Commit graph

14425 commits

Author SHA1 Message Date
Martin Wilke
aaf8e0c47c - Cleanup previous entry 2011-02-23 14:43:41 +00:00
Florian Smeets
8b5a0e6344 - add asterisk -- Exploitable Stack and Heap Array Overflows 2011-02-22 21:30:18 +00:00
Renato Botelho
eb8d173c48 Fix detection if python was built with threads support and run make check
accordingly

PR:		ports/154848
Submitted by:	Martin Simmons <martin@lispworks.com>
2011-02-21 11:35:52 +00:00
Cheng-Lung Sung
b5b9e94db8 - Update to 2.0.24 2011-02-20 11:32:58 +00:00
Xin LI
4443818f1f Document PivotX administrator password reset vulnerability. 2011-02-20 05:04:28 +00:00
Martin Wilke
a9d926beb4 - Update to 3.5.1
PR:		154588
Submitted by:	Cezary Morga <cm@therek.net>
Approved by:	maintainer timeout
2011-02-19 12:49:34 +00:00
Wesley Shields
c3765ac8e1 Apply two patches:
- Fix build when --enable-dynamicplugins is not given to configure. [1]
- Fix a segfault in HttpInspect

PR:		ports/154868
Submitted by:	Dean Freeman <wfreeman@sourcefire.com> (maintainer)
		[1]: Michael Scheidell
2011-02-18 20:06:36 +00:00
Wen Heping
8c6e637343 - Update to 0.5.29 2011-02-17 03:25:42 +00:00
Thomas Abthorpe
7387137ea8 Reassign ports to the pool, thanks for your service, we hope to see you
back.
2011-02-16 03:46:50 +00:00
Martin Wilke
9fb10a5d3e - Update lastest tomcat entry (tomcat6/7 have the same problem)
Note: Please ask for review at ports-security@  THX!
2011-02-15 08:18:21 +00:00
Wen Heping
b6bcb75050 - Document tomcat vulnerability 2011-02-15 08:00:38 +00:00
Johan van Selst
8e72fed5ce - Update libecc 0.13.0
- Includes shlib bump
2011-02-14 22:01:30 +00:00
Pav Lucistnik
0b40fb1da6 - Remove stray cmd from plist that created bogus file on pkg_add
Reported by:	pointyhat
2011-02-13 22:17:19 +00:00
Olli Hauer
997592b8db - fix leftover if APACHE_VERSION > 13
PR:		ports/147009
2011-02-13 22:06:37 +00:00
Olli Hauer
8d8c954d31 - update to version 5.51
Nmap 5.51 [2011-02-11]

o [Ndiff] Added support for prerule and postrule scripts. [David]

o [NSE] Fixed a bug which caused some NSE scripts to fail due to the
  absence of the NSE SCRIPT_NAME environment variable when loaded.
  Michael Pattrick reported the problem. [Djalal]

o [Zenmap] Selecting one of the scan targets in the left pane is
  supposed to jump to that host in the Nmap Output in the right pane
  (but it wasn't).  Brian Krebs reported this bug. [David]

o Fixed an obscure bug in Windows interface matching. If the MAC
  address of an interface couldn't be retrieved, it might have been
  used instead of the correct interface. Alexander Khodyrev reported
  the problem.  [David]

o [NSE] Fixed portrules in dns-zone-transfer and ftp-proftpd-backdoor
  that used shortport functions incorrectly and always returned
  true. [Jost Krieger]

o [Ndiff] Fixed ndiff.dtd to include two elements that can be diffed:
  status and address. [Daniel Miller]

o [Ndiff] Fixed the ordering of hostscript-related elements in XML
  output. [Daniel Miller]

o [NSE] Fixed a bug in the nrpe-enum script that would make it run for
  every port (when it was selected--it isn't by default).  Daniel
  Miller reported the bug. [Patrick]

o [NSE] When an NSE script sets a negative socket timeout, it now
  causes a controlled Lua stack trace instead of a fatal error.
  Vlatko Kosturjak reported the bug. [David]

o [Zenmap] Worked around an error that caused the py2app bootstrap
  executable to be non-universal even when the rest of the application
  was universal. This prevented the binary .dmg from working on
  PowerPC. Yxynaxen reported the problem. [David]

o [Ndiff] Fixed an output line that wasn't being redirected to a file
  when all other output was. [Daniel Miller]
2011-02-13 19:36:36 +00:00
Alexey Dokuchaev
616b037062 - Update jumbo patch to version 11
- Add LICENSE (GPLv2)
2011-02-13 14:12:21 +00:00
Sahil Tandon
034342f190 Expand the range of supported Python versions and
pacify portlint(1).

PR:		ports/154374
Submitted by:	Jase Thew <freebsd@beardz.net>
Approved by:	maintainer timeout
2011-02-13 07:01:53 +00:00
Frederic Culot
e74b252d55 - Update to 5.7
Changes:	http://squidclamav.darold.net/news.html
PR:		ports/154691
Submitted by:	Laurent Levier <llevier AT argosnet.com> (maintainer)
2011-02-12 09:38:53 +00:00
Andrej Zverev
85b13ac345 Fix WWW in pkg-descr to http://search.cpan.org/dist/<MODULE> for unification.
No functional changes.

Sponsored by:	p5 namespace
2011-02-12 09:30:23 +00:00
Xin LI
57763c8ea6 Document two phpMyAdmin vulnerabilities. 2011-02-11 22:23:47 +00:00
Juergen Lock
4edd8ea987 Update to 10.2r152.
PR:		ports/154630
Submitted by:	Tsurutani Naoki <turutani@scphys.kyoto-u.ac.jp>
Security:	http://www.freebsd.org/ports/portaudit/4a3482da-3624-11e0-b995-001b2134ef46.html
Feature safe:	yes
2011-02-11 21:39:03 +00:00
Xin LI
802d02a1b7 Document mupdf PDF handling remote code execution vulnerability.
Submitted by:	Tim Zingelman <tez netbsd.org>
2011-02-11 19:59:48 +00:00
Xin LI
7adbdc82a2 Document rubygem-mail Remote Arbitrary Shell Command Injection Vulnerability.
Submitted by:	Tim Zingelman <tez netbsd.org>
2011-02-11 19:51:20 +00:00
Xin LI
7fb7de0219 Document plone remote security bypass vulnerability.
Submitted by:	Tim Zingelman <tez netbsd.org>
2011-02-11 19:48:03 +00:00
Xin LI
daf58256ad Document exim local privilege escalasion vulnerability.
Submitted by:	Tim Zingelman <tez netbsd.org>
2011-02-11 19:40:12 +00:00
Xin LI
5664bbedc9 Document OpenOffice multiple vulnerabilities.
Submitted by:	Tim Zingelman <tez netbsd.org>
2011-02-11 19:36:45 +00:00
Brooks Davis
7eeab3d6e6 Update to 2.2.2
PR:		ports/154568
Submitted by:	Ruslan Mahmatkhanov
2011-02-11 18:12:28 +00:00
Sunpoet Po-Chuan Hsieh
846198cc68 - Update MAINTAINER address 2011-02-11 08:27:24 +00:00
Sunpoet Po-Chuan Hsieh
058c615405 - Update to 2.9.0.4
- Update snortsam checksum
- Fix LIBNET_CONFIG issue
- Pet portlint

Changes:	http://www.snort.org/downloads/740
PR:		ports/154668
Submitted by:	Dean Freeman <wfreeman@sourcefire.com> (maintainer)
2011-02-11 08:01:39 +00:00
Cy Schubert
2d5c97dc53 Apply fixes for kpropd denial of service (MITKRB5-SA-2011-001) and KDC
denial of service (MITKRB5-SA-2011-002).

Security:	MITKRB5-SA-2011-001 (CVE-2010-4022),
		MITKRB5-SA-2011-002 (CVE-2011-0281)
2011-02-11 01:04:09 +00:00
Dirk Meyer
74bfc0300e - Security update to 1.0.0d
Security: http://openssl.org/news/secadv_20110208.txt
Security: CVE-2011-0014
Feature safe:	yes
2011-02-10 18:30:34 +00:00
Martin Wilke
4f067e03ce - Cleanup previous commit 2011-02-10 16:44:00 +00:00
Koop Mast
f089b1925b Document multiple webkit-gtk2 security vulnabilities, fixed in 1.2.7. 2011-02-10 10:41:58 +00:00
Peter Pentchev
5bafc9702d Update to stunnel-4.35:
- drop the transparent proxying patch, integrated upstream
- while I'm here, fix the very first master site URL -
  the download page on stunnel.org just links to the sites now,
  and does not contain downloadable source

PR:		154631
Submitted by:	Tsurutani Naoki <turutani@scphys.kyoto-u.ac.jp>
2011-02-10 09:34:59 +00:00
Xin LI
1683ca14df Document awstat multiple vulnerability.
Notified by:    Tim Zingelman <tez netbsd.org>
2011-02-10 00:44:26 +00:00
Xin LI
8df64b351b Document Opera multiple vulnerabilities.
Notified by:	Tim Zingelman <tez netbsd.org>
2011-02-10 00:28:17 +00:00
Xin LI
6054a2050b Document multiple vulnerabilities in Django.
Notified by:	Jesco Freund <jesco.freund my-universe.com>
2011-02-09 21:37:55 +00:00
Cheng-Lung Sung
26212e8cb3 - Update to 2.9.0.3 [1]
- pass maintainership to William Freeman <wfreeman_AT_sourcefire dot com>

Note: This attached patch replaces the one in ports/153998.
      Also fixes the location of the dynamic libs/rules in ports/153224.
PR:		ports/154514 [1], ports/153998 [2]
Submitted by:	Michael Scheidell <scheidell_AT_secnap dot net>
2011-02-09 06:50:03 +00:00
Cy Schubert
fd14e293b5 Update 4.1.2 --> 4.1.3 2011-02-09 05:51:54 +00:00
Martin Wilke
1f309f19b4 - S/seriuos/serious 2011-02-09 05:36:33 +00:00
Martin Wilke
1b8421c704 - Document mediawiki - multiple vulnerabilites 2011-02-09 05:23:00 +00:00
Martin Wilke
9295de19b6 - Add chinese/wordpress-zh_CN and chinese/wordpress-zh_TW to the previous wordpress entry 2011-02-09 04:53:12 +00:00
Renato Botelho
2640092f35 Update to 0.97
Feature safe:	yes
2011-02-08 12:13:53 +00:00
Doug Barton
4cf0626f6b Version 2.0.17 was released on 2011-01-13:
What's New
===========
* Allow more hash algorithms with the OpenPGP v2 card.
* The gpg-agent now tests for a new gpg-agent.conf on a HUP.
* Fixed output of "gpgconf --check-options".
* Fixed a bug where Scdaemon sends a signal to Gpg-agent running in
  non-daemon mode.
* Fixed TTY management for pinentries and session variable update
  problem.
* Minor bug fixes.

For the port:
Camellia stopped being a configure option in 2.0.12
Fix minor typo for GPGSM OPTION
Minor plist update for 2.0.17

files/patch-keybox-blob.c seems to be no longer needed [2]

PR:		ports/153984
Submitted by:	me
Submitted by:	Hirohisa Yamaguchi <umq@ueo.co.jp> [2]
Approved by:	maintainer timeout (24 days)
Feature safe:	yes
2011-02-08 03:40:15 +00:00
Hajimu UMEMOTO
1c2c5282c5 Try to fix GSSAPI when using heimdal from ports.
Submitted by:	Graham Todd <gtodd__at__bellanet.org>
Feature safe:	yes
2011-02-06 08:00:08 +00:00
Hajimu UMEMOTO
cba09ab3e5 Backout previous commit.
Unfortunately, it broke GSSAPI when using heimdal in base.
I have no idea how to detect whether heimdal is in base or
from ports, now.

Feature safe:	yes
2011-02-06 07:41:12 +00:00
Martin Wilke
85c93697cb - Use GOOGLE_CODE/LOCAL macro
PR:		153113
Submitted by:	Sunpoet Po-Chuan Hsieh <sunpoet@FreeBSD.org>
Approved by:	maintainer timeout
Feature safe:	yes
2011-02-05 11:19:28 +00:00
Martin Wilke
da3e156fec * Fix GSSAPI when using heimdal from ports
PR:		152071
Submitted by:	Joerg Pulz <Joerg.Pulz@frm2.tum.de>
Approved by:	maintainer timeout
Feature safe:	yes
2011-02-05 06:55:32 +00:00
Martin Wilke
b7e4515267 - While here drop MD5 Support
Feature safe:	yes
2011-02-05 04:37:18 +00:00
Martin Wilke
3fdaa0b9fa - Add entry for wordpress - SQL injection vulnerability
PR:		153526
Submitted by:	Mark Foster <mark@foster.cc>
Feature safe:	yes
2011-02-05 04:36:36 +00:00