Commit graph

113 commits

Author SHA1 Message Date
Olli Hauer
3c8085b82e - update bugzilla bugzilla3 and bugzilla42
- use new bugzilla@ address (members skv@, tota@, ohauer@)
- patch russian/japanese/german bugzilla and bugzilla templates
  so the reflect the security updates in the original templates
- patch german/bugzilla42 templates
- adopt new Makefile header

	vuxml: 6ad18fe5-f469-11e1-920d-20cf30e32f6d
	CVE: CVE-2012-3981
	https://bugzilla.mozilla.org/show_bug.cgi?id=785470
	https://bugzilla.mozilla.org/show_bug.cgi?id=785522
	https://bugzilla.mozilla.org/show_bug.cgi?id=785511
2012-09-01 20:16:06 +00:00
TAKATSU Tomonari
b0a1748d56 - Fix PORTSCOUT
PR:		ports/170530
Submitted by:	tota (myself)
Approved by:	maintainer timeout (> 2 weeks)
2012-08-25 10:31:19 +00:00
Olli Hauer
63f3e3b0d4 - remove www/apache20 and devel/apr0
- s/USE_APACHE= 20+/USE_APACHE= 22+/
- unify s/YES/yes/
- cleanup APACHE_VERSION <= 22 usage
- add entry to MOVED

with hat apache@
2012-08-18 14:29:08 +00:00
Olli Hauer
d0228223f2 - pkgng: cosmetic fix against lstat messages 2012-07-28 16:25:11 +00:00
Olli Hauer
1a47fe9edb - security update bugzilla
new Versions: 3.6.10, 4.0.7, 4.2.2

  4.2.2

  This release fixes two security issues. See the Security Advisory for details.

  In addition, the following important fixes/changes have been made in this release:

  o A regression introduced in Bugzilla 4.0 caused some login names to be ignored
    when entered in the CC list of bugs. (Bug 756314)
  o Some queries could trigger an invalid SQL query if strings entered by the user
    contained leading or trailing whitespaces. (Bug 760075)
  o The auto-completion form for keywords no longer automatically selects the
    first keyword in the list when the field is empty. (Bug 764517)
  o A regression in Bugzilla 4.2 prevented classifications from being used in
    graphical and tabular reports in the "Multiple Tables" field. (Bug 753688)
  o Attachments created by the email_in.pl script were associated to the wrong
    comment. (Bug 762785)
  o Very long dependency lists can now be viewed correctly. (Bug 762783)
  o Keywords are now correctly escaped in the auto-completion form to prevent any
    XSS abuse. (Bug 754561)
  o A regression introduced in Bugzilla 4.0rc2 when fixing CVE-2011-0046 caused
    the "Un-forget the search" link to not work correctly anymore when restoring a
    deleted saved search, because this link was lacking a valid token. (Bug 768870)
  o Two minor CSRF vulnerabilities have been fixed which could let an attacker
    alter your default search criteria in the Advanced Search page. (Bugs 754672
    and 754673)

  4.0.7

  This release fixes one security issue. See the Security Advisory for details.

  In addition, the following bugs have been fixed in this release:

  o A regression introduced in Bugzilla 4.0 caused some login names to be ignored
    when entered in the CC list of bugs. (Bug 756314)
  o Keywords are now correctly escaped in the auto-complete form to prevent any
    XSS abuse. (Bug 754561)
  o A regression introduced in Bugzilla 4.0rc2 when fixing CVE-2011-0046 caused
    the "Un-forget the search" link to not work correctly anymore when restoring a
    deleted saved search, because this link was lacking a valid token. (Bug 768870)

  3.6.10

  This release fixes one security issue. See the Security Advisory for details.
  http://www.bugzilla.org/security/3.6.9/

Approved by:	implicit skv@ (bugzilla / bugzilla3)
Security:	CVE-2012-1968
		CVE-2012-1969
		https://bugzilla.mozilla.org/show_bug.cgi?id=777398
		https://bugzilla.mozilla.org/show_bug.cgi?id=777586
		vid=58253655-d82c-11e1-907c-20cf30e32f6d
2012-07-27 21:34:04 +00:00
Olli Hauer
f87e4270c3 - new port bugzilla42
New Features and Improvements:
- Experimental SQLite Support
- Creating an Attachment by Pasting Text Into a Text Field
- HTML Bugmail (default: on  can be disabled in user preference)
- Improved Searching System
- Disabling Old Components, Versions and Milestones
- Displaying a Custom Field Value Based on Multiple Values of Another Field
- Auditing of All Changes Within Bugzilla
- Accessibility Improvements

And many other Improvements, for complete list see:
 http://www.bugzilla.org/releases/4.2.1/release-notes.html
2012-07-24 21:37:07 +00:00
Olli Hauer
2d439473cb - convert to options NG
Approved by:	skv@ (implicit)
2012-07-24 20:41:55 +00:00
Olli Hauer
ae95c0833c - fix broken mod_perl include
apache version detect was not enabled,
the time SITE_PERL was removed from *_DEPENDS
2012-07-24 19:24:22 +00:00
Andrej Zverev
4f3dde191d graphics/ImageMagick can change package name via PKGNAMESUFFIX.
We should not rely on this.

Reported by:	Jarrod Sayers <jarrod at downtools.com.au>
Pointy hat:	az@
2012-07-03 17:38:41 +00:00
Chris Rees
7b74961dbc Update devel/p5-chart --> devel/p5-Chart to fix INDEX build
Pointyhat:	sunpoet
2012-07-01 14:43:24 +00:00
Andrej Zverev
47d7ecfddf - Remove SITE_PERL from *_DEPENDS
Approved by: portmgr@ (bapt@)
2012-06-29 10:20:00 +00:00
Olli Hauer
27815ff1a4 - security update to bugzilla 3.0.9 and 4.0.6
- update russian/bugzilla3-ru template
- patch german templates so revision match and no warning is displayed
- add vuxml entry

PR:
Submitted by:
Reviewed by:
Approved by:	skv (implicit)
Obtained from:
MFC after:
Security:	https://bugzilla.mozilla.org/show_bug.cgi?id=728639
		https://bugzilla.mozilla.org/show_bug.cgi?id=745397
		CVE-2012-0465
		CVE-2012-0466
2012-04-21 17:37:41 +00:00
Olli Hauer
5e7bd302a1 - update to 4.0.5
Vulnerability Details
=====================

Class:       Cross-Site Request Forgery
Versions:    4.0.2 to 4.0.4, 4.1.1 to 4.2rc2
Fixed In:    4.0.5, 4.2
Description: Due to a lack of validation of the enctype form
             attribute when making POST requests to xmlrpc.cgi,
             a possible CSRF vulnerability was discovered. If a user
             visits an HTML page with some malicious HTML code in it,
             an attacker could make changes to a remote Bugzilla installation
             on behalf of the victim's account by using the XML-RPC API
             on a site running mod_perl. Sites running under mod_cgi
             are not affected. Also the user would have had to be
             already logged in to the target site for the vulnerability
             to work.
References:  https://bugzilla.mozilla.org/show_bug.cgi?id=725663
CVE Number:  CVE-2012-0453

Approved by:	skv (implicit)
2012-04-10 05:15:47 +00:00
Sergey Skvortsov
4cf8edc874 Update to 4.0.4
Changes:	http://www.bugzilla.org/releases/4.0.4/release-notes.html#v40_point
Security:	http://www.vuxml.org/freebsd/309542b5-50b9-11e1-b0d8-00151735203a.html
2012-02-06 12:03:29 +00:00
Olli Hauer
03efecffe1 - update to version 3.6.7
- CVE-2011-3657
- CVE-2011-3667

Summary
=======

The following security issues have been discovered in Bugzilla:

* When viewing tabular or graphical reports as well as new charts,
  an XSS vulnerability is possible in debug mode.

* The User.offer_account_by_email WebService method lets you create
  a new user account even if the active authentication method forbids
  users to create an account.

* A CSRF vulnerability in post_bug.cgi and in attachment.cgi could
  lead to the creation of unwanted bug reports and attachments.

All affected installations are encouraged to upgrade as soon as possible.

Full Release Notes:
http://www.bugzilla.org/security/3.4.12/

Approved by:	skv@ (explicit)
2012-01-05 17:25:28 +00:00
Doug Barton
7ec7e2a3cf Remove references to mysql 323 and 40, most commonly of the form:
IGNORE_WITH_MYSQL=     323 40
2011-10-17 04:35:02 +00:00
Olli Hauer
ba1a02e4d9 - Fix checksetup issue if p5-version>=0.92 is installed (which is in current ports tree)
See https://bugzilla.mozilla.org/show_bug.cgi?id=678772

PR:		ports/159823
Submitted by:	ohauer
Approved by:	skv (per mail)
Obtained from:	https://bugzilla.mozilla.org/attachment.cgi?id=552915&action=diff
2011-08-27 10:18:44 +00:00
Sergey Skvortsov
a95da70810 Update to 4.0.2
Changes:	http://www.bugzilla.org/releases/4.0.2/release-notes.html
Security:	http://www.vuxml.org/freebsd/dc8741b9-c5d5-11e0-8a8e-00151735203a.html
PR:		ports/159576
Submitted by:	Peter Vereshagin <peter@vereshagin.org>
2011-08-13 18:24:21 +00:00
Olli Hauer
d399de5688 - create missing (empty) directory (bugzilla) so checksetup does not fail
- use DIST_SUBDIR for bugzilla and all translations
- sort pkg-plist (genplist)

OK from bugzilla maintainers per PM.

PR:		ports/158766
Submitted by:	ohauer
2011-07-18 21:56:02 +00:00
TAKATSU Tomonari
2859a152ab - Update to 4.0.1 [1]
- Cleanup CONFLICTS/PORTSCOUT among Makefiles and Makefile.common

Submitted by:	ohauer (via private e-mail) [1]
2011-06-11 04:25:06 +00:00
Sergey Skvortsov
930c90e87d - Remove obsolete devel/bugzilla2
- Tune devel/bugzilla* : add PORTSCOUT, LATEST_LINK, CONFLICTS, LICENSE
2011-06-07 16:00:26 +00:00
Sergey Skvortsov
7bd02d2b01 - Copy devel/bugzilla to devel/bugzilla3; russian/bugzilla-ru to russian/bugzilla3-ru
- Update devel/bugzilla, russian/bugzilla-ru to 4.0.1
- Update devel/bugzilla3, russian/bugzilla3-ru to 3.6.5

Changes:	http://www.bugzilla.org/releases/4.0.1/release-notes.html
		http://www.bugzilla.org/releases/3.6.5/release-notes.html
2011-06-07 13:30:01 +00:00
Olli Hauer
3806babe4b - bump because of mod_perl2 update
- order pkg-plist so it match autmated tools like genplist
- add missing empty directories (used by checksetup.pl) [1]

commit with hat apache@

PR:		[1] ports/154295
Submitted by:	me
2011-05-22 22:16:27 +00:00
Sergey Skvortsov
bad74004c0 Update to 3.6.4
Changes:        http://www.bugzilla.org/releases/3.6.4/release-notes.html
Security:       http://www.vuxml.org/freebsd/c8c927e5-2891-11e0-8f26-00151735203a.html
Feature safe:	yes
2011-01-25 15:49:49 +00:00
TAKATSU Tomonari
b2957a0a74 - Update to 3.6.3 [1]
- Use WWWDIR instead of some other custom locations [2]
- Add Makefile.common which Makefiles in devel/bugzilla, russian/bugzilla-ru
  and japanese/bugzilla include to use WWWDIR in common [2]

Changes:	http://www.bugzilla.org/releases/3.6.3/release-notes.html [1]
Security:	http://www.bugzilla.org/security/3.2.8/ [1]
PR:	ports/151912 [1], [2]
Submitted by:	ohauer [1], tota (myself) [2]
Approved by:	skv
2010-12-12 05:56:19 +00:00
Martin Matuska
17e550ca2f Explicitly depend on p5-Digest-MD5 only if PERL_LEVEL < 500703
Explicitly depend on p5-Digest-SHA only if PERL_LEVEL < 501000
2010-09-21 16:08:11 +00:00
Sergey Skvortsov
d2c1dc5fb7 Update to 3.6.2
Changes:        http://www.bugzilla.org/releases/3.6.2/release-notes.html
Security:       http://www.vuxml.org/freebsd/8cbf4d65-af9a-11df-89b8-00151735203a.html
PR:             ports/149721
Submitted by:   ohauer
2010-09-06 07:58:29 +00:00
Sergey Skvortsov
d9a265927e Update to 3.6.1
Changes:	http://www.bugzilla.org/releases/3.6.1/release-notes.html
Security:	http://www.vuxml.org/freebsd/f1331504-8849-11df-89b8-00151735203a.html
PR:		ports/148149
Submitted by:	olli hauer <ohauer@gmx.de>
Feature safe:   yes
2010-07-05 16:42:22 +00:00
Sergey Skvortsov
d0aa9f59cf Update to 3.6
Changes:	http://www.bugzilla.org/releases/3.6/release-notes.html
2010-04-16 07:15:08 +00:00
Dirk Meyer
de78af3ac5 - update to 1.4.1
Reviewed by:	exp8 run on pointyhat
Supported by:	miwi
2010-03-28 06:47:48 +00:00
TAKATSU Tomonari
34281ff693 - Update to 3.4.6 [1]
- Remove ja-bugzilla-2.* from CONFLICT entries of devel/bugzilla,
 devel/bugzilla2 and russian/bugzilla-ru [2]
- Change MAINTAINER address from tota@rtfm.jp to tota@FreeBSD.org

 [1] This port has been updated from the bugzilla Japanized patch to
    bugzilla Japanese language pack installation, both of which are
    maintained differently.
     * Japanized patch is not actively maintained anymore.
     * More sophisticated language pack framework has been introduced since
       Bugzilla 3.0.
 [2] This port no longer conflicts with those ports due to the new language
    pack framework.

Approved by:	maho (mentor)
2010-03-25 13:25:48 +00:00
Sergey Skvortsov
24f76b96b8 Fix dependency name.
Pointed by:	QAT
2010-03-08 12:51:42 +00:00
Sergey Skvortsov
300622f6fe Update to 3.4.6
Changes:	http://www.bugzilla.org/releases/3.4.6/release-notes.html
2010-03-08 12:26:34 +00:00
Dirk Meyer
ca9c60461c - update to jpeg-8 2010-02-05 11:46:55 +00:00
Sergey Skvortsov
a145386963 - Update to 3.4.5 [1]
- Use $SUB_FILES & $SUB_LIST to dynamically adjust pkg-message [2]

Changes:	http://www.bugzilla.org/security/3.0.10/ [1]
Security:	http://www.vuxml.org/freebsd/696053c6-0f50-11df-a628-001517351c22.html
PR:		ports/142446 [2]
Submitted by:	Sevan Janiyan <venture37 xx geeklan.co.uk> [2]
2010-02-01 16:53:26 +00:00
Jun Kuriyama
3efe84fba6 - Remove unneeded dependencies which is in perl-5.8.9 dist
(part 17).

Approved by:	portmgr (itetcu)
2010-01-29 04:56:59 +00:00
Pav Lucistnik
8a60d10be5 - Remove mail/p5-Email-MIME-Creator, it has been folded into mail/p5-Email-MIME
- Remove mail/p5-Email-MIME-Modifier, it has been folded into mail/p5-Email-MIME
- Remove mail/p5-Email-Simple-Creator, it has been folded into mail/p5-Email-Simple
- Adjust dependencies

Reported by:	pointyhat
With hat:	portmgr
2009-11-24 21:44:44 +00:00
Sergey Skvortsov
e7c5fa06dc Update to 3.4.4.
Changes:	http://www.bugzilla.org/security/3.4.3/
Security:	http://www.vuxml.org/freebsd/92ca92c1-d859-11de-89f9-001517351c22.html
2009-11-23 18:11:10 +00:00
Sergey Skvortsov
02bb066bb1 Update to 3.4.3
Changes:	http://www.bugzilla.org/releases/3.4.3/release-notes.html
PR:		ports/140327
Submitted by:	Sahil Tandon <sahil xx tandon.net>
2009-11-12 21:03:46 +00:00
Sergey Skvortsov
24e3d4005e Update to 3.4.2.
Changes:	http://www.bugzilla.org/security/3.0.8/
Security:	http://www.vuxml.org/freebsd/b9ec7fe3-a38a-11de-9c6b-003048818f40.html
Feature safe:	yes
2009-09-17 13:30:01 +00:00
Sergey Skvortsov
ab77e68ca1 Update to 3.4.1.
Changes:	http://www.bugzilla.org/security/3.4/
Security:	http://www.vuxml.org/freebsd/d67b517d-8214-11de-88ea-001a4d49522b.html
2009-08-17 11:05:10 +00:00
Sergey Skvortsov
7715840c07 Update to 3.4
Changes:	http://www.bugzilla.org/releases/3.4/release-notes.html
2009-07-30 15:41:50 +00:00
Sergey Skvortsov
dabb64b651 Update to 3.2.3
Changes:	http://www.bugzilla.org/releases/3.2.3/release-notes.html#v32_point
2009-04-12 20:39:05 +00:00
Sergey Skvortsov
425d5f8283 Update to 3.2.2
Changes:	http://www.bugzilla.org/releases/3.2.2/release-notes.html
PR:		ports/131404
Submitted by:	pgollucci
2009-02-14 21:54:27 +00:00
Sergey Skvortsov
da5c3a283b Install killer feature - 'Dusk' skin. 2008-12-01 19:07:45 +00:00
Sergey Skvortsov
f54171b7fc Update to 3.2
Changes:	http://www.bugzilla.org/releases/3.2/release-notes.html
PR:		ports/129333
Submitted by:	Eygene Ryabinkin <rea-fbsd xx codelabs.ru>
2008-12-01 15:38:51 +00:00
Sergey Skvortsov
3d0307bb60 Update to 3.0.6
Changes:	http://www.bugzilla.org/releases/3.0.6/release-notes.html
2008-11-07 14:45:07 +00:00
Sergey Skvortsov
e718a272b7 Update to 3.0.5
Changes:	http://www.bugzilla.org/releases/3.0.5/release-notes.html
Security:	http://www.vuxml.org/freebsd/1d96305d-6ae6-11dd-91d5-000c29d47fd7.html
2008-08-15 16:32:27 +00:00
Sergey Skvortsov
2be5e5ec03 Set PORTSCOUT. 2008-08-11 12:01:35 +00:00
Sergey Skvortsov
f6053e0929 Update to 3.0.4
Changes:		http://www.bugzilla.org/releases/3.0.4/release-notes.html#v30_point
2008-07-28 12:47:43 +00:00