  * LUA scripting support
  * LUAjit scripting support
  * Suricata socket client

- Fix a reverse logic bug for JSON option
- Suricata links to nspr as a dependent of nss, add it to LIB_DEPENDS
- Create LOGS_DIR post-install
- Add patch to fix upstream issue 1353 [1]

[1] https://redmine.openinfosecfoundation.org/issues/1353

PR:		196801
Submitted by:	cheffo freebsd-bg org (with changes)
2015-01-18 07:12:37 +00:00
Ruslan Makhmatkhanov
9af1bc3a48 security/py-potr: update to 1.0.1 2015-01-18 00:07:02 +00:00
Matthias Andree
05baf683fe Add a fix to prevent crashes on close if initialization failed. 2015-01-17 10:28:50 +00:00
Rong-En Fan
8ed73fa040 Drop maintainership as I no longer use these software nor have time and
energy to keep up.
2015-01-16 17:28:13 +00:00