Commit graph

24073 commits

Author SHA1 Message Date
Ben Woods
1681001e51 security/p5-File-KeePass: Add p5-XML-Parser as dependency.
This is required to be able to open files in KeePass v2 format.

PR:		212996
Approved by:	alexander.4mail@gmail.com (maintainer timeout), adamw (mentor, implicit)
2016-10-17 10:48:36 +00:00
Carlos J. Puga Medina
6cd87e3640 security/py-{acme,certbot}: Update to 0.9.3
- Update PORTVERSION and distinfo checksum (0.9.3)

Approved by:	koobs (mentor)
Differential Revision:	D8261
2016-10-17 09:14:48 +00:00
Kurt Jaeger
bd93ce25ba security/certificate-transparency: add missing patch
PR:		213502
2016-10-17 05:16:49 +00:00
Wen Heping
d3e3206493 - Update to 0.18
Changes: http://cpansearch.perl.org/src/MIKAGE/Crypt-SMIME-0.18/Changes
2016-10-17 01:51:48 +00:00
Antoine Brodin
b0fd6630fa Update to 1.1.1.6 2016-10-16 18:35:02 +00:00
Kurt Jaeger
f7683d1c5a security/certificate-transparency: update 20160102 -> 20161015
PR:		213502
Changes:	https://github.com/google/certificate-transparency/commits/master
2016-10-16 07:08:29 +00:00
Antoine Brodin
995e960a13 Update to 4.12.34 2016-10-16 07:07:06 +00:00
Antoine Brodin
b6d938e7b7 Update to 0.0.8 2016-10-16 07:06:33 +00:00
Antoine Brodin
70d526cc25 Update to 1.1.23 2016-10-16 07:06:05 +00:00
Antoine Brodin
5ffb4d4e36 Update to 0.2.4 2016-10-16 07:05:27 +00:00
Ben Woods
3f1289e732 security/libkpass: Update to version 6
- Change from Sourceforge to GitHub for upstream, as per note on SF page
- Add LICENSE_FILE to demonstrate GPLv3 license
- Delete patch-src_kpass.c as upstream incorporates similar changes

Changes this release:
  https://github.com/bldewolf/libkpass/blob/6/ChangeLog

Approved by:	vg (maintainer timeout), mat (mentor)
Differential Revision:	https://reviews.freebsd.org/D8034
2016-10-15 00:36:39 +00:00
Torsten Zuehlsdorff
9341fb6fc3 Rails 4: Document XSS Vulnerability in Action View and
Unsafe Query Generation Risk in Active Record

Security: CVE-2016-6316
Security: https://vuxml.freebsd.org/freebsd/43f1c867-654a-11e6-8286-00248c0c745d.html
Security: CVE-2016-6317
Security: https://vuxml.freebsd.org/freebsd/7e61cf44-6549-11e6-8286-00248c0c745d.html

Approved by: pi(mentor)
2016-10-14 12:03:47 +00:00
Torsten Zuehlsdorff
befb3c376f Document multiple security issues of PHP 7.0
Security: CVE-2016-7416
Security: CVE-2016-7412
Security: CVE-2016-7414
Security: CVE-2016-7417
Security: CVE-2016-7413
Security: CVE-2016-7418
Security: https://vuxml.freebsd.org/freebsd/f471032a-8700-11e6-8d93-00248c0c745d.html

Approved by: pi (mentor)
2016-10-14 12:01:46 +00:00
Torsten Zuehlsdorff
1bcb020f24 Document multiple security issues of PHP 5.6
Security: CVE-2016-7416
Security: CVE-2016-7412
Security: CVE-2016-7414
Security: CVE-2016-7417
Security: CVE-2016-7411
Security: CVE-2016-7413
Security: CVE-2016-7418
Security: https://vuxml.freebsd.org/freebsd/8d5180a6-86fe-11e6-8d93-00248c0c745d.html

Approved by: pi (mentor)
2016-10-14 11:59:35 +00:00
Carlos J. Puga Medina
c92ea04689 security/py-{acme,certbot}: Update to 0.9.2
Common:

Update PORTVERSION and distinfo checksum (0.9.2)
security/py-acme:

Add dns/py-dnspython dependency required to support both Python 2 and Python 3

Approved by:	koobs
Differential Revision: D8223
2016-10-13 15:29:12 +00:00
Kris Moore
cb6f73059a - Set DIST_SUBDIR to handle distfile without version string
Thanks for pointing it out: mat@
2016-10-13 14:59:21 +00:00
Kris Moore
30c985b913 - Add new port security/ngrok
Expose local servers behind NATs and firewalls to the public internet
over secure tunnels.

URL: https://ngrok.com

PR: 212883
Submitted by: jhixson@gmail.com
2016-10-13 14:31:38 +00:00
Dmitry Marakasov
15e66fb575 - Switch couple more ports to verbose build
- Remove --disable-silent-rules which are used by default

Approved by:	portmgr blanket
2016-10-13 13:08:09 +00:00
Mark Felder
94b1394a24 Document file-roller vulnerability
PR:		213199
Security:	CVE-2016-7162
2016-10-12 04:47:33 +00:00
Mark Felder
dd82903882 Document Virtualbox vulnerabilities
PR:		204406
Security:	CVE-2015-4813
Security:	CVE-2015-4896
2016-10-12 02:01:11 +00:00
Mark Felder
75511deb68 Document ImageMagick vulnerabilities
PR:		213032
2016-10-12 01:37:48 +00:00
Mark Felder
7fea14d1a8 Document libgd vulnerabilities
PR:		213023
2016-10-12 01:28:22 +00:00
Mark Felder
c721b848ac Document libvncserver vulnerabilities
PR:		212380
Security:	CVE-2014-6051
Security:	CVE-2014-6052
Security:	CVE-2014-6053
Security:	CVE-2014-6054
Security:	CVE-2014-6055
2016-10-12 01:22:04 +00:00
Mark Felder
9c365b8717 Document OpenOffice vulnerability
PR:		212379
Security:	CVE-2014-3575
2016-10-12 01:17:13 +00:00
Mark Felder
2aa75824fa Document mupdf vulnerabilites
PR:		212207
Security:	CVE-2016-6525
Security:	CVE-2016-6265
2016-10-12 00:49:00 +00:00
Mark Felder
111281e58d Fix OpenSSL vuln version range
Reported by:	mat
2016-10-11 19:59:56 +00:00
Kurt Jaeger
326e9bf742 security/p5-Crypt-LE: add missing dependencies
Submitted by:	des
2016-10-11 16:06:52 +00:00
Mark Felder
fd6f05caae Document openjpeg vulnerability
PR:		212672
Security:	CVE-2016-5157
Security:	CVE-2016-7163
2016-10-11 15:07:54 +00:00
Mark Felder
4bd338061f Document redis vulnerability
PR:		211709
Security:	CVE-2013-7458
2016-10-11 15:02:52 +00:00
Adam Weinberger
fb172ba3df Update to 0.0108, and donate to the Perl collective.
No Changes file, but they're at least available at https://github.com/JaHIY/Crypt-XTEA/commits/master
2016-10-10 19:59:19 +00:00
Mark Felder
77a4d720e4 Fix typo in vuxml topic 2016-10-10 16:20:05 +00:00
Dirk Meyer
223aa64413 - update to 1.0.29 2016-10-10 16:18:27 +00:00
Mark Felder
7c95a00386 Document FreeBSD-SA-16:31.libarchive 2016-10-10 12:43:44 +00:00
Mark Felder
6677ba01fd Document FreeBSD-SA-16:30.portsnap 2016-10-10 12:42:13 +00:00
Mark Felder
2eb7acfbea Document FreeBSD SA-16:29.bspatch 2016-10-10 12:41:35 +00:00
Mark Felder
ec93cc87f4 Add FreeBSD SA info to recent BIND vulnerability 2016-10-10 12:40:50 +00:00
Mark Felder
7e6caec094 Add FreeBSD SA info to recent OpenSSL vulnerability 2016-10-10 12:39:08 +00:00
Boris Samorodov
156c6cb357 Thank you Uffe for your past work on FreeBSD ports! Hope you'll find time
to contribute to FreeBSD in the future. Reset Uffe's ports maintainership.

Requested by:	 Uffe Jakobsen <uffe@uffe.org> (maintainer, via e-mail)
2016-10-09 22:01:34 +00:00
Adam Weinberger
4e582a1723 Update to 0.23.
Changes: https://metacpan.org/changes/distribution/Unix-Passwd-File
2016-10-09 15:58:20 +00:00
Adam Weinberger
b3f6c25c7a Update to 0.08 (which just improves the Makefile.PL), and strip
the XS module.

Changes: https://metacpan.org/changes/distribution/Crypt-OpenSSL-ECDSA
2016-10-09 15:52:44 +00:00
Jan Beich
f5f47a5a4e devel/nspr, security/nss: drop version from SONAME
No other downstream appends synthetic library version, and doing so
causes underlinking due to fragile build system (see below). Not to
mention being unable to swap out bundled libs from upstream builds.

  $ cc -lplds4 -L/usr/local/lib
  /usr/lib/crt1.o: In function `_start1':
  crt1_c.c:(.text+0xa6): undefined reference to `main'
  /usr/local/lib/libplds4.so: undefined reference to `pthread_set_name_np'
  /usr/local/lib/libplds4.so: undefined reference to `pthread_create'
  /usr/local/lib/libplds4.so: undefined reference to `pthread_condattr_init'
  /usr/local/lib/libplds4.so: undefined reference to `pthread_setschedparam'
  /usr/local/lib/libplds4.so: undefined reference to `pthread_getschedparam'

PR:		213144
Exp-run by:	antoine
2016-10-09 12:10:02 +00:00
Jan Beich
6dc8464d09 security/nss: update to 3.27.1 and define license
Changes:	https://developer.mozilla.org/docs/Mozilla/Projects/NSS/NSS_3.27.1_release_notes
PR:		213312
Submitted by:	Vladimir Krstulja <vlad-fbsd@acheronmedia.com>
MFH:		2016Q4
2016-10-09 10:45:33 +00:00
Antoine Brodin
5b143ae2e6 Update to 4.12.31 2016-10-09 09:00:35 +00:00
Antoine Brodin
d194310170 Update to 1.1.19 2016-10-09 09:00:06 +00:00
Antoine Brodin
fe6b2bbd2e New port: security/rubygem-rex-exploitation
This gem contains various helper mechanisms for creating exploits.  This
includes SEH Overwrite helpers, egghunters, command stagers and more.

WWW: https://github.com/rapid7/rex-exploitation
2016-10-09 08:57:49 +00:00
Antoine Brodin
5b275f3711 Update to 2.0.4 2016-10-09 08:40:49 +00:00
Antoine Brodin
5d092e2302 Update to 2.0.4 2016-10-09 08:40:20 +00:00
Antoine Brodin
0b23803147 Update to 0.1.1 2016-10-09 08:37:46 +00:00
Antoine Brodin
ee6e9f31a9 Update to 0.1.66 2016-10-09 08:21:38 +00:00
Thomas Zander
e25daa85b7 Document code execution vulnerability in mkvtoolnix < 9.4.1 2016-10-09 07:49:26 +00:00