Commit graph

7270 commits

Author SHA1 Message Date
joerg
2a7055907f Make PostgreSQL 8.2 the default version. Bump all packages using it.
Remove PostgreSQL 8.0 as choice.
2008-03-13 17:38:48 +00:00
drochner
48631583b0 update to 3.0.8
3.0.8 is a stable release which includes many significant enhancements and
new features, and the usual squashed bugs. The most prominent new
features are the ability to "tag" headers and apply actions based on those
tags, making Privoxy much more flexibile, and Privoxy can now act as an
"intercepting" proxy.
2008-03-12 21:35:03 +00:00
adrianp
8f47e979b6 Lots of changes, see the changelog for all the details:
http://tomcat.apache.org/tomcat-5.5-doc/changelog.html

Of note:
important: Data integrity   CVE-2007-6286
important: Information disclosure   CVE-2007-5461
low: Elevated privileges   CVE-2007-5342
low: Session hi-jacking   CVE-2007-5333

Are all fixed in this release.
2008-03-12 20:41:48 +00:00
tnn
882d3eb4fe Put back a couple of IRIX conditionals the way they used to behave,
e.g. match IRIX 5.x but not 6.x. Some of these may indeed apply to 6.x
too, but let's be conservative. PR pkg/38224.
2008-03-11 18:47:40 +00:00
taca
6e9c1153f6 Improve startup script:
- Revive support for system without NetBSD style rc/rc.d.
- Always pass command_args and squid_flags to squid command.

This should fix the PR pkg/38036 by Wolfgang Stukenbrock.

Bump PKGREVISION.
2008-03-11 15:46:41 +00:00
obache
03e9d4affd HOMEPAGE moved. 2008-03-11 04:19:04 +00:00
drochner
fcd5cc0af7 -make the gssapi option default on NetBSD (where Kerberos comes for free)
(suggested by Todd Kover in PR pkg/36144)
-propagate the krb dependency through bl3 if necessary
-bump PKGREVISION
2008-03-10 18:35:54 +00:00
drochner
22e5f6e7e4 update to 1.4.13
changes: minor bugfixes
2008-03-10 13:00:01 +00:00
drochner
d1b7851581 update to 2.0.5
changes:
- Works with Firefox 1.5.x and xulrunner 1.8.x
- Compiles with xulrunner 1.9, but a lot of functionality is disabled due
  to being no longer exposed by xulrunner (or not working)
  - MyPortal
  - User stylesheets
  - Remembering passwords
  - http authentication
- Support for external mailers which don't understand mailto: urls is
  completely removed. Pretty much all modern mailers support them now.
2008-03-10 12:56:20 +00:00
bjs
6a20e97c6c Update to 0.11.4rc1. No changelog available; if interested, please
see GIT history.

Made option elinks-fastmem the default, as it's significantly faster
and I don't trust their wrappers of malloc(), etc. al. anyway.
Version 0.12 supports boehm-gc, which will probably become the default.
If 0.12 isn't released fairly soon, I'll see about backporting support.
Also add elinks-html-highlight as a default, as there's really no
reason not to.
2008-03-10 01:57:43 +00:00
gdt
7ae55deff1 Don't try to check for apache22 option, but instead just
PKG_APACHE_ACCEPTED=	apache2 apache22
like every other ap2-foo package.
2008-03-08 21:00:06 +00:00
adrianp
fc29e471e6 Bump to 3.1.7
Major changes compared to Horde 3.1.6 are:
    * Fix arbitrary file inclusion through abuse of the theme preference.
2008-03-08 17:36:53 +00:00
jlam
b3b31977fd Drop the inet6 option and mark this package as simply "IPV6_READY"
because it doesn't care about the IP family.
2008-03-07 22:00:43 +00:00
mrg
aa48bebc5b incorporate a fix from the master bozohttpd repo: fix files with spaces.
(or any special char, with no ?.)
2008-03-07 18:17:26 +00:00
jlam
910aae38f8 Support user-destdir installation in all packages that include
this Makefile.common.
2008-03-07 05:43:42 +00:00
jlam
7d9dfc154d Turn on user-destdir installation for the *-bin-nightly packages --
these Makefiles include seamonkey-bin-nightly/Makefile.common which
just include seamonkey-bin/Makefile.common which already has user-destdir
support.
2008-03-07 05:18:21 +00:00
jlam
2c8c3ed113 Add support for user-destdir installation. 2008-03-07 05:16:48 +00:00
jlam
65404edba4 Add support for user-destdir installation -- seamonkey-bin/Makefile.common
has already been altered to support user-destdir, so we just need to turn
it on in these packages.
2008-03-07 05:14:04 +00:00
jlam
fff60b2c74 Add support for user-destdir installation. 2008-03-07 05:06:16 +00:00
adrianp
132208db3b Version 1.0.5 (released 28-Feb-2008)
* security fix: omit commits of all-forbidden files from query results
* security fix: disallow direct URL navigation to hidden CVSROOT folder
* security fix: strip forbidden paths from revision view
* security fix: don't traverse log history thru forbidden locations
* security fix: honor forbiddenness via diff view path parameters
* new 'forbiddenre' regexp-based path authorization feature
* fix root name conflict resolution inconsistencies (issue #287)
* fix an oversight in the CVS 1.12.9 loginfo-handler support
* fix RSS feed content type to be more specific (issue #306)
* fix entity escaping problems in RSS feed data (issue #238)
* fix bug in tarball generation for remote Subversion repositories
* fix query interface file-count-limiting logic
* fix query results plus/minus count to ignore forbidden files
* fix blame error caused by 'svn' unable to create runtime config dir
2008-03-06 21:21:10 +00:00
wiz
8e810a2bc9 Recursive PKGREVISION bump for gnutls-2.2.2 update with shlib major bump. 2008-03-06 14:53:47 +00:00
adrianp
1ad533c1c6 Drupal 5.7
* 208700 by pwolanin. Fix bad backport of #194579. Modified to use Form API.
* 118569 by bevan: document how should one set RewriteBase, if under a VirtualDocumentRoot. Backport by Bart Jansens.
* Patch 115606 by Junyor, thesaint_02: added support for PHP 5.2's 'recoverable fatal errors'.
* 209409 by Heine, webernet, dww: more accurate register globals value checking
2008-03-05 21:35:40 +00:00
jlam
13b9acb77f + Include termcap.buildlink3.mk instead of using ${OPSYS} to guess at
the right terminal library.

Bump the PKGREVISION of www/w3m and www/w3m-img to 2.
2008-03-05 18:01:50 +00:00
jlam
2edee7a749 + Use the correct termcap library instead of hardcoding -ltermcap.
Bump the PKGREVISION to 5.

+ Add full DESTDIR support.
2008-03-05 17:12:44 +00:00
wiz
d0451cf046 Update to 3.20:
2008-02-29  Andy Lester

        * Release 3.20 -- Added <div> to the list of p_closure_barriers.
2008-03-04 12:38:58 +00:00
kefren
b56a38e922 add temporary patch from
http://trac.lighttpd.net/trac/attachment/ticket/1562/Fix-372-and-1562.patch
in order to fix CVE-2008-0983. Bump PKGREVISION
2008-03-04 11:17:57 +00:00
rillig
ebcb0ce01e Resign from maintaining a lot of packages, so everyone is free to update
them at will.
2008-03-04 11:02:23 +00:00
wiz
9762c522bc Update links* to 2.1.0.33:
=== RELEASE 2.1pre33 ===

Thu Jan 31 21:11:40 MET 2008 mikulas:

	Fixed memory leak when there was an error in decompression

Thu Dec 27 23:37:03 MET 2007 mikulas:

	Support few more keycodes on ANSI terminal (PAGE UP, PAGE DOWN and few
	F* keys)

Wed Dec 26 03:43:35 cet 2007 mikulas:

	Disable smb:// URLs on OS/2, fork+threads can cause crashes in EMX
	Besides, there's no usable smb client program anyway

Tue Dec 25 01:44:28 MET 2007 mikulas (sponsored by Dondor Ltd.):

	A .nsi file to make Windows installer with Nullsoft scriptable install

Mon Dec 24 01:44:11 MET 2007 mikulas:

	Fixed a bug that strings with spaces could not be passed from command
	line

Mon Dec 24 00:43:57 MET 2007 mikulas:

	Socks 4A support (so that Links can be used with tor without
	intermediate proxy)

Thu Dec 20 05:40:22 cet 2007 mikulas:

	The previous Windows fix broke opening new windows on OS/2
2008-03-04 09:56:20 +00:00
drochner
9bd3464e7e add an option to enable gssapi, for GSS-Negotiate, from Todd Kover
per PR pkg/36144
(just compile-tested because I don't have a Kerberos installation)
2008-03-03 18:48:21 +00:00
jlam
bff59419d7 Update www/bozohttpd to version 20080303. Changes from version 20060517
include:

+ Add full DESTDIR support.
+ Split out package options into a separate options.mk file.

* Fix some cgi header processing
* Add simple Range: header processing
2008-03-03 15:53:03 +00:00
abs
05eb7d3eaf Let seamonkey treat official-mozilla-branding as a NOP 2008-03-02 15:24:07 +00:00
bjs
ec8b6e8590 Update to version 7.18.0 and add SSHv2 support via the newly imported
security/libssh2 package.

Changes:

 o --data-urlencode
 o CURLOPT_PROXY_TRANSFER_MODE
 o --no-keepalive - now curl does connections with keep-alive enabled by
   default
 o --socks4a added (proxy type CURLPROXY_SOCKS4A for libcurl)
 o --socks5-hostname added (CURLPROXY_SOCKS5_HOSTNAME for libcurl)
 o curl_easy_pause()
 o CURLOPT_SEEKFUNCTION and CURLOPT_SEEKDATA
 o --keepalive-time
 o curl --help output was re-ordered

This release includes the following bugfixes:

 o curl-config --features and --protocols show the correct output when built
   with NSS, and also when SCP, SFTP and libz are not available
 o free problem in the curl tool for users with empty home dir
 o curl.h version 7.17.1 problem when building C++ apps with MSVC
 o SFTP and SCP use persistent connections
 o segfault on bad URL
 o variable wrapping when using absolutely huge send buffer sizes
 o variable wrapping when using debug callback and the HTTP request wasn't sent
   in one go
 o SSL connections with NSS done with the multi-interface
 o setting a share no longer activates cookies
 o Negotiate now works on auth and proxy simultanouesly
 o support HTTP Digest nonces up to 1023 letters
 o resumed ftp upload no longer requires the read callback to return full
   buffers
 o no longer default-appends ;type= on FTP URLs thru proxies
 o SSL session id caching
 o POST with callback over proxy requiring NTLM or Digest
 o Expect: 100-continue flaw on re-used connection with POSTs
 o build fix for MSVC 9.0 (VS2008)
 o Windows curl builds failed file truncation when retry downloading
 o SSL session ID cache memory leak
 o bad connection re-use check with environment variable-activated proxy use
 o --libcurl now generates a return statement as well
 o socklen_t is no longer used in the public includes
 o time zone offsets from -1400 to +1400 are now accepted by the date parser
 o allows more spaces in WWW/Proxy-Authenticate: headers
 o curl-config --libs skips /usr/lib64
 o range support for file:// transfers
 o libcurl hang with huge POST request and request-body read from callback
 o removed extra newlines from many error messages
 o improved pipelining
 o improved OOM handling for data url encoded HTTP POSTs when read from a file
 o test suite could pick wrong tool(s) if more than one existed in the PATH
 o curl_multi_fdset() failed to return socket while doing CONNECT over proxy
 o curl_multi_remove_handle() on a handle that is in used for a pipeline now
   break that pipeline
 o CURLOPT_COOKIELIST memory leaks
 o progress meter/callback during http proxy CONNECT requests
 o auth for http proxy when the proxy closes connection after first response
2008-03-02 14:40:26 +00:00
tnn
a763843173 Add a MESSAGE file warning about potential profile lossage + how to avoid it.
Ok xtraeme@
2008-02-29 23:48:15 +00:00
xtraeme
c1a6f2bc4f Added www/firefox3-bin. 2008-02-29 23:01:57 +00:00
xtraeme
2daecdabf2 firefox 3.0beta3 linux binary version, for people that don't want
to wait for testing not-finished releases.

Ok by jlam@.
2008-02-29 23:01:03 +00:00
abs
3e9331bfd1 Put official-mozilla-branding in the PKG_SUPPORTED_OPTIONS for all packages that include this file - notably sunbird 2008-02-26 23:30:03 +00:00
sborrill
4a34902858 Use PKG_SYSCONFSUBDIR to ensure that configuration directory gets created
when using binary packages.
Bump PKGREVISION
2008-02-26 12:39:52 +00:00
obache
d0b8d3d185 Update ap-ssl to 2.8.31.
2.8.31: For Apache 1.3.41
2.8.30: Bug Fix
2.8.29: For Apache 1.3.39
2008-02-24 05:29:21 +00:00
obache
bd19e2efb4 Add DESTDIR support. 2008-02-23 05:26:01 +00:00
obache
ebadff7698 Update apache to 1.3.41.
Changes with Apache 1.3.41

  *) SECURITY: CVE-2007-6388 (cve.mitre.org)
     mod_status: Ensure refresh parameter is numeric to prevent
     a possible XSS attack caused by redirecting to other URLs.
     Reported by SecurityReason.  [Mark Cox]

Changes with Apache 1.3.40 (not released)

  *) SECURITY: CVE-2007-5000 (cve.mitre.org)
     mod_imap: Fix cross-site scripting issue.  Reported by JPCERT.
     [Joe Orton]

  *) SECURITY: CVE-2007-3847 (cve.mitre.org)
     mod_proxy: Prevent reading past the end of a buffer when parsing
     date-related headers.  PR 41144.
     With Apache 1.3, the denial of service vulnerability applies only
     to the Windows and NetWare platforms.
     [Jeff Trawick]

  *) More efficient implementation of the CVE-2007-3304 PID table
     patch. This fixes issues with excessive memory usage by the
     parent process if long-running and with a high number of child
     process forks during that timeframe. Also fixes bogus "Bad pid"
     errors. [Jim Jagielski, Jeff Trawick]

Changes with Apache 1.3.39

  *) SECURITY: CVE-2006-5752 (cve.mitre.org)
     mod_status: Fix a possible XSS attack against a site with a public
     server-status page and ExtendedStatus enabled, for browsers which
     perform charset "detection".  Reported by Stefan Esser.  [Joe Orton]

  *) SECURITY: CVE-2007-3304 (cve.mitre.org)
     Ensure that the parent process cannot be forced to kill non-child
     processes by checking scoreboard PID data with parent process
     privately stored PID data. [Jim Jagielski]

  *) mime.types: Many updates to sync with IANA registry and common
     unregistered types that the owners refuse to register.  Admins
     are encouraged to update their installed mime.types file.
     pr: 35550, 37798, 39317, 31483 [Roy T. Fielding]

There was no Apache 1.3.38
2008-02-23 05:16:33 +00:00
sborrill
8303b4b622 Add dansguardian 2008-02-22 17:13:58 +00:00
sborrill
f54adc018d DansGuardian is a web content filtering proxy for Linux, FreeBSD, OpenBSD,
and Solaris. It relies on a proxy server, for all fetching.  The preferred
proxy is Squid, however, DansGuardian should work with any proxy server.
2008-02-22 17:13:29 +00:00
jlam
8445ecc84c + Rename the "ncursesw" option to "wide-curses" and get rid of the
"ncurses" option.  "wide-curses" now just toggles whether we use
  wide or narrow curses, which is a much simpler knob for users.

Bump the PKGREVISION to 5.
2008-02-21 22:47:28 +00:00
jlam
db7d6f58bf Add full DESTDIR support. 2008-02-21 22:42:29 +00:00
xtraeme
33ae7e846c Update to 9.26.
Changes Since Opera 9.25:

Security
--------
Fixed an issue where simulated text inputs could trick users into uploading
arbitrary files, as reported by Mozilla. See our advisory.

Image properties can no longer be used to execute scripts, as reported by
Max Leonov. See our advisory.

Fixed an issue where the representation of DOM attribute values could allow
cross site scripting, as reported by Arnaud.lb. See our advisory.

Miscellaneous
-------------
Fixed a stability issue found in Opera 9.0 to 9.25, when Opera connects
securely to Windows Server 2008 or other servers supporting the TLS
Certificate Status extension.

Additional stability fixes.
2008-02-20 19:31:22 +00:00
markd
d7b3a9908e Update to kde 3.5.9
Quanta Plus
* Insert literal character entities if possible.
* List the plugin in the Open With context menu.
* Fix crashes when using XDebug.
* Do not keep an empty, Untitled document opened when opening new files.
* Fix crash when closing a plugin and no other document is opened.
* Make HTML forms work in the internal preview.
* Fix deadlock in CSS editor when the propery contains ":".

Kommander
* Support executing of widget slots.
* Add execute method for PushButton.
* Add possibility to pass parameters for ScriptObject.
* Add "return" command to get back the result of a ScriptObject.
* Add "createWidget" function for on-the-fly widget creation.
* Add "widgetExists" function.
* Add "execBackground" function.
* Add "connect/disconnect" function for on-the-fly signal/slot connection.
* Add indexed array functions
* Make "a="Label1"; a.setText("foo")" work.
* Add "TreeWidget.selectedIndexes".
* Add "Table.setCellWidget/cellWidget".
* Add "Table.selection" to get back the selection coordinates.
* New widgets: "AboutDialog, DatePicker, PopupMenu, ToolBox"
* Use the new parser by default for new dialogs.
* Support shebang ("#!/path_to/kmdr-executor") in the beginning of the
  .kmdr files. Running .kmdr files is possible directly if you make
  them executable.
* Warn if a dialog file is not executable.
* Store Kommander version in the "VERSION/_VERSION" global variable.
* Add experimental Kommander KPart (Kommander dialogs can be embedded in
  other KDE applications).
* Make "input_color" and "@Input.color" accept a default color argument.
* Make "TreeWidget.selection" work in multi selection mode.
* Make "TreeWidget.setSelection" show the selected item.
* Make "CheckBox.setChecked" accept as argument false, "false", true,
  "true", 0 (meaning false), everything else meaning "true".
* Optionally quote the strings inserted via the function browser.
* Use combobox for booleans in the function browser.
* Use multiline insert box in function browser.
* Add highlighting for the new parser.
* Make possible to open more associated editors at once.
* Make it possible to run external script in a ScriptObject.
* "execute" DCOP call returns a string.
* The editor does not save the dialog on running.
* Create backup files every 5 minutes.
* Rework the plugin system.
* Set new functions only available to new parser such as createWidget
  to not be shown in the function browser if the old parser is run.
* Show all available functions in the function browser.
* Insert the functions using the syntax of the new parser if #!kommander
  is specified in the associated text.
* Return the result of a division in floating form if the result is not
  an integer.
* Update the handbook.
* Install examples that are easily reachable from the editor.
* Fix "exit" command.
* Make "dcopid, pid, parentPid" work in the new parser.
* Fix problem with losing the parser type status in the editor when
  working with multiple dialogs.
* "@Array.fromString" should append the new elements to the array, just
  like it did before and how "array_fromString" does.
* Fix @eval for addition/substraction and handle division by zero.
* Process code written in external script using the old parser.
* Fix many cases when the code was executed altough it was in a codepath
  that should not be executed.
* Fixed the bug in the input text dialog where entering a default value
  returned the caption.
* Fix the for loop parsing if end < start.
2008-02-20 09:57:47 +00:00
taca
ef018fd7e3 Update plone3 package to 3.0.6.
Change log

* Various tests were enhanced to increase our test coverage
* Implement unlocking for content which does not use portal_factory
  and for LinguaPlone translations.
* Add a method to cleanup persistent schemas from content objects
  which were created by the 'update schema' feature from older
  Archetypes releases. This is available through the ZMI.
* Correct removing of all roles from a group. This fixes This fixes 6994.
* Correct generation of session cookies for long userids. This fixes
  problems with OpenID2 accounts.
* Correct handling of unicode arguments for
  acl_users.enumerateUsers. This fixes zope-pas bug 189627.
* Kupu updates:
    o Correct full screen mode. This fixes 7473.
    o Correct intenal link insertion for IE. This fixes 7494.
    o Correct stripping out of anchor to top of current page. This fixes 7680.
    o The 'Home' link nows goes to the content root instead of the
      Plone root. This fixes 7713.
    o 'Link using UIDs' broke indexing of richt text fields with
      non-ASCII characters. This fixes 7728.
    o Update the flags and languages list. This fixes 7441.
    o  Revert internal change in language selector code in the
       plone.app.i18n release from Plone 3.0.5 in the language
       selector widget which broke LinguaPlone.
    o Fix lock timeout which was set by default to 12 minutes, it is
      now set to maxtimeout (71582788 minutes). This fixes 7358.
    o Fix TypeError when an anonymous user locks content. This fixes 7246.

Updated packages

    * archetypes.kss 1.2.6
    * plone.app.i18n 1.0.3
    * plone.app.controlpanel 1.0.4
    * plone.app.linkintegrity 1.0.5
    * plone.app.vocabularies 1.0.3
    * plone.locking 1.0.5
    * plone.session 1.2
    * Archetypes 1.5.6
    * CMF 2.1.1
    * CMFPlone 3.0.6
    * PloneLanguageTool 2.0.2
    * PlonePAS 3.2
    * PloneTranslations 3.0.11
    * PluggableAuthService 1.5.3
    * kupu 1.4.8
2008-02-19 14:12:46 +00:00
xtraeme
5bca68529b - Do not use DEPENDS directly if there's a bl3.mk file available.
- Simplify PKGNAME.
2008-02-18 17:06:32 +00:00
kefren
87de2d8877 MAKE_JOBS_SAFE=no 2008-02-18 14:01:56 +00:00
kefren
3ea8195c3c Add dependency on databases/sqlite3. Noticed by wiz@ 2008-02-18 10:36:53 +00:00
wiz
95cb8b6c1d Needs pkg-config, add it to tools. 2008-02-18 08:44:30 +00:00
tnn
96782e2293 Fix use of obsolete tail(1) syntax which coreutils 6.10 doesn't grok. 2008-02-17 20:15:07 +00:00
minskim
892bcc73a4 Remove ruby-actionwebservice, which was obsoleted by ruby-activeresource. 2008-02-17 18:19:14 +00:00
obache
b79482e720 Added p5-I18N-AcceptLanguage 2008-02-16 05:03:58 +00:00
obache
1c574283cd Import p5-I18N-AcceptLanguage version 1.04.
Based on PR 38029, remove redundant PLIST and markd as DESTDIR ready.

I18N::AcceptLanguage matches language preference to available languages
per rules defined in RFC 2616, section 14.4: HTTP/1.1 - Header Field
Definitions - Accept-Language.
2008-02-16 05:02:36 +00:00
kefren
8a8336e1c6 add mono-xsp 2008-02-13 19:58:48 +00:00
tnn
eb9ffc056d include openssl bl3 2008-02-13 19:40:13 +00:00
kefren
db57399b6d Add XSP, a standalone web server written in C# that can be used
to run ASP.NET applications with minimal effort.
2008-02-13 14:56:28 +00:00
obache
efb4bbfc2d Define MASTER_SITE simply. Don't add "contrib" automatically.
No package using "contrib" sub directory now and it is redundant.
If such a package exists on a platform, should use MOZ_DIR individually instead.

This change also fixes fetch problem of www/firefox-bin when MASTER_SITE_MOZILLA
is not defined in /etc/mk.conf.
2008-02-13 14:43:00 +00:00
jnemeth
5f5fca3e60 sort 2008-02-09 20:45:27 +00:00
minskim
351f3c09f1 Update rails to 2.0.2. Now the default database is sqlite3, not mysql.
There are many other changes.  Please see CHANGELOG for the complete list:

http://dev.rubyonrails.org/browser/tags/rel_2-0-2/railties/CHANGELOG
2008-02-09 06:31:59 +00:00
minskim
f4edf44815 Add ruby-activesupport. 2008-02-09 06:29:42 +00:00
minskim
4b5e88aee9 Import ruby-activeresource.
Active Resource (ARes) connects business objects and Representational
State Transfer (REST) web services.  It implements object-relational
mapping for REST webservices to provide transparent proxying
capabilities between a client (ActiveResource) and a RESTful service.
2008-02-09 06:27:48 +00:00
minskim
cdd6ce7240 Update ruby-actionpack to 2.0.2.
There have been too many changes.  Please see CHANGELOG for the complete list:

http://dev.rubyonrails.org/browser/tags/rel_2-0-2/actionpack/CHANGELOG
2008-02-09 06:23:29 +00:00
ghen
00b57e5e6e Update seamonkey, seamonkey-bin and seamonkey-gtk1 to Seamonkey 1.1.8.
Security fixes in this version:

MFSA 2008-10 URL token stealing via stylesheet redirect
MFSA 2008-09 Mishandling of locally-saved plain text files
MFSA 2008-06 Web browsing history and forward navigation stealing
MFSA 2008-05 Directory traversal via chrome: URI
MFSA 2008-03 Privilege escalation, XSS, Remote Code Execution
MFSA 2008-02 Multiple file input focus stealing vulnerabilities
MFSA 2008-01 Crashes with evidence of memory corruption (rv:1.8.1.12)

For more info, see http://www.seamonkey-project.org/releases/seamonkey1.1.8/
2008-02-08 18:04:33 +00:00
ghen
175915d583 Update firefox, firefox-bin and firefox-gtk1 to 2.0.0.12.
Security fixes in this version:

MFSA 2008-11 Web forgery overwrite with div overlay
MFSA 2008-10 URL token stealing via stylesheet redirect
MFSA 2008-09 Mishandling of locally-saved plain text files
MFSA 2008-08 File action dialog tampering
MFSA 2008-06 Web browsing history and forward navigation stealing
MFSA 2008-05 Directory traversal via chrome: URI
MFSA 2008-04 Stored password corruption
MFSA 2008-03 Privilege escalation, XSS, Remote Code Execution
MFSA 2008-02 Multiple file input focus stealing vulnerabilities
MFSA 2008-01 Crashes with evidence of memory corruption (rv:1.8.1.12)

For more info, see http://www.mozilla.com/en-US/firefox/2.0.0.12/releasenotes/
2008-02-08 11:28:30 +00:00
tnn
5c13124820 Fix more cases of non-chainable PKGSRC_COMPILER tests. 2008-02-08 10:34:19 +00:00
bjs
32c233feac Update to 0.11.4rc0. ChangeLog only available in GIT history: see
HOMEPAGE for more information.  While here, switch to using lang/ossp-js
package instead of lang/spidermonkey.  Goodbye, nspr dependency!
Javascript support seems more stable.

Mark option 'spidermonkey' deprecated in favor of option 'javascript'.
2008-02-06 04:30:37 +00:00
tnn
6538a067b9 PR 37952: Aleksey Cheusov: more missed tools in USE_TOOLS 2008-02-04 20:10:34 +00:00
tnn
e0a55ac43f Fix check interpreter warnings. 2008-02-03 14:07:40 +00:00
tnn
011ab3dcff Honour PKGMANDIR. 2008-02-03 13:24:22 +00:00
drochner
15b546ee23 update to 1.4.12
changes:
-fix a crash when selecting news bins
-add compatibility with non-standard "xmlURL" OPML attributes
 used by LiveJournal
-bugfixes
2008-02-03 11:14:27 +00:00
adam
890a8c7887 Fix createdirs command 2008-01-31 20:01:13 +00:00
rillig
522219d1cc Needs REPLACE_PERL. PKGREVISION++ 2008-01-31 18:59:37 +00:00
rillig
9c9af8e1c6 Replaced PYTHON_VERSIONS_ACCEPTED with PYTHON_VERSIONS_INCOMPATIBLE. 2008-01-31 13:43:34 +00:00
heinz
1155ff12ae Enabled p5-Captcha-reCAPTCHA and p5-Captcha-reCAPTCHA-Mailhide. 2008-01-25 02:32:30 +00:00
heinz
5b4097915c Initial import of Captcha-reCAPTCHA-Mailhide.
This is a Perl implementation of the reCAPTCHA Mailhide API. It can
generate URLs or even directly usable HTML code for using the reCAPTCHA
Mailhide web service, which provides a way of asking people to solve a
reCAPTCHA before they can view your email address.
2008-01-25 02:31:06 +00:00
heinz
0830e03fe8 Initial import of module Captcha-reCAPTCHA.
This is a Perl implementation of the reCAPTCHA API.
From the recaptcha.net web site:

    reCAPTCHA improves the process of digitizing books by sending words that
    cannot be read by computers to the Web in the form of CAPTCHAs for
    humans to decipher. More specifically, each word that cannot be read
    correctly by OCR is placed on an image and used as a CAPTCHA. This is
    possible because most OCR programs alert you when a word cannot be read
    correctly.
2008-01-25 01:59:06 +00:00
heinz
7aace31ac1 Enabled p5-HTML-Tiny 2008-01-25 01:39:08 +00:00
heinz
e5e3d734b7 Initial import of Perl module HTML-Tiny.
HTML::Tiny is a simple, dependency free Perl module for generating HTML
(and XML). It concentrates on generating syntactically correct XHTML using
a simple Perl notation.
2008-01-25 01:35:53 +00:00
obache
c245802f72 No need to use wget to fetch now.
(previously, need cookie capable to fetch).
2008-01-24 07:23:47 +00:00
taca
2d96ab4b56 Use the same order as zope210. 2008-01-21 16:55:01 +00:00
taca
8a0349dad8 Move post-patch target to post-extract changed as www/zope29.
And avoid to use -0 option of xargs(1).
2008-01-21 16:51:46 +00:00
xtraeme
87f9eaa73b Update to 2.2.8, please check http://www.apache.org/dist/httpd/CHANGES_2.2.8
for the list of changes.
2008-01-21 15:07:10 +00:00
taca
0b1e7f0ed3 Add comment that this file is used by devel/apr0/Makefile detected
by pkglint.
2008-01-21 14:38:29 +00:00
taca
6df84688a8 Update apache package to 2.0.63.
Changes with Apache 2.0.63

  *) winnt_mpm: Resolve modperl issues by redirecting console mode stdout
     to /Device/Nul as the server is starting up, mirroring unix MPM's.
     PR: 43534  [Tom Donovan <Tom.Donovan acm.org>, William Rowe]

  *) winnt_mpm: Restore Win32DisableAcceptEx On directive and Win9x platform
     by recreating the bucket allocator each time the trans pool is cleared.
     PR: 11427 #16 (follow-on)  [Tom Donovan <Tom.Donovan acm.org>]

Changes with Apache 2.0.62 (not released)

  *) SECURITY: CVE-2007-6388 (cve.mitre.org)
     mod_status: Ensure refresh parameter is numeric to prevent
     a possible XSS attack caused by redirecting to other URLs.
     Reported by SecurityReason.  [Mark Cox, Joe Orton]

  *) SECURITY: CVE-2007-5000 (cve.mitre.org)
     mod_imagemap: Fix a cross-site scripting issue.  Reported by JPCERT.
     [Joe Orton]

  *) Introduce the ProxyFtpDirCharset directive, allowing the administrator
     to identify a default, or specific servers or paths which list their
     contents in other-than ISO-8859-1 charset (e.g. utf-8). [Ruediger Pluem]

  *) log.c: Ensure Win32 resurrects its lost robust logger processes.
     [William Rowe]

  *) mpm_winnt: Eliminate wait_for_many_objects.  Allows the clean
     shutdown of the server when the MaxClients is higher then 257,
     in a more responsive manner [Mladen Turk, William Rowe]

  *) Add explicit charset to the output of various modules to work around
     possible cross-site scripting flaws affecting web browsers that do not
     derive the response character set as required by  RFC2616.  One of these
     reported by SecurityReason [Joe Orton]

  *) http_protocol: Escape request method in 405 error reporting.
     This has no security impact since the browser cannot be tricked
     into sending arbitrary method strings.  [Jeff Trawick]

  *) http_protocol: Escape request method in 413 error reporting.
     Determined to be not generally exploitable, but a flaw in any case.
     PR 44014 [Victor Stinner <victor.stinner inl.fr>]
2008-01-21 14:37:22 +00:00
taca
2b3e9be3f3 Start update of apr0 pacakge to 0.9.17 and apache2 package to 2.0.63. 2008-01-21 14:30:01 +00:00
ghen
30056fce31 Update PKGNAME for links-gui as well after recent ../../www/links update. 2008-01-21 14:27:35 +00:00
rillig
afe7223523 Fixing permissions is done in the post-extract stage, since it belongs
there, not in post-patch.

There's no need to use xargs -0: Solaris doesn't know that option, POSIX
doesn't require it, and all the filenames are sane anyway.
2008-01-21 07:17:49 +00:00
reed
c42e306c06 Change a BUILD_DEFS and add some more.
(As discussed in September 2007 on tech-pkg.)
2008-01-20 04:06:03 +00:00
reed
60605890c4 Improve the description. 2008-01-20 03:51:14 +00:00
tnn
ad6ceadd25 Per the process outlined in revbump(1), perform a recursive revbump
on packages that are affected by the switch from the openssl 0.9.7
branch to the 0.9.8 branch. ok jlam@
2008-01-18 05:06:18 +00:00
smb
5535249300 Fix a reentrancy bug, and a portability bug involving a Linux documentation
error and the behavior of NetBSD on 64-bit machines.  All three bugs
(including the Linux documentation problem) have been reported upstream
and will be fixed there.
2008-01-16 19:53:24 +00:00
taca
6eafdd97ca Don't print replaced name by pax(1). It was simply debugging aid. 2008-01-16 14:54:41 +00:00
wiz
853f57e975 Update to 2.1pre32:
=== RELEASE 2.1pre32 ===

Thu Dec 13 04:44:01 MET 2007 mikulas:

	Do not display links to alternate stylesheets

Tue Dec 11 06:37:56 MET 2007 mikulas:

	Use Content-Disposition as a suggestion for downloaded file name

Sun Dec  9 04:52:37 MET 2007 mikulas:

	Fixed write to freed memory resulting in misbehavior of radio buttons
	and a possible crash

Wed Dec  5 23:26:55 MET 2007 mikulas:

	Make it run without Cygwin environment (only with Cygwin DLLs)
	Workaround for flaws in Cygwin Unix emulation:
		SIGWINCH is sometimes lost
		Signal handlers write to a pipe and it should wake select() up,
			sometimes, it doesn't
		exec("command.com") crashes Windows 98 when some sockets are
			open

Wed Dec  5 18:05:00 MET 2007 mikulas:

	Do not search for compressed-file extension (.gz, .bz2) in URLs
	containing '?', '&' or ';' --- they are likely scripts and they should
	provide information about compression in the header.

Tue Dec  4 04:09:51 MET 2007 mikulas:

	When the document was truncated to zero size on reload and no data were
	received, links didn't invalidate formatted document cache

Wed Nov  7 00:20:12 MET 2007 mikulas:

	Accept capital 'X' as a hex number mark in html entities

Fri Nov  2 19:53:01 MET 2007 mikulas:

	Do not print links to stylesheet to the document

Fri Nov  2 19:52:22 MET 2007 mikulas:

	Slightly improve parsing of ftp --- when the line contains "<DIR>", we
	can assume that it is a directory

Tue Oct 30 21:22:27 cet 2007 mikulas:

	Previous release didn't compile on OS/2 due to missing SIGCONT
2008-01-15 22:43:26 +00:00
taca
a54f39ca19 Remove MacOS X derived files which start from "._".
Bump PKGREVISION reflecting PLIST change.
2008-01-15 14:38:08 +00:00
yyamano
671f99004c Make this build on Darwin. 2008-01-14 09:46:45 +00:00
adam
707dd64033 db4 update related revision bump 2008-01-12 11:36:28 +00:00
taca
1d8ea67392 Update squid package to 2.6.18 (2.6.STABLE18)
Changes to squid-2.6.STABLE18 (10 Jan 2008)

	- Fix 2 assertion failures related to the fix for SQUID-2007:2
	- GPL license cleanup to GPLv2 or later. One file in edir_digest_auth
	  was GPLv2 only, now replaced with a GPLv2 or later licensed vesion.
	- Minor cleanups to make certain 64-bit platforms happier
	- Several Digest authentication bugs fixed wich was causing random
	  authenitcation popups or failures.
	- --with-valgrind-debug updated for valgrind-3.3.0.
2008-01-12 06:20:45 +00:00
taca
6d9324864c Remove an unused commented out lint. 2008-01-11 15:41:02 +00:00
abs
326116e64f replace "empty (foo)" with "empty(foo)" 2008-01-11 14:52:42 +00:00
drochner
2af61cea29 update to 2.20.3
sorry, no changelog available
2008-01-11 13:45:46 +00:00
drochner
3b81ef8f13 update to 2.20.3
no entries in the changelog, presumably just a version bump
for the gnome-2.20.3 release
pkgsrc note: installation os developer docs was fixed
2008-01-11 13:42:56 +00:00
drochner
a36fc30222 update to 3.16.3
change: a minor bugfix
2008-01-11 12:49:13 +00:00
adrianp
7f82031693 Update to 5.6
This release fixes security vulnerabilities. Sites are urged to upgrade immediately. For more details, please see the security announcement:
SA-2008-005 - Drupal core - Cross site request forgery
SA-2008-006 - Drupal core - Cross site scripting (UTF8)
SA-2008-007 - Drupal core - Cross site scripting (register_globals)

In addition to this security vulnerability, the following bugs have been fixed since the 5.5 release:
173858 by Gábor Hojtsy: skip UTF-8 BOM when importing locale files
179164 by Heine: sort modules by name on the module admin page
199640 by webernet: (usability) add option to select no taxonomy term in multiselect forms, not to rely on browser trickery
199084 by chx: better conformance with ISO date formats in our xmlrpc code
173459 by Dave Cohen. Backport of #78487 by FredCK, forngren and bjaspan: document support in url() and l() and proper active class support for .
89218 by Gábor Hojtsy. Properly initialize a counter variable and fix poll editing.
64388 by Gábor Hojtsy. Add missing db_rewrite_sql(); not a security issue since it is a count() query.
200338 by m3avrck and quicksketch: fix transparent GIF resizing
194652 by Heine: specify explicit accept-charset for forms to avoid browser guessing
182410 by greggles: HTTP Basic authentication username and password was parsed in drupal_http_request() but then not used in the request
- Patch 201894 by David Rothstein: fixed typo in user output.
180126 by mmoreno, drewish and scor: add realpath() call to file_save_data(), so Windows will create temporary files properly
115689 by chx: new content types should not overwrite old ones. Backport by Pancho.
203727 by Arancaytar. More effectively use hook API.
204855 by webernet. Add missing * in documentation.
168315 by schuyler1d: previous active database name was not consistently returned in db_set_active()
- Patch 199955 by saxofaan: file_upload_max_size() returns results in bytes, not in mega bytes.
194579 patch by pwolanin: clear filter cache when allowed HTML tags configuration changes in an input format
#166433 by Ralf Stamm. Use correct menu item type for revsion confirm pages.
58806 by fwalch and wicksteedc. Do not override MENU_VISIBLE_IF_HAS_CHILDREN on editing.
Partial backport of 112715 to fix 124641.

Changes from 5.4 -> 5.5
Fixed missing missing brackets in a query in the user module.
Fixed taxonomy feed bug introduced by SA-2007-031
2008-01-11 12:37:11 +00:00
adrianp
f666c3d44e Major changes compared to Horde 3.1.5 are:
* Fixed privilege escalation in the Horde API.
* Improved XSS filtering.
* Fixed locked portal blocks.
* Further improved webroot detection.
* Updated Japanese translation.
2008-01-10 23:08:06 +00:00
taca
c1c653d93d Update plone3 package to 3.0.5.
o Changes from 3.0.4

    * Update translations.
    * If you are using the fullscreenmode.js script, you can now pass
      in a minimal=1 argument in the URL to make a page start out in
      the minimal mode.
    * Fix problems with non-savepoint capable connections (such as SQL
      connections) involved in folder_delete, folder_publish of
      folder_rename actions.
    * Hiding page history, page navigation, and busy icon (spinner) in
      print CSS. This relates to 7402 and 7433.
    * Fix persistant translation service creation code. This corrects
      broken translations on initial Zope start. This fixes 7470.
    * Visual editor improvements:
          o Style whitelist and class blacklist now work when there is
      	    only one entry in the list.
          o Span tags with no attributes after filtering are removed.
    * Make the content rule configuration page fully
      translatable. This fixes 6886.
    * Update the object-not-found error page to search for
      alternatives within the navigation root instead of the entire
      site.
    * Fix translation for default item in display content menu for
      situations. This fixes 7281.
    * Fix absolute_url() for content rules add views, content rules
      traversal adapters, portlet add views, portlet assignment
      mappings and portlet assignments.
    * Fix handling of RSS feeds which do not include an update
      timestamp for feed entries. This fixes 7515.
    * Change KSS saveField to not require value explicitply but take
      it from the request if not specifies. This makes it possible to
      use saveField-kssSubmitForm: currentForm(); which is needed for
      multi-valued form variables.
    * Fix handling of the portal type criteria for collections. This
      fixes 7467.
    * Update the delete-confirmation page for objects that are
      references elsewhere to order all referencing items in
      alphabetical order.
    * Fix handling of types where allow_discussion is set as a class
      attribute which could lead to an AttributeError when changing
      the discussion settings. This fixes 761.
    * Extend the Archetypes widget API to inform widgets when
      processing the form in the validation phase. This fixes 760.
    * Correct zope.i18n.translate calls in Archetypes: should use the
      request, not the instance itself as the context. This fixes
      translation problems seen in Plone 3.0.4.
    * Do not create an empty <ul> in the personal actions bar if there
      are no items in it. This fixes an XHTML syntax error.
    * Fix the languages method of the language selector to include the
      native language name.
    * Fix invalid context argument passed into the translation
      machinery in the workflow state vocabulary. This fixes 7492.
    * Fix potential acquisition problem in five.localsitemanager when
      assigning values to the utilities registry of the component
      registry.
    * Raise a ValueError when the Zope3 translation utilities get
      passed in an invalid context argument. Translations in Zope3
      work against the request alone and while the keyword is called
      context it was too easily confused with a contentish context.

o Updated packages

    * Archetypes 1.5.5
    * ATContentTypes 1.2.4
    * CMFPlone 3.0.5
    * GenericSetup 1.3.3
    * kupu 1.4.7
    * PlacelessTranslationService 1.4.8
    * PloneTranslations 3.0.10
    * archetypes.kss 1.2.5
    * plone.app.contentmenu 1.0.5
    * plone.app.contentrules 1.0.5
    * plone.app.i18n 1.0.1
    * plone.app.kss 1.2.5
    * plone.app.linkintegrity 1.0.4
    * plone.app.portlets 1.0.5
    * plone.app.redirector 1.0.5
    * plone.app.vocabulary 1.0.2
    * plone.app.layout 1.0.5
    * plone.contentrules 1.0.5
    * five.localsitemanager 0.3
2008-01-09 22:13:12 +00:00
taca
96f1c7678b Make PLONE3_VERSION to 3.0.5. 2008-01-09 22:12:23 +00:00
taca
f6e1a655e1 Exclude install files whose name begin from "._". 2008-01-09 22:10:50 +00:00
smb
aef471b12e Change #define of _XOPEN_SOURCE to make strptime() happy 2008-01-09 21:09:26 +00:00
smb
89ef082df4 Get the patch right this time... 2008-01-09 20:35:28 +00:00
smb
b58d777007 Replace calls to gmtime() with calls to gmtime_r() in a threaded routine. 2008-01-09 20:12:19 +00:00
ghen
4936f67d29 Update to nginx-0.5.35.
*) Change: now the ngx_http_userid_module adds start time microseconds
       to the cookie field contains a pid value.

    *) Change: now the uname(2) is used on Linux instead of procfs.
       Thanks to Ilya Novikov.

    *) Feature: the "If-Range" request header line support.
       Thanks to Alexander V. Inyukhin.

    *) Bugfix: in HTTPS mode requests might fail with the "bad write retry"
       error; bug appeared in 0.5.13.

    *) Bugfix: the STARTTLS in SMTP mode did not work.
       Thanks to Oleg Motienko.

    *) Bugfix: large_client_header_buffers did not freed before going to
       keep-alive state.
       Thanks to Olexander Shtepa.

    *) Bugfix: the "limit_rate" directive did not allow to use full
       throughput, even if limit value was very high.

    *) Bugfix: the $status variable was equal to 0 if a proxied server
       returned response in HTTP/0.9 version.

    *) Bugfix: if the "?" character was in a "error_page" directive, then
       it was escaped in a proxied request; bug appeared in 0.5.32.
2008-01-09 14:42:54 +00:00
bjs
83602a1987 Update to current 0.11 branch as of 2008/01/09. Too many changes/fixes
to list here; one may check the log at <http://repo.or.cz/w/elinks.git>
(see the elinks-0.11 branch).  There should be a 0.11.4 release out
fairly soon.

While here, add two patches (from debian maintainer): one to ensure that
its gettext doesn't look for files in ../po/, and the other to disable
transparency by default.

Bump revision.
2008-01-09 03:48:07 +00:00
heinz
5a59ae67cd No compiler necessary. 2008-01-09 00:58:24 +00:00
heinz
4c98f1202e The package needs a C compiler. 2008-01-08 20:58:30 +00:00
smb
2e4ede884a Add options to liferea to permit selection of different rendering engines 2008-01-08 15:14:25 +00:00
ghen
134615ac8e Update to nginx 0.5.34
*) Change: now the full request line instead of URI only is written to
       error_log.

    *) Feature: Cygwin compatibility.
       Thanks to Vladimir Kutakov.

    *) Feature: the "merge_slashes" directive.

    *) Feature: the "gzip_vary" directive.

    *) Feature: the "server_tokens" directive.

    *) Feature: the "access_log" directive may be used inside the
       "limit_except" block.

    *) Bugfix: if the $server_protocol was used in FastCGI parameters and a
       request line length was near to the "client_header_buffer_size"
       directive value, then nginx issued an alert "fastcgi: the request
       record is too big".

    *) Bugfix: if a plain text HTTP/0.9 version request was made to HTTPS
       server, then nginx returned usual response.

    *) Bugfix: URL double escaping in a redirect of the "msie_refresh"
       directive; bug appeared in 0.5.28.

    *) Bugfix: a segmentation fault might occur in worker process if
       subrequests were used.

    *) Bugfix: the big responses may be transferred truncated if SSL and
       gzip were used.

    *) Bugfix: compatibility with mget.

    *) Bugfix: nginx did not unescape URI in the "include" SSI command.

    *) Bugfix: the segmentation fault was occurred on start or while
       reconfiguration if variable was used in the "charset" or
       "source_charset" directives.

    *) Bugfix: nginx returned the 400 response on requests like
       "GET http://www.domain.com HTTP/1.0".
       Thanks to James Oakley.

    *) Bugfix: a segmentation fault occurred in worker process if
       $date_local and $date_gmt were used outside the
       ngx_http_ssi_filter_module.

    *) Bugfix: a segmentation fault might occur in worker process if debug
       log was enabled.
       Thanks to Andrei Nigmatulin.

    *) Bugfix: ngx_http_memcached_module did not set
       $upstream_response_time.
       Thanks to Maxim Dounin.

    *) Bugfix: a worker process may got caught in an endless loop, if the
       memcached was used.
2008-01-07 10:42:01 +00:00
heinz
a1068bc1e8 The package supports installation to DESTDIR. 2008-01-06 17:41:31 +00:00
taca
ca996dce91 - Add version number to COMMENT.
- Remove -quiet option from CONFIGURE_ARGS.  This cause verbose output
  but it prevent detect errors.
- use INSTALLATION_DIRS.
- Use ../zope/Makefile.common. and common files from ../zope/files.
- Don't install unused runzope.bat.in template file.
- take maintainership.
- Add missing sitecustomize.py{,c} in PLIST.

Bump PKGREVISION.
2008-01-06 15:59:26 +00:00
taca
19ba0775ed - Add version number to COMMENT.
- Remove -quiet option from CONFIGURE_ARGS.  This cause verbose output
  but it prevent detect errors.
- use INSTALLATION_DIRS.
- Use ../zope/Makefile.common. and common files from ../zope/files.
- Don't install unused runzope.bat.in template file.
- take maintainership.

Bump PKGREVISION.
2008-01-06 15:57:45 +00:00
drochner
0a8d6d43d3 update to 1.4.10
This is a bugfix release that tries to fix three issues:
- The reappearing of already downloaded items
  (caused by an incorrect cache handling)
- The continuous growth of the sqlite DB file
  (caused by comments not being removed along with their parent items).
- The general performance problem with search folders.
2008-01-06 15:53:43 +00:00
taca
9242153fe0 Add common Makefile part for zope29, zope210 and possibly zope211 in feature. 2008-01-06 15:52:29 +00:00
taca
df8393ac24 Add common files for zope29, zope210 and possibly zope211 in feature. 2008-01-06 15:51:39 +00:00
taca
aba67881d5 - Add definition for zope-211.
- Complete zope33 (Zope 3.3.x) related names.
2008-01-06 15:49:42 +00:00
heinz
650294610d The package supports installation to DESTDIR.
No compiler necessary.
2008-01-05 22:41:27 +00:00
heinz
162bc27b93 The package supports installation to DESTDIR 2008-01-05 22:38:08 +00:00
ghen
d8def81b0e Full DESTDIR support. 2008-01-04 15:42:34 +00:00
ghen
f95a36d0df Full DESTDIR support. 2008-01-04 11:48:12 +00:00
adrianp
b707a6d3d8 Update to 4.4.8
Improved fix for MOPB-02-2007.
Fixed an integer overflow inside chunk_split(). Identified by Gerhard Wagner.
Fixed integer overlow in str[c]spn().
Fixed regression in glob when open_basedir is on introduced by 41655 fix.
Fixed money_format() not to accept multiple %i or %n tokens.
Addded "max_input_nesting_level" php.ini option to limit nesting level of input variables. Fix for MOPB-03-2007.
Fixed INFILE LOCAL option handling with MySQL - now not allowed when open_basedir or safe_mode is active.
Fixed session.save_path and error_log values to be checked against open_basedir and safe_mode (CVE-2007-3378).
Fixed bug 43010 (Fixed regression in imagearc with two equivelent angles).
Fixed bug 41765 (Recode crashes/does not work on amd64).
Fixed bug 41630 (segfault when an invalid color index is present in the image data).
Fixed bug 41628 (PHP settings leak between Virtual Hosts in Apache 1.3).
Fixed bug 38798 (OpenSSL init corrected in php5 but not in php4).
2008-01-04 10:07:52 +00:00
adrianp
e34d778df6 Add in an options.mk for Geo IP Free 2008-01-03 12:37:06 +00:00
taca
cfca13ebb5 Zope 3.x dose not migrate to the new frame work yet. 2008-01-03 12:31:13 +00:00
reed
a3fea0a824 Add another REPLACE_PERL for a perl script to replace interpreter.
Skip an interpreter check for a python script (as the
REPLACE_PERL is ignored because no python dependency yet).
(Add a TODO for later: add an option for reStructuredText
support to depend on python-docutils.)

Bump PKGREVISION.

Noticed in bulk builds. Fixed this during freeze so it will be
built by some bulk builders and available with the upcoming quarterly
branch packages. This is a leaf package.
2008-01-02 15:39:57 +00:00
abs
0317e1d6ea Update ns-remote to 1.11nb4 - from PR/37624 by Eric Schnoebelen:
- Include seamonkey as a valid option in NETSCAPE_PREFERRED
2008-01-01 16:45:35 +00:00
obache
2ea98af72b * Fixed EGDIR, installation of sample config files works again.
* Using VARBASE.
* This package does not have share/doc/screws/examples.

Bump PKGREVISION.
2007-12-31 07:05:00 +00:00
obache
1cfaf4f375 Fixed typo of config filename (Russian_UTF8 => Russian_UTF-8).
Bump PKGREVISION.
2007-12-31 06:53:17 +00:00
joerg
289a846b7a Drop a stupid sed from configure that breaks the itlocaledir patching. 2007-12-30 17:55:11 +00:00
xtraeme
7ff06143b7 Provide correct checksums for all supported platforms, like I said
"emul-fetch and emul-distinfo" is needed.
2007-12-26 21:44:49 +00:00
jdolecek
db2b18789b remove opera-distinfo - it's superseded by generic emul-distinfo 2007-12-26 20:32:59 +00:00
jdolecek
419a394dc5 Update opera to 9.25.
Changes in v9.25:

Security
* Fixed an issue where plug-ins could be used to allow cross domain
  scripting, as reported by David Bloom. Details will be disclosed
  at a later date.
* Fixed an issue with TLS certificates that could be used to execute
  arbitrary code, as reported by Alexander Klink (Cynops GmbH).
  Details will be disclosed at a later date.
* Rich text editing can no longer be used to allow cross domain
  scripting, as reported by David Bloom. See our advisory.
* Prevented bitmaps from revealing random data from memory, as
  reported by Gynvael Coldwind. Details will be disclosed at a
  later date.

Miscellaneous
* Fixed a problem where malformed BMP files could cause Opera to
  temporarily freeze.

For pkgsrc use, put back opera-distinfo target (to easily re-generate
checksums for supported platforms)
2007-12-26 19:39:41 +00:00
taca
13b316de88 zope 2.10.x depends on py-expat package. 2007-12-25 06:03:54 +00:00
taca
1b5c6554d0 zope 2.9.x depends on py-expat package. 2007-12-25 06:02:54 +00:00
tnn
4afc82bd8b Update flash player packages to the latest version (9.0.115).
Done during 2007Q4 freeze because the old distfile is no longer available.

New audio/video options
    * H.264/HE-AAC codec support
Improved Performance
    * Multi-core support
    * Multi-threaded video decoding
    * Image scaling
    * Flash Player cache
    * Flash Media Server buffering
Universal Reach
    * Full screen mode for Linux
    * Accessibility support for the plugin
    * Mac Os X Leopard support

Fixed in this version:

    * On Linux, modal dialogs displayed by Flash Player stay in front of browser windows but do not prevent interaction with the browser as they should. (191331)
    * On certain SUSE 9.2 installations using the standalone player only, trying to Open a browser from the standalone player with SeaMonkey open will cause the player to hang. (193383)
    * On Linux, networking operations in the standalone player are currently slow. (193158)
    * On Linux, when the mouse is hovering over Flash content, keyboard input is not sent to the browser. (194265)
    * Full-screen mode is not supported in the Opera Browser on Macintosh systems. (189140)
    * Full-screen mode is now supported on Linux.
    * The plugin version of Flash Player does not fire flash.events.Event.RENDER when wmode is set as transparent. (198515)
    * Full-screen can be used when wmode is set (202290)
    * Passing large amounts of XML through External Interface is significantly faster (206828)
    * ExternalInterface now works with HTML objects that contain dots within the object name (199614)
2007-12-23 22:27:15 +00:00
obache
6456ebb5c8 Change MOZILLA master sites difinitions, related to PR 37379.
There are three types Mozilla mirrors.
(http://www.mozilla.org/mirroring.html)
 * mozilla-current
        contains only the current version of Firefox and Thunderbird
 * mozilla-release
        contains Firefox, Thunderbird, and Sunbird releases
 * mozilla-all
        complete archive

Define following variables for mozilla master sites:
        MASTER_SITE_MOZILLA_ALL = mozilla-all
        MASTER_SITE_MOZILLA     = mozilla-release
and change some packages to use appropriate variable.

Update contents of MASTER_SITE_MOZILLA with master and primary mirrors
taken from http://www.mozilla.org/mirrors.html and add some sample definitions.
2007-12-22 07:22:04 +00:00
taca
0e628135ea Correct HOMEPAGE. 2007-12-22 03:04:44 +00:00
joerg
2fc344764c Depend on yacc, lex and flex as needed. Fixes PR 37586. 2007-12-21 22:54:56 +00:00
taca
d02856e6d5 - More proper fix to previous change; correct real python scripts' path.
- Change the order of including files in Makefile to use REPLACE_PYTHON
  properly.
- Remove shebang line from a library file which would never be executed
  directly.
2007-12-21 16:18:35 +00:00
taca
f5acc4fcaa Fix typo which cause PKG_OPTIONS ignorance. 2007-12-21 03:38:06 +00:00
taca
fbad1a172e Avoid CHECK_INTERPRETER and CHECK_PERMS for some files.
Fix build problem with these checks.
2007-12-21 03:09:25 +00:00
sborrill
ca65197cab Split ap-auth-external into Apache 1.x and 2.x versions 2007-12-20 15:04:26 +00:00
sborrill
3dbdd0370d Import apache 2.x portion after splitting ap-auth-external into 1.x and 2.x.
mod_auth_external allows you to use an external script for Apache authentication.
2007-12-20 14:59:14 +00:00
sborrill
19c0589c82 Split out Apache 2.x code into ap2-auth-external. Fixes pkg/37362 2007-12-20 14:31:52 +00:00
taca
24cff6fb54 Update squidGuard to 1.3 with patch-20071117.
pkgsrc changes:

- Honor squidGuard's name.
- Use PKGINSTALL frame work.
- More integration to squid; common configuration and logging directories.
  Now depends on squid package.
- Switch to use db4; it might be selectable by option.
- Install some examples of configuration.

Todo:
- LDAP support option.
- Installing documents.
- DESTDIR support.


Release 1.3
2007-09-19	Included configurable logging. New configure option --nolog
		suppress all runtime logmessages. Start and stop is still logged.
		Default behaviour is now to log the non debug messages except
		when the runtime option -d is supplied to squidGuard. May need
		some more finetuning in later versions. (bug 11)
		Made some slight changes to the outdated FAQ file.
2007-09-13	Modified auth code to work with and without ldap (choosing
		subroutine rfc1738_unescape or sgFindUser in sg.y.in)
2007-08-20	Corrected include statement in sg.h.in.
2007-07-16	Added patch by Marc Clayton to include a progressbar to the
	 	build of the database files (bug 6).
2007-07-01	Added patch by Eric Harrison to enable full sed compliance
		to rewrite statements (bug 7).
2007-06-02	Corrected missing evaluation of configure parameters for
		logdir, dbhome and config file (bug 11).
2007-05-25	Added patch from satish to block urls entries that include
		hostnames (bug 4).
2007-05-20	Fixed broken regex evaluation (bug 12)
		Fixed a compile problem on some systems (bug 10).
2007-05-10	Corrected an issue with the fix for the double
		slash vulnerability (incorrectly found double
		slashes) (bug 1).


Release 1.2.1
2007-04-10      Fixed multiple slash bypass vulnerabilty.
2007-03-17	Fixed some bugs in squidGuard-simple.cgi and added a
		German version of it.
2007-03-16	Fixed encoding bypass vulnerabilty.
2007-03-16	Updated y.tab.c.bison and y.tab.h.bison to the recent
		version.
2007-02-02	Fixed bug in user authentication.
2007-01-20	Fixed some typos which broke compilation on Sun Solaris
		when using the Sun CC compiler.
2007-01-12	Corrected unproper evaluated if-clause, which broke the
		BerkeleyDB 2 compatibility.
		Fixed minor typo in samples/Makefile.in.
2006-12-29	Replaced the sleepycat links from the configure program with
		the oracle links.
		Corrected typo in Makefile.in.
2006-12-16	Removed a stupid bug from the Makefile in the docs directory.
2006-12-10	Removed references to squidguard.org in Makefile.in in the
		Doc directory (squidguard.org is down).
		Added ISSUES.txt file about known problem with the current
		code (any information that is missing and should go in there
		is gladly welcomed).
2006-06-17	Release now supports LDAP queries for authentication:
		Added Chris Frey's ldap patches and fixes (03, 05, 06,
		07 and 10; Patches from:
		http://www.netdirect.ca/software/category.php?cat=SquidGuard).
		The LDAP feature can be included during the configure run
		by setting --with-ldap. Per default ldap support will not
		be compiled in.
		Added a fix provided by Francesco Ranieri to solve an issue
		with the (un)escaping of the authentication "domain%5cusername".

Patch Release 1.2.0p3

2005-12-09	Modfied configure Skript to allow to specify the name of
		the useraccount the squid cache is using.
		Modified Makefile.in that during the installation the
		necessary squidGuard directories are created if they are
		not existing. Additionally a default configuration file
		will be copied to the default location for squidGuard unless
		an old one is found there.

Patch Release 1.2.0p2

2005-10-13	Added Adam Gorski's bugfix to correct a a null pointer access
	 	bug in logging.
		Added Chris Freys bugfix a bug where it won't search the url
		db if the domain db is empty.
		Added Chris Frey's buffer overflow checks (except for commenting
		out the part from line 446 to 470 in sgDb.c).
		(Patches from:
		http://www.netdirect.ca/software/category.php?cat=SquidGuard)

Patch Release 1.2.0p1

2005-10-11      Added support for Berkeley DB 4.x
2007-12-20 03:36:59 +00:00
taca
c8b700c662 - Rename DATADIR to SQUID_DATADIR.
- Move some common parameter to Makefile.common; squid's user, group and
  data directory.
- Add LOGDIR to Makefile.common.

These changes have no functional change but make it possible for
squidGuard package to share parameters.
2007-12-20 03:17:14 +00:00
taca
253a039671 Add and enable zope-ejsplitter and zope-jamailhost. 2007-12-18 16:05:43 +00:00
taca
6d6c8b7b0c Importing zope-jaMailHost 0.4.4.
MailHost is Zope-integrated feature to send mail from Web applications,
but can not send Japanese mail correctly.
This "jaMailHost" product will solve this problem.
2007-12-18 16:03:48 +00:00
taca
bd688fa234 Importing zope-ejSplitter 0.5.1.
Zope needs a word splitter to search in text with ZCTextIndex.
This ejSplitter is one of Japanese splitters and can be used with
other Zope products.
2007-12-18 16:02:18 +00:00
taca
41c1475ec1 - Add plone and zope with commented out.
- Add plone25, plone3 and zope210.
2007-12-18 15:51:13 +00:00
taca
68c6d1318f Importing Plone 3.0.4 as plone3.
This package is based on new zope's framework.

Plone is a ready-to-run content management system that is built on the
powerful and free Zope application server. Plone is easy to set up,
extremely flexible, and provides you with a system for managing web
content that is ideal for project groups, communities, web sites,
extranets and intranets.

Plone 3 runs on Zope 2.10.x and has many improved features from Plone 2.5.

   1. Inline editing
   2. Working Copy support
   3. Link and reference integrity checking
   4. Automatic locking and unlocking
   5. Easy collaboration and sharing
   6. Versioning, history and reverting content
   7. Upgraded visual HTML editor
   8. Powerful workflow capabilities
   9. Flexible authentication back-end
  10. Full-text indexing of Word and PDF documents
  11. Collections
  12. Presentation mode for content
  13. Support for the search engine Sitemap protocol
  14. Support for multiple mark-up formats
  15. Wiki support
  16. Automatic previous/next navigation
  17. Rules engine for content
  18. Auto-generated tables of contents
  19. Portlets engine
  20. Professional support, development, hosting & training
2007-12-18 15:46:59 +00:00
taca
9048f495cb Importing Plone 2.5.5 as plone25.
This package based on new zope's framework and finally replace
zope25-CMFPlone pacakge.

Plone is a ready-to-run content management system that is built on the
powerful and free Zope application server. Plone is easy to set up,
extremely flexible, and provides you with a system for managing web
content that is ideal for project groups, communities, web sites,
extranets and intranets.

Plone 2.5.5 runs on Zope 2.9.x.
2007-12-18 15:42:32 +00:00
taca
33e9adab05 Importing makefile fragments for Plone packages. 2007-12-18 15:37:49 +00:00
taca
507f458370 Importing Zope 2.10.5 as zope210 with new framework.
Zope is an exciting new object-based, open source web application
platform. It allows you to build powerful and dynamic web applications
easily. Zope comes with source code and is friendly to developers as
well as users.

Zope 2.10.x is needed to run Plone 3.
2007-12-18 15:35:22 +00:00
taca
abdfd3de88 Update zope29 to 2.9.8 (Zope 2.9.8) with new framework.
Zope 2.9.8 (2007/07/05)

   Bugs fixed

      - updated to ZODB 3.6.3

      - updated to Zope 3.2.3 codebase

      - Collector #1306: Missing acquisition context on local roles screen.

      - The REQUEST no longer accepts holds after it has been closed.

      - Collector #2153: Supporting unquoted cookies with spaces.

      - Collector #2295: Comments in PythonScripts could lead to syntax
        errors

      - Collector #2307: ObjectCopiedEvent not dispatched to sublocations.

      - Fixed ZClass test breakage due to non-pickleability of
        'zope.interface.Implements'

        N.B.: updated 'zope.interface' package to Zope 3.2 branch;
              should be pinned to a tag or a release before releasing
              2.9.8).

      - Collector #2260: fixed a bug in Examples.zexp

      - Collector #2321: Skip trusted proxies when extracting the client IP
        address from the request.

      - Collector #2318: Allow override of zopectl's control socket in
        zope.conf

      - Collector #2316: correctly unpack DateTimeIndex dates when browsing the
        index.

      - Collector #1866: a 304 HTTP status should not have a content length.

      - Collector #2300: delimit *all* HTTP Response headers with CRLF.

  Zope 2.9.7 (2007/03/25)

   Bugs fixed

      - Protected various security mutators with a new postonly decorator.
        The decorator limits method publishing to POST requests only, and
        is a backport from Zope 2.11's requestmethod decorator factory.

      - Collector #2298: webdav.Resource.COPY and webdav.Resource.MOVE did
        not send the expected copy/move events.

      - Collector #2296: Fixed import of ZClass products, broken by removal
        of BBB support for pasting objects whose meta_type info was
        permission-free.

      - Collector #2294: Protected DOS-able ControlPanel methods with the
        same 'requestmethod' wrapper.

      - Collector #2294: Protected various security mutators with a new
        'postonly' decorator.  The decorator limits method publishing to
        POST requests only, and is a backport from Zope 2.11's requestmethod
        decorator factory.

      - Collector #2288: @ and + should not be quoted when forming
        request URLs in BaseRequest and HTTPRequest

      - Undeprectated 'zLOG' package, which is going to remain a
        backward-compatibility shim for the Python logger.

      - Collector #2263: 'field2ulines' did not convert empty string
        correctly.

      - Reverted backward-incompatible fix for Collector #2191.

      - added Python 2.4.4 as optimal Python version to 'configure'


  Zope 2.9.6 (2006-11-22)

   Bugs fixed

      - Collector #2191: extended DateTime parser for better support
        to the ISO8601 specification.

      - Reworking of _cached_result in Shared.DC.ZRDB.DA.DA:

        - fixed KeyError reported in Collector #2212

        - fixed two memory leaks that occurred under high load

        - fixed broken cache keys for people using the obscure
          Shared.DC.ZRDB.DA.DA.connection_hook

        - fixed incorrect cache ordering resulting in newer results
          being dumped when the cache became too large.

      - Collector #2237: 'make' doesn't tell you to run 'make inplace'
        before running 'make instance'.

      - Collector #2235: A number of ZCatalog methods were doing boolean
        evaluation of objects that implemented __len__ instead of checking
        them against None. Replaced a number of "if not obj" with
        "if obj is None".

      - Collector #2218: fixed wrong logger argument in OFS/Cache.py

      - Collector #2205: fixed wrong logger argument in ZRDB/Connection.py

      - Collector #2208: rewriting/setting the 'charset' part of the
        content-type HTTP header will be done only for 'text/*'

      - Collector #2206: Set PYTHONPATH to include existing PYTHONPATH
        in skel/bin/zopectl.in and skel/bin/runzope.in

  Zope 2.9.5 (2006/10/03)

   Bugs fixed

      - Call setDefaultSkin on new requests created as the result of
        ConflictError retries.

      - Collector #2189: Fix logging of errors during product refresh.

      - Collector #2185: Log username for FCGI requests.

      - Collector #2152: Fixed MailHost documentation; simple_send does not
        process or validate its arguments in any way.

      - Collector #2175: ZTUtils.make_hidden_input did not escape double-quotes.

      - Collector #1907: Moved 'alt' property from File to Image.

      - Collector #1983: Specifying session-resolution-seconds >= 1200 caused
        Zope startup to fail.

      - Collector #2169: webdav.Resource.COPY did not send ObjectClonedEvent.

      - Updated Five to bugfix release 1.3.7.

      - Collector #2157: Expose name of broken class in SystemError raised
        from '__getstate__' of a broken instance.

      - Usage of 'urljoin' in 'webdav.davcmds' could lead to wrongly
        constructed urls.

      - Collector #2155: Fix wrong parameter being passed to
        logger's error() method, with tests.

      - Collector #2178: Fix ZopeTestCase doctest support for layers

      - included Zope 3.2.2
2007-12-18 15:31:11 +00:00
taca
3097e76566 Importing makefile's fragments of new framework for Zope packages. 2007-12-18 15:27:23 +00:00
gdt
1aac2e9591 Update to 1.3 (from Jan Danielsson).
Fix bug whereby mod_wsgi daemon process could hang when a request with
content greater than UNIX socket buffer size, was directed at a WSGI
application resource handler which in turn returned a response, greater
than UNIX socket buffer size, without first consuming the request content.
2007-12-18 01:00:13 +00:00
drochner
9ddd0e6622 update to 2.0.4
changes: "Some useful bug fixes."
2007-12-17 19:14:25 +00:00
drochner
167fb031d3 update to 1.4.9
changs:
-fixes a security issue with the LD_LIBRARY_PATH handling in the
 starter script (CVE-2005-4791)
-translation updates
-minor bugfixes
2007-12-17 19:10:02 +00:00
obache
d4f24af293 Add DESTDIR support. 2007-12-17 10:33:56 +00:00
uebayasi
fd40d08dfe Add missing w3/buildlink3.mk which is conditionally included by devel/semi.
Pointed out by wiz.
2007-12-16 13:45:59 +00:00
rhaen
b427665a35 Fixing error reported by babylon5.NetBSD.org weekly pkgsrc output (Missing newline) 2007-12-16 07:12:33 +00:00
rhaen
9771199d69 Fixing error reported by babylon5.NetBSD.org weekly pkgsrc output 2007-12-16 07:11:51 +00:00
epg
841326effe - Document what what we're doing with LimitExcept.
- Drop POST from the allowed list; this mistake has been here since 2003,
  but it doesn't really matter as POST on a Subversion repository is an
  invalid operation anyway.
2007-12-13 20:03:36 +00:00
taca
0bf5fc0006 Use more Ruby specific name: s/REPLACE_FILE_PAT/REPLACE_RUBY_PAT/.
In this case, simply remove REPLACE_RUBY_PAT because file under
${WRKSRC}/examples should be replaced.
2007-12-13 14:48:09 +00:00
taca
9a5ce3acf4 Use more Ruby specific name: s/REPLACE_FILE_PAT/REPLACE_RUBY_PAT/. 2007-12-13 14:46:58 +00:00
wiz
b524dc18ff Reset maintainer on his request. 2007-12-12 20:42:28 +00:00
ghen
ffffdadfde + nginx. 2007-12-11 09:13:18 +00:00
ghen
948dda2d46 Import nginx (pronounced "engine X") from pkgsrc-wip, a lightweight web (HTTP)
server/reverse proxy and mail (IMAP/POP3) proxy.
2007-12-11 09:12:26 +00:00
minskim
0a20710c88 Update ruby-actionpack to 1.13.6.
Changes:
* Correct Broken Fix for session_fixation attacks
* Ensure that cookies handle array values correctly.  Closes #9937 [queso]
2007-12-10 05:47:02 +00:00
minskim
addec114c0 Update rails to 1.2.6. Based on the patch provided by Geert Hendrickx.
Changes:
* Fix :cookie_only to correctly avoid session fixation attacks (CVE-2007-6077)
* Fix regression where the association would not construct new finder
  SQL on sav e causing bogus queries for "WHERE owner_id = NULL" even
  after owner was saved.
2007-12-10 05:24:01 +00:00
rhaen
913cb50911 - updated to 1.29
- new maintainer
- PKG_DESTDIR_SUPPORT
- ok by joerg
Changelog:
1.29 21 Aug 2007 - Documentation fix to performance hints section.
                   No functional changes.

1.28 18 Aug 2007 - Improved mod_perl2 handling (patch courtesy of Jeremy Nixon).
                    Added a ':no_subprocess_env' flag to suppress populating
                    the %ENV environment hash. Added a 'subprocess_env'
                    static class method to allow smooth co-existance of
                    ModPerl2 scripts that use ':no_subprocess_env' with ModPerl2
                    scripts that do not on the same server.

1.27 25 May 2007 - Added example of a command line 'wrapper' script and
                    of using environment variables as an alternate way
                    to test scripts via the command line. Added example
                    for use with FastCGI. Changed behavior for unsupported
                    HTTP methods. The module used to 'croak' for unsupported
                    methods, it now 'carp's instead and treats as a 'GET'
                    (behavior change at suggestion of Roman Mashirov to support
                    FastCGI better).

 1.26 06 Apr 2007 - Added decoding of Javascript/EMCAScript style unicode
                    escaped (%uxxxx form) parameter data (both to the main
                    'param' method and to the 'url_decode'/'url_encode' methods)
                    at the suggestion of Michael Kröll (the core code for
                    this additional functionality is derived from CGI.pm).

                    Fixed META.yml problems introduced with 1.25.

                    Changed POD/POD Coverage tests to only execute if specifically requested

                    Added examples directory and scripts

 1.25 20 Apr 2006 - Added 'allow_hybrid_post_get' class method. Tweaked file permissions.
                    Added regression tests for hybrid forms.

 1.24 23 Sep 2005 - Added 'Carp' to install requirements. Extended build tests.
                    Fixed multi-part form decoding bug in handling of degenerate MIME
                    boundaries. Added fatal errors for mis-calling of param_mime
                    and param_filename methods.

 1.23 18.Sep 2005 - Made Test::More optional in build tests. No functional changes.

 1.22 13.Sep 2005 - Changed POD tests to be more friendly to CPANTS.

 1.21 11.Sep 2005 - Fixed pod coverage test for compatibility with Perl 5.005.

 1.20 11.Sep 2005 - Fixed issue causing mod_perl to issue
                    'Use of uninitialized value.' warnings.
                    Extended build tests.

 1.19 10.Sep 2005 - Fixed POD Coverage test error.

 1.18 08.Sep 2005 - Adjusted prerequiste modules lists. Tweaked code for 'strict'.
                    Extended regression tests to cover more of the code.

 1.17 04 Sep 2005 - More tweaks to regression tests to work around MS-Windows
                    problems with binary file handles under Perl 5.6.1.
                    Added 'Build.PL' support back in. Added POD tests.
                    Minor documentation tweaks.
2007-12-09 22:23:42 +00:00
rhaen
2191a3719c - updated to 4.06
- new maintainer
- PKG_DESTDIR_SUPPORT
- ok by joerg
Changelog:
4.06 Wed Apr 12, 2006
    (No code changes)
    - Updated tests to work with status codes emitted before and after CGI.pm 3.16.
      The requirement for CGI.pm 3.16 or newer has been relaxed, so any version
      of CGI.pm will do. (Rhesa)

4.05 Wed Mar  1, 2006
    (No code changes)

    -  Updated tests for redirects to check for 'Found', not 'Moved'.
       This correctly matches the standard, and was changed in CGI.pm 3.16.
       As a result, we now require CGI.pm 3.16 for consistent results.
2007-12-09 22:21:59 +00:00
jdolecek
70612a3687 add USE_LANGUAGES c++, so that some extensions using C++ build properly
fixes problem reported by reinhold ropper for php-gd
2007-12-09 14:40:08 +00:00
jdolecek
c898f4d0da Update to 0.9.5.2.
Changes since 0.9.5:
* Fix bug that causes problems with protected attributes and php 5.2
* Fix ttl bug in list_keys
2007-12-09 13:59:38 +00:00
adrianp
10644dafd0 This release fixes a security vulnerability. Sites are urged to upgrade immediately. For more details, please see the security announcement:
* SA-2007-031 - Drupal core - SQL Injection possible when certain contributed modules are enabled

In addition to this security vulnerability, the following bugs have been fixed since the 5.2 release:

* 178478 by scor: typo in text displyed when the DB is installed but not accessible
* Patch 122759 by Robrecht: fixed broken query in upgrade path.
* 55277 by catch and JirkaRybka: when flat comment view is used, order comments by cid (ie. original submission order) instead of timestamp (ie. last editing time order) to avoid comments jumping around when being edited
* Patch 181063 by chx and bjaspan: fixed problem with drupal_bootstrap() not booting to the proper level.
* 184668 by hazexp, Remove unnecessary ';'
* Patch 182728 by Darren Oh: improved PHPdoc of db_rewrite_sql().
* 93425 by bjaspan: remove pre-Drupal 4.6 era destination handling cruft carried over in comment module
* 154388 (backport of 172262) by JirkaRybka. Better globals handling in install system, so the choosen profile and language are remembered.
* 171117 by JirkaRybka: set access time for admin created or edited accounts so they are exempt from the spam protection we have for accounts never logged in
* Patch 168829 by Neil Drumm: fixed link in documentation.
* 165924 by odious. Use accurate count query for user list.
* 187601 by Bart Jansens. Use correct HTTP status codes for redirects.
* 180109 by JirkaRybka: overcome browser quirk to detect when no taxonomy term was selected
* 134984 by mikesmullin. Fix x2 coordinate for rendering gradients.
2007-12-05 23:16:19 +00:00
ghen
b5a2c7dcba APACHE_MANUAL is different in Apache 2.x and 1.3.x. Substitute in shared
MESSAGE accordingly and bump PKGREVISION for ap2-fastcgi only.
2007-12-05 17:42:49 +00:00
reed
6d161d3708 Update ikiwiki to 2.15. This includes latest security fix.
Remove patch -- make changes using SUBST_SED framework.

Add imagemagick as an option (not on by default).

Add perl:run for USE_TOOLS.

Add another script to REPLACE_PERL.

Get rid of most of post-install target and let the ikiwiki Makefile
do the installation.

Too many changes from CHANGELOG to list. Here are the most recent:

ikiwiki (2.15) unstable; urgency=low

  * Add a new ikiwiki-makerepo program, that automates setting up a repo
    and importing existing content for svn, git, and mercurial. This makes
    the setup process much simpler.
  * Reorganised git documentation.
  * Actually install the ikiwiki-update-wikilist program.
  * Improve workaround for perl bug #376329. Rather than double-encoding,
    which has been reported to cause encoding problems (though I haven't
    reproduced them), just catch a failure of markdown, and retry.
    (The crazy perl bug magically disappears on the retry.)
    Closes: #449379
  * Add umask configuration option. Closes: #443329

 -- Joey Hess <joeyh@debian.org>  Sat, 01 Dec 2007 11:44:01 -0500

ikiwiki (2.14) unstable; urgency=high

  * Let CC be used to control what compiler is used to build wrappers.
  * Use 'cc' instead of gcc as the default compiler.
  * Security fix: Ensure that there are no symlinks anywhere in the path
    to the top of the srcdir. In certian unusual configurations, an attacker
    who could commit to one of the parent directories of the srcdir could
    use a symlink attack to cause ikiwiki to publish files elsewhere in the
    filesystem. More details at <http://ikiwiki.info/security/#index29h2>

 -- Joey Hess <joeyh@debian.org>  Mon, 26 Nov 2007 15:26:06 -0500
2007-12-05 04:09:53 +00:00
abs
eda1229d25 Update www/apache to 2.2.6nb1
Add apache SVN revision 574884 to fix garbage characters in Server header
http://issues.apache.org/bugzilla/show_bug.cgi?id=43334

When it hits, this issue can completely screw up returned pages if the
Server header gets embedded newlines
2007-12-04 12:08:45 +00:00
ghen
e5bb2ea843 Update seamonkey, seamonkey-bin and seamonkey-gtk1 to Seamonkey 1.1.7.
Security fixes in this version:

MFSA 2007-39 Referer-spoofing via window.location race condition
MFSA 2007-38 Memory corruption vulnerabilities (rv:1.8.1.10)
MFSA 2007-37 jar: URI scheme XSS hazard

For more info, see http://www.mozilla.org/projects/seamonkey/releases/seamonkey1.1.7/
2007-12-03 10:56:27 +00:00
ghen
849bc2247a Add distinfo for solaris10 binaries (weren't available yet when the 2.0.0.11
release was announced).
2007-12-02 21:28:36 +00:00
taca
838745aa13 Update squid package to 2.6.17 (2.6.STABLE17).
Changes to squid-2.6.STABLE17 (26 Nov 2007)

	- Fix compile error with old GCC 2.x or other ANSI-C compilers before
	  C99
	- Mention the login= cache_peer option in release notes
	- Fix bad cache_peer example in squid.conf
	- Bug #2086: Fix a compile-time memory corruption error causing cf_gen
	  to fail
	- Bug #2048: Clarify high_memory_warning usage
	- Reject DNS responses which result in no data
	- Fix version number in configuration manual
	- Move cache and request/reply_header_max_size to their proper
	  sections
	- Bug #2088: sbrk statistics broken when process size >2GB
	- Move logopen() much earlier to have fatal startup errors sent to the
	  proper syslog facility
	- Fix HTTP/0.9 responses
	- Correct bad example config for tos_outgoing_tos
	- Fix grammar in description of mail_program squid.conf option
	- Ignore Content-Length in chunked responses instead of rejecting the
	  response as invalid
	- Documented that http_port no longer have a default
	- Cleanup of cache digest documentation
	- Make aufs store rebuilding back off a little if I/O load too high
	- Bug #2100: Respect DNS ttl=0
	- Update udp_(incoming|outgoing)_address documentation to reflect
	  current bahaviour.
	- Update HTCP documentation
	- Document the overlapping helper request format
	- Change priority of proxy auth and extacl provided username in
	  login=*:pass
	- pack header entries on cache updates
	- Make squid_db_auth reopen the database connection on each query by
	  default
	- Improve helper debug ouput, including the channel number
	- Update cachePeerEntry MIB description to mention what is used as
	  index key
	- Import squid_radius_auth for authenticating to RADIUS
2007-12-02 14:47:07 +00:00
wiz
c76bbdae35 Remove Ex-MASTER_SITEs. From Zafer Aydogan. 2007-12-02 12:32:40 +00:00
wiz
7df37351d3 Remove Ex-MASTER_SITE. From Zafer Aydogan. 2007-12-02 12:29:02 +00:00
wiz
15c82cc52b Remove Ex-MASTER_SITE. From Zafer Aydogan. 2007-12-02 11:41:48 +00:00
ghen
d1a431b3d0 Update firefox, firefox-bin and firefox-gtk1 to 2.0.0.11.
This update fixes a bug introduced by the 2.0.0.10 update in the <canvas>
feature that affected some web pages and extensions.

For more info, see http://www.mozilla.com/en-US/firefox/2.0.0.11/releasenotes/
2007-12-01 21:43:23 +00:00
rillig
8ba20c7dbb I finally found out what the error message "Need libIDL >= 0.6.3" really
meant: I need Orbit.
2007-12-01 21:29:52 +00:00
wiz
a34ac258dd Bump PKGREVISION because openexr now depends on ilmbase. 2007-11-30 21:55:01 +00:00
rillig
5d845f71b1 Fixed duplicate definition of strsep on NetBSD. 2007-11-30 20:46:18 +00:00
rillig
1ab529e81c Fixed invalid lvalue. 2007-11-30 20:43:08 +00:00
bjs
0f19e76069 I somehow lost the patch I made and it didn't get committed. It's late
now, so I decremented the PKGREVISION and I will revisit this later.
Sorry for any confusion.
2007-11-30 09:59:59 +00:00
bjs
288a552d07 Disable code which creates a race condition exclusively for the benefit of
GPM (which we do not support) and its lovely signal handler.

See my comment in main.c for more information.  This fixes the extremely
annoying behavior I've been noticing on NetBSD-current where links seems to
send a SIGSTP to any jobs attempting to use its terminal after it received
a SIGSTP.

Bump rev.
2007-11-30 09:11:11 +00:00