Commit graph

7564 commits

Author SHA1 Message Date
Joe Marcus Clarke
68bf3df3eb Disable the automatic tests on 4.X. They are known to fail.
Reported by:	pointyhat via kris
Approved by:	portmgr (implicit)
2005-08-03 22:08:09 +00:00
Simon L. B. Nielsen
379edd924d Document proftpd -- format string vulnerabilities.
Approved by:	portmgr (blanket, VuXML)
2005-08-03 17:14:16 +00:00
Simon L. B. Nielsen
fa7419cac1 Note that the fix for gnupg -- OpenPGP symmetric encryption
vulnerability in gnupg is not complete (see entry for details).

Discussed with:	nectar
Approved by:	portmgr (blanket, VuXML)
2005-08-03 16:54:47 +00:00
Simon L. B. Nielsen
79a8a98fa3 Mark p5-Crypt-OpenPGP, pgp, and pgpin as vulnerable to gnupg --
OpenPGP symmetric encryption vulnerability.

Reminded by:	nectar
Approved by:	portmgr (blanket, VuXML)
2005-08-03 11:58:12 +00:00
Simon L. B. Nielsen
e439b01dd9 Mark latest gdal version as fixed for all tiff vulnerabilities. 2005-08-01 18:38:11 +00:00
James E. Housley
7cc996ede3 UPdate to DAT 4547 2005-08-01 16:53:45 +00:00
Jun Kuriyama
4ae59b6f7d Fix build failure on 4.x.
Reported by:	"Sander Holthaus - Orange XL" <info@orangexl.com>
2005-08-01 11:17:24 +00:00
Niels Heinen
1e90f90311 Added nbsmtp format string vulnerability.
Approved by:	nectar (mentor)
2005-08-01 07:45:17 +00:00
Simon L. B. Nielsen
78b7cf7598 Mark latest the linux-tiff and pdflib ports safe from latest tiff
vulnerability.

Thanks to lawrance and netchild for fast fixes.
2005-07-31 23:39:50 +00:00
Michael Nottebrock
ecc191066f Update to KDE 3.4.2 / KOffice 1.4.1 2005-07-31 22:46:35 +00:00
Jun Kuriyama
2a9bde49bb Upgrade to 1.4.2.
PR:		ports/84289
Submitted by:	Vasil Dimov <vd@datamax.bg>
2005-07-31 22:31:11 +00:00
Joe Marcus Clarke
2c10cd6b80 Re-add IGNORE message for Alpha < 500035.
Reported by:	mjl on #freebsd-gnome
2005-07-31 21:49:47 +00:00
Thierry Thomas
e6b6ab8c0c Update to 2.0.8.
PR:		83960
Submitted by:	Babak Farrokhi <babak (at) farrokhi.net>
Approved by:	maintainer
2005-07-31 19:53:33 +00:00
Yen-Ming Lee
be396bcc0d - Update to 0.97
PR:		83639
Submitted by:	leeym
Approved by:	maintainer timeout
2005-07-31 17:19:47 +00:00
Simon L. B. Nielsen
609dafe78b Document sylpheed -- MIME-encoded file name buffer overflow
vulnerability.
2005-07-31 15:00:54 +00:00
Simon L. B. Nielsen
5d71ef8197 Document phpmyadmin -- cross site scripting vulnerability. 2005-07-31 13:50:20 +00:00
Simon L. B. Nielsen
053cdd10d9 Document gnupg -- OpenPGP symmetric encryption vulnerability.
Note: this is mainly a theoretical vulnerability.
2005-07-31 13:23:50 +00:00
Sergey Matveychuk
bb022ec8e2 - Look for libraries in LOCALBASE
PR:		ports/83455
Submitted by:	maintainer
2005-07-31 12:06:25 +00:00
Remko Lodder
c58dccb6b5 Bump entry date.
Forgotten by:	remko
Spotted by:	simon
2005-07-31 11:38:25 +00:00
Remko Lodder
1053ed30f3 Document vim -- vulnerabilities in modeline handling: glob, expand.
Discussed with:		nectar, simon
2005-07-31 11:31:52 +00:00
Sergey Matveychuk
984b7312f9 - Update to 20050730
PR:		ports/84360
Submitted by:	maintainer
2005-07-31 09:43:53 +00:00
Joe Marcus Clarke
ba00a2c341 * Update to 3.10 [1]
* Add a target for regression testing, and run that target automatically
  when building on the package build cluster [1]
* Cleanup some portlint nits

Submitted by:	mi [1]
2005-07-31 00:06:49 +00:00
Simon L. B. Nielsen
39a985e2b4 Document that ekg -- insecure temporary file creation was fixed in
1.6r2,1.

Noted by:	Michal Kalkowski
2005-07-30 22:20:27 +00:00
Oliver Lehmann
c149369e83 Just remove the user if BATCH is set in env, don't ask for users feedback.
PR:		84349
Submitted by:	Matthias Andree <matthias.andree@gmx.de>
2005-07-30 21:55:23 +00:00
Simon L. B. Nielsen
64a8f10e17 Add pdflib-perl, fractorama, gdal, iv, ivtools, ja-iv, ja-libimg,
paraview to recent libtiff vulnerabilities since they contain (and
compile) an embedded version of libtiff...
2005-07-30 20:20:52 +00:00
Simon L. B. Nielsen
8c91f8349c Change MAINTAINER address for ports maintained by the Security Team to
secteam@ instead of security@ to make it more clear that the ports are
not maintained by the freebsd-security@ mailing list.  Both addresses
go to the same people.
2005-07-30 19:13:10 +00:00
Simon L. B. Nielsen
819cb94b17 Document tiff -- buffer overflow vulnerability. 2005-07-30 15:48:06 +00:00
Simon L. B. Nielsen
80d009be80 - Misc. markup/whitespace fixes.
- Collapse a few package entries from the latest apache entry (still
  matches same package names, is just shorter markup-wise).
- Use standard topic style for jaberd entry.
- Fix entry date for jaberd entry.
2005-07-30 11:18:20 +00:00
Vsevolod Stakhov
c2cb81e45a Document jabberd vulnerabilities that were fixed by the latest update.
Approved by:	perky (mentor)
2005-07-30 10:00:41 +00:00
Simon L. B. Nielsen
b151450eb0 Be consistent and use the same title for the latest ethereal
vulnerabilities as used for previous entries.
2005-07-30 09:24:47 +00:00
Simon L. B. Nielsen
1c4842c911 Document opera -- image dragging vulnerability and opera -- download
dialog spoofing vulnerability.
2005-07-30 09:13:14 +00:00
Simon L. B. Nielsen
c5114fefb3 Document ethereal -- multiple vulnerabilities. 2005-07-30 08:26:06 +00:00
Volker Stolz
e79710b377 Fix build on amd64 with -fPIC
PR:		ports/84156
Submitted by:	Hirohisa Yamaguchi
Approved by:	maintainer

Note w.r.t. 4.x: The .depend-issue can be fixed through 'gmake'.
However, then it still needs a patch for a missing <sys/time.h>, and still
won't build with neither gcc-2.95, 3.4 or 4.0, so I didn't bother.
2005-07-29 17:18:17 +00:00
Renato Botelho
6f5b6a6666 Pass maintainership to last submitter
Approved by:	actual maintainer
2005-07-29 15:12:18 +00:00
Renato Botelho
ca4ca9f4f2 - Update to 0.1.0.12
PR:		ports/84281
Submitted by:	rik <freebsd-ports@rikrose.net> (maintainer)
2005-07-29 11:05:21 +00:00
Renato Botelho
b99c822452 - Fix pkg-plist and Unbreak the port
PR:		ports/84261
Submitted by:	Jean Milanez Melo <jmelo@freebsdbrasil.com.br>
Approved by:	maintainer timeout - BROKEN over to 4 months
2005-07-29 10:52:16 +00:00
James E. Housley
6b97e0c6cd * Update second master site
* Update to DAT 4545
2005-07-28 18:35:22 +00:00
Renato Botelho
5e3cc60a87 This package implements an algorithm for breaking the PkZip cipher that was
devised by Eli Biham and Paul Kocher.

This program applies a known plaintext attack to an encrypted file.
A known-plaintext-attack recovers a password using the encrypted file and
(part of) the unencrypted file.

Please note that cryptographers use the word 'plaintext' for any kind of
unencrypted data - not necessarily readable ASCII text.

Before you ask why somebody may want to know the password when he already knows
the plaintext think of the following situations:

 - Usually there's a large number of files in a ZIP-archive. Usually all these
   files are encrypted using the same password. So if you know one of the files,
   you can recover the password and decrypt the other files.
 - You need to know only a part of the plaintext (at least 13 bytes). Many files
   have commonly known headers, like DOS .EXE-files. Knowing a reasonably long
   header you can recover the password and decrypt the entire file.

WWW: http://www.unix-ag.uni-kl.de/~conrad/krypto/pkcrack.html

PR:		ports/84192
Submitted by:	Emanuel Haupt <ehaupt@critical.ch>
2005-07-28 10:32:17 +00:00
Clement Laforet
f758062b43 - Fix apache 2.1 range for CAN-2005-2088 entry which prevents apache 2.0 from
upgrading.

Pointyhat to:	clement, remko
Reviewed by:	erwin
2005-07-28 08:51:43 +00:00
Joe Marcus Clarke
2a8578098e Update to 0.7.9. 2005-07-28 05:41:40 +00:00
Remko Lodder
086e9785f3 Mark apache+mod_ssl-1.3.33+2.8.22_1 as not vulnerable in the latest Apache entry. 2005-07-28 04:22:14 +00:00
James E. Housley
3065ae6d99 Patch MASTER_SITE since they seem to redirect to a second one sometimes 2005-07-27 18:03:37 +00:00
Sergey Matveychuk
fbc7c05ec6 - Fix startup script for milter
PR:		ports/84104
Submitted by:	maintainer
Reported by:	Erin Fortenberry <kahn@deadbbs.com>
2005-07-27 17:22:05 +00:00
Remko Lodder
7e01fa0b51 There must be an curse. s/il/li/.
Noticed by:	nectar
2005-07-27 17:21:35 +00:00
Remko Lodder
5199530afe Update my latest Apache entry to make clear that this only affects certain
installations (when Apache is used as a HTTP proxy in combination with some
web servers). I didn't make that clear in the first commit.

Requested by:		nectar
Discussed with:		clement
2005-07-27 17:01:45 +00:00
James E. Housley
48b6a4adce update to DAT 4544 2005-07-27 16:06:06 +00:00
Remko Lodder
fe0cc1d802 Document apache -- http request smuggling.
Requested by:	clement
Glanced at by:	clement
2005-07-27 15:57:54 +00:00
Ade Lovett
a07f614337 Add courierpasswd, a user authentication and password changing utility
for the courier imap/pop3 system.
2005-07-27 03:37:38 +00:00
Michael Johnson
2c943364b7 - Update to 1.7
PR:		ports/84149
Submitted by:	maintainer
2005-07-27 01:45:06 +00:00
Pav Lucistnik
e0a553e7f6 - Update to 1.2.8
PR:		ports/84074
Submitted by:	Andrej Zverev <az@inec.ru>
Approved by:	Keith J. Jones <kjones@realdigitalforensics.com> (maintainer)
2005-07-26 22:42:39 +00:00
Stefan Eßer
1f1c78dfb5 Fix URL of project web site.
Submitted by:	Dru Lavigne via Dan Langille
2005-07-26 20:10:31 +00:00
James E. Housley
0205b66d90 Update to DAT 4543 2005-07-26 19:57:05 +00:00
Renato Botelho
3ee5e28fa3 TLSWrap is a TLS/SSL FTP wrapper/proxy for UNIX and Windows, allowing you to
use your favourite FTP client with any TLS/SSL-enabled FTP server.

WWW: http://tlswrap.sunsite.dk/

PR:		ports/84028
Submitted by:	Daniel J. O'Connor <darius@dons.net.au>
Thanks to:	novel
2005-07-26 18:47:06 +00:00
Stefan Eßer
42df98b965 New port: Yersinia
Yersinia is a layer 2 vulnerability scanner with support for the
following protocols:

- Cisco Discovery Protocol (CDP)
- Dynamic Host Configuration Protocol (DHCP)
- Dynamic Trunking Protocol (DTP)
- Hot Standby Router Protocol (HSRP)
- IEEE 802.1q
- Spanning Tree Protocol (STP, RSTP)
- Virtual Trunking Protocol (VTP)
2005-07-26 17:13:00 +00:00
Renato Botelho
dd70311d11 BSDsfv is a flexible and highly compatible SFV checksum utility.
Features:

  - create SFV files, verify downloaded single files or whole releases
  - add banners to your SFV files
  - very flexible and compatible with all other SFV tools currently known,
    including SFVNIX compatibility mode concerning SFV files created
  - easy to console application
  - plug & play support for glFTPd and other demons including
    count-missing-files feature for race scripts

WWW: http://bsdsfv.sourceforge.net/

PR:		ports/84108
Submitted by:	Emanuel Haupt <ehaupt@critical.ch>
Approved by:	flz (mentor)
2005-07-26 17:10:11 +00:00
Renato Botelho
b69d7949c9 This utility creates .SFV (Simple File Verify) and .PAR (Parity Archive) data
files.

Features:

  * Recursive directories handling
  * Automatic checksum file naming ability in create mode
  * Meaningful and documented exit values for easy scripting
  * Wildcards for file names
  * Creation of PAR (Parity Archive) files
  * Create Multiple recovery sets if number of files in SFV greater than 255

WWW: http://pure-sfv.sourceforge.net/

PR:		ports/84127
Submitted by:	Emanuel Haupt <ehaupt@critical.ch>
Approved by:	flz (mentor)
2005-07-26 17:08:48 +00:00
Erwin Lansing
4667fefaa7 Set modified date in entry for previous commit.
Cluebat swung by:	simon
2005-07-26 13:32:39 +00:00
Erwin Lansing
3070ab2383 Note that the fd_set vulnerability in net/bld was fixed in 0.3.3
Prodded by:	garga
Glanced at by:	remko
2005-07-26 10:50:56 +00:00
Hiroki Sato
783a425a47 Document clamav -- multiple remote buffer overflows. 2005-07-25 15:57:46 +00:00
Sergey Matveychuk
4c26422d83 - Update to 0.86.2
PR:		ports/84038
Submitted by:	dawnshade <h-k@mail.ru>
Approved by:	maintainer
2005-07-25 13:43:33 +00:00
James E. Housley
6785cefc24 Update to 4541 2005-07-25 10:19:32 +00:00
Norikatsu Shigemura
0d841e0dd7 Don't overwrite installed aide.conf by using -f FILE
instead of -d FILE.

Damaged by:	ume
Wept by:	ume
Approved by:	maintainer slience
2005-07-23 22:53:23 +00:00
Jeremy Messenger
71ef1c8557 Update to 2.2.5.
PR:		ports/83927
Submitted by:	Udo Schweigert <udo.schweigert@siemens.com> (maintainer)
2005-07-23 22:19:00 +00:00
Oliver Lehmann
905f27b7d6 update to 0.57 2005-07-23 14:34:31 +00:00
Yen-Ming Lee
794af7b937 - update distinfo
(I compared the new distfile with the old one. The author didn't change
   anything, just repacked the distfile)

Noticed by:	kris
2005-07-23 10:55:33 +00:00
Simon L. B. Nielsen
820ff3497c - Document isc-dhcpd -- format string vulnerabilities (older
vulnerabilty). [1]
- Use standard title format for latest egroupware entry.

Reminded by:	Panagiotis Christias [1]
2005-07-23 09:30:01 +00:00
Kris Kennaway
0d8f47d8f7 This port is scheduled for deletion on 2005-09-22 if it is still broken
at that time and no PRs have been submitted to fix it.
2005-07-23 02:53:43 +00:00
Jun Kuriyama
e9ae1a90f5 Add entry for eGroupWare's recent vulnerabilities. 2005-07-23 02:03:37 +00:00
Simon Barner
632103ed79 Document denial of service attack in fetchmail 6.5.2.1.
Reported by:	Matthias Andree <matthias.andree@gmx.de>
Reviewed by:	simon
2005-07-22 09:44:32 +00:00
Vsevolod Stakhov
610a24dbac Update my email address.
Approved by:	perky (mentor)
2005-07-22 09:33:36 +00:00
Simon L. B. Nielsen
3d69e33260 Update phppgadmin entry to note that it was fixed in 3.5.4 and add a
few references while here anyway.

Prodded by:	Tobias Roth (I think :-) )
2005-07-21 21:13:45 +00:00
Renato Botelho
9bb745580f Change MASTERSITE from ~renato to ~garga because I change my account
here

Approved by:	flz (mentor)
2005-07-21 17:53:45 +00:00
Simon L. B. Nielsen
f1b860d9e5 Document dnrd -- remote buffer and stack overflow vulnerabilities. 2005-07-21 16:31:13 +00:00
Simon L. B. Nielsen
e2038fe047 Fix typo in last commit
Noticed by:	Matthias Andree <matthias.andree@gmx.de>
2005-07-21 13:38:26 +00:00
Simon L. B. Nielsen
f085ba4502 Add more references to latest fetchmail entry [1] and sort references
while here anyway.

Submitted by:	Matthias Andree <matthias.andree@gmx.de> [1]
2005-07-21 10:56:44 +00:00
Sergey Matveychuk
9615db4bd4 - Fix a bug in SHA256
PR:		ports/76289
Reported by:	Kenichi Morioka <morioka@openloop.co.jp>
Fixed by:	Vsevolod Stakhov <vsevolod@highsecure.ru> (maintainer)
2005-07-21 09:43:26 +00:00
Pav Lucistnik
83cb040fb2 - Update to 1.3.5
PR:		ports/83823
Submitted by:	Travis Poppe <tlp@liquidx.org>
2005-07-21 09:03:48 +00:00
Tom Rhodes
8eb060fe5c Document an issue with the LDAP backend provided by PowerDNS. 2005-07-21 08:43:12 +00:00
Kris Kennaway
fb53e3e217 BROKEN on !i386: Does not compile 2005-07-20 23:40:37 +00:00
Simon L. B. Nielsen
a23f66e331 Document fetchmail -- remote root/code injection from malicious POP3
server.

Submitted by:	Matthias Andree <matthias.andree@gmx.de>
2005-07-20 19:43:05 +00:00
Renato Botelho
172f2acbd8 Bridge betwean ClamAV antivirus software and Squid caching proxy.
Squidclam is a replacement for SquidClamAV-Redirector.py written
in C using libclamav and libcurl

Author:	squidclam@users.sourceforge.net
WWW:	http://sourceforge.net/projects/squidclam/

PR:		ports/82652
Submitted by:	Alexander Novitsky <alecn2002@yandex.ru>
Approved by:	flz (mentor)
2005-07-20 17:43:59 +00:00
Joe Marcus Clarke
dddd4bf3c5 s/freebsd.org/FreeBSD.org/
Reported by:	oliver
2005-07-20 17:19:48 +00:00
Pav Lucistnik
dea2c27d67 - Revive security/ruby-acl port and unbreak it
- Reset maintainership

PR:		ports/76917
Submitted by:	IWATSUKI Hiroyuki <don@na.rim.or.jp>
2005-07-20 12:28:42 +00:00
Pav Lucistnik
8cbc803ff7 - Fix plist and unbreak [1, 2]
- Clean up Makefile and update pkg-message handling

PR:		ports/81492 [1], ports/83128 [2]
Submitted by:	Boris B. Samorodov <bsam@ipt.ru>,
		Norikatsu Shigemura <n-shigemura@ensure.jp>
Approved by:	maintainer timeout (2 months)
2005-07-20 11:57:36 +00:00
Pav Lucistnik
4c16572c83 - Update to 2.0.8
PR:		ports/83679
Submitted by:	vadim@vk.crocodile.org <vadim@vk.crocodile.org> (maintainer)
2005-07-20 07:49:35 +00:00
Pav Lucistnik
2822182689 - Update to 2.0.8
PR:		ports/83678
Submitted by:	vadim@vk.crocodile.org <vadim@vk.crocodile.org> (maintainer)
2005-07-20 07:49:12 +00:00
Pav Lucistnik
0604419893 - Update to 1.1
PR:		ports/83741
Submitted by:	Marcus Grando <marcus@corp.grupos.com.br>
2005-07-19 19:23:22 +00:00
Roman Bogorodskiy
b64179da64 - Update to 0.3.1
- Update WWW and MASTER_SITES
- Now install examples too

PR:		83740
Submitted by:	Marcus Grando (maintainer)
2005-07-19 19:22:50 +00:00
James E. Housley
111c9d7641 Update to 4538 2005-07-19 16:15:50 +00:00
Pav Lucistnik
690e751982 - Update to 1.4.2
PR:		ports/83659
Submitted by:	Meno Abels <meno.abels@adviser.com> (maintainer)
2005-07-18 22:28:52 +00:00
Pav Lucistnik
2d0c1561fe - Use PLIST_FILES
- Add Author: to pkg-descr

PR:		ports/83683
Submitted by:	Andrej Zverev <az@inec.ru>
2005-07-18 22:19:46 +00:00
Michael Landin
4ccb5ee963 o add kdebase (kate) vulnarability.
Reviewed by:	simon
2005-07-18 20:07:26 +00:00
Pav Lucistnik
61f27f1460 - Update to 0.2.1
PR:		ports/83657
Submitted by:	Vsevolod Stakhov <vsevolod@highsecure.ru>
2005-07-18 19:00:19 +00:00
Pav Lucistnik
31d7fffbe5 - Update to 1.4
PR:		ports/83654
Submitted by:	Vsevolod Stakhov <vsevolod@highsecure.ru>
2005-07-18 18:59:33 +00:00
James E. Housley
5feb9d3bb3 Update to 4537 2005-07-18 17:28:33 +00:00
Pav Lucistnik
b22378f7b1 This module brings to Python programs the capability of evaluating password
strength. To achieve this noble aim it uses the well known cracklib toolkit,
hence the name.

PR:		ports/83603
Submitted by:	Vsevolod Stakhov <vsevolod@highsecure.ru>
2005-07-18 16:29:47 +00:00
Dirk Meyer
8e5bb0a052 - fix manpages 2005-07-18 11:35:53 +00:00
Simon L. B. Nielsen
28825cc36f Add CVE names to recent bugzilla entry. 2005-07-18 09:54:06 +00:00
Pav Lucistnik
3d19fa5eda - Update to 0.9.2
PR:		ports/80238
Submitted by:	Vasil Dimov <vd@datamax.bg>
Approved by:	maintainer timeout (3 months)
2005-07-18 08:14:57 +00:00
Adam Weinberger
586a9efe97 Make sure LATEST_LINK is unique from that of the calife-nondevel port. 2005-07-18 07:26:40 +00:00
Mark Linimon
adda42bec2 With portmgr hat on, reset eik's ports since he has been inactive for
several months (not responding to email).

Discussed among:	portmgr team
2005-07-18 03:49:55 +00:00
Yen-Ming Lee
b7847f5b55 - fix installation of start script on 4.x
PR:		83604
Submitted by:	Blaz Zupan <blaz@si.FreeBSD.org>
2005-07-17 21:42:11 +00:00
Joe Marcus Clarke
79ec2ec03a Fix alignment problems on non-i386 platforms. 2005-07-17 01:54:54 +00:00
Simon L. B. Nielsen
e47a7c39fe - Document firefox & mozilla -- multiple vulnerabilities.
- Minor style nit in drupal entry: Use port name (i.e. lower case) as
  first part of the title.
2005-07-16 14:38:04 +00:00
Oliver Lehmann
656815afa5 make it compile on 7
Noted by:	pointyhat via kris
2005-07-16 13:59:40 +00:00
Erwin Lansing
ede485957c Add an entry for the drupal vulnerabilities. 2005-07-16 11:29:43 +00:00
James E. Housley
ad1bdea4c7 Update to 4536 2005-07-15 22:34:29 +00:00
Niels Heinen
5bab4982a8 Fixed incorrect newsfetch and mnogosearch affected package versions
Approved by:	nectar (mentor)
2005-07-15 14:34:59 +00:00
Jeremy Messenger
e0becca596 Update to 2.3.1.
PR:		ports/83146
Submitted by:	Udo Schweigert <udo.schweigert@siemens.com> (maintainer)
2005-07-14 17:38:40 +00:00
James E. Housley
e889b39b47 Update to 4535 2005-07-14 16:05:27 +00:00
Pav Lucistnik
f6febd09e0 NewPKI is a PKI based on the OpenSSL low-level API, all the datas are handled
through a database, which provides a much more flexible PKI than with OpenSSL,
such as seeking a certificate with a search engine.

CA implementation.

PR:		ports/83387
Submitted by:	Vsevolod Stakhov <vsevolod@highsecure.ru>
2005-07-14 13:58:43 +00:00
Pav Lucistnik
64b73b6642 NewPKI is a PKI based on the OpenSSL low-level API, all the datas are handled
through a database, which provides a much more flexible PKI than with OpenSSL,
such as seeking a certificate with a search engine.

GUI client that uses wxWidgets.

PR:		ports/83386
Submitted by:	Vsevolod Stakhov <vsevolod@highsecure.ru>
2005-07-14 13:24:04 +00:00
Renato Botelho
cc323eeba5 Add PW_PASS option to compile with --enable-pass-save
PR:		82494
Submitted by:	Landon Fuller <landonf@threerings.net>
Reviewed by:	Matthias Andree <matthias.andree@gmx.de> (maintainer)
Approved by:	mantainer, flz (mentor)
2005-07-14 13:15:47 +00:00
Pav Lucistnik
c08970fbc3 NewPKI is a PKI based on the OpenSSL low-level API, all the datas are handled
through a database, which provides a much more flexible PKI than with OpenSSL,
such as seeking a certificate with a search engine.

PR:		ports/83385
Submitted by:	Vsevolod Stakhov <vsevolod@highsecure.ru>
2005-07-14 13:01:35 +00:00
Sam Lawrance
5553e04f1c Mark broken on 4.x
Approved by:	maintainer
2005-07-13 23:51:15 +00:00
Florent Thoumie
a7633f04ef - Update to 0.11.
PR:		ports/83401
Submitted by:	Marcus Grando <marcus@corp.grupos.com.br>
2005-07-13 21:39:43 +00:00
Florent Thoumie
9c86219ccc - Update to 0.9.
PR:		ports/83402
Submitted by:	Marcus Grando <marcus@corp.grupos.com.br>
2005-07-13 21:38:35 +00:00
James E. Housley
0d2c105a44 Update to 4534 2005-07-13 17:36:52 +00:00
Peter Pentchev
6d01095715 Update to stunnel 4.11, which is deemed a stable release.
Remove our local patches for ucontext/pthread/fork model choice, since
this is handled by a configure argument now.
Note that ucontext is not supported on FreeBSD versions less than 5.0.

PR:		83245 (mostly)
Submitted by:	Vasil Dimov <vd@datamax.bg>
2005-07-13 08:41:58 +00:00
Jun Kuriyama
29216de4a6 Markup fixed version of net-snmp problem. 2005-07-13 03:04:17 +00:00
Cy Schubert
4871e2a3be Fix:
- MIT KRB5 Security Advisory 2005-002: Buffer overflow, heap corruption in KDC

- MIT KRB5 Security Advisory 2005-003: Double free in krb5_recvauth
2005-07-12 21:29:26 +00:00
Jean-Yves Lefort
df9f562ee6 - Let configure know that we have fnmatch.h (fixes some fnmatch-using
C++ ports, since the fnmatch.h which was uselessly installed by
  heimdal did not wrap the fnmatch() declaration in extern C {}) [1]
- Fix the packing list on 4.x

[1]
PR:		ports/80366
Submitted by:	Joan Picanyol i Puig <lists-freebsd-gnats@biaix.org>
Approved by:	maintainer timeout (76 days)
2005-07-12 17:07:46 +00:00
James E. Housley
f165c74da7 Update to DAT 4533 2005-07-12 16:09:35 +00:00
Brooks Davis
d3fa98c565 Update to the latest hpn-ssh patches for 3.9p1. The previous patches
were unfetchable.  An upgrade to 4.1p1 will follow soon.

Reported by:	pointyhat (via kris)
2005-07-11 23:53:08 +00:00
Renato Botelho
d5a8ad9d47 Change MAINTAINER to my @FreeBSD.org account
Approved by:	flz (mentor)
2005-07-11 16:47:16 +00:00
James E. Housley
57cf7428a8 Update to DAT 4532 2005-07-11 16:43:56 +00:00
Sergey Matveychuk
e6280f9d48 - Sync with master port update
PR:		ports/83181
Submitted by:	Vsevolod Stakhov <vsevolod@highsecure.ru>
2005-07-11 08:27:18 +00:00
Sergey Matveychuk
2fca1584ba - Update to latest NetBSD snapshot
- Use tarball instead of set of files
- Pass maintainership to submitter

PR:		ports/83180
Submitted by:	Vsevolod Stakhov <vsevolod@highsecure.ru>
Approved by:	eik MIA
2005-07-11 08:26:19 +00:00
Munechika SUMIKAWA
04746592a6 Make compilable on 64bit system. 2005-07-11 03:04:38 +00:00
Clement Laforet
8d580866e5 - Update to 0.46 2005-07-10 19:52:15 +00:00
Kris Kennaway
628d94d0e3 Replace master site with working ones 2005-07-10 19:17:15 +00:00
Dirk Meyer
b62e1d6967 - update to 0.9.8 for WITH_OPENSSL_BETA=yes 2005-07-10 19:15:12 +00:00
Kris Kennaway
91c92459a5 Chase master site 2005-07-10 18:48:28 +00:00
Kris Kennaway
d1be4450f5 Update to nikto-1.35 to fix fetching 2005-07-10 17:54:53 +00:00
Marius Strobl
8840fad723 - Update to 1.1.0-7 in order to fix fetching. For a list of changes see
the installed ChangeLog.
- Silencing the 'cannot access config file "/etc/antivir.conf"' warnings
  by creating a respective symlink.

Notes:
- AntiVir Milter 1.1.0-7 ships with a faulty anti-virus engine which
  may just exit with the following error when trying to start it:
  cannot access config file "/etc/avguard.conf"
  Please update to the latest anti-virus engine by e.g. running the
  antivirupdater script in order to solve this.
- The future of the free licenses for private use and thus of this
  port currently is uncertain:
  <...>
  PersonalEdition Classic UNIX: Advance Notice
  We have decided to orient the version 6.32 which will be released on
  September 6, 2005 much more towards the successful PersonalEdition
  Classic Windows.
  This means that version 6.32 will be released with a graphical user
  interface which will make it much easier to work with the program. It
  will also no longer be necessary to register for the program before
  downloading it. With version 6.32 the PersonalEdition Classic UNIX
  will no longer contain any MailGate/Milter functionality.
  <...>

Approved by:	netchild
2005-07-10 15:04:00 +00:00
Sergey Matveychuk
7a17fbe604 - Was marked as unmaintained by accident.
So set MAINTAINER to the port submitter.

Submitted by:	niels
2005-07-10 14:13:00 +00:00
Remko Lodder
2472e1c59f Correct a typo: s/lemote/remote/
Spotted by:	simon
2005-07-09 20:02:57 +00:00
Remko Lodder
112e0da40d Document the following vulnerabilities:
phpSysInfo -- cross site scripting vulnerability
mysql-server -- insecure temporary file creation
net-snmp -- fixproc insecure temporary file creation
phpbb -- multiple vulnerabilities
shtool -- insecure temporary file creation

Approved by:		simon
2005-07-09 19:57:12 +00:00
Joe Marcus Clarke
8f4dde6a65 Update to Gaim 1.4.0. See http://gaim.sourceforge.net/ChangeLog for
the list of changes.  Also, bump all PORTREVISIONs for ports that depend on
Gaim.
2005-07-09 01:07:45 +00:00
Simon L. B. Nielsen
0580c39d0f Document phppgadmin -- "formLanguage" local file inclusion vulnerability. 2005-07-08 21:36:19 +00:00
Simon L. B. Nielsen
f76a96caad Document pear-XML_RPC -- information disclosure vulnerabilities. 2005-07-08 21:17:12 +00:00
Simon L. B. Nielsen
81b2a86d18 Document ekg -- insecure temporary file creation. 2005-07-08 21:03:14 +00:00
Simon L. B. Nielsen
775ddef518 Document bugzilla -- multiple vulnerabilities. 2005-07-08 20:29:16 +00:00
Simon L. B. Nielsen
5bbec38d7c Document nwclient -- multiple vulnerabilities (old issues).
PR:		ports/82101
Submitted by:	niels
Noticed by:	Derik van Zuetphen <dz@426.ch>
2005-07-08 20:04:13 +00:00
James E. Housley
50ca37cfca Update to DAT 4531 2005-07-08 16:50:48 +00:00
Pav Lucistnik
f823ca743a - Fix a typo in patch to default configuration file
PR:		ports/82930
Submitted by:	Dmitry A Grigorovich <odip@bionet.nsc.ru>
Approved by:	Alexander Demin <support@spectrum.ru> (maintainer)
2005-07-08 12:18:26 +00:00
James E. Housley
39eb85576c Update to DAT 4530 2005-07-07 21:02:13 +00:00
Simon L. B. Nielsen
feedb4a329 Add CAN reference to recent phpbb vulnerability. 2005-07-06 22:46:02 +00:00
Simon L. B. Nielsen
a7f693e9cd Document acroread -- insecure temporary file creation. 2005-07-06 22:25:11 +00:00
Simon L. B. Nielsen
e51ea6f83d Document two calmav vulnerabilities. 2005-07-06 22:14:55 +00:00
Simon L. B. Nielsen
7d9bb89690 - Add FreeBSD-SA-05:16.zlib.
- Fix ranges for recent security advisories, a bunch of <le> really
  should have been <lt>.
2005-07-06 21:34:32 +00:00
Simon L. B. Nielsen
417582572e Document acroread -- buffer overflow vulnerability. 2005-07-06 20:45:34 +00:00
James E. Housley
bdbde67b8c Update to DAT 4529 2005-07-06 16:21:32 +00:00
Pav Lucistnik
7ea7c22500 OpenCT, a middleware framework for smart card terminals.
It all started with a reader driver library to provide a framework for people
writing drivers for smart card readers. The idea was to provide all the usual
stuff (T=0, T=1, serial vs. USB device handling, etc) in a single place, and
reduce driver writing to interaction with the device itself.

OpenCT provides a native OpenCT, CT-API and PC/SC Lite IFD interface with an
OpenCT ifdhandler resource manager.

PR:		ports/82990
Submitted by:	Janos Mohacsi <janos.mohacsi@bsd.hu>
2005-07-06 14:35:12 +00:00
Florent Thoumie
453bba93d7 - Update to 2.3.2.
- Use USE_RC_SUBR / USE_RCORDER for amavis.sh.
- Use SUB_FILES / SUB_LIST for pkg-* files.
- Add new MILTER option.
- Probably some other fixes I've forgot.

PR:		ports/82423
Reported by:	Petr Rehor <prehor@gmail.com>
Submitted by:	maintainer
2005-07-06 08:47:09 +00:00
Roman Bogorodskiy
215451e342 Update to 20050705.
PR:		83026
Submitted by:	Tim Bishop (maintainer)
2005-07-06 05:19:12 +00:00
Simon L. B. Nielsen
04bda21000 Document net-snmp -- remote DoS vulnerability. 2005-07-05 21:13:38 +00:00
Simon L. B. Nielsen
3cf5b1eda5 Document cacti -- multiple vulnerabilities.
Prodded by:	Babak Farrokhi <babak@farrokhi.net>
2005-07-05 20:33:11 +00:00
Simon L. B. Nielsen
24dbf34258 - Add another reference to bzip2 -- denial of service and permission
race vulnerabilities.
- Document two cases of wordpress -- multiple vulnerabilities.
2005-07-05 19:01:15 +00:00
James E. Housley
73957b05e2 Update to DAT 4528 2005-07-05 16:01:55 +00:00
James E. Housley
22d76e9d58 Update to DAT 4527 2005-07-05 13:32:37 +00:00
Roman Bogorodskiy
f412917876 Update to 0.11.0.
PR:		82954
Submitted by:	Vsevolod Stakhov <vsevolod@highsecure.ru>
2005-07-05 08:37:10 +00:00
Munechika SUMIKAWA
71d0194942 Fix pkg-plist. 2005-07-05 05:09:01 +00:00
Roman Bogorodskiy
ddc4918fb4 Update to 20050704.
PR:		82972
Submitted by:	Renato Botelho <freebsd@galle.com.br>
Approved by:	Rob Evers (maintainer)
2005-07-04 17:38:52 +00:00
Munechika SUMIKAWA
2331db7af7 IKEv2 has been supported. 2005-07-04 16:41:41 +00:00
Munechika SUMIKAWA
70b9263b1e Upgrade to 20050625b. IKEv2 has been supported. 2005-07-04 16:40:02 +00:00
Peter Pentchev
2e1a161511 Fix cracklib support:
- there is no lib/crack.a [1], and moreover
- apg actually links to the dynamic library, so BUILD -> LIB_DEPENDS.
Bump PORTREVISION, since the package dependencies changed.

PR:		79673 [1]
Submitted by:	Vasil Dimov <vd@datamax.bg>
2005-07-04 11:27:40 +00:00
Roman Bogorodskiy
dc9244fd41 - update to 2.0.1
- use PYTHON_SITELIBDIR in plist

PR:		82958
Submitted by:	Vsevolod Stakhov <vsevolod@highsecure.ru>
2005-07-04 05:20:55 +00:00
Simon L. B. Nielsen
04e3a67805 - Set maintainership to security@.
Suggested by:	nectar, remko
2005-07-03 20:46:48 +00:00
Simon L. B. Nielsen
9e1a5a3459 portaudit 0.5.10:
- Unbreak portaudit -vF.
- Sync usage with reality.
- Document the q, v, and V options.
- Markup fixes for the portaudit(1) manual page.
- Make quiet mode output even less "redundant" text [1].
- Set maintainership to security@. [2]

Suggested by:	Phil Kernick philk at rotfl dot com dot au [1]
Suggested by:	nectar, remko [2]
2005-07-03 20:31:00 +00:00
Joe Marcus Clarke
944359ea20 Update to 0.4.3. 2005-07-03 19:15:40 +00:00
Pav Lucistnik
359f5da974 - Update to 0.1.0.11
PR:		ports/82921
Submitted by:	rik <freebsd-ports@rikrose.net> (maintainer)
2005-07-03 15:40:57 +00:00
Thierry Thomas
1b6860190c Add support for FreeBSD 5.4.
PR:		82370
Submitted by:	Babak Farrokhi <babak (at) farrokhi.net>
Approved by:	maintainer time-out (> 15 days)
2005-07-03 13:06:08 +00:00
Thierry Thomas
194aa248ed Fix dependency and remove the ancient pkg-message.
PR:		82336
Submitted by:	Babak Farrokhi <babak (at) farrokhi.net>
Approved by:	maintainer time-out (> 15 days)
2005-07-03 12:42:08 +00:00
Hiroki Sato
0c4160ee5f Document the following issues:
- phpbb -- remote PHP code execution vulnerability
 - pear-XML_RPC -- arbitrary remote code execution
2005-07-03 08:40:51 +00:00
Simon L. B. Nielsen
f47912670d Add certvu reference to kernel -- TCP connection stall denial of service
vulnerability.
2005-07-03 08:12:20 +00:00
Jean-Yves Lefort
f95bf0e733 Chase the libevent update.
Reported by:	pointyhat
2005-07-01 22:47:21 +00:00
Adam Weinberger
fc66828a08 Update to 1.0.0. 2005-07-01 22:37:00 +00:00
Michael Nottebrock
dadc885df8 Adjust CONFLICTS. 2005-07-01 21:26:07 +00:00
James E. Housley
d83bca4c4d Update to DAT 4526 2005-07-01 16:08:21 +00:00
Florent Thoumie
8a29704740 - Update to 0.14.9.
PR:		ports/82802
Submitted by:	maintainer
2005-06-30 19:28:20 +00:00
Cy Schubert
fd9cbca09b Fix typo in URL. 2005-06-30 19:20:17 +00:00
Florent Thoumie
5958cddd4f - Fix missing dependency.
- Complete pkg-message (note on Apache configuration).

PR:		ports/82829
Submitted by:	maintainer
2005-06-30 17:09:58 +00:00
James E. Housley
ccdffd9fb7 Update DAT to 4525 2005-06-30 16:16:11 +00:00
Ollivier Robert
ffecd5806b Fix install on 4.x on which PAM is not used for calife.
Submitted by:	kris (through pointyhat)
Approved by:	thomas (MAINTAINER)
2005-06-30 10:39:35 +00:00
Yen-Ming Lee
d191ff8761 - update to amap-5.1
PR:		82780
Submitted by:	Yonatan <onatan@gmail.com>
2005-06-30 07:39:00 +00:00
Simon L. B. Nielsen
0ced0e71fb Add FreeBSD-SA-05:13.ipfw, FreeBSD-SA-05:14.bzip2, and
FreeBSD-SA-05:15.tcp.
2005-06-29 23:00:52 +00:00
James E. Housley
7d301524c4 Update DAT to 4524 2005-06-29 16:09:21 +00:00
Sam Lawrance
708d30f711 Fix pkg-plist
Reported by:	kris
2005-06-29 10:59:40 +00:00
Sam Lawrance
8d3be987da Remove mtree dir from pkg-plist 2005-06-29 04:57:38 +00:00
Jean-Yves Lefort
d07f9a99c8 Fix compilation of the milter interface. 2005-06-28 18:58:07 +00:00
Jean-Yves Lefort
d873ba09a4 Fix the fix of the compilation of the milter interface. 2005-06-28 18:57:42 +00:00
Jean-Yves Lefort
85e7fc9aff Fix compilation of the milter interface.
Reported by:	Tony Shadwick <tshadwick@goinet.com>
2005-06-28 18:19:28 +00:00
Michael Nottebrock
85df12641d Change dependency pattern for libusb to usb-0.1 2005-06-28 17:58:44 +00:00
James E. Housley
4e6d758feb Update DAT to 4523 2005-06-28 16:07:19 +00:00
Sam Lawrance
5aa972f925 Remove mtree dir from pkg-plist 2005-06-28 14:03:45 +00:00
James E. Housley
611533e21e Update DAT to 4522 2005-06-27 19:31:08 +00:00
Joe Marcus Clarke
d184cf8e71 Update to 1.7.8, now with a shiny new man page. 2005-06-26 17:39:19 +00:00
Michael Nottebrock
8bf4bd1c32 Update to KDE 3.4.1 2005-06-26 15:38:58 +00:00
Sam Lawrance
88217bed8c Update to 0.12.6.
Add missing % in pkg-message substitution.

PR:		ports/82622
Submitted by:	J Randolph <snortsms@servangle.net> (maintainer)
2005-06-25 12:06:04 +00:00