Commit graph

10895 commits

Author SHA1 Message Date
Martin Wilke
7690f9d607 Document png -- multiple vulnerabilities
Reviewed by:	simon
2007-10-11 17:28:01 +00:00
Renato Botelho
e8a017c37d Update WWW 2007-10-11 16:35:05 +00:00
Cy Schubert
bdb7d01307 Fix build under 7.0-CURRENT (gcc 4.2.1 20070719).
PR:		112884
Submitted by:	Scot Hetzel<swhetzel@gmail.com>
2007-10-10 19:12:46 +00:00
Remko Lodder
279fd2f245 Document ImageMagick - Multiple vulnerabilities
Submitted by:		Nick Barkas
2007-10-10 12:47:22 +00:00
Remko Lodder
d325269732 Correct mediawiki package names.
Spotted by:	Nick Barkas
2007-10-10 12:35:43 +00:00
Cheng-Lung Sung
4236f3410c - Update to 1.10 2007-10-10 09:46:18 +00:00
Martin Wilke
de0d021646 - Update to 0.9.1084
PR:		116859
Submitted by:	Sergei Vyshenski <svysh@pn.sinp.msu.ru> (maintainer)
2007-10-09 22:36:58 +00:00
Martin Wilke
92faf13e1e - Update to 0.9.957
PR:		116860
Submitted by:	Sergei Vyshenski <svysh@pn.sinp.msu.ru> (maintainer)
2007-10-09 22:35:36 +00:00
Martin Wilke
d60173b8a8 - Update to 0.9.985
PR:		116858
Submitted by:	Sergei Vyshenski <svysh@pn.sinp.msu.ru> (maintainer)
2007-10-09 22:34:53 +00:00
Martin Wilke
a0d840679d - Update to 0.9.1068
PR:		116863
Submitted by:	Sergei Vyshenski <svysh@pn.sinp.msu.ru> (maintainer)
2007-10-09 22:33:49 +00:00
Martin Wilke
d028564739 - Update to 0.9.1068
PR:		116861
Submitted by:	Sergei Vyshenski <svysh@pn.sinp.msu.ru> (maintainer)
2007-10-09 22:32:49 +00:00
Martin Wilke
4e7867b2f5 - Update to 0.9.1086
PR:		116862
Submitted by:	Sergei Vyshenski <svysh@pn.sinp.msu.ru> (maintainer)
2007-10-09 22:31:43 +00:00
Martin Wilke
801fee5af1 - Mark DEPRECATED (distribution is broken and no longer supported.)
PR:		116870
Submitted by:	Sergei Vyshenski <svysh@pn.sinp.msu.ru> (maintainer)
2007-10-09 22:30:21 +00:00
Oliver Lehmann
6fc4b47407 update to 0.60.1 2007-10-09 20:03:32 +00:00
David Thiel
71e2b0222a Update to 0.11.7. 2007-10-09 18:48:35 +00:00
Martin Wilke
85cbee74af - Dokument jdk/jre -- Applet Caching May Allow Network Access Restrictions to be Circumvented
Reviewed by:	remko
2007-10-09 07:18:11 +00:00
Cy Schubert
049f43b12b Update 0.11 --> 0.13.1 2007-10-09 06:18:28 +00:00
Florent Thoumie
19c9068753 Document xfs -- multiple vulnerabilities. 2007-10-08 12:05:08 +00:00
Mark Linimon
37688beae5 Mark as broken on gcc4.2. 2007-10-07 12:42:36 +00:00
Stefan Walter
cca9adb7db Respect OPENSSLBASE.
PR:		116986 [1], 109041 [2]
Submitted by:	maintainer [1], supraexpress@globaleyes.net [2]
2007-10-07 12:36:46 +00:00
Chin-San Huang
ef978159f3 - Update security/chntpw to 070923.
PR:		ports/116967
Submmitter:	maintainer
2007-10-06 06:36:21 +00:00
Andrew Pantyukhin
12053ed044 - Update to 3.04 2007-10-06 00:06:25 +00:00
Andrew Pantyukhin
123d815215 - Sort category Makefiles
Inspired by:	Jason Harris <jharris@widomaker.com>
Howto:		http://twiki.cenkes.org/Cenkes/SortingCategoryMakefiles
2007-10-05 23:33:27 +00:00
Oliver Lehmann
279889d2e3 fix the patch I messed up!
*sigh*
2007-10-05 19:50:19 +00:00
Marcus Alves Grando
6263358d77 - Update gsskex patch to 20070927
- Update HPN patch to hpn12v19 [1]

Notified by:	ale [1]
2007-10-05 12:41:25 +00:00
Martin Wilke
30f9615ad2 - Document tcl/tk -- buffer overflow in ReadImage function
PR:		116881
Submitted by:	Nick Barkas <snb@threerings.net>
Reviewed by:	simon
2007-10-05 09:35:49 +00:00
Alex Dupre
6b7a9b8cd6 Update to 1.04 release. 2007-10-05 06:09:00 +00:00
Cheng-Lung Sung
83da1daa95 - Update to 2.24 2007-10-05 05:13:03 +00:00
Edwin Groothuis
9ab4c6dd21 Remove errornous # DO NOT DELETE lines caused by makedepend(1) 2007-10-05 03:07:12 +00:00
Cheng-Lung Sung
af1fe83651 - update prelude library dependency
PR:		ports/116111
Submitted by:	Robin Gruyters <r dot gruyters_AT_yirdis dot nl>
2007-10-05 01:48:34 +00:00
Cheng-Lung Sung
bdf32af2dd - update dependency on libprelude
PR:		ports/116110
Submitted by:	maintainer (Robin Gruyters)
2007-10-05 01:47:09 +00:00
Cheng-Lung Sung
a285174426 - Update to 0.9.13
- bump libprelude library

Changelog libpreludedb:
- Source and Target now use a 16 bits index (required for CorrelationAlert
  with large number of source/target). CorrelationAlert Alertident now use a
  32 bits index (required to link large number of Alert together).
- Fix compilation on system without ENOTSUP (fix #227):
  Include modified patch from Alexandre Anriot <aanriot@atlantilde.com>.
- [pgsql] Patch by Pierre Chifflier <chifflier@inl.fr>, that fixes type
  conversions preventing PostgreSQL to use indexes (fix #225).
- [preludedb-admin] Use separate alert / heartbeat command: this is done to
  have a coherent implementation of the --offset and --count command line
  options.
- [preludedb-admin] Fix --offset with the load command.
- [preludedb-admin] Give the delete table a decent size, should speedup the
  delete command.
- [documentation] preludedb-admin manpage (fix #230), by Pierre Chifflier
  <chifflier@inl.fr>.

PR:		ports/116109
Submitted by:	maintainer (Robin Gruyters)
2007-10-05 01:46:14 +00:00
Cheng-Lung Sung
17114d625b - Update to 0.9.9.1
- bump libprelude library

Changelog prelude-manager:
- Fix for new libprelude (0.9.15) runtime warning.
- Add documentation for SQLite3 in the template configuration file
  (S??繅astien Tricaud <toady at gscore.org>).

PR:		ports/116108
Submitted by:	maintainer (Robin Gruyters)
2007-10-05 01:45:06 +00:00
Cheng-Lung Sung
1e36b84691 - Update to 0.9.15.2
- Updated patch-Makefile.in
- Added Man page

Changelog libprelude:
- prelude-adduser has been renamed to prelude-admin, and now include command
  to print or send files containing binary IDMEF data.
- Brand new failover implementation, Feature a real 'journaling' log,
  allowing to restart where we were interupted. Allow multiple process to write to
  the same failover, and is chroot safe.
- prelude-admin manpage, thanks to Frederic Motte <fred at ubixis com>.
- Use SHA1 in place of MD5 for Analyzer checksum.
- Do not set TCP option on UNIX socket, avoid un-necessary warning.
- New measure all over the public interface to protect against bad API
  usage, when a function is not used correctly, a critical warning is triggered.
- [logging]: New PRELUDE_LOG_CRIT logging priority.
- [logging]: Correctly map Prelude log level to Syslog priority.
- [logging]: Improved logging format (include timestamp, level, process pid).
- [logging]: New LIBPRELUDE_ABORT variable, useful if you'd like libprelude
  to abord on critical assertion.
- [logging]: Automatically switch to syslog mode if we detect stdout/stderr
  closure.
- [IDMEF-Criteria]: When we try to match a value against a path that is not
  part of a message using a 'not' operator, the match should succeed
  (Example:
   alert.classification.text != 'stuff' should match if the message has no
   classification object).
- [IDMEF-Criteria]: When matching multiple listed values within the same
  path using a 'not' operator, return an explicit 'no match' if the provided
  comparison value was found at least once.
- [IDMEF-Path] (fix #251): Fixes NULL pointer dereference when the last
  element of an IDMEF path to an enumeration is not the enumeration itself
  (S??鞋bastien Tricaud <toady at gscore.org>
- Fix a possible race condition with the internal libprelude reference to
  the program idmef_analyzer_t when asynchronous timer were used.
- Workaround possible deadlock at exit on OpenBSD, Linux Glibc.
- Only configure libltdl if it is required.
- Various bug fixes, minor enhancements.
- Write the children PID into specified pidfile (fixes #257).
- Fix double free on idmef_criterion_value_t cloned regexp object (thanks
  to Helmut Azbest <helmut.azbest at gmail.com>).
- Allow Python thread to run, while entering libprelude C function.
- Return PRELUDE_ERROR_ASSERTION when API check fail, in place of
  PRELUDE_ERROR_GENERIC.
- Make prelude_plugin_unsubcribe() work as expected (call the plugin
  instance destroy function).
- Various bug fixes, minor enhancements.

PR:		ports/116107
Submitted by:	maintainer (Robin Gruyters)
2007-10-05 01:44:07 +00:00
Diane Bruce
369baeaa34 - This patch fixes broken install.
PR:		ports/116875
Reported by:	db
Submitted by:	Maintainer
2007-10-05 01:21:47 +00:00
Edwin Groothuis
c947287940 Remove always true/always false OSVERSION conditions. 2007-10-04 23:08:40 +00:00
Xin LI
d42f9fd9d4 Document firebird multiple remote buffer overflow vulnerabilities 2007-10-04 22:56:29 +00:00
Oliver Lehmann
b3950a7bca fix build of courier-authlib-vchkpw 2007-10-04 14:57:29 +00:00
Rong-En Fan
2866a78221 Wapiti allows you to audit the security of your web applications.
It performs "black-box" scans, i.e. it does not study the source code of
the application but will scans the webpages of the deployed webapp,
looking for scripts and forms where it can inject data.
Once it gets this list, Wapiti acts like a fuzzer, injecting payloads to
see if a script is vulnerable.

WWW: http://wapiti.sourceforge.net/

PR:		ports/116873
Submitted by:	Philippe Audeoud <jadawin at tuxaco.net>
2007-10-04 13:21:39 +00:00
Edwin Groothuis
678db880d8 remove double bsd.port.mk 2007-10-04 09:21:59 +00:00
Edwin Groothuis
13441eac4b Remove always-false/true conditions based on OSVERSION 500000 2007-10-04 06:02:06 +00:00
Edwin Groothuis
0d263e77cb Remove support for OSVERSION < 5 2007-10-04 00:00:38 +00:00
Edwin Groothuis
f1826a6393 [PATCH] security/fwbuilder: cleanup non-supported FreeBSD versions
- removed support to 4.X (EOL)
	- add correct NOPORTDOCS

PR:		ports/111822
Submitted by:	Marcelo Araujo <araujo@bsdmail.org>
Approved by:	maintainer timeout
2007-10-03 12:19:22 +00:00
Oliver Lehmann
2ec39f47c3 update to 0.60.0 2007-10-03 12:10:07 +00:00
Remko Lodder
f0bb9c6ed8 Update the bugzilla and mediawiki entries to properly match their corrected
versions.

Prodded by:	Nick Barkas (and a few others)
2007-10-02 18:27:37 +00:00
Xin LI
abc5f7d1e6 Update to reflect the fixed version of id3lib. 2007-10-02 02:04:41 +00:00
Xin LI
c28f02d4c5 Document id3lib insecure temporary file creation vulnerability 2007-10-01 21:04:45 +00:00
Mark Linimon
b551476ed8 Mark as broken with gcc4.2 on 64-bits archs. 2007-09-30 11:01:00 +00:00
Mark Linimon
531874040c Fine-tune broken message. 2007-09-30 10:59:11 +00:00
Mark Linimon
3997490dc6 Mark as broken on gcc4.2. 2007-09-30 10:55:57 +00:00
Mark Linimon
b23621676d Remove 4.X cruft. 2007-09-30 10:54:00 +00:00
Mark Linimon
0ad7412dc4 Remove cruft. 2007-09-30 10:51:24 +00:00
Mark Linimon
99cb35bd20 Also broken with gcc4.2. 2007-09-30 10:47:51 +00:00
Mark Linimon
b77b407107 Mark as broken with gcc4.2. 2007-09-30 10:43:57 +00:00
Mark Linimon
65d7f39607 Mark as broken with gcc4.2 on 64-bit archs. 2007-09-30 10:39:07 +00:00
Mark Linimon
554c4dc7c4 Mark as broken: fails to install. 2007-09-30 10:35:32 +00:00
Mark Linimon
9bc52272d3 Mark as only for i386-6.
Based on:

PR:		ports/115474
Submitted by:	maintainer
2007-09-30 10:33:03 +00:00
Mark Linimon
522be11394 Add USE_PERL5. This will be needed to conditionalize bsd.perl.mk inclusion.
Approved by:	maintainer
2007-09-30 09:21:42 +00:00
Edwin Groothuis
8754909e19 [update] security/pam-mysql to 7.0RC1
Includes fix for correct use of -lmd to find MD5 functions
	(see: http://sourceforge.net/tracker/index.php?func=detail&aid=1485390&group_id=5741&atid=105741)

Note: Used autoconf 2.61 to prevent problems with the upcoming sweep

PR:		ports/113882
Submitted by:	Angelo Turetta <aturetta@bestunion.it>
Approved by:	maintainer timeout
2007-09-30 06:14:09 +00:00
Mark Linimon
dc572b07ee Before bsd.port.pre.mk, set either USE_PERL5 or WANT_PERL, depending on
whether the perl dependency is unconditional or conditional.  This will
be needed for the conditional inclusion of bsd.perl.mk.
2007-09-30 04:55:31 +00:00
Mark Linimon
48420a5ebd Switch autoconf dependencies from 2.53 or 2.59 to 2.61.
PR:		ports/116639
Submitted by:	aDe
2007-09-30 04:47:36 +00:00
Hiroki Sato
3a4ea6e7e2 Update to 1.2.4.1. Changes include:
- "*grabServer" resource bug has been fixed.
2007-09-29 23:19:28 +00:00
Alejandro Pulver
cc6a4eebad - Make it work on 64-bit systems.
- Avoid the build failing when OpenSSL is installed as a port too.

PR:		ports/94921
Submitted by:	Mats Palmgren <mats.palmgren@bredband.net>
2007-09-29 22:12:20 +00:00
Alejandro Pulver
6709dbfa47 - Turn off keyboard grabbing to avoid mouse pointer lock after returning from
the screensaver.

PR:		ports/103395
Submitted by:	Vladimir Grebenschikov <vova@fbsd.ru>
2007-09-29 20:39:43 +00:00
Pav Lucistnik
0bc99cad27 - Mark BROKEN everywhere: does not compile
Reported by:	pointyhat
2007-09-29 12:48:56 +00:00
Thomas Abthorpe
6124fba7a8 - cleanup Makefile
- update comment/descripttion to indicate port is a wrapper to Digest::MD5
- pass maintainership to perl@

Approved by:	miwi (co-mentor)
2007-09-27 18:40:42 +00:00
Shaun Amott
bb373dcac1 Upgrade to 1.0.1.
PR:		ports/115589
Submitted by:	Rasmus Kaj <kaj@kth.se>
2007-09-27 00:16:01 +00:00
Edwin Groothuis
0578757a74 [UPDATE] security/tor-devel
Update to latest release. Suggest all users upgrade as there
	is a remote code exploit in versions less than 2.0.7

PR:		ports/115534
Submitted by:	Peter Thoenen <peter.thoenen@yahoo.com>
2007-09-25 12:50:17 +00:00
Edwin Groothuis
ca45b5f7cc Add missing files from pkg-plist after upgrade to masterport
Noticed by: YAPHR

PR:		ports/115868 (indirect)
2007-09-24 21:38:19 +00:00
Martin Wilke
130c7b4833 - Update to 1.3.1
- Fix using sendmail from Ports (115270)

PR:		116587
Submitted by:	Petr Rehor <prehor@gmail.com> (maintainer)
2007-09-24 17:23:32 +00:00
Mark Linimon
cd4b80489b Dominic is a new dad, and will be too busy for a while to work on ports.
Congratulations :-)
2007-09-24 07:38:42 +00:00
Edwin Groothuis
bb2e13e258 security/libgcrypt portlint fixes
1. remove quotes from COMMENT
	2. INSTALLS_SHLIB -> USE_LDCONFIG

PR:		ports/115286
Submitted by:	David Yeske <dyeske@gmail.com>
Approved by:	maintainer timeout
2007-09-24 00:35:45 +00:00
Rong-En Fan
bd519e53d3 - In managed mode the script does not return the proper value due to $?
is reset by the if command. Therefore, the script does not fail when
  starts with broken configuration files
- While I'm here, use %%RC_SUBR%% instead of /etc/rc.subr

PR:		ports/110320
Submitted by:	Dominic Fandrey <lon_kamikaze at gmx.de>
Approved by:	maintainer timeout (6 months)
2007-09-23 12:47:55 +00:00
Stefan Walter
03fc0b4b47 Update to 0.7.6. 2007-09-23 12:12:59 +00:00
Martin Wilke
9763e55d65 - Add missing patch
- Fix whitspaces

Submitted by:	Dave Grochowski <malus.x@gmail.com> (maintainer)
2007-09-23 09:14:20 +00:00
Martin Wilke
0d4684e032 - modify mediawiki entry (add missing mediawiki18)
Reviewed by:	remko
2007-09-23 09:09:33 +00:00
Li-Wen Hsu
566c495359 - Update to 0.9
PR:		ports/116554
Submitted by:	Peter Johnson <johnson.peter AT gmail.com> (maintainer)
2007-09-23 05:44:25 +00:00
Edwin Groothuis
ef4fc524f8 Update port: security/sfs, fix build with gcc42
The attached patch fixes security/sfs so it builds with
	gcc42. The only change I made that I am wary of is commenting
	out the LIBTOOL variable in ${WRKSRC}/sfsrwcd/Makefile.
	However, this seems to work fine on both 7.0-CURRENT and
	6.2-STABLE.

	In addition, I would not mind maintaining the port.

PR:		ports/116389
Submitted by:	Dave Grochowski <malus.x@gmail.com>
2007-09-23 03:17:21 +00:00
Xin LI
403f96dca0 Some PHP 5.x vulnerabilities is also found in PHP 4.x series,
unfortunately it seems that there is no newer PHP release to
fix these issue for 4.x series, so mark it as so.

While I'm there add a new CVE that was not mentioned in
previous revision of entry.
2007-09-23 01:37:06 +00:00
Erwin Lansing
f61dfd43eb Update to 0.57 2007-09-22 19:23:18 +00:00
Marcus Alves Grando
5a1d1148e1 - Change libevent lib and bump PORTREVISION since devel/libevent are updated. 2007-09-21 20:21:30 +00:00
Remko Lodder
c226087002 Document mediawiki -- cross site scripting vulnerability, our port versions
had not been updated yet, 1.8.x is not vulnerable by default unless you are
using the $wgEnableAPI = true; statement, in that case please set it to
$wgEnableAPI = false; (where possible ofcourse, else upgrade to 1.8.5).
2007-09-21 13:14:29 +00:00
Remko Lodder
0dc1a827d6 Document wordpress -- remote sql injection vulnerability, our versions are
already up to date for this vulnerability.
2007-09-21 13:02:53 +00:00
Remko Lodder
860a19c188 samba -- nss_info plugin privilege escalation vulnerability, the FreeBSD
port had already been fixed for this.
2007-09-21 12:41:29 +00:00
Remko Lodder
073f037882 Document bugzilla -- multiple vulnerabilities
PR:		ports/116060
Submitted by:	Nick Barkas <snb at threerings dot net>, minor nits from me
2007-09-21 06:49:49 +00:00
Xin LI
3739d27ad1 Document clamav CVE-2007-4510 issue (Remote DoS). 2007-09-21 06:35:53 +00:00
Cy Schubert
cbede968ff Make the Protocol Helpers advanced settings window aesthetically
pleasing once again.
2007-09-20 22:46:23 +00:00
Remko Lodder
e5c43d59a4 Document coppermine -- multiple vulnerabilities, the FreeBSD
port is already up to date.
2007-09-20 12:20:27 +00:00
Remko Lodder
97fb53af1d Document openoffice -- arbitrary command execution vulnerability,
all current versions marked vulnerable, everything as of 2.3 is
believed to be fixed, but we do not have that yet ( I am also not
sure whether the -devel version has the correct fix or not ) so
lets be on the safe side till we know what version will be fixed
in our repro.
2007-09-20 12:12:53 +00:00
Remko Lodder
aea8d6dfc2 Document bugzilla -- "createmailregexp" security bypass vulnerability,
marking all versions as vulnerable till we know what version is the
one fixed in our CVS repository.
2007-09-20 12:04:29 +00:00
Beech Rintoul
9776b26859 - Update to 0.26
PR:		ports/116429
Submitted by:	TAKAHASHI Kaoru <kaoru@kaisei.org> (maintainer)
Reviewed by:	sat (mentor)
2007-09-19 23:03:16 +00:00
Cy Schubert
a6362a37c0 Add support for Kerberos 5 kshell and Kerberos 4 ekshell using the IP Filter
rcmd proxy.
2007-09-19 22:48:24 +00:00
Simon L. B. Nielsen
d455c815f2 Spell Ulf Harnhammar (ASCII version of name) using UTF-8 instead of HTML
entities which can't be assumed is available to a paser by default.

This fixes a warning from packaudit.
2007-09-19 19:24:45 +00:00
Remko Lodder
995f5c074d Document kdm -- passwordless login vulnerability
Document konquerer -- address bar spoofing

Inspired by:	lofi's cvs commits
2007-09-19 17:06:27 +00:00
Remko Lodder
ce6cba4277 Document flyspray -- authentication bypass
Submitted by:	Nick Hilliard <nick at foobar dot org>
2007-09-19 16:56:12 +00:00
Remko Lodder
7edc14ebb7 Document mozilla -- code execution via Quicktime media-link files,
The Mozilla advisory talks somewhat about Windows for this matter,
but better be safe then sorry (An updated firefox is available already).
2007-09-19 16:50:47 +00:00
Martin Wilke
797fbf53b1 2007-08-29 security/vncrypt: not supported on any current version of FreeBSD
2007-09-15 net-mgmt/ocs-unix-agent: Use net-mgmt/ocsinventory-agent instead
2007-09-18 15:14:53 +00:00
Thomas Abthorpe
5619909972 - make work with fqdn
- bump PORTREVISION

PR:		ports/115210
Submitted by:	Alex Keda <admin_AT_lissyara.su>
Approved by:	Jui-Nan Lin (maintainer), clsung (mentor)
2007-09-18 13:16:12 +00:00
Martin Matuska
17a20706d0 - Add PORTSCOUT skipv 2007-09-18 12:52:40 +00:00
Alex Dupre
d7bdf1188a Add COMMENT escaping. 2007-09-18 12:36:58 +00:00
Jose Alonso Cardenas Marquez
99a00aac42 - Update to 2.2.0 2007-09-18 06:53:29 +00:00
Jose Alonso Cardenas Marquez
56016e8f40 - New port: security/fpc-openssl
Free Pascal unit for OpenSSL
2007-09-18 06:39:28 +00:00
Li-Wen Hsu
cddc55bd06 - Update to 1.1.4 2007-09-18 01:24:57 +00:00
Joe Marcus Clarke
ec4ded3549 Chase the libpurple shared lib version. 2007-09-17 19:48:18 +00:00
Tom McLaughlin
9d5bfc0d23 Update to 1.6.9p5:
- Fixed a bug in the IP address matching introduced by the IPV6 merge.
- Fixed sudoedit when used on a non-existent file.
- Groups and netgroups are now valid in an LDAP sudoRunas statement.
2007-09-17 14:55:13 +00:00
Martin Wilke
0fe3ed8976 - Update to 1.09 2007-09-17 12:59:50 +00:00
Andrew Pantyukhin
12fe54dab0 - Update to 3.03 2007-09-15 08:52:22 +00:00
Stefan Eßer
ec1a9016a7 Add marker that reminds to keep the last of the dirrm lines when
the (only temporarily included) local copy of pygoogle is removed.
2007-09-14 12:16:10 +00:00
Marcus Alves Grando
2d5e352aea - Update MD5/SHA256 of openssh hpn patch. This patch are rerolled to update version:
--- openssh-4.7p1-hpn12v18.diff 2007-09-13 17:11:05.000000000 -0300
+++ /usr/ports/distfiles/openssh-4.7p1-hpn12v18.diff    2007-09-05 18:13:03.000000000 -0300
@@ -1580,5 +1580,5 @@

  #define SSH_PORTABLE  "p1"
 -#define SSH_RELEASE   SSH_VERSION SSH_PORTABLE
-+#define SSH_HPN         "-hpn12v18"
++#define SSH_HPN         "-hpn12v17"
 +#define SSH_RELEASE   SSH_VERSION SSH_PORTABLE SSH_HPN

Reported by:	Tsurutani Naoki <turutani___scphys.kyoto-u.ac.jp>
2007-09-14 01:32:25 +00:00
David Thiel
91575d52a2 Upgrade to 2.3.7, which fixes a Prelude integration bug. 2007-09-13 21:29:50 +00:00
Xin LI
da652c7e22 Update the PHP vulnerability entry:
- Use php5 to cover php 5.x as the port did.
 - Add more information about the vulnerability.

Submitted by:	Nick Barkas <snb threerings net>
PR:		ports/116182
2007-09-13 05:50:33 +00:00
Pav Lucistnik
4c6425226d - Properly clean up directories
Reported by:	pointyhat
2007-09-12 08:01:43 +00:00
Edwin Groothuis
bc6779061e Update port: security/kopete-otr
Update kopete-otr to version 0.6.

PR:		ports/116271
Submitted by:	Dave Grochowski <malus.x@gmail.com>
2007-09-12 07:19:05 +00:00
Cy Schubert
9c73679b41 Patch for MIT krb5 Security Advisory 2007-006 - kadmind RPC lib buffer
overflow, uninitialized pointer
Security:	MIT krb5 Security Advisory 2007-006
2007-09-11 23:52:19 +00:00
Cy Schubert
f7158eba51 Update 2.1.13 --> 2.1.14 2007-09-11 23:12:05 +00:00
Edwin Groothuis
78892e719d Undo changes to the header. 2007-09-11 20:50:54 +00:00
Remko Lodder
7e08d5963d Correct a style nit and bump modification date.
Bump modification date for "xpdf -- stack based buffer overflow"
which was forgotten by Jeremy (mezz) :-)
2007-09-11 19:40:02 +00:00
Xin LI
8fc8f53403 Document Apache 2.0.x, 2.2.x series' vulnerabilities as well
as security related improvements in php 5.2.4.
2007-09-11 06:20:54 +00:00
Jeremy Messenger
64e2ff2812 There is no code of CVE-2007-3387 vulnerability in evince, therefore remove
it from the database. It only merely depends on poppler and poppler has been
patched (marked as safe in database).
2007-09-10 21:59:15 +00:00
Alex Dupre
6c25254e4d Update to 0.11.4 release. 2007-09-10 18:57:01 +00:00
Andrew Pantyukhin
b3ba000236 - Update to 3.02 2007-09-10 16:56:53 +00:00
Marcus Alves Grando
3807aca979 - lighttpd -- FastCGI header overrun in mod_fastcgi 2007-09-10 13:37:24 +00:00
Edwin Groothuis
13b2aeec3d security/bro, port upgrade to version 1.2.1, take over maintainership
This is an upgrade of the security/bro port to the current
	stable version.  The port is very complex, so it needs to
	be tested carefully to make sure that I'm not screwing
	anything up or using wrong conventions. Also, I'm willing
	to take over maintainership of the port if it's accepted
	into the tree.

	Please note, there are several files that need to be removed
	from the port and quite a few that need to be added. All
	these files are in FILESDIR.  I have provided blank patches
	for the files that need to be removed, so the patches will
	create blank files.

Added IS_INTERACTIVE to the port
Left original freebsd header comments in it.
Next time please use one big patch-file instead of lots of little ones :-)

PR:		ports/114999
Submitted by:	Paul Schmehl <pauls@utdallas.edu>
2007-09-10 13:28:12 +00:00
Edwin Groothuis
f49f3264b6 [UPDATE] security/vinetto to 0.07
Update from 0.06 to 0.07. Changelog:
	- Added utf8 support and symlinks from real filenames to
	numbered filenames

PR:		ports/116063
Submitted by:	"R.Mahmatkhanov" <R.Mahmatkhanov@SKYLINK.ru>
2007-09-10 11:17:30 +00:00
Edwin Groothuis
65fd767d1f [patch] Ossec-hids-server upgrade to 1.3
Attached patch updates ossec-hids-server to version 1.3

PR:		ports/115868
Submitted by:	valerio.daelli@gmail.com
2007-09-10 08:20:02 +00:00
Li-Wen Hsu
a8939da708 - Update to 1.1.3 2007-09-09 22:12:21 +00:00
David Thiel
07dcebdc47 RATS is under new ownership, so change download and WWW info.
PR:		ports/116194
Submitted by:	bf <bf2006a@yahoo.com>
Approved by:	lx
2007-09-09 03:39:54 +00:00
Edwin Groothuis
a4b7f57f65 Add fix for compilation problems as suggested at
http://point-at-infinity.org/ssss/

Noticed by: YAPHR
2007-09-09 00:26:25 +00:00
Mark Linimon
5e02beeb53 Fix mismerge.
Hat:	portmgr
2007-09-09 00:10:46 +00:00
Gabor Kovesdan
58007414c8 - Update to 1.0.6 2007-09-08 14:32:52 +00:00
Edwin Groothuis
eb818ba0a8 new port: security/afterglow, a collection of graph-generating scripts
AfterGlow is a collection of scripts which facilitate the
	process of generating event graphs and treemaps. AfterGlow
	1.x is written in Perl and generates output that can be
	read by GraphViz or LGL.  All the scripts and other files
	for afterglow are installed in ${DATADIR}

	WWW: http://sourceforge.net/projects/afterglow

PR:		ports/115186
Submitted by:	Paul Schmehl <pauls@utdallas.edu>
2007-09-08 05:49:35 +00:00
Marcus Alves Grando
651b04a669 - Update to 4.7p1
- Update HPN patch to 4.7p1-hpn12v18
- Mark as BROKEN WITH_KERB_GSSAPI while developer release a new patch
2007-09-08 01:18:31 +00:00
Mark Linimon
9839011ec3 Welcome bsd.perl.mk. Add support for constructs such as USE_PERL5=5.8.0+.
Drop support for antique perl.

Work done by:	gabor
Sponsored by:	Google Summer of Code 2007
Hat:		portmgr
2007-09-08 01:12:10 +00:00
Mark Linimon
41a56135d1 Remove support for antique perl.
Hat:	portmgr
2007-09-08 00:45:08 +00:00
Edwin Groothuis
a0125022d7 new port security/ssss - Shamir's Secret Sharing Scheme
ssss is an implementation of Shamir's secret sharing scheme
	for UNIX/linux machines. It is free software, the code is
	licensed under the GNU GPL. ssss does both: the generation
	of shares for a known secret and the reconstruction of a
	secret using user provided shares. The software was written
	in 2006 by B. Poettering, it links against the GNU libgmp
	multiprecision library (version 4.1.4 works well) and
	requires the /dev/random entropy source.

PR:		ports/115949
Submitted by:	Lukasz Komsta <luke@novum.am.lublin.pl>
2007-09-07 11:55:09 +00:00
Edwin Groothuis
4e8d63bcc7 New port: security/seccure - SECCURE Elliptic Curve Crypto Utility for Reliable Encryption
The seccure toolset implements a selection of asymmetric
	algorithms based on elliptic curve cryptography (ECC). In
	particular it offers public key encryption / decryption,
	signature generation / verification and key establishment.

	ECC schemes offer a much better key size to security ratio
	than classical systems (RSA, DSA). Keys are short enough
	to make direct specification of keys on the command line
	possible (sometimes this is more convenient than the
	management of PGP-like key rings). seccure builds on this
	feature and therefore is the tool of choice whenever
	lightweight asymmetric cryptography -- independent of key
	servers, revocation certificates, the Web of Trust or even
	configuration files -- is required.

PR:		ports/115943
Submitted by:	Lukasz Komsta <luke@novum.am.lublin.pl>
2007-09-07 08:15:24 +00:00
Edwin Groothuis
934dc5b816 new port: security/hamachi (supersedes ports/110850)
New port of Hamachi VPN, using Linux official binary and a
	patch on tuncfg.c based on the official OSX release.

	Hamachi is a software that eases the creation of secure
	VPNs even between nodes that would not be able to connect
	to each other (server-assisted connection can be established
	from two NATted client, if at least one of the two NAT
	associates the port to the client not checking remote host).

	UPX port is required in order to decompress the linux binary
	and avoid run-time dependency on /proc.

PR:		ports/112982
Submitted by:	Lapo Luchini <lapo@lapo.it>
2007-09-07 07:47:07 +00:00
Joe Marcus Clarke
d84f52593e As promised, remove net-im/gaim, and all dependent ports. Gaim has been
replaced by net-im/pidgin.
2007-09-07 03:47:30 +00:00
Edwin Groothuis
028101c0d6 New port: security/openvpn-auth-ldap - LDAP authentication plugin for OpenVPN
The OpenVPN Auth-LDAP Plugin implements username/password
	authentication via LDAP for OpenVPN 2.x. It also includes
	some integration with the OpenBSD packet filter, supporting
	adding and removing VPN clients from PF tables.

	WWW: http://dpw.threerings.net/projects/openvpn-auth-ldap/

PR:		ports/113925
Submitted by:	Nick Barkas <snb@threerings.net>
2007-09-07 02:47:13 +00:00
David Thiel
40f22eeeba Update to 2.3.6. 2007-09-06 20:24:25 +00:00
Stefan Eßer
574cef12b7 Fix build on -stable. Pointed out by Pointyhat via Pav. (Thanks!) 2007-09-06 13:44:01 +00:00
David Thiel
05fc48fbf2 Chase libprelude version bump.
PR:		ports/116112
Submitted by:	Robin Gruyters <r.gruyters@yirdis.nl>
Approved by:	lx
2007-09-05 16:39:23 +00:00
Kirill Ponomarev
01f34445a9 Update to 0.2.21 2007-09-05 13:55:04 +00:00
Remko Lodder
ac7d766ec1 Fix mod_jk's version since PORTEPOCH came into play.
PR:		116115
Reported by:	Klavs Klavsen <klavs at EnableIT dot dk>
2007-09-05 11:26:31 +00:00
Gabor Kovesdan
f855bc5f58 rkhunter -- insecure temporary file creation
Reviewed by:	remko
2007-09-05 08:50:44 +00:00
Gabor Kovesdan
4dec94b806 lsh -- multiple vulnerabilities
Reviewed by:	remko
2007-09-05 08:47:00 +00:00
Doug Barton
0a0bd34d09 Unbreak the build by adding an explicit dependency on intltool 2007-09-04 22:35:33 +00:00
Jean Milanez Melo
0ec0a28143 - Fix typo. 2007-09-04 19:22:28 +00:00
Jean Milanez Melo
33b9011dce - Update to 0.3.6c.
- Unbreak port.
2007-09-04 19:21:25 +00:00
Stefan Eßer
0cde28d9a4 Remove spurious backslash. 2007-09-04 18:47:44 +00:00
Stefan Eßer
3da2dbd5f6 New port of w3af, the Web Application Audit and Attack Framework.
This is a Python based package of tools that can be used to assess
the security of a web server (including automated advanced tests,
e.g. for XSS or SQL injection vulnerabilities).

I did not get this port to work with the py-google port, there for
a local copy of pygoogle is included and packaged with this port.
2007-09-04 18:44:41 +00:00
Mathieu Arnold
d1a296d9d2 Update to 0.004 2007-09-04 17:16:31 +00:00
Tom McLaughlin
3c005206b9 Install schema.OpenLDAP into DOCSDIR.
Prompted by:	flz
2007-09-03 17:13:29 +00:00
Roman Bogorodskiy
ada3746c03 Backout the commit with addition of pinentry as a run dependency because
it needs discussion.
2007-09-03 04:31:51 +00:00
Tilman Keskinoz
5b091352b9 Update to 0.1.2.17
PR:             116002
Submitted by:   Nils Vogels <nivo+kw+ports.bfa274@is-root.com>
2007-09-02 17:14:07 +00:00
Tilman Keskinoz
3b616a5ff7 Update to 0.7
PR:		115978
Submitted by:	VANHULLEBUS Yvan <vanhu@netasq.com>
2007-09-02 16:48:50 +00:00
Simon L. B. Nielsen
5a5dfabb6a Document fetchmail -- denial of service on reject of local
warning message.

Submitted by:	Matthias Andree <matthias.andree@gmx.de>
PR:		ports/??? (Not received by GNATS yet)
2007-09-02 12:09:33 +00:00
Roman Bogorodskiy
004b28f65a Add RUN_DEPEND on security/pinentry because gpg is almost useless
without it.

PR:		115760
Submitted by:	novel
Approved by:	maintainer timeout (1 week, linimon ok)
2007-09-02 11:08:10 +00:00
Christian Weisgerber
7ff7ed0c21 Document gtar directory traversal vulnerability.
PR:		115914
Submitted by:	Nick Barkas <snb@threerings.net>
2007-09-01 16:04:23 +00:00
Andrew Pantyukhin
25b157f255 - Update to 3.01 2007-08-31 18:06:18 +00:00
Mathieu Arnold
d1850a3d8c Use the CPAN site macro.
Use DISTVERSION in place of DISTNAME where possible.
Remove perl 5.005 shims.
2007-08-31 13:37:23 +00:00
Renato Botelho
942f9e9c28 Update to 20070830 2007-08-30 16:25:07 +00:00
Marcus Alves Grando
a33136265a - Enable ssl-engine
- Update gsskex patch to 4.6p1-gsskex-20070312
- Update lpk patch to 4.6p1-0.3.9
- Update hpn patch to 4.6p1-hpn12v17
- Fix challenge-response issue
- Bump PORTREVISION

Reported by:	Stefan Lambrev [1], ale@ [1]
2007-08-30 15:40:39 +00:00
Sergey Matveychuk
5474f2b893 - Modern rc.d script
PR:		ports/115198
Submitted by:	Jan Srzednicki <w@wrzask.pl>
Approved by:	maintainer
2007-08-30 15:02:47 +00:00
Martin Wilke
cc5c791ddd - Marked sylpheed2 as safe.
Reviewed by:	remko
2007-08-28 21:03:19 +00:00
Roman Bogorodskiy
77c1dd6440 Update to 1.7.19. 2007-08-28 13:17:28 +00:00
Peter Pentchev
4afa9507f4 Reserve a user and group ID for the stunnel daemon.
Loosely based on the PR, although I just used the next available UID/GID.

PR:		108784
Submitted by:	Alex Kozlov <spam@rm-rf.kiev.ua>
2007-08-28 10:01:00 +00:00
Alex Dupre
e2c87050d0 Update to 0.6.13 release. 2007-08-28 06:07:22 +00:00
Martin Wilke
1d39bb8c71 - Fix a typo. 2007-08-27 19:52:30 +00:00
Martin Wilke
b78c971c8a - Document Sylpheed / Sylpheed-Claws POP3 Format String Vulnerability
Reviewed by:	simon
2007-08-27 19:44:03 +00:00
Tom McLaughlin
f384e1030f Update to 1.6.9p4
- IPv6 support added.
- Added notes to default sudoers for handling environmental variables
  related to our pkg_* tools and portupgrade.
2007-08-27 19:40:48 +00:00
Johan van Selst
333ccdd698 Update to 0.4.12 2007-08-26 11:50:07 +00:00
Simon L. B. Nielsen
539ab171b2 From latest Opera entry:
- Remove redundant information.
- Bump modified date for recent changes to the entry.
2007-08-25 19:36:42 +00:00
Chin-San Huang
f271e58e93 - Update to 1.5.
PR:		ports/115809
Submitted by:	chinsan
Approved by:	maintainer
2007-08-25 13:38:52 +00:00
Michael Nottebrock
4af96e7ccc Update to 1.0.3.
PR: ports/115778
Submitted by:   Hirohisa Yamaguchi <umq@ueo.co.jp>
2007-08-25 13:13:15 +00:00
Ion-Mihai Tetcu
710346a74a linux-opera and (for the moment defunct) opera-devel are also affected by
df4a7d21-4b17-11dc-9fc2-001372ae3ab9 - Vulnerability in javascript handling so
addd them to the entry.

Submitted by:	sat@
2007-08-24 15:20:16 +00:00
Rong-En Fan
4d9f7e706a - Update download and license url
PR:		ports/115754
Submitted by:	Adi Pircalabu <apircalabu at bitdefender.com> (maintainer)
2007-08-24 03:01:52 +00:00
Cy Schubert
78e4a1a65f Update 2.1.12 --> 2.1.13 2007-08-23 23:16:37 +00:00
Doug Barton
e8a706e264 1. Update to 3.1.0
2. Update the MASTER_SITES
3. Add a verify target for the PGP signature, and download the signature
4. Add USE_GMAKE
5. Add an unconditional USE_GETTEXT since there is no way to disable it
6. Update pkg-plist with the *.mo files

Approved by:	maintainer timeout

PR:		ports/115664 (pkg-plist fix)
Submitted by:	Matthias Andree <matthias.andree@gmx.de>
2007-08-23 21:21:19 +00:00
Doug Barton
a4b970eb78 1. Update to version 3.1.0
2. Add a verify target for the PGP signature, and download the signature

Approved by:	maintainer

PR:		ports/115664 (pkg-plist fix)
Submitted by:	Matthias Andree <matthias.andree@gmx.de>
2007-08-23 20:57:59 +00:00
Doug Barton
7cff31552a Since gaim is no more, refer to pidgin instead 2007-08-23 20:55:15 +00:00
Thomas Abthorpe
2574f69107 - change maintainer address on ports I maintain
Approved by:	clsung (mentor)
2007-08-23 04:00:04 +00:00
Xin LI
edcf248194 Update vuln.xml for rsync 2.6.9_1 which fixed CVE-2007-4091 2007-08-22 16:31:46 +00:00
Xin LI
18567a346b Document rsync off-by-one stack overflow vulnerability. 2007-08-21 17:20:28 +00:00
Renato Botelho
1c4eb6b78e - Update to 0.91.2
PR:		ports/115682
Submitted by:	Michael Scheidell <scheidell@secnap.net>
2007-08-21 16:03:49 +00:00
Martin Matuska
e5adf620cd - Fix RUN_DEPENDS
- Bump PORTREVISION

devel/gmake was accidentially included in RUN_DEPENDS
2007-08-21 14:02:41 +00:00
Anton Berezin
18d9f10c34 Update to 0.16.
Remove 4.X support bits.
Changes: http://search.cpan.org/src/DKAMHOLZ/Authen-Htpasswd-0.16/Changes
2007-08-21 08:34:45 +00:00
Ion-Mihai Tetcu
29bb719115 Chaosreader is a perl script that parses snoop or tcpdump logs
and extracts sessions for a number of different appplications:
ssh, telnet, smtp, irc, ftp, etc.  The data are formatted into
an html file and can be used to replay some sessions.

Sshkeydata is a perl script that attempts to recreate ssh
sessions extracted by chaosreader by estimating what commands
may have been typed.

Both scripts are installed in ${PREFIX}/bin

WWW: http://sourceforge.net/projects/chaosreader

PR:		ports/115125
Submitted by:	pauls
2007-08-20 17:55:31 +00:00
Munechika SUMIKAWA
5a6edef7df Revert removing USE_AUTOTOOLS. 2007-08-20 01:07:18 +00:00
Gabor Kovesdan
0db228246f - Update to 5.45
- Install example dups file when NOPORTEXAMPLES unset

PR:		ports/115347
Submitted by:	Felippe de Meirelles Motta <lippe@freebsdbrasil.com.br>
2007-08-19 14:12:18 +00:00
Joe Marcus Clarke
451823bbd0 * Improve COMMENT to more properly reflect what seahorse has become
* Fix a crash that occurs with newer OpenLDAP versions

PR:		115160
Submitted by:	Yuri Pankov <yuri@darklight.org.ru>
2007-08-18 16:15:38 +00:00
Hye-Shik Chang
56731917e4 Fix port to use openssl configurations provided by bsd.openssl.mk.
PR:		115532
Submitted by:	Piet Delport <pjd@satori.za.net>
2007-08-18 10:55:26 +00:00
Jose Alonso Cardenas Marquez
2473b64d7f - Update to 0.6 2007-08-17 20:11:21 +00:00
Roman Bogorodskiy
b5b3f7cc18 Update to 1.7.18. 2007-08-17 16:41:51 +00:00
Munechika SUMIKAWA
ee001df892 Make compilable with recent FAST_IPSEC changes on -CURRENT. 2007-08-17 07:36:17 +00:00
Martin Wilke
8a0f887836 - Update the wordpress -- unmoderated comments disclosure entry. Is safe with the 2.2.2 Release.
Approved by:	simon
2007-08-16 11:53:01 +00:00
Andrew Pantyukhin
c4fc19cf10 Add port security/p5-Net-Server-Mail-ESMTP-AUTH:
Net::Server::Mail::ESMTP::AUTH is an extension to provide
support for SMTP authentication with Net::Server::Mail::ESMTP
module.

Currently only LOGIN and PLAIN methods are supported.

WWW: http://search.cpan.org/dist/Net-Server-Mail-ESMTP-AUTH/
Author: Sylvain Cresto <scresto [_at_] gmail.com>

PR:		ports/114785 (with corrections)
Submitted by:	Zane C. Bowers <vvelox@vvelox.net>
2007-08-15 18:48:12 +00:00
Ion-Mihai Tetcu
3eebdacd1c Add info about www/opera's JavaScript vulnerability
PR:		ports/115543
Submitted by:	Arjan van Leeuwen (maintainer)
Reviewed by:	simon@
2007-08-15 12:15:39 +00:00
Cheng-Lung Sung
3a8f5e82e4 - Update to 0.9.9
- Fix error when changing ownership of spool directory

Changelog prelude-manager 0.9.9:
- Update configuration template, add documentation for Prelude
  generic TCP options.
- Implement modified patch from Pierre Chifflier <chifflier@inl.fr>
  to fix the example log path (fix #224).
- Move IDMEF message normalization in the scheduler, rather than
  doing it upon reception. This remove some load from the server
  and allow Prelude-Manager own IDMEF messages to go through the
  normalizer path.
- Implement heartbeat->analyzer normalization.
- Improve IPv4 / IPv6 address normalization.
  IPv4 mapped IPv6 addresses are now mapped back to IPv4.
  Additionally, the Normalize plugin now provide two additionals option:
  ipv6-only: Map any incoming IPv4 address to IPv6.
  keep-ipv4-mapped-ipv6: do not map IPv4 mapped IPv6 addresses back to
  IPv4.
- Make a difference between exceptional report plugin failure (example:
  a single message couldn't be processed) and "global" plugin failure
  (example: database server is down). We use a different failover for
   'exceptional' failure, so that we don't try to reinsert a bogus message
   (fix #247).
- Start of a Prelude-Manager manpages (#236).
- Various bug fixes.

PR:		ports/115233
Submitted by:	maintainer (Robin Gruyters)
2007-08-15 06:48:36 +00:00
Cheng-Lung Sung
4f9e6e3da5 - Add support for PHP binding
- Use libxml2 in USE_GNOME (instead of LIB_DEPENDS)
- Use USE_PYTHON_BUILD instead of USE_PYTHON
- bump PORTREVISION

PR:		ports/115457
Submitted by:	maintainer (Gea-Suan Lin)
2007-08-15 03:26:40 +00:00