Commit graph

17069 commits

Author SHA1 Message Date
Steve Wills
ea9f3c8d6f - Update to 0.9.14 to fix CVE-2013-1756
Security:	aa7764af-0b5e-4ddc-bc65-38ad697a484f
2013-02-28 01:46:41 +00:00
Martin Wilke
b0522932ed - Broken checksum mismatch
- While here convert header
2013-02-27 14:27:06 +00:00
Eitan Adler
bfe92b3914 Update to 11.2r202.273
Security:	http://www.vuxml.org/freebsd/dbdac023-80e1-11e2-9a29-001060e06fd4.html
2013-02-27 13:40:46 +00:00
Jason Helfman
68eae8a432 - update to 1.137, trim historical header and adopt optionsNG for DOCS
PR:		176464
Submitted by:	jgh@
Approved by:	maintainer, tsshbatch@tundraware.com
2013-02-27 05:50:20 +00:00
Steve Wills
cbc04de392 - Fix build 2013-02-27 02:44:25 +00:00
Steve Wills
5f4c72c020 - Update to 2.6.5 2013-02-27 02:13:43 +00:00
David Thiel
ef2e0817be - Add randombytes.o to the libnacl.a archive
- Add -fPIC

PR:	ports/175820
Submitted by:	Gasol Wu
2013-02-26 23:59:25 +00:00
Jason Helfman
d99788e364 - take maintainership and drop verify target 2013-02-26 23:11:52 +00:00
Sunpoet Po-Chuan Hsieh
05731af3f5 - Update affected ettercap versions: CVE-2012-0722 was fixed in 0.7.5.2-Assimilation 2013-02-26 17:27:06 +00:00
Ryan Steinmetz
55d4c46af9 - Update to 2.4.4 2013-02-26 13:10:09 +00:00
Bryan Drewery
8644e31f6a - Document 3 OTRS vulnerabilities from 2012
- CVE-2012-4751
 - CVE-2012-4600
 - CVE-2012-2582
2013-02-26 01:38:58 +00:00
Andrey A. Chernov
184c72ca2a Remove patch unneded in 0.8.8
PR:     176426
Submitted by:   Christoph Theis <theis@gmx.at> [maintainer]
2013-02-25 22:23:15 +00:00
Dirk Meyer
5afe83dbd5 - fix broken symlink in manpage
Submitted by:	Warren Block
2013-02-25 06:07:10 +00:00
Steve Wills
19b9b04511 - Document Ruby REXML DoS 2013-02-24 18:21:02 +00:00
Steve Wills
4ebcd6044d - Document rubygem-ruby_parser issue 2013-02-24 17:51:49 +00:00
Po-Chien Lin
92ebf424d6 - Document Django 2013-02-21 vulnerabilty
Approved by:	araujo (mentor)
2013-02-24 14:23:46 +00:00
Frederic Culot
62dd034679 - Update to 0.8.8
Changes:        https://raw.github.com/fail2ban/fail2ban/master/ChangeLog
PR:             ports/176368
Submitted by:   Christoph Theis <theis@gmx.at> (maintainer)
2013-02-23 12:36:57 +00:00
Florian Smeets
9923e186d9 Move this check to the correct place.
Submitted by:	Jan Beich <jbeich@tormail.org>
Pointhat to:	flo
2013-02-23 09:16:01 +00:00
Jason Helfman
b64e768cf5 - no longer broken
- trim historical header
2013-02-23 07:38:03 +00:00
Rene Ladan
8800a2b6fd Document vulnerabilities in www/chromium < 25.0.1364.97
Obtained from:	http://googlechromereleases.blogspot.nl/search/Stable%20Updates
2013-02-22 23:49:44 +00:00
Cy Schubert
7833a0f195 Document security/krb5 1.11 and prior null pointer dereference in the
KDC PKINIT code [CVE-2013-1415].

Security:	CVE-2013-1415
2013-02-22 20:28:21 +00:00
Cy Schubert
2dcaa3f892 Update 1.11 --> 1.11.1.
Security:	Fix a null pointer dereference in the KDC PKINIT code [CVE-2013-1415].
2013-02-22 20:03:17 +00:00
Remko Lodder
1be2aa0120 Convert the ! back into a 1.
Noticed by:	crees
2013-02-22 08:07:26 +00:00
Ryan Steinmetz
92f7d89c52 - Use @dirrmtry instead of @exec rmdir
Submitted by:	Bryan Drewery <bdrewery@FreeBSD.org>
2013-02-22 00:58:56 +00:00
Remko Lodder
71be45ba2c Add the latest two FreeBSD Security Advisories. 2013-02-21 21:38:16 +00:00
Sunpoet Po-Chuan Hsieh
79cf1453ad - Add BUILD_DEPENDS
- Sort MAN3
- Take maintainership
- Cleanup Makefile header
- Reformat pkg-descr
- Complete PLIST
2013-02-21 17:17:54 +00:00
Florian Smeets
466477311a Add support for older FreeBSD released by relying on USE_GCC
Requested by:	ale
Submitted by:	Jan Beich <jbeich@tormail.org>
2013-02-21 16:43:22 +00:00
Florian Smeets
719a920981 Document drupal7 Denial of service 2013-02-21 07:11:50 +00:00
Florian Smeets
253286a025 The files we are looking for are also in ${LOCALBASE}/bin, this should
help people that installed binutils on an older version of FreeBSD
and upgraded base in the meantime.

e.g. Install binutils on 9.0 they got installed in

${LOCALBASE}/x86_64-portbld-freebsd9.0

after upgrading to 9.1 the nss port would look in

${LOCALBASE}/x86_64-portbld-freebsd9.1

and not find the tools its looking for, falling back to the tools from base
that don't support all the instructions the nss ports needs.

Avoid all this by using ${LOCALBASE}/bin
2013-02-20 21:12:06 +00:00
Ruslan Makhmatkhanov
a3f2f050cc - add an entry for net/nss-pam-ldapd stack-based buffer overflow
According to advisory, vulnerability exists in nss-pam-ldapd < 0.8.11,
but since we never had this version in the ports tree, mark everything
< 0.8.12 as vulnerable.

PR:		176293
Submitted by:	pluknet
2013-02-20 13:58:19 +00:00
Matthias Andree
35f2e5abb5 Support WITH_DEBUG=yes to get more debug output from the bundle
creation, to verbosely print omitted and included certificates.

Approved by:	flo@ on "as long as you fix it if it breaks" condition
2013-02-20 08:07:13 +00:00
Florian Smeets
b452328822 Fix up the latest gecko update by:
- reapplying the workaround for svn:eol-style and svn:keywords
- fixing version matching in vuln.xml, 17.0.3 is NOT vulnerable
2013-02-20 07:16:31 +00:00
Olli Hauer
c6abd552ea - update bugzilla ports to latest version
Bugzilla 4.0.10 and 3.6.13 are security updates for the 4.0
  branch and the 3.6 branch, respectively. 4.0.10 contains several
  useful bug fixes and 3.6.13 contains only security fixes.

Security:	CVE-2013-0785
		CVE-2013-0786
2013-02-20 06:16:01 +00:00
Florian Smeets
d39d92427c - update firefox to 19.0
- update firefox-esr, thunderbird, linux-firefox, linux-thunderbird to 17.0.3
- update linux-seamonkey to 2.16
- update nspr to 4.9.5
- update nss to 3.14.3
- add DuckDuckGo search plugin to firefox [1]
- mark kompozer deprecated
- clang fixes for www/libxul19 [2]

Security:	http://www.vuxml.org/freebsd/e3f0374a-7ad6-11e2-84cd-d43d7e0c7c02.html
Submitted by:	DuckDuckGo [1], dim [2]
In collaboration with:	Jan Beich <jbeich@tormail.org>
2013-02-19 23:53:07 +00:00
Hiroki Sato
5602556351 Update to 1.3.1. Changes include:
- Fix tunnel support.
2013-02-19 20:16:22 +00:00
Martin Wilke
c18d2549a6 - Unbreak PAM initialize
- While here trim header

PR:		176264
Submitted by:	Constantin Stefanov <cstef@parallel.ru>
2013-02-19 16:05:18 +00:00
Dima Panov
cbf1ec26a6 - Adopt ports from avl@ to myself by his request
Approved by:	maintainer via IM
2013-02-19 13:12:37 +00:00
Ryan Steinmetz
1e013d498e - Update to 1.1.0 [1]
- Fix build when using alternate PREFIX/LOCALBASE
- Fix plist by adding MANCOMPRESSED=no

PR:		ports/176254
Submitted by:	Eric F Crist <ecrist@secure-computing.net> (maintainer) [1]
2013-02-19 03:25:46 +00:00
Ryan Steinmetz
77241d88d0 - Add patch to resolve invalid XML produced by praudit -x
- Bump PORTREVISION
2013-02-19 02:20:27 +00:00
Ryan Steinmetz
41a95c5e37 - Fix version range for recent ruby vulnerabilities (d3e96508-056b-4259-88ad-50dc8d1978a6 and c79eb109-a754-45d7-b552-a42099eb2265) due to missing port epoch in package range
Submitted by:	Matthias Andree <mandree@FreeBSD.org>
2013-02-19 00:19:14 +00:00
Dirk Meyer
fcb98a504a - update libnet to 1.1.6
- build shared lib
- fix dependend ports when libnet.so.8 was linked in
- fix dependend ports when includes where missing
2013-02-18 21:13:02 +00:00
Martin Wilke
994be75443 Editor for yara rules
WWW: http://code.google.com/p/yara-editor/

PR:		ports/175170
Submitted by:	antoine@FreeBSD.org
2013-02-18 04:45:53 +00:00
Martin Wilke
c712cce2be - Update to 0.8.0
- Trim header
- Optiongn

PR:		174592
Submitted by:	maintainer
2013-02-18 01:03:14 +00:00
Martin Wilke
262e62789b - Update to 0.8.0
- Optionng
- Trim header

PR:		174591
Submitted by:	maintainer
2013-02-18 01:01:11 +00:00
Martin Wilke
8e694fbb17 - Update to 0.8.0
- Trim header
- Convert to OPTIONSng

PR:		174956
Submitted by:	maintainer
2013-02-18 00:56:47 +00:00
Martin Wilke
6f40746b84 An open source PHP-based OpenID identity provider using LDAP as
backend.

OpenID-LDAP is a small, fairly lightweight, standalone, multi user
Identity Provider for OpenID authentication.  It comprises a few PHP
scripts that can be used by one individual to run their own personal
OpenID IdP.

This program requires no external libraries, and has very minimal
requirements.  It should run on any PHP server (v4.2+), and can
support OpenID in 'Smart Mode.'  This program caches all data using
built-in PHP session handling, so it requires no database, and no
explicit write access to the file system.

OpenID-LDAP is NOT compatible with Suhosin or other hardened PHP
systems.

WWW: http://www.openid-ldap.org/

PR:		ports/175258
Submitted by:	Matthew X. Economou <xenophon+freebsd@irtnog.org>
2013-02-18 00:18:20 +00:00
Renato Botelho
e9a4250e29 Update to 20130217 2013-02-17 23:26:39 +00:00
TAKATSU Tomonari
7280a763b4 - Update to 0.6.3 2013-02-17 20:11:40 +00:00
Eitan Adler
83689ac33a Combine ranges into one entry to prevent false positives 2013-02-17 19:58:28 +00:00
Steve Wills
c1a7765ec7 - Document rubygem-rack issue 2013-02-17 16:47:06 +00:00