Commit graph

22067 commits

Author SHA1 Message Date
Thomas Zander
a8d0d986c6 Un-break build on systems where cxx does not support c++11
PR:		203992
Submitted by:	eric@camachat.org (maintainer)
2015-10-24 13:10:50 +00:00
Matthias Andree
70092ef822 Handle OpenSSL/PolarSSL options in the right way,
such that it is maintainable if we add more SSL libs in the future.

To fix fall-out from r399858 and r399982.
2015-10-24 11:18:04 +00:00
Jason Unovitch
f919e6acd7 Document redirect vulnerability in the drupal7 overlay module
PR:		203977
Security:	CVE-2015-7943
Security:	https://vuxml.FreeBSD.org/freebsd/75f39413-7a00-11e5-a2a1-002590263bf5.html
2015-10-24 03:55:25 +00:00
Danilo Egea Gondolfo
75f6a10389 - New port: security/s2n
s2n is a C99 implementation of the TLS/SSL protocols that
is designed to be simple, small, fast, and with security as
a priority. It is released and licensed under the Apache Software License 2.0.

WWW: https://github.com/awslabs/s2n
2015-10-23 22:48:34 +00:00
Matthew Seaman
1cf82dbf08 Record phpMyAdmin -- content spoofing vulnerability. 2015-10-23 20:39:41 +00:00
Thomas Zander
6f1821384b Update to upstream version 2.4.1, add BROKER OPTION
PR:		203849
Submitted by:	leres@ee.lbl.gov (maintainer)
2015-10-23 19:04:50 +00:00
Dmitry Marakasov
d0e4a5817f - Add NO_ARCH
- Drop @dirrm* from plist

Approved by:	portmgr blanket
2015-10-23 18:36:52 +00:00
Thomas Zander
8e02189b35 Adopt broccoli version numbering, update to 1.97
The gist from maintainer's explanation of the situation:
Upon creation of the port, the version number of the bro
distribution broccoli was packaged with was used. But it
makes more sense to use broccoli's actual version number.

PR:		203848
Submitted by:	leres@ee.lbl.gov (maintainer)
2015-10-23 18:12:26 +00:00
Xin LI
08f34c37a2 Add CVE references to the NTP entry. 2015-10-23 11:59:59 +00:00
Jason Unovitch
fc111cf1ce Document Mediawiki security vulnerabilities for 1.25.3, 1.24.4, and 1.23.11
Security:	https://vuxml.FreeBSD.org/freebsd/b973a763-7936-11e5-a2a1-002590263bf5.html
2015-10-23 03:43:36 +00:00
Martin Matuska
f927ae941d Horde package update:
comms/pear-Horde_ActiveSync 2.29.2 -> 2.30.0
devel/pear-Horde_Core 2.22.0 -> 2.22.1
devel/pear-Horde_Nls 2.0.5 -> 2.1.0
devel/pear-Horde_Notification 2.0.2 -> 2.0.3
textproc/pear-Horde_Pdf 2.0.5 -> 2.0.6
devel/pear-Horde_Queue 1.1.2 -> 1.1.3
security/pear-Horde_Secret 2.0.4 -> 2.0.5
www/pear-Horde_SessionHandler 2.2.4 -> 2.2.5
devel/pear-Horde_Token 2.0.6 -> 2.0.7
devel/horde-content 2.0.4 -> 2.0.5
ftp/horde-gollem 3.0.5 -> 3.0.6
www/horde-base 5.2.7 -> 5.2.8
mail/horde-imp 6.2.10 -> 6.2.11
mail/horde-ingo 3.2.6 -> 3.2.7
deskutils/horde-kronolith 4.2.9 -> 4.2.11
deskutils/horde-mnemo 4.2.7 -> 4.2.8
deskutils/horde-nag 4.2.5 -> 4.2.6
www/horde-passwd 5.0.3 -> 5.0.4
www/horde-trean 1.1.2 -> 1.1.3
mail/horde-turba 4.2.8 -> 4.2.10
mail/horde-webmail 5.2.10 -> 5.2.11
deskutils/horde-groupware 5.2.10 -> 5.2.11
2015-10-22 16:00:30 +00:00
Mathieu Arnold
89d49eb53f Fix build without POLARSSL.
Pointy hat to:	mat
Sponsored by:	Absolight
2015-10-22 14:07:10 +00:00
Kubilay Kocak
ce8374460e security/suricata: Update to 2.0.9
- Update PORTVERSION and distinfo checksum (2.0.9)

Changes:

  https://github.com/inliniac/suricata/blob/suricata-2.0.9/ChangeLog

While I'm here,

- Standardize the length of pkg-message separators and add spaces
  between them and the text body. <idea> It would be cool if the ports
  framework could wrap these pkg-message's in standard formatting for
  all ports automagically</idea>

Requested by:	Martin Olsson (via email)
2015-10-22 11:56:31 +00:00
Cy Schubert
898655c0cb Document October 2015 NTP Security Vulnerability Announcement (Medium) 2015-10-22 03:03:30 +00:00
Dan Langille
395599811e - Update to 2.9.7.6
Reviewed by: zi (maintainer)
Differential Revision: https://reviews.freebsd.org/D3963
2015-10-21 17:59:38 +00:00
Mathieu Arnold
4cb8340ae5 Update to 2.0-beta2.
- Bump PORTEPOCH as version goes backwards
- Remove unneeded variables
- Pet portlint

PR:		203913
Submitted by:	maintainer
Sponsored by:	Absolight
2015-10-21 14:16:25 +00:00
Mathieu Arnold
4597301bdf Update to 201541. [1]
Convert to options helpers.

PR:		203823 [1]
Submitted by:	maintainer
Sponsored by:	Absolight
2015-10-21 14:16:18 +00:00
Tijl Coosemans
fd89eecc7a Update to 4.1.8 2015-10-21 11:53:36 +00:00
Cy Schubert
fa0fbc575d Add sonames and minor versioned library names.
PR:             203882
2015-10-21 06:59:10 +00:00
Kubilay Kocak
d9484b7997 security/py-cryptography: Add enum43 to RUN_DEPENDS
Refactor *_DEPENDS to match setup.py's less than obvious dependencies

cffi is both a build/run dependency, the rest are only run dependencies.

This was causing a build failure for net-im/papyon:

  ImportError: No module named enum

Reported by:	kwm, pkg-fallout
Assisted by:	antoine
2015-10-20 15:14:08 +00:00
Mathieu Arnold
ca0156916b Use options helpers.
Sponsored by:	Absolight
2015-10-20 15:03:44 +00:00
Jason Unovitch
379ee526f4 Document multiple XSS vulnerabilities fixed in CodeIgniter
PR:		203403
Security:	https://vuxml.FreeBSD.org/freebsd/95602550-76cf-11e5-a2a1-002590263bf5.html
2015-10-20 02:33:47 +00:00
Sunpoet Po-Chuan Hsieh
2743e8d9cf - Add NO_ARCH
- While I'm here, use "yes" instead of "YES"

Approved by:	portmgr (blanket)
2015-10-19 20:22:29 +00:00
Sunpoet Po-Chuan Hsieh
5b9e9cd2dc - Use USES=localbase
- Pet portlint: fix diff header of patch files
2015-10-19 20:21:10 +00:00
Renato Botelho
b5f8054f06 Add new VuXML entry for git arbitrary code execution bug on versions before
2.6.1
2015-10-19 17:04:02 +00:00
Dmitry Marakasov
67971bd0fb Improve shebangfix framework
- Support multiple values in *_OLD_CMD, i.e. we can now fix both "/usr/bin/python" and "/usr/bin/env python" at the same time
- Default *_OLD_CMD values are now always appended, so you don't need to specify them in individual ports
- Add lua support (depends on USES=lua)
- Add more default values, such as "/usr/bin/env foo" for python, perl, bash, ruby and lua
- Shebangfix now matches whole words, e.g. we will no longer (erroneously) replace "/usr/bin/perl5.005" with "${perl_CMD}5.005" (but "/usr/bin/perl -tt" is still (correctly) replaced with "${perl_CMD} -tt")

Note that *_OLD_CMD items containing spaces must now be quoted (e.g. perl_OLD_CMD=/bin/perl /usr/bin/perl "/usr/bin/env perl")

Update shebangfix usage according to new rules in many ports:

- Remove *_OLD_CMD for patterns now replaced by default
- Quote custom *_OLD_CMD which contain spaces

Fix shebangfix usage in many ports (irrelevant to infrastructure change):

- Remove redundant SHEBANG_LANG (no need to duplicate default langs)
- Remove redundant *_CMD (such as python_CMD=${LOCALBASE}/bin/python${PYTHON_VER} when USES=python is present)
- Never use *_OLD_CMD in REINPLACE_CMD matchers, these should always look for exact string

Approved by:	portmgr (bapt)
Differential Revision:	D3756
2015-10-19 14:50:52 +00:00
Antoine Brodin
b49bc725a0 Finish removing yubikey-personalization 2015-10-19 13:59:03 +00:00
Ryan Steinmetz
e5c19fce71 - Update variable name in previous commit
- Bump PORTREVISION
2015-10-19 13:42:11 +00:00
Ryan Steinmetz
622c375809 - Add additional instances variable for puppet/chef/cfengine/etc use
- Bump PORTREVISION
2015-10-19 13:30:28 +00:00
Jimmy Olgeni
1ff7395d51 Upgrade security/elixir-comeonin to version 1.3.0. 2015-10-19 08:14:23 +00:00
Cy Schubert
ba44c33bf8 Bump PORTREVISION. 2015-10-19 07:29:08 +00:00
Cy Schubert
f43d2cea80 Fix READLINE option.
Add support for libedit (LIBEDIT option).
Both command line editing options now supported by RADIO button.

Fix typo in gssapi: bootstrap.
2015-10-19 07:17:47 +00:00
Cy Schubert
86da5965d8 Fix READLINE option.
Add support for libedit (LIBEDIT option).
Both command line editing options now supported by RADIO button.
2015-10-19 07:13:33 +00:00
Guido Falsi
2f90775268 - Update to 1.3.2
- Add QT4 and QT5 options, to choose toolkit.

PR:		203804
Submitted by:	Ports Fury
2015-10-18 13:41:15 +00:00
Romain Tartière
d4119bd942 Remove security/yubikey-personalization (duplicate of security/ykpers)
PR:		203835
Submitted by:	cmt@burggraben.net
2015-10-18 09:55:55 +00:00
Kubilay Kocak
8b7f69106a security/py-cryptography: Update to 1.0.2
- Update to 1.0.2
- Strip shared libraries
- Add patch to support building with LibreSSL
- Remove ALPN patch (upstreamed)

Changes:

  https://github.com/pyca/cryptography/blob/1.0.2/CHANGELOG.rst

PR:		203819
Submitted by:	Ralf van der Enden <tremere cainites net>
2015-10-18 03:13:53 +00:00
Sunpoet Po-Chuan Hsieh
d791a4add6 - Document Salt multiple vulnerabilities 2015-10-17 18:16:56 +00:00
Sunpoet Po-Chuan Hsieh
b8dd7bfcf0 - Update to 1.4.0
- Add LICENSE
- Add NO_ARCH
- Fix indent

Changes:	http://pear.php.net/package/Crypt_GPG/download/
2015-10-17 18:10:31 +00:00
Sunpoet Po-Chuan Hsieh
5943262277 - Add LICENSE_FILE
- Use USES=localbase
2015-10-17 18:08:22 +00:00
Romain Tartière
f35d4877c1 The YubiKey Personalization Tool is a Qt based Cross-Platform utility designed
to facilitate re-configuration of YubiKeys on Windows, Linux and Mac platforms.
The tool provides a same simple step-by-step approach to make configuration of
YubiKeys easy to follow and understand, while still being powerful enough to
exploit all functionality both of the YubiKey 1 and YubiKey 2 generation of
keys. The tool provides the same functionality and user interface on Windows,
Linux and Mac platforms.

The Cross-Platform YubiKey Personalization Tool provides the following main
functions:
  - Programming the YubiKey in "Yubico OTP" mode;
  - Programming the YubiKey in "OATH-HOTP" mode;
  - Programming the YubiKey in "Static Password" mode;
  - Programming the YubiKey in "Challenge-Response" mode;
  - Programming the NDEF feature of the YubiKey NEO;
  - Testing the challenge-response functionality of a YubiKey;
  - Deleting the configuration of a YubiKey;
  - Checking type and firmware version of the YubiKey.

WWW: https://github.com/Yubico/yubikey-personalization-gui
2015-10-17 12:59:34 +00:00
Romain Tartière
4e001bf384 The YubiKey Personalization package contains a library and command line tool
used to personalize (i.e., set a AES key) YubiKeys.

WWW: https://github.com/Yubico/yubikey-personalization
2015-10-17 12:58:50 +00:00
Steve Wills
f880925a41 Document CVE-2015-7184 in firefox 2015-10-16 18:57:28 +00:00
Steve Wills
dcfa462ca6 security/quantis: fix build with OpenJDK8
PR:		203513
Approved by:	maintainer timeout (ale, >2 weeks)
2015-10-16 18:17:58 +00:00
Koop Mast
82f203006a Document flash 0-day, remove code execution.
Security:	CVE-2015-7645, CVE-2015-7647, CVE-2015-7648
2015-10-16 16:11:19 +00:00
Kubilay Kocak
91364fbc63 security/fwknop: Update to 2.6.7
* Update to 2.6.7
* Update and sort pkg-plist
* Group/sort sections
* Convert to OPTIONS helpers
* Use install-strip target so binaries/libraries are stripped

PR:		203168
Submitted by:	Sean Greven <sean.greven gmail com> (maintainer)
2015-10-16 12:25:21 +00:00
Peter Wemm
e4482bc1e2 Fix the vuxml build caused by a multitude of errors in r399425 (libressl). 2015-10-16 07:44:55 +00:00
Bernard Spil
3dba139b7a security/libressl: Fix memory leak and buffer overflow DoS vulnerability
* Update to 2.2.4 (fixing vulnerabilities)
  * Create vuxml entry

Differential Revision: https://reviews.freebsd.org/D3916
Submitted by:	Bernard Spil <brnrd@freebsd.org>
Reviewed by:	delphij
Approved by:	delphij (secteam)
MFC after:	2015Q4
Security:	e75a96df-73ca-11e5-9b45-b499baebfeaf
Security:	CVE-2015-5333, CVE-2015-5334
2015-10-16 07:13:03 +00:00
Bernard Spil
eac75ec131 security/libressl: Fix memory leak and buffer overflow DoS vulnerability
* Update to 2.2.4 (fixing vulnerabilities)
  * Create vuxml entry

Differential revision: https://reviews.freebsd.org/D3916
Submitted by:	Bernard Spil <brnrd@freebsd.org>
Reviewed by:	delphij (secteam)
Approved by:	delphij
MFC after:	2015Q4
Security:	CVE-2015-5333, CVE-2015-533
2015-10-16 07:08:40 +00:00
Dmitry Marakasov
bf3bcf82ea - Handle permissions in plist
- Unsilence install

Approved by:	portmgr blanket
2015-10-15 21:00:20 +00:00
Sunpoet Po-Chuan Hsieh
41b5b48741 - Add LICENSE_FILE
- Move LICENSE upward
- Add NO_ARCH

Approved by:	portmgr (blanket)
2015-10-15 20:18:56 +00:00