Commit graph

29512 commits

Author SHA1 Message Date
Antoine Brodin
f1f4b7df4c Update to 5.0.19 2019-04-28 06:22:50 +00:00
Antoine Brodin
5c27723305 Update to 1.3.66 2019-04-28 06:20:37 +00:00
Antoine Brodin
6eb3d5bb3c Update to 0.5.12 2019-04-28 06:19:58 +00:00
Antoine Brodin
c72616c42d Update to 2.3.0 2019-04-28 06:17:34 +00:00
Antoine Brodin
b67251ae31 Update to 0.1.80 2019-04-28 06:16:41 +00:00
Sunpoet Po-Chuan Hsieh
cbcfcbd620 Change RUN_DEPENDS from rubygem-msgpack1 to rubygem-msgpack
- Bump PORTREVISION for dependency change
2019-04-27 18:28:13 +00:00
Sunpoet Po-Chuan Hsieh
a3330b6962 Update to 0.708
- Fix *_DEPENDS

Changes:	https://metacpan.org/changes/distribution/Dancer2-Plugin-Auth-Extensible
2019-04-27 18:27:18 +00:00
Sunpoet Po-Chuan Hsieh
7cf7ae9ad1 Update to 0.33.0
Changes:	https://gitlab.com/m2crypto/m2crypto/blob/master/CHANGES
		https://gitlab.com/m2crypto/m2crypto/commits/master
2019-04-27 18:26:05 +00:00
Muhammad Moinur Rahman
20098820b4 security/snort3: Update version 3.0.0_253=>3.0.0-254 2019-04-27 17:31:39 +00:00
Piotr Kubaj
bdd980e301 security/git-crypt: fix build with GCC-based architectures
Add USES=compiler:c++11-lang.

Don't add -L${OPENSSLLIB} unconditionally, do it only when SSL library from ports is used. The reason is that adding -L/usr/lib makes ports GCC want to link to libstdc++ from /usr/lib, not from /usr/local/lib/gcc8. This causes linking errors

PR:		237525
Approved by:	ashish (maintainer), tcberner (mentor)
Differential Revision:	https://reviews.freebsd.org/D20053
2019-04-27 08:41:58 +00:00
Sunpoet Po-Chuan Hsieh
f92921520f Add BUILD_DEPENDS
security/nettle requires gmp 6.0.0+, otherwise support for public key algorithms will be unavailable.

PR:		237582
Submitted by:	eugen
2019-04-26 20:49:52 +00:00
Steve Wills
b335f6a631 security/p5-IO-Socket-SSL: update to 2.066
PR:		237556
Submitted by:	Sergei Vyshenski <svysh.fbsd@gmail.com> (maintainer)
2019-04-26 19:34:05 +00:00
Kubilay Kocak
41dddc0643 security/vuxml: Add buildbot CRLF injection vulnerability 2019-04-26 11:29:16 +00:00
Kubilay Kocak
794d50f688 security/py-cryptography: Fix build with libressl 2.9.1
Backport upstream pull request #4855 by Charlie Li <ml+freebsd vishwin info>

PR:		237487
Submitted by:	Maciej Pasternacki <maciej pasternacki. net> (v1)
Submitted by:	gahr (v2)
Reported by:	Simeon Simeonov <sgs pichove org>
Obtained from:	https://github.com/pyca/cryptography/pull/4855
Tested by:	gahr (all USES=ssl versions), many
2019-04-26 05:13:26 +00:00
Tobias Kortkamp
1c1d242912 security/testssl.sh: Update to 3.0rc5
Changes:	https://github.com/drwetter/testssl.sh/releases/tag/3.0rc5
2019-04-26 04:45:49 +00:00
Cy Schubert
32ffc39b65 Update to the latest MIT/KRB5 commit on github. 2019-04-26 03:13:01 +00:00
Steve Wills
1a9ac8c93a security/vault: add vault user to daemon class
This allows use of mlock() when vault is started via rc script.

Submitted by:	dch
Reviewed by:	jrm
Differential Revision:	https://reviews.freebsd.org/D20025
2019-04-25 21:00:52 +00:00
Sean Chittenden
e1476071c4 Update security/teleport to 3.2.2
Approved by:	swills (mentor)
Differential Revision:	https://reviews.freebsd.org/D20042
2019-04-25 18:02:41 +00:00
Steve Wills
7c3c209b7e security/vault: update to 1.1.2 2019-04-25 16:51:47 +00:00
Lev A. Serebryakov
06f5af28e1 Add LTS version of subversion to ports.
PR:		235934
2019-04-25 16:28:46 +00:00
Antoine Brodin
31a04da981 Make UNSAFESSL default on all archs
Reported by:	pkg-fallout
MFH:		2019Q2
2019-04-25 16:14:24 +00:00
Antoine Brodin
cf6456491e Clean up plist 2019-04-25 14:48:37 +00:00
Lev A. Serebryakov
815a20bf93 Update to 1.12.0 2019-04-25 12:27:42 +00:00
Tobias Kortkamp
2d1585f68c security/signify: Add OpenBSD 6.6 key and retire no longer useful 6.3 key
Reported by:	tj@mrsk.me
2019-04-25 05:52:50 +00:00
Kubilay Kocak
327a679b9e security/py-pysha3: Update to 1.0.2
Changelog:

  https://github.com/tiran/pysha3/blob/1.0.2/CHANGES.txt
2019-04-25 05:08:36 +00:00
Jose Alonso Cardenas Marquez
c9a2964717 - Add drupal7 and drupal8 entries 2019-04-25 02:05:05 +00:00
Steve Wills
6942b99e98 add missed PORTEPOCH to libssh2 version 2019-04-24 16:55:12 +00:00
Josh Paetzel
6765ea38d9 Document py-yaml vulnerability
PR:	237501
Submitted by:	sergey@akhmatov.ru
Security:	CVE-2017-18342
2019-04-24 15:30:40 +00:00
Tobias Kortkamp
02d549c902 security/clamfs: Switch to devel/poco
poco-ssl will expire soon.

PR:		237176
Approved by:	anastasios@mageirias.com (maintainer timeout, 2 weeks)
2019-04-24 06:08:30 +00:00
Eugene Grosbein
12b3bab807 openssl/gost-engine: specify OPENSSL_ENGINES_DIR explicitly
because the software does not always determine it automatically
in FreeBSD environment.

No PORTREVISION bump as it unbreaks build.
2019-04-24 05:44:50 +00:00
John Baldwin
58a9580aa6 Add AES-CCM and plain SHA digest test vectors.
These will be used to expand testing of OCF crypto algorithms in
future changes to the base system OCF tests.

Reviewed by:	cem, sef, ngie
Approved by:	bdrewery, jmg (maintainer timeout)
MFH:		2019Q2
Differential Revision:	https://reviews.freebsd.org/D19853
2019-04-23 21:39:37 +00:00
Mathieu Arnold
33634159f7 Remove conflicts from bind-tools and the server ports.
All servers now depend on the same bind-tools, from the latest BIND9
release.

Chase dependencies to make sure they now depend on the correct port.

Differential Revision:	https://reviews.freebsd.org/D19922
2019-04-23 13:04:11 +00:00
Matthias Fechner
019fd5d35d Obsolete, please use security/rubygem-rack-oauth2 instead. 2019-04-23 12:18:10 +00:00
Bernard Spil
50facabe8b security/libressl-devel: Update to 2.9.1
- Add option to enable experimental TLSv1.3
2019-04-23 10:26:23 +00:00
Pietro Cerutti
95d1593823 security/p5-Net-SSLeay: fix build with libressl 2.9
I'm considering a maintainer timeout for this one, as the bug was first
reported in December. LibreSSL 2.9.1 is now the main version in the ports tree,
so this is urgent.

perl@, feel free to commit a better fix.

PR:		234102
Submitted by:	Charlie Li <ml+freebsd@vishwin.info>
Approved by:	maintainer (timeout)
2019-04-23 09:24:56 +00:00
Cy Schubert
27416f44d4 Document wpa_supplicant/hostapd EAP-pwd message reassembly issue with
unexpected fragment.

Security:	no CVE documented,
	https://w1.fi/security/2019-5/eap-pwd-message-reassembly-issue-\
	with-unexpected-fragment.txt
2019-04-23 03:03:45 +00:00
Cy Schubert
f9ca6f54aa Document wpa_supplicant/hostapd EAP-pwd missing commit validation.
CVE-2019-9497 (EAP-pwd server not checking for reflection attack)
CVE-2019-9498 (EAP-pwd server missing commit validation for
scalar/element)
CVE-2019-9499 (EAP-pwd peer missing commit validation for
scalar/element)

Security:	CVE-2019-9497, CVE-2019-9498, CVE-2019-9499,
	https://w1.fi/security/2019-4/eap-pwd-missing-commit-validation.txt
2019-04-23 03:03:40 +00:00
Cy Schubert
804879bc6a Document hostapd SAE confirm missing state validation.
CVE-2019-9496 (SAE confirm missing state validation in hostapd/AP)

Security:	CVE-2019-9496,
    https://w1.fi/security/2019-3/sae-confirm-missing-state-validation.txt
2019-04-23 03:03:35 +00:00
Cy Schubert
51e1aedfe7 Document wpa_supplicant/hostapd EAP-pwd side-channel attack.
CVE-2019-9495 (cache attack against EAP-pwd)

Security:	CVE-2019-9495,
	https://w1.fi/security/2019-2/eap-pwd-side-channel-attack.txt
2019-04-23 03:03:29 +00:00
Cy Schubert
8891f30e2f Document wpa_supplicant/hostapd SAE side-channel attacks.
CVE-2019-9494 (cache attack against SAE)

Security:	CVE-2019-9494, VU#871675,
	https://w1.fi/security/2019-1/sae-side-channel-attacks.txt
2019-04-23 03:03:24 +00:00
Danilo Egea Gondolfo
b9f58a7e15 - Update to 0.4.0 2019-04-22 21:39:28 +00:00
Tobias Kortkamp
04e0e4b796 Rebuild statically linked security/libressl consumers after r499667 2019-04-22 20:38:59 +00:00
Danilo Egea Gondolfo
bfec5191cd - Document istio vulnerabilities. 2019-04-22 20:30:18 +00:00
Bernard Spil
8528cb14e0 security/libressl: Update to 2.9.1
- Requires a rebuild of all dependent ports
2019-04-22 19:44:57 +00:00
Dmitry Marakasov
8c595075cd - Update to 0.5.1 2019-04-22 17:18:37 +00:00
Cy Schubert
72f661dc41 Update wpa_supplicant/hostapd 2.7 --> 2.8 2019-04-22 15:56:58 +00:00
Antoine Brodin
50261a696c Mark BROKEN on FreeBSD 12 and 13
Reported by:	pkg-fallout
MFH:		2019Q2
2019-04-22 15:08:53 +00:00
Eugene Grosbein
f9a8be3cc6 New port: security/gost-engine
OpenSSL 1.0.2 had built-in implementation of Russian cryptography standards
(GOST) as additional engine, but since then that implementation
moved to distinct repository at Github.

This port presents loadable engine for OpenSSL 1.1.1+ and algorithms:

GOST R 34.10-2001
GOST R 34.10-2012
GOST R 34.11-94
GOST R 34.11-2012
GOST 28147-89
GOST R 34.132015
2019-04-22 09:26:37 +00:00
Tijl Coosemans
4c6ee2ee60 - Prevent detection of autogen. It causes some files to be regenerated
and then they require a newer header than is provided with gnutls.
- Remove ZLIB option.  It's no longer available.

PR:		237419
Reported by:	Kevin Oberman <rkoberman@gmail.com>
2019-04-22 08:30:46 +00:00
Ryan Steinmetz
fbebfcf11f - Fix start order
- Bump PORTREVISION
2019-04-22 01:32:18 +00:00