Commit graph

21545 commits

Author SHA1 Message Date
Sunpoet Po-Chuan Hsieh
3c81d00b20 - Update to 1.70
Changes:	http://search.cpan.org/dist/Net-SSLeay/Changes
2015-06-28 09:45:29 +00:00
Dmitry Marakasov
9d8944598b - Mark ONLY_FOR_ARCHS: uses x86 assembly
- Optionize EXAMPLES
2015-06-26 21:34:35 +00:00
Pawel Pekala
c7b9866617 - Make xsel run dependency optional - it makes clipboard pasting
not working under some conditions [1]
- Make xdotool also optional
- Add NO_ARCH

PR:		200931 [1]
Submitted by:	Sascha Holzleiter <sascha@root-login.org> [1]
Approved by:	maintainer [1]
2015-06-26 19:49:15 +00:00
Juergen Lock
4bf59b9fdf Document qemu pcnet guest to host escape vulnerability - CVE-2015-3209
PR:		201064
Submitted by:	koobs
Security:	https://vuxml.FreeBSD.org/freebsd/acd5d037-1c33-11e5-be9c-6805ca1d3bb1.html
2015-06-26 19:13:31 +00:00
John Marino
b07e9251a8 security/clambc is not jobs safe.
This has failed on me at least twice recently.  Here's the last fail:
Assembler messages:
Fatal error: llvm[3]: Compiling Mangler.cpp for Release build
can't create /wrkdirs/security/clambc/work/clamav-bytecode-compiler-
  clambc-0.98.5rc1/obj/lib/Target/ClamBC/Release/version.o: No such file
  or directory
2015-06-26 19:02:45 +00:00
Steve Wills
1a16ad2949 security/vault: create port
Vault is a tool for securely accessing secrets. A secret is anything that you
want to tightly control access to, such as API keys, passwords, certificates,
and more. Vault provides a unified interface to any secret, while providing
tight access control and recording a detailed audit log.

WWW: https://vaultproject.io/
2015-06-26 17:02:42 +00:00
Xin LI
98c0e54a89 Document CVE-2014-3120, CVE-2014-6439, CVE-2015-1427, CVE-2015-3337,
and CVE-2015-4165 (various Elasticsearch vulnerabilities).

PR:		ports/201008
Submitted by:	Jason Unovitch
2015-06-26 04:35:45 +00:00
Dmitry Marakasov
49e64cca97 - Mark BROKEN on 9.x:
/usr/bin/make  all-recursive
Making all in po
Error expanding embedded variable.
*** [all-recursive] Error code 1

- Fix plist for disabled NLS case

Approved by:	portmgr blanket
Submitted by:	pkg-fallout
2015-06-25 22:06:10 +00:00
Xin LI
40718f9572 security/afl: Update to 1.83b
While at it, reset maintainer to ports@ as the port now
contains LICENSE goo whose meaning remains a mystery.

PR:		201107
Submitted by:	Fabian Keil <fk fabiankeil de> (maintainer)
2015-06-25 19:41:27 +00:00
Dmitry Marakasov
bf590da6ca - Mark BROKEN on 9.x:
config.h:249: error: expected identifier or '(' before '/' token
config.h:249: error: stray '#' in program

Approved by:	portmgr blanket
Submitted by:	pkg-fallout
2015-06-25 13:37:05 +00:00
Dmitry Marakasov
a976c75dca - Mark BROKEN on 9.x:
aead.cc:84:32: error: 'EVP_aes_128_ctr' was not declared in this scope

Approved by:	portmgr blanket
Submitted by:	pkg-fallout
2015-06-25 13:35:42 +00:00
Kubilay Kocak
5f31c61931 security/py-libnacl: Update to 1.4.3
- Update to 1.4.3
- Patch setup.py so test command is supported
- Add regression-test target

Changes:

  https://libnacl.readthedocs.org/en/latest/topics/releases/1.4.3.html

Based on:

PR:		200830
Submitted by:	Christer Edwards <christer dot edwards gmail com>
2015-06-25 05:48:02 +00:00
Xin LI
72fb5fd16e Split CVE-2015-4152 to its own entry as the affected port is logstash only.
While there also document CVE-2014-4326 (already fixed) for logstash.

PR:		ports/201001
Submitted by:	Jason Unovitch
2015-06-24 20:35:39 +00:00
Xin LI
1a71a0432f Add entry for logstash-forwarder/logstash.
PR:		ports/201065
Submitted by:	Jason Unovitch
2015-06-24 20:17:20 +00:00
Bryan Drewery
07d4a6adef Support changed ETCDIR in pkg-plist 2015-06-24 19:35:58 +00:00
Jan Beich
ea5d1656ea Aggressively mark more consumers of bundled dcraw as vulnerable
ljpeg_start() originates from dcraw, no need to list every package with
copy of it at the expense of readability.
2015-06-24 18:54:36 +00:00
Bryan Drewery
366d32fba5 Allow user overriding ETCDIR 2015-06-24 18:37:59 +00:00
Bryan Drewery
43be3ffdf0 Update to 20150624 snapshot 2015-06-24 17:59:51 +00:00
Sunpoet Po-Chuan Hsieh
00ebccf31a - Update to 1.4.11
- Add NO_ARCH

Changes:	https://github.com/google/oauth2client/blob/master/CHANGELOG.md
2015-06-24 17:41:21 +00:00
Dmitry Marakasov
2c89fd1b3e - Update to 1.80b
- While here, add LICENSE

PR:		201091
Submitted by:	fk@fabiankeil.de (maintainer)
2015-06-24 16:51:15 +00:00
Adam Weinberger
bd48f30188 Convert all p5-Test-use-ok dependencies to p5-Test-Simple, but only on
perl < 5.22. For www/p5-Catalyst-Controller-BindLex, change it from a
BUILD/RUN depend to TEST, as it is only used for the test target, and bump
PORTREVISION on that port.
2015-06-24 16:29:25 +00:00
Johannes Jost Meixner
d709b0fc86 Document linux-*-flashplugin11 CVE.
Reported by:	kwm
Reviewed by:	kwm
Security:	d02f6b01-1a3f-11e5-8bd6-c485083ca99c
Security:	CVE-2015-3113
Sponsored by:	Perceivon Hosting Inc.
2015-06-24 09:01:07 +00:00
Sunpoet Po-Chuan Hsieh
219b5528e6 - Add LICENSE
Approved by:	portmgr (blanket)
2015-06-23 20:26:32 +00:00
Ruslan Makhmatkhanov
9b5e54b8b5 Remove expired port
Functionality of py-backports.ssl_match_hostname is available in Python standard
library as ssl.match_hostname() since Python 2.7.9 [1].

[1] https://docs.python.org/2.7/library/ssl.html#ssl.match_hostname
2015-06-23 18:31:28 +00:00
Sunpoet Po-Chuan Hsieh
315ee05035 - Add NO_ARCH 2015-06-23 12:22:40 +00:00
Sunpoet Po-Chuan Hsieh
c69c71a5ff - Update to 1.2.1
- Add NO_ARCH

Changes:	https://github.com/toyokazu/omniauth-shibboleth/commits/master
2015-06-23 12:22:14 +00:00
Xin LI
2aa9f59daf Fix entry date. 2015-06-23 00:15:18 +00:00
Xin LI
9d0b4cf5d6 Document rubygem-bson DoS and possible injection vulnerability.
PR:		201061
Submitted by:	Jason Unovitch
2015-06-23 00:13:58 +00:00
Xin LI
f9f83a6deb Document 3 vulnerabilities with PHP that affected 4 extensions.
PR:		200926
Submitted by:	Jason Unovitch
2015-06-22 23:39:34 +00:00
Xin LI
1814e54078 Reflect version range change after r390340. While I'm there, also fix
the CVE-2015-4556 entry because it's not yet fixed in the ports tree and
add a reference to the PR while there.

PR:		200980
Submitted by:	Vitaly Magerya (with changes suggested by Jason Unovitch)
2015-06-22 23:22:23 +00:00
Jimmy Olgeni
cced5ca8fe Document vulnerabilities in devel/ipython < 3.2.0. 2015-06-22 22:28:05 +00:00
Baptiste Daroussin
c9066f6ae0 Remove deprecated USE_RCORDER which was already off except if one enforced
WITH_RCORDER
2015-06-22 19:43:42 +00:00
Ruslan Makhmatkhanov
ea0d346031 security/py-backports.ssl_match_hostname: add comment on blocker PR
Add comment on PR 201050 that blocking removal of this port. I tried to
contact maintainer couple of days ago, but still got no response, so just
created an PR to have a chance to commit this by timeout.
2015-06-22 19:33:51 +00:00
Rene Ladan
5dcea86754 Document new vulnerabilities in www/chromium < 43.0.2357.130
Obtained from:	http://googlechromereleases.blogspot.nl/2015/06/chrome-stable-update.html
2015-06-22 19:23:46 +00:00
Xin LI
2931ed1db6 Document rubygem-paperclip validation bypass vulnerabilitiy.
PR:		200979
Submitted by:	Jason Unovitch
2015-06-22 07:13:46 +00:00
Xin LI
58c3a2a130 Document lang/chicken vulnerabilities CVE-2014-9651 and CVE-2015-4556.
PR:		200980
Submitted by:	Jason Unovitch
2015-06-22 07:02:20 +00:00
Xin LI
3c6e62d8c9 Document cacti multiple vulnerabilities (affects < 0.8.8c) and
multiple XSS/SQL injection vulnerabilities (affects < 0.8.8d).

PR:		200963
Submitted by:	Jason Unovitch
2015-06-22 06:44:54 +00:00
Baptiste Daroussin
6bd636a8b6 Convert to USES=autoreconf 2015-06-21 16:14:16 +00:00
Sunpoet Po-Chuan Hsieh
51534f57a6 - Update to 0.18
- Add NO_ARCH

Changes:	http://search.cpan.org/dist/IO-Async-SSL/Changes
2015-06-21 10:40:33 +00:00
Jun Kuriyama
149f9abe94 Add p5-Dancer vuln. 2015-06-20 12:11:56 +00:00
Dmitry Marakasov
bf47170ae7 Fix fetch 2015-06-19 13:54:03 +00:00
Vanilla I. Shu
16d07ef7f4 remove target 'regression-test', it's on perl5.mk already.
Submitted by:	sunpoet@
2015-06-19 13:25:06 +00:00
Cy Schubert
a7862307e6 Fix: pkg-static: POST-INSTALL script failed 2015-06-19 05:44:57 +00:00
Xin LI
168e12be9b Document Drupal multiple vulnerabilities. 2015-06-19 00:13:25 +00:00
Dmitry Marakasov
c01a730273 - Strip binaries 2015-06-18 21:24:36 +00:00
Dmitry Marakasov
9b9532394f - Fix library installation 2015-06-18 21:23:25 +00:00
Ruslan Makhmatkhanov
9e6426db93 Chase py-ldap2 rename in more ports that I missed.
Do not bump PORTREVISION in security/py-crits because it marked BROKEN.
2015-06-18 20:10:29 +00:00
Vanilla I. Shu
4438c4b6a6 Fix build on non-root user.
Submitted by:	mat@
2015-06-18 04:52:13 +00:00
Vanilla I. Shu
501ed63033 1: bump version for add depends to p5-JSON.
2: strip binary.
3: add LICENSE/LICENSE_FILE.
2015-06-18 02:29:40 +00:00
Vanilla I. Shu
ba1b358aeb Upgrade to 0.023. 2015-06-18 01:25:52 +00:00
Xin LI
d400423100 Document two vulnerabilities of cURL. 2015-06-17 21:40:51 +00:00
Sunpoet Po-Chuan Hsieh
80f5b0357c - Make it compatible with Python 3.x
Approved by:	delphij
2015-06-17 17:35:58 +00:00
Sunpoet Po-Chuan Hsieh
d49f53be74 - Document Ruby on Rails multiple vulnerabilities 2015-06-17 17:24:31 +00:00
Antoine Brodin
6d0b696dd8 Mark BROKEN: Depends on conflicting versions of django
[101amd64-default-job-03] Installing py27-django-tastypie-0.12.1...
[101amd64-default-job-03] `-- Installing py27-django-1.8.2...
pkg-static: py27-django-1.8.2 conflicts with py27-django16-1.6.11 (installs files into the same place).  Problematic file: /usr/local/man/man1/django-admin.1.gz

Reported by:	pkg-fallout
2015-06-17 17:20:36 +00:00
Xin LI
1669c4980e Modify a5f160fa-deee-11e4-99f8-080027ef73ec so it covers ja-mailman too.
Submitted by:	Yasuhito FUTATSUKI
2015-06-17 17:18:38 +00:00
Xin LI
e6f5575fe0 A Python library for parsing PGP packets
WWW: https://pypi.python.org/pypi/pgpdump/

PR:		200364
Submitted by:	Yuri Victorovich <yuri@rawbw.com>
2015-06-17 01:05:24 +00:00
Xin LI
0d8dfa7ce4 Document testdisk multiple vulnerabilities.
PR:		ports/200250
Submitted by:	Jason Unovitch
2015-06-17 00:24:46 +00:00
Xin LI
b460ada75a Update to 0.15.1.
PR:		200473
Submitted by:	sef
Approved by:	maintainer timeout
2015-06-17 00:09:39 +00:00
Ryan Steinmetz
ff6b6f57ed - Update to 5.19 2015-06-16 14:02:51 +00:00
Dmitry Marakasov
5a23c27329 - Add missing perl run-dependency
- Add NO_ARCH
- Drop @dirrm* from plist
2015-06-16 02:17:02 +00:00
Dmitry Marakasov
bec7efd6d9 - Simplify docs and plist handling 2015-06-16 02:16:43 +00:00
Xin LI
54b16086f1 Update to 201523.
PR:		200774
Submitted by:	maintainer
2015-06-16 01:29:47 +00:00
Xin LI
e1aed4b396 Document Tomcat multiple vulnerabilities. 2015-06-16 00:44:01 +00:00
Sunpoet Po-Chuan Hsieh
073d65d105 - Update to 1.2.0
Changes:	https://github.com/nov/rack-oauth2/commits/master
2015-06-15 19:20:06 +00:00
Alex Dupre
ac3b010227 Update to 2.6.0 release. 2015-06-15 05:53:07 +00:00
Alex Dupre
c8918d2ca8 Update PHP ports:
- php5 to 5.4.42
- php55 to 5.5.26
- php56 to 5.6.10
2015-06-14 20:23:09 +00:00
Jason E. Hale
0418b8bf61 Update to 1.5.5 2015-06-14 20:10:26 +00:00
Carlo Strub
819d599f0a Bump PORTREVISION because of svn commit r389649 2015-06-14 19:56:48 +00:00
Carlo Strub
7945c412e8 fix broken pkg-plist 2015-06-14 19:53:32 +00:00
Olli Hauer
b32814820f - update to upstream svn r269
- use pkg-plist
2015-06-14 19:31:20 +00:00
Bernard Spil
e1cbff132c security/libressl: Update to 2.2.0
- Update to 2.2.0
  - Remove opensslfeatures.h patch (included upstream)
  - Add pkg-plist (mainly documentation)
  - Bump libcrypto SHLIB version in Mk/bsd.openssl.mk

Changes:

  http://marc.info/?l=openbsd-announce&m=143404058913441

Reviewed_by:	vsevolod, koobs
Approved by:	vsevolod (maintainer, mentor), koobs (mentor)
Security:	8305e215-1080-11e5-8ba2-000c2980a9f3
Differential revision:	D2770
MFH:		2015Q2
2015-06-14 13:28:26 +00:00
Thomas Zander
629cdc24e7 Add py-gpsoauth, a Python client library for Google Play Services OAuth 2015-06-14 07:26:44 +00:00
Jun Kuriyama
4ff6e86d0e - Upgrade to 0.36. 2015-06-14 04:56:43 +00:00
Jun Kuriyama
6c9fce01fa - Upgrade to 2.0.28 (bugfixes). 2015-06-14 04:56:10 +00:00
Sunpoet Po-Chuan Hsieh
834d4b262d - Add NO_ARCH 2015-06-13 20:16:15 +00:00
Sunpoet Po-Chuan Hsieh
0437326565 - Update RUN_DEPENDS: use newer rubygem-rack
- Add NO_ARCH
- Bump PORTREVISION for dependency change
2015-06-13 20:02:59 +00:00
Sunpoet Po-Chuan Hsieh
efbdbff72e - Update RUN_DEPENDS: use newer rubygem-rack
- Bump PORTREVISION for dependency change
2015-06-13 20:02:55 +00:00
Vsevolod Stakhov
89b79e70ec - Updated libsodium to 1.0.3 [1]
- Bump revision for dependent ports

PR:		200548 [1]
Submitted by:	rsimmons0 at gmail.com [1]
2015-06-13 16:14:54 +00:00
Sunpoet Po-Chuan Hsieh
3a920b46ae - Update WWW
With hat:	ruby
2015-06-13 15:34:37 +00:00
Jimmy Olgeni
865541f233 Sort entries. 2015-06-13 09:38:04 +00:00
Jun Kuriyama
b016fff0ef - Upgrade to 2.1.5 (bugfixes, minor enhancements). 2015-06-13 07:34:04 +00:00
TAKATSU Tomonari
434f261464 - Update to 0.9.6 2015-06-13 04:38:19 +00:00
TAKATSU Tomonari
75e885d2ff - Update to 0.6.8
- Update pkg-descr
2015-06-13 03:55:29 +00:00
Dirk Meyer
32ee0ec0e7 - update to 1.0.2c 2015-06-12 16:47:11 +00:00
Tijl Coosemans
98cdddb183 - Update security/polarssl13 to 1.3.11
- Patch a Makefile so regular make install works
- Replace a patch with MAKE_ENV
- Bump dependent ports

PR:		200816
2015-06-12 16:14:54 +00:00
Dirk Meyer
a6ff76fde0 - use portable cpu option for sparcv8 2015-06-12 14:42:23 +00:00
Dirk Meyer
257e59cd70 - fix path in SIZE lines 2015-06-12 14:40:27 +00:00
Ryan Steinmetz
022b29b6f2 - Correct patch filename for SIZE 2015-06-12 14:19:48 +00:00
Brad Davis
7f16b2fac1 Update security/ossec-hids-* to 2.8.2.
Approved by:	swills (mentor)
MFH:		2015Q2
Security:	c470db07-1098-11e5-b6a8-002590263bf5
2015-06-12 14:13:29 +00:00
Brad Davis
7b047d168a Add ossec-hids-* vulnerabilities.
PR:		200801
Submitted by:	Jason Unovitch <jason.unovitch@gmail.com>
Approved by:	swills (mentor)
2015-06-12 14:10:38 +00:00
Ryan Steinmetz
37ff6460c4 - Restore missing checksum for 1001-crypto-hmac-support-EVP_MD_CTX_FLAG_ONESHOT-and-set-.patch
- Correct ordering
2015-06-12 14:09:08 +00:00
Brendan Fabeny
890c1c1343 Update to 0.2.6.9
PR:		200814
2015-06-12 13:11:38 +00:00
Vsevolod Stakhov
688b1d3b73 - Update to 2.1.7 that fixes the recent openssl vulnerabilities
Submitted by:	zi via IRC
2015-06-12 02:23:33 +00:00
Ryan Steinmetz
8f5fadbbf0 - Add vulnerability information for additional ports affected by openssl CVEs in 8305e215-1080-11e5-8ba2-000c2980a9f3 2015-06-12 02:12:37 +00:00
Ryan Steinmetz
b4b8ed25f1 - Resolve build issue
With hat:	ports-secteam
2015-06-12 01:47:00 +00:00
Ryan Steinmetz
2edc2d000e - Update to 1.0.2b
- Partially pacify portlint

With hat:	ports-secteam
Security:	8305e215-1080-11e5-8ba2-000c2980a9f3
2015-06-11 21:37:29 +00:00
Ryan Steinmetz
ad01f5ea18 - Document recent vulnerabilities in security/openssl 2015-06-11 21:35:48 +00:00
Johannes Jost Meixner
353f452b19 Document 13 Flash vulnerabilities.
Affected: www/linux-*-flashplugin11.
2015-06-11 15:53:37 +00:00
Muhammad Moinur Rahman
b61e7410a4 security/sguil: Fix wrong dependency for databases/mysqltcl [1]
- Fix patch files to reflect 'make makepatch'
- Convert to new @dir framework

PR:		200762 [1]
Submitted by:	Trond.Endrestol@ximalas.info [1]
2015-06-11 10:49:40 +00:00
Dmitry Marakasov
56825a8792 - Add LICENSE
- Switch to USES=tar:tgz
- Fix shebangs

MFH:		2015Q2
2015-06-11 10:17:18 +00:00
Martin Matuska
0421721e83 Horde package update:
comms/pear-Horde_ActiveSync 2.27.1 -> 2.28.4
devel/pear-Horde_Core 2.20.0 -> 2.20.4
security/pear-Horde_Crypt_Blowfish 1.0.3 -> 1.1.0
devel/pear-Horde_Date 2.0.13 -> 2.1.0
mail/pear-Horde_Imap_Client 2.28.0 -> 2.28.1
mail/pear-Horde_Mime 2.9.0 -> 2.9.1
security/pear-Horde_Share 2.0.6 -> 2.0.7
deskutils/horde-kronolith 4.2.6 -> 4.2.7
2015-06-10 20:08:19 +00:00
Matthias Andree
a155e91284 Update to new upstream release 2.3.7.
Fixes
PR:		194745
2015-06-10 19:18:56 +00:00
Michael Moll
fbb167f38e security/rubygem-ezcrypto: update gemspec patch to new ruby-gems version
Approved by:	swills (mentor)
2015-06-10 18:31:23 +00:00
Xin LI
68d04a0b91 Document libzmq4 V3 protocol handler protocol downgrade vulnerability.
PR:		200502
Submitted by:	Jason Unovitch
2015-06-10 18:09:20 +00:00
Xin LI
aec2eea161 Document pgbouncer remote denial of service vulnerability.
PR:		200537
Submitted by:	Jason Unovitch
2015-06-10 17:34:21 +00:00
Dmitry Marakasov
2bde83a0ab - Add NO_ARCH
- Drop @dirrm* from plist
2015-06-10 17:31:28 +00:00
Dmitry Marakasov
52f63861fa - Add LICENSE
- Drop @dirrm* from plist
2015-06-10 17:31:10 +00:00
Dmitry Marakasov
0ff1d82b3d - Fix library installation
- Drop @dirrm* from plist
2015-06-10 17:30:39 +00:00
Sunpoet Po-Chuan Hsieh
89095d6067 - Update to 0.06
- Fix LICENSE section
- Strip shared library
- Sort PLIST
2015-06-10 16:46:52 +00:00
Sunpoet Po-Chuan Hsieh
a8b39f7972 - Add NO_ARCH
- Sort USE_PYTHON
2015-06-10 16:45:41 +00:00
David Thiel
7de0f110f8 Update to 3.10.2
PR:		200644
2015-06-09 23:30:05 +00:00
Xin LI
c79d94ea8a Document cups multiple vulnerabilities. 2015-06-09 23:17:10 +00:00
Carlo Strub
b7de740ccd Update to 1.4.1 2015-06-09 21:16:43 +00:00
Sunpoet Po-Chuan Hsieh
63ca95e487 - Update to 15.2.1
Changes:	http://twistedmatrix.com/trac/browser/tags/releases/twisted-15.2.1/twisted/conch/topfiles/NEWS
2015-06-09 18:29:48 +00:00
Renato Botelho
30bfe91aba Update to 5.3.2
PR:		200721
Approved by:	strongswan@Nanoteq.com (maintainer)
MFH:		2015Q2
Security:	CVE-2015-3991
Sponsored by:	Netgate
2015-06-09 09:51:07 +00:00
Xin LI
b882d8e5f7 Document two strongswan vulnerabilities.
PR:		200721
Submitted by:	Jason Unovitch (with changes: wrapped long line and changed
		CVE-2015-3991's coverage to cover only < 5.3.1 to reflect
		the reality).
2015-06-09 08:23:28 +00:00
Dirk Meyer
bdc1f678dc - add freebsd-mips target 2015-06-09 03:54:40 +00:00
Xin LI
28dc96b72b Document redis EVAL Lua sandbox escape vulnerability. 2015-06-08 22:33:12 +00:00
Bryan Drewery
38f4ee3546 Update to 20150608 snapshot 2015-06-08 20:32:39 +00:00
Muhammad Moinur Rahman
96849c29ea security/fcrackzip: Take MAINTAINERSHIP
- Fix pkg-descr
- Add LICENSE (GPLv2)
- Fix patch files to reflect 'make makepatch'

Approved by:	stefan (maintainer)
2015-06-08 18:20:24 +00:00
Thierry Thomas
767875cfe8 Add an entry for www/tidy-* heap-buffer-overflow.
PR:		ports/200631
Submitted by:	Walter Hop
2015-06-08 17:30:48 +00:00
Xin LI
b3b0de6332 Fix typo and remove PHP from pcre vulnerabilities, as the bundled pcre
is not used.
2015-06-07 21:07:34 +00:00
Xin LI
1e55242432 Document fixed version of pcre in e69af246-0ae2-11e5-90e4-d050996490d0. 2015-06-07 20:53:12 +00:00
Dmitry Marakasov
a9702cc92e - Fix shebangs
Approved by:	portmgr blanket
MFH:		2015Q2
2015-06-07 15:02:47 +00:00
Cy Schubert
9c8a8cdb81 MIT KRB5 ports build unusable binaries due to incorrect linking
when build under poudriere. This commit fixes that.
2015-06-06 20:27:21 +00:00
Sunpoet Po-Chuan Hsieh
4e60fe4607 - Update VuXML
PR:		200196
Submitted by:	Jason Unovitch <jason.unovitch@gmail.com>
2015-06-06 18:21:17 +00:00
Sunpoet Po-Chuan Hsieh
cac3c7bdd8 - Update to 2.0.2
Changes:	https://github.com/pbhogan/scrypt/blob/master/CHANGELOG.md
2015-06-06 18:09:02 +00:00
Johan van Selst
8f3a22bc3d Update ocaml-ssl to 0.5.1 2015-06-06 10:16:08 +00:00
Kubilay Kocak
71ee70bfe9 security/ca_root_nss: Enable certificate verification (for Base OpenSSL)
Enable the ETCSYMLINK option so that SSL certificate verification is
enabled by default for OpenSSL in base.

This change is the third in a set of changes [1][2] that improves the
default configuration and behaviour of client software relying on
OpenSSL for SSL/TLS and certificate verification.

A symlink is installed which points to the root certificate bundle in
the location that OpenSSL in base looks for them, as configured at build
time [2].

This allows any and all software utilising SSL_CTX_load_verify_locations
function to verify SSL certificates by default after installation of
this package.

[1] https://svnweb.freebsd.org/changeset/ports/372629
[2] https://svnweb.freebsd.org/changeset/ports/378720

PR:		189811 196357
Requested by:	many
Submitted by:	dreamcat4 gmail com
Approved by:	maintainer timeout (>1 year)
2015-06-06 07:41:51 +00:00
Ryan Steinmetz
56eb86dda9 - Re-add PHP removed in previous commit
- Update pcre to use lt instead of gt
2015-06-05 23:54:01 +00:00
Dmitry Marakasov
d97acea550 - Fix shebangs
MFH:		2015Q2
2015-06-05 21:10:28 +00:00
Sunpoet Po-Chuan Hsieh
81b0a6b1ad - Update to 1.69
- Allow to strip shared library as regular user

Changes:	http://search.cpan.org/dist/Net-SSLeay/Changes
2015-06-05 18:58:42 +00:00
Sunpoet Po-Chuan Hsieh
99da532f7b - Update to 2.0.1
Changes:	https://github.com/pbhogan/scrypt/blob/master/CHANGELOG.md
2015-06-05 18:57:39 +00:00
Ryan Steinmetz
6089ce0942 - Make version matching on the pcre vuln a little more sane
- Remove PHP as the vulnerability appears to be in devel/pcre, not php
2015-06-05 15:42:30 +00:00
Xin LI
dd0a369a8e Document two recent pcre vulnerabilities that can be triggered by
specifically crafted *patterns* and would lead to stack or heap
overflow.
2015-06-04 18:18:32 +00:00
Renato Botelho
4ad8b7b012 Fix spell 2015-06-04 16:49:18 +00:00
Kurt Jaeger
971a2d4418 security/p5-Crypt-OpenSSL-X509: 1.8.04 -> 1.8.06
- Patch from James Hunt to print OpenSSL version during tests.
- Patch from Uli Scholler to expose more SHA1 hash functions.
2015-06-04 14:24:28 +00:00
Dmitry Marakasov
2007ab6213 - Add CPE info
Approved by:	portmgr blanket
2015-06-04 09:41:11 +00:00
Sergey A. Osokin
60265856d7 Update information for graphics/libraw.
PR:	200194
2015-06-04 00:35:58 +00:00
Sunpoet Po-Chuan Hsieh
e0e15d5350 - Add NO_ARCH 2015-06-03 18:44:40 +00:00
Philippe Audeoud
fe28e34a73 - Update to 2.016 2015-06-03 14:59:16 +00:00
Bryan Drewery
661be7b08d Add openssh-portable-devel which is based on the upstream snapshots for staging and testing.
Its initial version is 20150602 which is nearly the upcoming 6.9 version.
2015-06-02 15:00:43 +00:00
Muhammad Moinur Rahman
ad200cb53f security/munge: Add munged_flags in rc file
PR:		200401
Submitted by:	jrm@ftfl.ca
2015-06-02 14:58:24 +00:00
Dmitry Marakasov
711fc64907 - Drop @dirrm* from plist 2015-06-02 12:28:39 +00:00
Dmitry Marakasov
876d7ded10 - Drop @dirrm* from plist 2015-06-02 12:27:50 +00:00
Dmitry Marakasov
fd9fd03443 - Drop @dirrm* from plist 2015-06-02 12:27:44 +00:00
John Marino
a81958dcf7 security/vuxml: multiple vulnerabilities of wpa_supplicant and hostapd
Security:	CVE-2015-4141
Security:	CVE-2015-4142
Security:	CVE-2015-4143
Security:	CVE-2015-4144
Security:	CVE-2015-4145
Security:	CVE-2015-4146
PR:		200568
2015-06-02 09:44:25 +00:00
John Marino
05d3374ae0 security/wpa_supplicant: Address 3 latest security advisories
These are combined upstream patches 2015-2, 2015-3, 2015-4
They address the following security advisories:

  * CVE-2015-4141
  * CVE-2015-4142
  * CVE-2015-4143
  * CVE-2015-4144
  * CVE-2015-4145
  * CVE-2015-4146

These advisories also apply to net/hostapd

PR:		200568
Submitted by:	Jason Unovitch
2015-06-02 09:35:23 +00:00
Tijl Coosemans
8d4f980030 Update to 4.1.2 2015-06-02 09:23:15 +00:00
Cy Schubert
a306e71bc9 Update 1.12.3 --> 1.12.4 2015-06-02 05:09:22 +00:00
Jan Beich
5e082eba1f Document recent ffmpeg0 vulnerabilities 2015-06-02 02:50:04 +00:00
Thomas Zander
1f90a61858 Add entry for vulnerable versions of avidemux2 and avidemux26
PR:		200507
Submitted by:	venture37@geeklan.co.uk
2015-06-01 19:37:57 +00:00
Michael Moll
26e358d867 security/vuxml: add www/rubygem-rest-client vulnerabilities
PR:		200504
Differential Revision:	https://reviews.freebsd.org/D2699
Submitted by:	Sevan Janiyan <venture37@geeklan.co.uk>
Approved by:	ports-secteam (delphij, eadler)
Security:	CVE-2015-1820
Security:	CVE-2015-3448
2015-06-01 18:44:14 +00:00
Antoine Brodin
4165d4f275 Adjust after rubygem-jsobfu update 2015-06-01 18:43:21 +00:00
Jan Beich
590b9cdbb8 - Update NSS and ca_root_nss to 3.19.1
- Update Firefox to 38.0.5

Changes:	https://developer.mozilla.org/docs/Mozilla/Projects/NSS/NSS_3.19.1_release_notes
Changes:	https://www.mozilla.org/firefox/38.0.5/releasenotes/
MFH:		2015Q2
2015-06-01 14:21:53 +00:00
Dmitry Marakasov
e870e89760 - Strip library
- Drop @dirrm* from plist
2015-06-01 13:20:25 +00:00
Dmitry Marakasov
4b30f5196d - Fix license
- Add LICENSE_FILE
- Switch to USES=autoreconf
- Strip library
2015-06-01 13:20:18 +00:00
Dmitry Marakasov
89ce01537e - Strip binary
- Add empty directory to plist
2015-06-01 13:19:52 +00:00
Dmitry Marakasov
5210757db1 - Add LICENSE
- Strip binaries
2015-06-01 13:19:34 +00:00
Dmitry Marakasov
f55ed12d52 - Strip libraries 2015-06-01 13:19:21 +00:00
Dmitry Marakasov
2a5a38f385 - Drop @dirrm* from plist
- Strip libraries
2015-06-01 12:59:22 +00:00
Dmitry Marakasov
316301e7ae - Drop @dirrm* from plist
- Add LICENSE
2015-06-01 12:58:46 +00:00
Dmitry Marakasov
f62f47e405 - Strip library 2015-06-01 12:58:12 +00:00
Dmitry Marakasov
51939be9ff - Strip library 2015-06-01 12:57:59 +00:00
Bernard Spil
26f1835cc0 security/libressl: Backport change for missing EGD feature
- LibreSSL uses opensslfeatures.h to set defines for removed features
 - RAND_egd support was removed before first portable release
 - Change adds OPENSSL_NO_EGD define to make porting easier
 - Change is part of coming 2.2.0 version

Approved by:    vsevolod (maintainer, mentor), koobs (mentor)
Obtained from:  OpenBSD
MFC after:      1 month
2015-06-01 07:25:54 +00:00
Xin LI
959368f6ce - Add kodi to 57325ecf-facc-11e4-968f-b888e347c638 [1]
- Update entry dates for newly added entry.

PR:		200200 [1]
Submitted by:	Jason Unovitch [1]
2015-06-01 07:24:48 +00:00
Xin LI
821766b0f6 Reflect CVE-2015-2060 and CVE-2014-9556.
PR:		ports/198955
Submitted by:	Jason Unovitch
2015-06-01 05:59:00 +00:00
Dmitry Marakasov
3fdeaafa50 - Clarify LICENSE
- Add LICENSE_FILE
- Modernize plist
2015-06-01 01:30:37 +00:00
Dmitry Marakasov
14a697a9f1 - Add LICENSE_FILE
- Modernize plist
2015-06-01 01:30:03 +00:00
Dmitry Marakasov
7b85f229ae - Strip library 2015-06-01 01:29:30 +00:00
Sunpoet Po-Chuan Hsieh
ddc8d1cbdc - Update RUN_DEPENDS
- Update WWW
2015-05-31 19:28:02 +00:00
Li-Wen Hsu
1176ccfe8b - Document django vulnerability CVE-2015-3982 2015-05-31 16:07:52 +00:00
Sunpoet Po-Chuan Hsieh
629c083392 - Update to 0.4.2
Changes:	https://github.com/jgraichen/omniauth-multipassword/commits/master
2015-05-31 14:58:37 +00:00
Jason E. Hale
ddabf7e94e Update to 2.2.1 2015-05-31 14:30:55 +00:00
Dmitry Marakasov
4d4b259bcd - Add NO_ARCH
Approved by:	portmgr blanket
2015-05-31 13:37:20 +00:00
Dmitry Marakasov
04f8be528a - Fix shebangs
- Add NO_ARCH

Approved by:	portmgr blanket
MFH:		2015Q2
2015-05-31 13:23:34 +00:00
Dmitry Marakasov
fddee7fcd6 - Fix shebangs
- Add NO_ARCH

Approved by:	portmgr blanket
MFH:		2015Q2
2015-05-31 13:22:34 +00:00
Dmitry Marakasov
b44679900d - Fix shebangs
Approved by:	portmgr blanket
MFH:		2015Q2
2015-05-31 13:16:51 +00:00
Xin LI
fc893d96d5 Extend 57325ecf-facc-11e4-968f-b888e347c638 to cover rawstudio as well.
PR:		200199
Submitted by:	Jason Unovitch
2015-05-31 08:08:16 +00:00
Sunpoet Po-Chuan Hsieh
35bab580f9 - Update to 2.2.1
Changes:	https://github.com/doorkeeper-gem/doorkeeper/blob/master/NEWS.md
2015-05-30 23:12:14 +00:00
Mathieu Arnold
90a49f0472 Cleanup USE_GITHUB usage.
With hat:	portmgr
Sponsored by:	Absolight
2015-05-30 21:25:06 +00:00
Sunpoet Po-Chuan Hsieh
bbf5e20d82 - Update to 0.17
Changes:	http://search.cpan.org/dist/IO-Async-SSL/Changes
2015-05-30 13:13:03 +00:00
Dmitry Marakasov
73428e8a99 - Fix shebangs
- Add NO_ARCH

Approved by:	portmgr blanket
MFH:		2015Q2
2015-05-30 12:30:31 +00:00
Muhammad Moinur Rahman
d66cb91098 security/afterglow: Fix PORTSCOUT to skip 2.0 beta version 2015-05-30 12:04:19 +00:00
Dmitry Marakasov
7c8576cf93 - Drop @dirrm* from plist
- Add LICENSE_FILE
2015-05-30 00:31:34 +00:00
Xin LI
cf1948f801 Document the issue with proxychains-ng which uses current directory when
searching for its own shared library (CVE-2015-3887).

PR:		200511
Submitted by:	Jason Unovitch
2015-05-29 22:20:31 +00:00
Dmitry Marakasov
60fe6f7f2c - Add LICENSE_FILE
- Remove MAN1
2015-05-29 11:04:36 +00:00
Dmitry Marakasov
1ff32a297c - Switch to USES=autoreconf 2015-05-28 20:27:53 +00:00
Xin LI
97d2747632 Document wireshark multiple vulnerabilities. 2015-05-28 19:47:24 +00:00
Xin LI
78feb50be8 Apply vendor patch for CVE-2015-2694 (changeset
b0c571e709c72da799ccc15fb5755f7910170e33) to prevent requires_preauth
bypass.

Approved by:	so
Obtained from:	b0c571e709.diff
Security:	CVE-2015-2694
Security:	0b040e24-f751-11e4-b24d-5453ed2e2b49
MFH:		2015Q2
2015-05-28 17:48:17 +00:00
Xin LI
59eb6493d2 Document krb5 requires_preauth bypass in PKINIT-enabled KDC. 2015-05-28 17:46:26 +00:00
Dmitry Marakasov
f6299e88b2 - Update to 0.40
PR:		200490
Submitted by:	hvo.pm@xs4all.nl (maintainer)
2015-05-28 11:13:53 +00:00
Dmitry Marakasov
3c276a0a9f Unbreak INDEX 2015-05-27 23:01:14 +00:00
Dmitry Marakasov
9cee0306eb - Update to 0.400
PR:		200392
Submitted by:	hvo.pm@xs4all.nl (maintainer)
2015-05-27 21:22:43 +00:00
Dmitry Marakasov
bef55936cf This module provides a secure, efficient, and simple interface for
creating session tokens, password reset codes, temporary passwords,
random identifiers, and anything else you can think of.

Like this: my $token = Session::Token->new->get; # 128 bits

WWW: http://search.cpan.org/dist/Session-Token/

PR:		200390
Submitted by:	hvo.pm@xs4all.nl
2015-05-27 21:21:54 +00:00
Ryan Steinmetz
8c315c3a3b - Update to 2.9.7.3 2015-05-27 17:54:56 +00:00
Dmitry Marakasov
68a5cc350c - Don't cat pkg-message from Makefiles
Approved by:	portmgr blanket
2015-05-27 00:09:55 +00:00
Dmitry Marakasov
74654a4da4 - Update to upstream version 1.20
- Quote variable in MAKE_ARGS
- Remove STACKPROTECTOR and STACKPROTECTORALL from OPTIONS
- Use tag instead of commit hash in GH_TAGNAME

- While here, add LICENSE_FILE

PR:		200412
Submitted by:	horia@racoviceanu.com (maintainer)
2015-05-26 23:47:18 +00:00
Xin LI
2a743f346c Retrofit document cURL multiple vulnerabilities. 2015-05-26 22:15:05 +00:00
Michael Moll
68bf3ab2bb new port: security/rubygem-rack-oauth2
OAuth 2.0 Server & Client Library.

WWW: https://github.com/nov/rack-oauth2

PR:		199922
Differential Revision:	https://reviews.freebsd.org/D2638
Submitted by:	Torsten Zuehlsdorff <ports@toco-domains.de>
Approved by:	mat (mentor)
2015-05-26 18:11:32 +00:00