Commit graph

20601 commits

Author SHA1 Message Date
Kurt Jaeger
07b7d49a72 security/bro, security/broccoli: 2.3 -> 2.3.2
This updates bro and broccoli from 2.3 and 2.3.2, which is a security
update.

Changes to the bro port:
- Rework openssl option logic
- Remove obsolete
- pkgng related changes

Changes to the broccoli port:
- Remove unused DOCS option
- Enable PYTHON by default
- pkgng related changes
- Minor portlint changes

Changes in 2.3.2:
- DNP3: fix reachable assertion and buffer over-read/overflow.
  CVE number pending. (Travis Emmert, Jon Siwek)
- Update binpac: Fix potential out-of-bounds memory reads in
  generated code. CVE-2014-9586. (John Villamil and Chris Rohlf
  - Yahoo Paranoids, Jon Siwek)
- BIT-1234: Fix build on systems that already have ntohll/htonll.
  (Jon Siwek)
- BIT-1291: Delete prebuilt python bytecode files from git.  (Jon Siwek)
- Adding call to new binpac::init() function. (Robin Sommer)

Changes in 2.3.1:
- Fix a reference counting bug in ListVal ctor. (Jon Siwek)
- Fix possible buffer over-read in DNS TSIG parsing. (Jon Siwek)
- Change EDNS parsing code to use rdlength more cautiously.  (Jon Siwek)
- Fix null pointer dereference in OCSP verification code in
  case no certificate is sent as part as the ocsp reply. Addresses
  BIT-1212.  (Johanna Amann)
- Fix OCSP reply validation. Addresses BIT-1212 (Johanna Amann)
- Make links in documentation templates protocol relative. (Johanna Amann)

PR:		197107
Submitted by:	Craig Leres <leres@ee.lbl.gov> (maintainer)
Reviewed by:	koobs
2015-02-02 22:25:23 +00:00
Rene Ladan
1869512c53 Remove expired ports:
2015-01-31 audio/py-eyed3-06: In audio/abcde dependency has been changed to audio/py-eyed3
2015-01-31 mail/postfix210: Use mail/postfix instead.
2015-01-31 net-im/venom: No more support from the project
2015-02-01 security/openssh-portable66: security/openssh-portable now has all patches working. This port is obsolete.
2015-01-31 www/p5-WWW-Scraper-ISBN-Driver: Merged to www/p5-WWW-Scraper-ISBN by upstream
2015-01-31 www/p5-WWW-Scraper-ISBN-Record: Merged to www/p5-WWW-Scraper-ISBN by upstream
2015-02-02 22:22:23 +00:00
Dmitry Marakasov
3f739bb4e6 - Update to 1.38b
PR:		197274
Submitted by:	fk@fabiankeil.de (maintainer)
2015-02-02 19:33:06 +00:00
Johannes Jost Meixner
6aeb32db74 Add linux-f10-devtools (any version) and linux-c6-devtools (prior to 6.6_3) to
the CVE-2015-0235 entry from 2015-01-28.

Approved by:	swills (mentor)
2015-02-02 19:09:35 +00:00
Mark Felder
ff9005823f Add net-mgmt/xymon-server CVE-2015-1430 2015-02-02 15:25:31 +00:00
Johannes Jost Meixner
3db147c9dc www/linux-*-flashplugin11: Add CVE-2015-0313
Spotted by:	kwm
Approved by:	swills (mentor)
2015-02-02 14:53:56 +00:00
Dmitry Marakasov
b0b23ec37e - Fix build from plain user 2015-02-02 14:34:20 +00:00
Hiroki Sato
26c9dc3ec2 Fix a typo. 2015-02-01 20:25:43 +00:00
Hiroki Sato
f18568b5b9 Add security/p5-Heimdal-Kadm5, a perl module for Heimdal Kerberos
administrative client library (libkadm5clnt).
2015-02-01 18:55:29 +00:00
Hiroki Sato
6fd55f7db6 Add security/p5-Authen-Simple-Kerberos, Kerberos backend for
p5-Authen-Simple.
2015-02-01 18:51:34 +00:00
Hiroki Sato
c622075b3a Add security/p5-Authen-Krb5-Simple, simple Kerberos authentication module. 2015-02-01 18:48:50 +00:00
Hiroki Sato
36a0ba4d9a - Add Heimdal support.
- Use USES=gssapi.
2015-02-01 18:43:42 +00:00
Jan Beich
8b2b9d3a6b - Update NSPR to 4.10.8
- Update NSS to 3.17.2
- Update Firefox to 35.0.1

Changes:	http://mozilla.6506.n7.nabble.com/ANNOUNCE-NSPR-4-10-8-Release-td332365.html
Changes:	https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.17.4_release_notes
Changes:	https://www.mozilla.org/en-US/firefox/35.0.1/releasenotes/
Differential Revision:	https://reviews.freebsd.org/D1736
Approved by:	bapt (mentor)
2015-02-01 16:46:24 +00:00
Antoine Brodin
997e0966fd Update to 20150129 2015-02-01 15:45:44 +00:00
Antoine Brodin
e5435d92c1 - Update textproc/py-pyelasticsearch to 1.0
- Adjust security/py-plaso dependencies and patch it to be less noisy
2015-02-01 12:42:54 +00:00
Jimmy Olgeni
7933cbc833 Add CVE-2015-0862 for net/rabbitmq. 2015-01-31 16:09:37 +00:00
Olli Hauer
6a093ced96 - document apache24 issues 2015-01-31 15:07:28 +00:00
Thomas Zander
148114425f - Update to upstream version 1.11.7
- Add non-default SMB (samba) option

PR:		194155
Submitted by:	syepes@gmail.com
Reviewed by:	lukas.slebodnik@intrak.sk (maintainer), riggs
Approved by:	lukas.slebodnik@intrak.sk (maintainer)
2015-01-31 13:53:54 +00:00
Vsevolod Stakhov
97015e0940 Add hpenc utility port.
https://github.com/vstakhov/hpenc
2015-01-31 10:25:36 +00:00
Guido Falsi
79ede1bfbe Document asterisk security issues.
While here, add CVE number to a previous asterisk entry.
2015-01-29 11:20:51 +00:00
Dmitry Marakasov
e5f034214d - Add missing plist files and empty dirs, drop @dirrm*
PR:		197147
Submitted by:	amdmi3
Approved by:	eric@camachat.org (maintainer)
2015-01-29 02:17:29 +00:00
Renato Botelho
4e6332642c Update to 0.98.6 2015-01-28 14:24:48 +00:00
Johannes Jost Meixner
b94dece6fd Add CVE-2015-0235.
- Affects linux_base-*

Approved by:	so@ (des)
2015-01-28 08:39:20 +00:00
Dmitry Marakasov
d694e148e6 - Drop @dirrm* from and add empty directories to pkg-plists
Approved by:	portmgr blanket
2015-01-28 01:41:25 +00:00
Sunpoet Po-Chuan Hsieh
cd528e3870 - Update to 1.68
Changes:	http://search.cpan.org/dist/Net-SSLeay/Changes
2015-01-27 11:26:54 +00:00
Kubilay Kocak
62abfe3028 devel/libhtp, security/suricata: Use iconv:translit
Use translit for USES=iconv, fixing a build error on specific (10-STABLE r???)
versions of FreeBSD that dont contain a libiconv implementation with certain
features [1] in base.

PR:		196720 [1]
Reported by:	<trond.endrestol ximalas info>
2015-01-27 10:47:48 +00:00
Vanilla I. Shu
5cedef19bd Add p5-Crypt-Sodium 0.06, perl bindings for portable NaCL (libsodium).
PR:		197088
Submitted by:	Thomas von Dein <freebsd@daemon.de>
2015-01-27 06:32:33 +00:00
Tijl Coosemans
20ebd85bff Document critical Adobe Flash Player vulnerability (CVE-2015-0311) 2015-01-26 21:20:43 +00:00
Olli Hauer
dad6a4f07c - document bugzilla security issues 2015-01-26 20:24:08 +00:00
Antoine Brodin
aa49f292d4 Fix DEPENDS 2015-01-24 21:49:41 +00:00
Antoine Brodin
a0e397213e Fix a typo in DEPENDS 2015-01-24 20:30:13 +00:00
Antoine Brodin
bd63b368ac Fix some _DEPENDS 2015-01-24 19:27:27 +00:00
Li-Wen Hsu
8ad3597657 - Fix description of 9c7b6c20-a324-11e4-879c-00e0814cab4e 2015-01-24 17:58:07 +00:00
Antoine Brodin
364abe76fd Switch some dependencies from a directory name or a file generated by pkg-install
to a package name,  as the former can't be attributed to a package
2015-01-24 15:07:39 +00:00
Alexey Dokuchaev
62b818217f Sanitize port description (obtained upstream) and kill EOL whitespace. 2015-01-24 10:25:21 +00:00
Koop Mast
268c173ab8 Install vala "bindings"
Add LICENSE
Update WWW
2015-01-24 10:09:10 +00:00
Mark Felder
ff76b3eb0c Patch parser to fix matching for Cyrus IMAP login attempts which are not
plaintext.

PR:		196943
Submitted by:	jakob.alvermark@bsdlabs.com
2015-01-23 20:15:34 +00:00
Tijl Coosemans
86c6fc4c0d - Update devel/automake to 1.15
- Update devel/gettext to 0.19.4
- Update devel/libtool and devel/libltdl to 2.4.5
- This version of libtool has been fixed to pass -fstack-protector to the
  compiler during linking.  Add the same fix to USES=libtool.  This should
  improve SSP support on FreeBSD/i386 8 and 9.
- databases/libmemcached, security/sssd: patch configure.ac so
  AC_CONFIG_AUX_DIR appears earlier.
  For databases/libmemcached changing configure.ac causes manpages to be
  regenerated which requires extra dependencies so patch a makefile to
  prevent that.
- devel/xfce4-dev-tools: only depend on recent versions of autoconf and
  automake

PR:		196938
Exp-run by:	antoine
Approved by:	portmgr (antoine)
2015-01-23 18:54:01 +00:00
Li-Wen Hsu
f3324ced2c Document Django 2014-01-13 vulnerabilty 2015-01-23 17:47:00 +00:00
Ryan Steinmetz
d67d09e2ba - Update to 5.10 2015-01-22 23:33:14 +00:00
Mikhail Teterin
af56c7fc52 Add a note about the just-fixed vulnerability of applications using net/libutp.
PR:		196351
Differential Revision:	D1575
Submitted by:	Jan Beich
Approved by:	bapt
2015-01-22 17:43:47 +00:00
Jase Thew
4a3017391b security/polarssl13:
- Add upstream patch to address crafted certificates vulnerability
- Add USES cpe

MFH:		2015Q1
Security:	CVE-2015-1182
Security:	a5856eba-a015-11e4-a680-1c6f65c3c4ff
Approved by:	maintainer (chris@bsdjunk.com)
2015-01-22 17:28:10 +00:00
Johannes Jost Meixner
128d64ac67 security/linux-c6-openssl: upgrade to 1.0.1e_3
- Upgrade to 1.0.1e_3
- Fixes CVEs from 2015-01-08.

Differential Revision:	https://reviews.freebsd.org/D1597
Security:	4e536c14-9791-11e4-977d-d050992ecde8
Approved by:	swills (mentor)
2015-01-22 17:10:25 +00:00
Johannes Jost Meixner
2925c75bbb Amend linux-c6-openssl version in OpenSSL entry from 2015-01-08.
Approved by:	swills (mentor)
2015-01-22 17:09:22 +00:00
Vsevolod Stakhov
a91fe34f1e Add CVE-2015-0206 description for LibreSSL port. 2015-01-22 17:02:40 +00:00
Vsevolod Stakhov
469e0c88d8 - Update to 2.1.3
PR:		197005
Submitted by:	Bernard Spil <spil.oss at gmail.com>
2015-01-22 16:48:37 +00:00
Tijl Coosemans
96f7bce425 Document Adobe Flash Player vulnerabilities 2015-01-22 12:54:13 +00:00
David Thiel
cd4ac85168 Update to 1.31.
PR:		196529
Submitted by: lightside
2015-01-22 00:42:35 +00:00
Rene Ladan
3872f5cc79 Document new vulnerabilities in www/chromium < 40.0.2214.91
Also affects FFmpeg, ICU, DOM but the links on the webpage all result in a 403.

Obtained from:	http://googlechromereleases.blogspot.nl
2015-01-21 22:09:38 +00:00
Frederic Culot
39557796a8 - Update to 1.12
- Shorten COMMENT

Changes:	http://search.cpan.org/dist/Data-Password/Changes
2015-01-21 15:03:22 +00:00