Commit graph

25163 commits

Author SHA1 Message Date
Martin Wilke
c8f36c3aa4 - Mark py-crits deprecated and set expired date as for the same reason explained in r437796
PR:		        216758
Approved by:	dvl (maintainer via irc)
2017-04-06 13:22:53 +00:00
Bartek Rutkowski
493e090680 security/govpn: update 7.2 -> 7.3
PR:		218382
Submitted by:	Sergey Matveev <stargrave@stargrave.org> (maintainer)
2017-04-06 12:47:36 +00:00
Jason E. Hale
f9d0b63e5b Update security/gpgme and friends to 1.9.0 [1]
Fix LICENSE
Add regression test support for master port. Slave port tests are not working
properly and need further investigation.

PR:		218316 (based on) [1]
Submitted by:	gahr [1]
Changes:	https://lists.gnupg.org/pipermail/gnupg-users/2017-March/057963.html
2017-04-05 20:13:00 +00:00
Bernard Spil
a1d4cc9264 security/acme-client: Update pkg-message
- Remove duplicate double-qoute [1]
  - Remove warning about letskencrypt rename (>6mo)

PR:		218182 [1]
Submitted by:	Anatoly Kamchatnov <akamch@gmail.com>
2017-04-05 18:34:13 +00:00
Bernard Spil
0d932288af security/vuxml: Add missing topic
Reported by:	Guido Falsi <madpilot@FreeBSD.org>
2017-04-05 16:47:13 +00:00
Bernard Spil
9d6fc16e27 security/vuxml: Document curl vulnerability 2017-04-05 14:34:15 +00:00
Joseph Mingrone
38cff13b4a New port, security/acmetool: An automatic certificate acquisition tool for
ACME (Let's Encrypt)

WWW: https://github.com/hlandau/acme

PR:		216779
Submitted by:	samm@os2.kiev.ua (maintainer)
Reviewed by:	mat
Approved by:	swills (mentor, implicit)
Differential Revision:	https://reviews.freebsd.org/D10280
2017-04-05 13:00:02 +00:00
Babak Farrokhi
5c1200fcd6 Update security/erlang-fast_tls to 1.0.11
Reviewed by:	bapt
Approved by:	bapt
Differential Revision:	https://reviews.freebsd.org/D10271
2017-04-05 07:13:12 +00:00
Martin Wilke
abec34cd06 - Document django -- multible vulnerabilities 2017-04-04 18:10:17 +00:00
Guido Falsi
8fbe9c3dc9 Document net/asterisk13 vulnerability. 2017-04-04 16:39:29 +00:00
Tobias Kortkamp
18bb245b3a Update to 2.40b
- Move to LLVM 4.0

Changes:	http://lcamtuf.coredump.cx/afl/ChangeLog.txt
Approved by:	lme (mentor)
Differential Revision:	https://reviews.freebsd.org/D10270
2017-04-04 07:31:23 +00:00
Martin Matuska
bf96246c07 Horde package update:
devel/pear-Horde_Core 2.28.2 -> 2.28.3
security/pear-Horde_Crypt 2.7.5 -> 2.7.6 (CVE-2017-7413, CVE-2017-7414)
www/pear-Horde_Form 2.0.16 -> 2.0.17
mail/horde-webmail 5.2.18 -> 5.2.19
deskutils/horde-groupware 5.2.18 -> 5.2.19

Security:	CVE-2017-7413, CVE-2017-7414
2017-04-04 06:41:38 +00:00
Alexey Dokuchaev
f333635680 - Document recent NVIDIA GPU display driver vulnerabilities
- Spell "NVIDIA UNIX driver" consistently throughout the file

PR:	217341
2017-04-04 02:27:15 +00:00
Adam Weinberger
693d393747 Update to 2.1.20.
* gpg: New properties 'expired', 'revoked', and 'disabled' for the
   import and export filters.

 * gpg: New command --quick-set-primary-uid.

 * gpg: New compliance field for the --with-colon key listing.

 * gpg: Changed the key parser to generalize the processing of local
   meta data packets.

 * gpg: Fixed assertion failure in the TOFU trust model.

 * gpg: Fixed exporting of zero length user ID packets.

 * scd: Improved support for multiple readers.

 * scd: Fixed timeout handling for key generation.

 * agent: New option --enable-extended-key-format.

 * dirmngr: Do not add a keyserver to a new dirmngr.conf.  Dirmngr
   uses a default keyserver.

 * dimngr: Do not treat TLS warning alerts as severe error when
   building with GNUTLS.

 * dirmngr: Actually take /etc/hosts in account.

 * wks: Fixed client problems on Windows.  Published keys are now set
   to world-readable.

 * tests: Fixed creation of temporary directories.

 * A socket directory for a non standard GNUGHOME is now created on
   the fly under /run/user.  Thus "gpgconf --create-socketdir" is now
   optional.  The use of "gpgconf --remove-socketdir" to clean up
   obsolete socket directories is however recommended to avoid
   cluttering /run/user with useless directories.

 * Fixed build problems on some platforms.
2017-04-03 20:53:48 +00:00
Jung-uk Kim
56cab9fcdb Remove obsolete OpenSSL hacks for IDEA crypto.
We have some hacks in the ports tree to detect or to unconditionally disable
IDEA crypto support.  These hacks existed because OpenSSL in FreeBSD 9.3 and
earlier was shipped without IDEA support by default but we were allowed to
enable it via WITH_IDEA src.conf(5) option.

https://www.freebsd.org/cgi/man.cgi?query=src.conf&manpath=FreeBSD+9.3-RELEASE

Therefore, we had to implement some hacks to support three different cases,
i.e., a) 9.3 and earlier without IDEA crypto (default), b) 9.3 and earlier
with IDEA crypto (via WITH_IDEA src.conf option), and c) 10.0 and later with
unconditional IDEA support.  Now we can safely remove them because 9.3 and
earlier is no longer supported.

PR:		218233
Exp-Run by:	antoine
Approved by:	antoine (portmgr)
2017-04-03 17:33:48 +00:00
Sunpoet Po-Chuan Hsieh
32ac92ffeb Update to 4.2.5
Changes:	https://github.com/doorkeeper-gem/doorkeeper/blob/master/NEWS.md
2017-04-03 12:58:33 +00:00
Vanilla I. Shu
716a082d8c Update to 1.8.3. 2017-04-03 12:24:50 +00:00
Vanilla I. Shu
29b17f5cf6 Update to 1.8.3. 2017-04-03 12:24:33 +00:00
Vanilla I. Shu
6a89783132 Update to 0.045. 2017-04-03 12:20:21 +00:00
Steve Wills
b2d54d85c9 security/vault: update to 0.7.0
PR:		218232
Submitted by:	Scott Larson <stl@ossuary.net>
2017-04-03 08:17:58 +00:00
Kurt Jaeger
999edc441c security/p5-Crypt-LE: update 0.19 -> 0.20
Relnotes:	http://cpansearch.perl.org/src/LEADER/Crypt-LE-0.20/Changes
2017-04-02 08:40:13 +00:00
Baptiste Daroussin
68bf8e634c Update to 0.18.5 2017-04-01 23:15:07 +00:00
Gerald Pfeifer
04d6f52202 Bump PORTREVISIONs for ports depending on the canonical version of GCC and
lang/gcc which have moved from GCC 4.9.4 to GCC 5.4 (at least under some
circumstances such as versions of FreeBSD or platforms).

This includes ports
 - with USE_GCC=yes or USE_GCC=any,
 - with USES=fortran,
 - using using Mk/bsd.octave.mk which in turn has USES=fortran, and
 - with USES=compiler specifying openmp, nestedfct, c++11-lib, c++14-lang,
   c++11-lang, c++0x, c11, or gcc-c++11-lib.

PR:		216707
2017-04-01 15:23:30 +00:00
Sunpoet Po-Chuan Hsieh
72a20a7edb Update to 1.13.1
Changes:	https://github.com/capistrano/sshkit/blob/master/CHANGELOG.md
2017-04-01 10:52:33 +00:00
Kurt Jaeger
0bc67c7cac security/p5-Crypt-RSA-Parse: fix dependencies
- fix RUN_DEPENDS
- add TEST_DEPENDS
- mark as NO_ARCH

PR:		218277
Submitted by:	Anton Yuzhaninov <citrin+pr@citrin.ru>
Approved by:	pi (maintainer)
2017-04-01 06:51:05 +00:00
Antoine Brodin
82f4b0053b Revert r436952, it breaks build
Reported by:	pkg-fallout
With hat:	portmgr
2017-04-01 06:22:28 +00:00
Bryan Drewery
9051821be1 - Update to 7.5p1.
- Update X509 to 10.1.
- Disable KERB_GSSAPI for now as it does not build.

Changes: https://www.openssh.com/txt/release-7.5
2017-04-01 01:59:25 +00:00
Carlos J. Puga Medina
d40fc5aa91 Document new vulnerabilities in www/chromium < 57.0.2987.133
Obtained from:	https://chromereleases.googleblog.com/2017/03/stable-channel-update-for-desktop_29.html
2017-03-30 21:43:45 +00:00
Mathieu Arnold
f70343fa84 Remove obsolete PROJECTHOST.
Sponsored by:	Absolight
2017-03-30 21:12:43 +00:00
Johan van Selst
1bbe14e739 Update to libssh 0.7.4
https://www.libssh.org/2017/02/03/libssh-0-7-4/

PR:		218230
Submitted by:	Iblis Lin
2017-03-30 19:41:05 +00:00
Jason Unovitch
d544c46db1 Document Xen Security Advisory (XSA 206)
CVE lists none (yet) assigned

While here, fix a typo on my last Xen entry

Security:	https://vuxml.FreeBSD.org/freebsd/47873d72-14eb-11e7-970f-002590263bf5.html
2017-03-30 01:58:06 +00:00
Jason Unovitch
e61f6dcac2 Actually, let's refer to the original entries for these hostapd CVEs
Reflect CVE-2016-4476 / VID 967b852b-1e28-11e6-8dd3-002590263bf5 in cancelled

CVE-2015-5314 is in VID 976567f6-05c5-11e6-94fa-002590263bf5

PR:		217906
Security:	https://vuxml.FreeBSD.org/freebsd/976567f6-05c5-11e6-94fa-002590263bf5.html
Security:	https://vuxml.FreeBSD.org/freebsd/967b852b-1e28-11e6-8dd3-002590263bf5.html
2017-03-30 01:47:42 +00:00
Sunpoet Po-Chuan Hsieh
acd61b4661 Update to 0.18
Changes:	http://search.cpan.org/dist/Net-SSH-AuthorizedKeysFile/Changes
2017-03-29 23:36:31 +00:00
Matthew Seaman
92aff0b4a8 phpMyAdmin: document PMASA-2017-8 -- bypass restrictions on 'no
password' accounts.
2017-03-29 16:47:39 +00:00
Mark Felder
bcbc95120f Document hostapd vulnerabilities
PR:		217906
2017-03-28 23:19:47 +00:00
Sunpoet Po-Chuan Hsieh
6b18b88f36 Update to 1.81
Changes:	http://search.cpan.org/dist/Net-SSLeay/Changes
2017-03-28 20:52:39 +00:00
Alan Somers
b9a543b963 security/sssd: upstream has moved from fedorahosted to pagure.io
PR:		218082
Reviewed by:	lukas.slebodnik@intrak.sk (maintainer)
Approved by:	brd (ports)
2017-03-27 20:48:27 +00:00
Shaun Amott
f74915b157 Update to 0.11.
PR:		217982
Submitted by:	Anton Yuzhaninov <citrin+pr@citrin.ru>
Approved by:	Thomas von Dein <freebsd@daemon.de> (maintainer)
2017-03-27 17:34:24 +00:00
Sunpoet Po-Chuan Hsieh
65fcde55df Update to 1.6.1
Changes:	https://github.com/nov/rack-oauth2/commits/master
2017-03-27 11:12:37 +00:00
Sunpoet Po-Chuan Hsieh
4d2d6736ea Update to 0.26.0
Changes:	https://gitlab.com/m2crypto/m2crypto/blob/master/CHANGES
		https://gitlab.com/m2crypto/m2crypto/commits/master
2017-03-27 11:12:00 +00:00
Alex Dupre
551ec60b99 Change MASTER_SITES and unbreak. 2017-03-27 10:00:48 +00:00
Bartek Rutkowski
45314e8b77 security/snort2pfcd: update 1.2 -> 1.3
PR:		218149
Submitted by:	Samee Shahzada <onestsam@gmail.com> (maintainer)
2017-03-27 09:52:38 +00:00
Sunpoet Po-Chuan Hsieh
1ec007b645 Update to 1.13.0
Changes:	https://github.com/capistrano/sshkit/blob/master/CHANGELOG.md
2017-03-26 21:24:43 +00:00
Bernard Spil
9e7d5d132f security/libp11: Fix build with LibreSSL
- Fix-up OPENSSL_VERSION_NUMBER checks

PR:		217006
Approved by:	maintainer timeout
2017-03-26 18:55:21 +00:00
Shaun Amott
6c3212f7b2 Update to 0.2.9.10.
PR:		217830
Submitted by:	Yuri Victorovich <yuri@rawbw.com> (maintainer)
2017-03-26 18:30:24 +00:00
Bernard Spil
914b2fb385 security/libressl-devel: Update to 2.5.1
- Update to 2.5.1 [1]

[1] Release Notes: https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-2.5.2-relnotes.txt
2017-03-26 18:01:27 +00:00
Kurt Jaeger
7da315e7b0 security/p5-Crypt-LE: add some depends and sort RUN_DEPENDS
Submitted by:	des
2017-03-26 16:03:20 +00:00
Wen Heping
b100e87a5a - Update to 1.209
Changes: http://cpansearch.perl.org/src/CAPOEIRAB/Digest-Bcrypt-1.209/Changes
2017-03-26 15:09:33 +00:00
Bernard Spil
969678376a security/acme-client: Add run-time dep on ca_root_nss
- acme-client fails at runtime if CA roots not installed

PR:		215722
Reported by:	pete@nomadlogic.org
2017-03-26 10:47:44 +00:00
Bernard Spil
b189f2aaef security/certificate-transparency: Fix build issues with LibreSSL
- Fix OPENSSL_VERSION_NUMBER checks
  - Fix LibreSSL detection
  - Modify CMS disabling to BoringSSL and LibreSSL

PR:		217013
Obtained from:	https://github.com/google/certificate-transparency/pull/1364
2017-03-26 10:40:48 +00:00