Commit graph

3459 commits

Author SHA1 Message Date
Mark Felder
cee4eb51b0 Add entry for foreman-proxy
Obtained from:	mmoll
2014-10-09 13:09:52 +00:00
Rene Ladan
92e654eadb Document new vulnerabilities in www/chromium < 38.0.2125.101
Obtained from:	http://googlechromereleases.blogspot.nl/2014/10/stable-channel-update.html
MFH:		2014Q4
2014-10-08 08:32:04 +00:00
Olli Hauer
4f19d92e37 - document bugzilla security issues 2014-10-06 19:09:34 +00:00
Bryan Drewery
a1d0d79986 Fix rsyslog entry for pkgname matching 2014-10-02 21:14:31 +00:00
Matthew Seaman
c042b3ff7e www/rt42 < 4.2.8 is vulnerable to shellshock related exploits through
its SMIME integration.

Security:	81e2b308-4a6c-11e4-b711-6805ca0b3d42
2014-10-02 19:59:02 +00:00
Brad Davis
fb3f37589e - Update the rsyslog entry to reflect the new versions
Reviewed by:	bdrewery
2014-10-02 19:30:56 +00:00
Bryan Drewery
ddc9d6d9b4 Update Jenkins entry 549a2771-49cc-11e4-ae2c-c80aa9043978 to be readable. 2014-10-02 01:06:43 +00:00
Bryan Drewery
25485f86c6 Update grammar of DoS in Jenkins entry 2014-10-02 00:54:29 +00:00
Bryan Drewery
c2c59333ab Fix Jenkins entry to note that XSS is an issue, not as compiler 2014-10-02 00:53:43 +00:00
Bryan Drewery
59834325c3 Document Jenkins vulnerabilities
Security:		CVE-2014-3661
Security:		CVE-2014-3662
Security:		CVE-2014-3663
Security:		CVE-2014-3664
Security:		CVE-2014-3680
Security:		CVE-2014-3681
Security:		CVE-2014-3666
Security:		CVE-2014-3667
Security:		CVE-2013-2186
Security:		CVE-2014-1869
Security:		CVE-2014-3678
Security:		CVE-2014-3679
2014-10-02 00:46:54 +00:00
Bryan Drewery
33e5a12d5b Fix bash entries to also mark bash-static vulnerable 2014-10-01 22:57:16 +00:00
Bryan Drewery
15015e6b02 Document CVE-2014-6277 and CVE-2014-6278 for bash. 2014-10-01 22:30:59 +00:00
Bryan Drewery
ca11fc5279 - Document CVE-2014-7187 fixed in bash-4.3.27_1 2014-10-01 22:12:11 +00:00
Matthew Seaman
a763414630 Document the latest phpMyAdmin vulnerability.
- while here fix the '>' breakage in the rsyslogd entry.

Security:	3e8b7f8a-49b0-11e4-b711-6805ca0b3d42
2014-10-01 21:25:46 +00:00
Bryan Drewery
a703832b9e Document CVE-2014-7186 for bash 2014-10-01 03:40:03 +00:00
Brad Davis
b210b76fd9 - Document sysutils/rsyslog vulnerabilities CVE-2014-3634
Reviewed by:	bdrewery@
2014-09-30 20:09:32 +00:00
Bryan Drewery
e7ca3763f8 Document shells/fish vulnerabilities 2014-09-29 23:34:30 +00:00
Johannes Jost Meixner
af93a5d189 Add linux-c6-nss-3.15.1 package to the NSS vulnerability report.
Approved by:	swills (mentor)
2014-09-26 17:34:26 +00:00
Johannes Jost Meixner
6a6123d47e Add linux_base-c6-6.5 package to the bash vulnerability report.
Approved by:	swills (mentor)
2014-09-26 17:05:38 +00:00
Bryan Drewery
a7b1fd362d The 2nd bash issue was reassigned to CVE-2014-7169:
http://seclists.org/oss-sec/2014/q3/685

Reported by:	jkim
2014-09-25 16:22:06 +00:00
Bryan Drewery
f0256b1c19 Update bash entry for CVE-2014-3659
Security:	CVE-2014-3659
Security:	ca44b64c-4453-11e4-9ea1-c485083ca99c
2014-09-25 15:44:00 +00:00
Eygene Ryabinkin
7d75c62abd VuXML entry 48108fb0-751c-4cbb-8f33-09239ead4b55: expanded details
Reviewed by:	des@
2014-09-25 13:29:38 +00:00
Johannes Jost Meixner
e1e8f53b39 www/linux-*-flashplugin11: Fix multiple security vulnerabilities
Adobe has discovered multiple security vulnerabilities in Flash
linux-*-flashplugin-11.2r202.400. Ugrade the two Linux ports to
version .406, which fixes these.

While there, assign www/linux-c6-flashplugin11 to emulation@
in order to match r369160.

PR:		193904
Differential Revision:	https://reviews.freebsd.org/D831
Submitted by:	Jung-uk Kim
Approved by:	koobs (mentor)
MFH:		2014Q3
Security:	ca44b64c-4453-11e4-9ea1-c485083ca99c
2014-09-25 12:48:21 +00:00
Dag-Erling Smørgrav
f884047cb4 fix 2014-09-25 07:45:16 +00:00
Dag-Erling Smørgrav
46f042b4d0 Add entry for the NSS signature forgery bug.
PR:		193906
MFH:		2014Q3
Security:	CVE-2014-1568
2014-09-25 07:43:17 +00:00
Rene Ladan
9e4133005f Document new vulnerability in www/chromium < 37.0.2062.124
Obtained from:	http://googlechromereleases.blogspot.nl/
MFH:		2014Q3
2014-09-25 07:34:52 +00:00
Raphael Kubo da Costa
2c2f3a2f60 Add entry for net/krfb (CVE-2014-6055). 2014-09-24 21:22:02 +00:00
Xin LI
60ee221669 Document bash remote code execution vulnerability. 2014-09-24 18:07:12 +00:00
Guido Falsi
2814daf170 Document new asterisk11 vulnerability.
MFH:		2014Q3
2014-09-18 19:53:09 +00:00
Guido Falsi
33e5dc1889 Document new squid vulnerability.
PR:		193737
Submitted by:	timp87 at gmail.com
MFH:		2014Q3
2014-09-18 13:20:57 +00:00
Koop Mast
3a4a25974f Document new dbus vulnabilities.
MFH:		2014Q3
2014-09-17 11:04:33 +00:00
Sergey A. Osokin
dc7dfebbe6 Document nginx security advisory (CVE-2014-3616). 2014-09-16 17:35:34 +00:00
Matthew Seaman
0b57820092 Document the latest phpMyAdmin vulnerability
Security:	cc627e6c-3b89-11e4-b629-6805ca0b3d42
2014-09-13 21:18:56 +00:00
Brad Davis
d159ee42c7 Document CVE-2014-5284 affecting security/ossec-hids-* < 2.8.1.
Reviewed by:	zi@
2014-09-11 14:09:43 +00:00
Rene Ladan
934764e569 Document new vulnerabilities in www/chromium < 37.0.2062.120
Obtained from:	http://googlechromereleases.blogspot.nl/
MFH:		2014Q3
2014-09-09 21:27:24 +00:00
Tijl Coosemans
218ef4e8d4 Document trafficserver vulnerability
MFH:		2014Q3
2014-09-05 14:45:47 +00:00
Olli Hauer
2e538bbbe7 - update vid f927e06c-1109-11e4-b090-20cf30e32f6d
(httpd-2.2.29 was released today)

MFH:		2014Q3
2014-09-03 20:16:29 +00:00
Rene Ladan
772a313bc5 Document new vulnerabilities in www/chromium < 37.0.2062.94
Obtained from:	http://googlechromereleases.blogspot.nl
MFH:		2014Q3
2014-08-26 16:36:41 +00:00
Ryan Steinmetz
b91a107bb8 - Document buffer overrun in sysutils/file 2014-08-21 19:46:21 +00:00
Li-Wen Hsu
61faa6c3bc Add missing <package> tag 2014-08-21 17:13:16 +00:00
Li-Wen Hsu
b4c5d1d593 Document Django 2014-08-20 vulnerabilty
Reviewed by:	koobs
2014-08-21 17:09:58 +00:00
Florian Smeets
df03bac70c Record PHP 5.3 vulnerabilities 2014-08-18 21:11:32 +00:00
Matthew Seaman
e9714da8d4 Document the latest phpMyAdmin security advisories.
XSS in view operations page

and

Multiple XSS vulnerabilities in browse table, ENUM editor, monitor, query charts and table relations pages

Security:	fbb01289-2645-11e4-bc44-6805ca0b3d42
2014-08-17 19:48:04 +00:00
Rene Ladan
bd5028c8d0 Document new vulnerabilities in www/chromium < 36.0.1985.143
Submitted by:	Carlos Jacobo Puga Media <cpm@fbsd.es>
Obtained from:	http://googlechromereleases.blogspot.nl/
MFH:		2014Q3
2014-08-13 06:43:35 +00:00
Olli Hauer
4d6d20cd7a - fix package name s/subversion18/subversion/
Thanks to jkim@ for the notice!
2014-08-11 20:19:40 +00:00
Ryan Steinmetz
4221067e37 - INSERT URL HERE 2014-08-11 19:06:36 +00:00
Olli Hauer
67688b393f - document serf CVE-2014-3504
MFH:		2014Q3
2014-08-11 18:52:33 +00:00
Olli Hauer
809ba9c35b - document subversion CVE-2014-3522, CVE-2014-3528
MFH:		2014Q3
2014-08-11 18:42:37 +00:00
Sergey A. Osokin
7b41a1a84d Fix typo.
Found by:	rene
2014-08-10 03:07:54 +00:00
Sergey A. Osokin
03b0bc919d Document nginx vulnerability. 2014-08-09 18:26:53 +00:00