Commit graph

5986 commits

Author SHA1 Message Date
Vanilla I. Shu
e7dbf6fab0 Fix build on 4-stable
PR:		ports/72808
Submitted by:	maintainer
2004-10-27 15:46:11 +00:00
Vanilla I. Shu
2dbbb3cf12 Fix build on 4-stable.
PR:		ports/72807
Submitted by:	maintainer
2004-10-27 15:42:29 +00:00
Jacques Vidrine
9cfb8ca626 Create a VuXML entry for Horde XSS help window vulnerability to replace
the portaudit-db entry.
2004-10-27 12:25:06 +00:00
Cheng-Lung Sung
f65891b6eb - update to 1.0
PR:		ports/73181
Submitted by:	Marcus Grando <marcus AT corp dot grupos dot com dot br>
Approved by:	co-mentor (vanilla)
2004-10-27 02:15:22 +00:00
Dirk Meyer
8af65f3ae1 - Bugfix update to 0.9.7e
- md5 verfied with website
2004-10-26 21:32:19 +00:00
Thierry Thomas
6833f56de3 Add an entry for a vulnerability fixed in horde-2.2.7. 2004-10-26 19:37:44 +00:00
Kirill Ponomarev
ee5080e0e9 Chase libraries for new devel/libidn version. 2004-10-26 15:26:43 +00:00
Jacques Vidrine
322ec63640 Document a denial-of-service issue in bogofilter.
This entry is slightly modified from one that was
Submitted by:	Matthias Andree <matthias.andree@gmx.de>
2004-10-26 11:12:57 +00:00
Norikatsu Shigemura
ac37d1b5a1 Fix integer overflow vulnerabilities.
Patch made by:	Chris Evans, Dirk Muller, Sebastian Krahmer,
		Derek Noonburg and Marcus Meissner
Submitted by:	nectar
2004-10-26 05:41:47 +00:00
Jacques Vidrine
47b48767ad Document xpdf 2 and xpdf 3 vulnerabilities. 2004-10-25 20:22:38 +00:00
Jacques Vidrine
9e47b8e345 Document several security issues in gaim, fixed in various versions from
0.82 through 1.0.2.  While I'm here, notice that there have been ru-,
ko-, and ja- flavors of gaim, as well as a fairly short-lived range of
version numbers based on dates (snapshots).
2004-10-25 19:27:02 +00:00
Jacques Vidrine
b9d5212e26 Note that the Red Hat based linux_base ports contain
vulnerable libXpm.so files.

Noticed by:	maho
2004-10-25 17:21:15 +00:00
Dag-Erling Smørgrav
74bbdb749b Braino: install the file with correct name. 2004-10-25 13:55:21 +00:00
Edwin Groothuis
8703e533e5 Clean up time for email addresses MIA!
If you know new email addresses for the people involved, please send-pr it!

<mcsi@agava.com>: host relay.agava.net.ru[195.161.118.3] said: 550
    <mcsi@agava.com>: User unknown in local recipient table (in reply to RCPT
    TO command)

<woju@bbsmail.ntu.edu.tw> (expanded from <woju@bbsmail>): Host or domain name
    not found. Name service error for name=bbsmail.ntu.edu.tw type=A: Host not
    found

<esoha@attbi.com>: host gateway.attbi.com[204.127.198.6] said: 551 not our
    customer (in reply to RCPT TO command)

<crow@nektor.hu>: host mail.kapu.hu[195.70.32.236] said: 550 unknown user (in
    reply to RCPT TO command)

<cyrilm@tower.pp.ru>: host mail.tower.pp.ru[213.85.109.133] said: 550 unknown
    user (in reply to RCPT TO command)

<ports@henrik-motakef.de>: Host or domain name not found. Name service error
    for name=henrik-motakef.de type=A: Host not found

<jj@nttmcl.com>: host mx1.nttmcl.com[216.69.64.132] said: 550 5.2.1
    <jj@nttmcl.com>... Mailbox disabled for this recipient (in reply to RCPT TO
    command)

<koji@jet.es>: host mx.wanadoo.es[62.81.235.75] said: 550 Relay not permitted /
    No such user (in reply to RCPT TO command)

<proot@iaces.com>: host horton.iaces.com[204.147.87.98] said: 550 5.1.1
    <proot@iaces.com>... User unknown (in reply to RCPT TO command)

<roland.jesse@gmx.net>: host mx0.gmx.net[213.165.64.100] said: 550 5.1.1
    {mx034} <roland.jesse@gmx.net>... User is unknown (in reply to RCPT TO
    command)

<vess@slavof.net>: host mail.slavof.net[213.130.68.146] said: 550 5.7.1 Access
    denied (in reply to MAIL FROM command)

<tuxsuximus@hotmail.com>: host mx3.hotmail.com[65.54.253.99] said: 550
    Requested action not taken: mailbox unavailable (in reply to RCPT TO
    command)

<zenin@archive.rhps.org>: host mail.rhps.org[66.250.128.137] said: 550 5.7.1
    <zenin@archive.rhps.org>... Relaying denied (in reply to RCPT TO command)
2004-10-25 13:39:57 +00:00
Dag-Erling Smørgrav
248fc3aabc Add Auth_HTTP 2.0 from PEAR. 2004-10-25 13:28:19 +00:00
Hajimu UMEMOTO
718daad6eb Update to 2.1.20.
* Fixes to cram plugin to avoid attempting to canonify uninitialized data.
  * NTLM portability fixes.
  * Avoid potential attack using SASL_PATH when sasl is used in a setuid
    environment.
  * A trivial number of small bugfixes.
2004-10-25 12:42:40 +00:00
Josef El-Rayes
9f77225ee7 Document SSL_Cypherbypass vulnerability in mod_ssl
and buffer overflow vulnerability in gaim.
2004-10-24 19:39:27 +00:00
Michael Nottebrock
d7892a1f84 Add entries for vulnerabilites in imported xpdf code in kdegraphics
and koffice.
2004-10-24 14:46:52 +00:00
Oliver Lehmann
f4c03164ec fix unprev. IPv6 for FreeBSD 4
Bump PORTREVISION

Noted By:	Dariusz Kulinski <d.kulinski@gmail.com>
2004-10-24 12:16:51 +00:00
Yen-Ming Lee
d959c237da - fix building problem and unbreak this port
- remove redundant declaration in makefile.conf and use MAKE_ENV directly
- utilize DATADIR in pkg-plist

Noticed by:	kris
2004-10-24 03:09:51 +00:00
Simon L. B. Nielsen
7f69ed5df9 - Document more buffer overflows in mpg123.
- Fix package name in two older mpg123 entries.

Approved by:	nectar
2004-10-23 16:08:43 +00:00
Jacques Vidrine
2c6feb87b3 I suck. (Correct a typo that would have been readily detected if
I would have run `make validate' before committing.)
2004-10-22 12:21:52 +00:00
Jacques Vidrine
56e53bffbb Add CVE name for cabextract issue. 2004-10-22 12:13:40 +00:00
Simon L. B. Nielsen
d845566b81 Fix a copy/paste typo in last commit. 2004-10-21 22:23:56 +00:00
Simon L. B. Nielsen
ce37c86e07 Document DoS in Apache 2 SSL handling.
Approved by:	nectar
2004-10-21 22:17:21 +00:00
Jacques Vidrine
b31b14f0dc Mark deprecated due to no maintainer and unpatched denial-of-service
vulnerability:
http://vuxml.freebsd.org/b7cb488c-8349-11d8-a41f-0020ed76ef5a.html
2004-10-21 21:25:00 +00:00
Jacques Vidrine
60aaf4ac7b Note that xpm has been fixed.
Also, it appears that Motif itself is affected, so add related packages.
2004-10-21 20:04:21 +00:00
Yen-Ming Lee
7a16211850 - bump PORTREVISION after update dependency.
PR:		72961
Submitted by:	Matt <matt@xtaz.net>
2004-10-21 15:18:58 +00:00
Yen-Ming Lee
8a7a357b0f add procmail into dependency list.
Noticed by:	kris
Submitted by:	Matt <matt@xtaz.net>
2004-10-21 14:30:27 +00:00
Pav Lucistnik
4362f450bd - Fix OPTIONS handling 2004-10-21 12:37:50 +00:00
Jacques Vidrine
28d75b9f8c Update entry regarding INN 2.4.x buffer overflow:
- The email archive referenced is no longer available.  Use
   marc.theaimsgroup.com archive instead.
 - Note that only 2.4.x versions are affected (earlier ones
   are not).

Reported by:	leeym
2004-10-21 12:34:33 +00:00
Simon L. B. Nielsen
366a5335b3 Document remote command execution vulnerability in phpMyAdmin.
Approved by:	nectar
2004-10-20 21:21:52 +00:00
Dirk Meyer
2d6723f827 - don't delete the virus database on deinstall
(sync with clamav-devel)
Approved by:	Rob Evers
2004-10-20 20:48:21 +00:00
Cy Schubert
cba050d77c Update 1.3.4 --> 1.3.5 2004-10-20 20:20:06 +00:00
Simon L. B. Nielsen
eeff877c8f Document insecure directory handling in cabextract.
Approved by:	nectar
2004-10-20 18:38:07 +00:00
Marius Strobl
4be9679506 - Update to 1.1 (final). For changes since 1.1-beta see the ChangeLog
in the DOCSDIR.
- Rename the start script from antivir-milter.sh to avmilter.sh to be
  consistent with naming of the rest of the installed AntiVir Milter
  files and directories.
- Now that AntiVir Milter supports using a different location from
  /etc for the ignore, scan and warn config files no longer install
  them in the EXAMPLESDIR but in PREFIX/etc/avmilter (i.e. install
  as sample files, copy over when not already existent, etc.).
- Change the location of the AntiVir Milter config file (avmilter.conf)
  but not that of the scan engine (antivir.conf; shared between different
  AntiVir products) from PREFIX/etc to PREFIX/etc/avmilter in order to
  have all AntiVir Milter config files in one place but don't directly
  populate PREFIX/etc with them.

If you had previously changed PREFIX/etc/avmilter.conf you have to
bring over your changes to PREFIX/etc/avmilter/avmilter.conf but note
that some variables have been renamed. If you used ignore, scan and/or
warn files in /etc you can now move them to PREFIX/etc/avmilter.

Approved by:	netchild
2004-10-20 18:22:23 +00:00
Joe Marcus Clarke
e555d587fa Chase the Gaim 1.0.2 upgrade. 2004-10-20 18:06:05 +00:00
James E. Housley
db1f97cd0a Update to DAT 4400 2004-10-20 17:21:51 +00:00
James E. Housley
dd925d5081 Base if the last update was successful on the dontents of file_id.diz,
since that is in the .tar and will only update after a successful download
and extract

Submitted By:		Steven Guerin
2004-10-20 17:20:53 +00:00
Alexey Dokuchaev
62872b88bd Fix code so it is favored by both GCCs (2.x and 3.x), and unbreak the build.
Approved by:	fjoe (mentor, implicit)
		maintainer timeout
2004-10-20 12:33:37 +00:00
Pav Lucistnik
223791cc87 - Update to 0.0.14
PR:		ports/72823
Submitted by:	Ports Fury
2004-10-20 11:46:56 +00:00
Pav Lucistnik
f133dd5ea1 - Update to 0.0.18
PR:		ports/72824
Submitted by:	Ports Fury
2004-10-20 11:45:52 +00:00
Sergei Kolobov
c37e9ced3a - Update to 20041019
W32/Netsky.AH@mm
  W32/Korgo.AB
  W32/Mydoom.AF

PR:		ports/72890
Submitted by:	Tim Bishop (maintainer)
2004-10-20 07:52:52 +00:00
Simon L. B. Nielsen
14e9c74b1a Set correct entry date for the a2ps issue.
Noticed by:	nectar
Pointy hat to:	simon
2004-10-19 22:08:34 +00:00
Simon L. B. Nielsen
682402bd22 Document insecure command line argument handling in a2ps.
Approved by:	nectar
2004-10-19 21:41:22 +00:00
Jacques Vidrine
91d7cbe48c Document a vulnerability in ifmail. (There does not exist
an appropriate public reference yet--- this entry should be
updated when the port is updated.)

Reported by:	Niels Heinen <niels.heinen@ubizen.com>
2004-10-19 16:40:34 +00:00
Oliver Eikemeier
3a6a1c8514 - update to version 3.75
+ updated OS fingerprint database
2004-10-19 16:04:13 +00:00
Jacques Vidrine
436dbd733e Document a vulnerability in imwheel. 2004-10-19 15:41:37 +00:00
Jacques Vidrine
6643e3dd29 Add CVE names for FreeRADIUS vulnerabilities. 2004-10-19 14:11:44 +00:00
Sergey Skvortsov
d938a56505 Updated to 0.7a 2004-10-19 09:03:00 +00:00