Commit graph

196752 commits

Author SHA1 Message Date
adam
8d090b5025 Updated devel/scmgit to 1.8.1.2 2013-01-30 17:40:46 +00:00
adam
6ffd173e81 Changes 1.8.1.2:
* An element on GIT_CEILING_DIRECTORIES list that does not name the
  real path to a directory (i.e. a symbolic link) could have caused
  the GIT_DIR discovery logic to escape the ceiling.
* Command line completion for "tcsh" emitted an unwanted space
  after completing a single directory name.
* Command line completion leaked an unnecessary error message while
  looking for possible matches with paths in <tree-ish>.
* "git archive" did not record uncompressed size in the header when
  streaming a zip archive, which confused some implementations of unzip.
* When users spelled "cc:" in lowercase in the fake "header" in the
  trailer part, "git send-email" failed to pick up the addresses from
  there. As e-mail headers field names are case insensitive, this
  script should follow suit and treat "cc:" and "Cc:" the same way.
2013-01-30 17:39:39 +00:00
drochner
785fb0207d add patch from upstream to fix Buffer Overflow in ASF Demuxer
bump PKGREV
2013-01-30 15:52:18 +00:00
schmonz
3dfa489b1d Fix fetch: MASTER_SITES is just ${HOMEPAGE} (no :Q). 2013-01-30 14:45:40 +00:00
wiz
2b404cb793 Updated devel/scmgit to 1.8.1.1nb1 2013-01-30 14:45:09 +00:00
wiz
398ebfd568 Add scmgit-gitk to meta package.
Bump PKGREVISION.
2013-01-30 14:45:00 +00:00
wiz
c2a9eadbff Mention cvsps3. 2013-01-30 13:39:37 +00:00
wiz
ac4686d869 + csvps3. 2013-01-30 13:38:53 +00:00
obache
45c5a5574b + di 2013-01-30 12:30:14 +00:00
obache
c12223b205 Added sysutils/di version 4.34 2013-01-30 12:29:33 +00:00
obache
54adf62c10 Import di-4.34 as sysutils/di.
based on PR 47495 by Brad Lanam, some small fixes by me.

di is a disk information utility, displaying everything (and more)
that your df command does. It features the ability to display your
disk usage in whatever format you prefer. It also checks the user
and group quotas, so that the user sees the space available for
their use, not the system wide disk space.
2013-01-30 12:29:06 +00:00
taca
57d059732e - samba-3.6.11.
+ samba-4.0.2, sudo-1.8.6p5, typo3-6.0.1.
2013-01-30 11:44:35 +00:00
taca
c7a0a690ea Note update of smaba packages.
net/samba35	3.5.21
	net/samba	3.6.12
2013-01-30 11:43:53 +00:00
taca
996aedc1cf Update samba to 3.6.12.
==============================
                   Release Notes for Samba 3.6.12
                          January 30, 2013
                   ==============================


This is a security release in order to address
CVE-2013-0213 (Clickjacking issue in SWAT) and
CVE-2013-0214 (Potential XSRF in SWAT).

o  CVE-2013-0213:
   All current released versions of Samba are vulnerable to clickjacking in the
   Samba Web Administration Tool (SWAT). When the SWAT pages are integrated into
   a malicious web page via a frame or iframe and then overlaid by other content,
   an attacker could trick an administrator to potentially change Samba settings.

   In order to be vulnerable, SWAT must have been installed and enabled
   either as a standalone server launched from inetd or xinetd, or as a
   CGI plugin to Apache. If SWAT has not been installed or enabled (which
   is the default install state for Samba) this advisory can be ignored.

o  CVE-2013-0214:
   All current released versions of Samba are vulnerable to a cross-site
   request forgery in the Samba Web Administration Tool (SWAT). By guessing a
   user's password and then tricking a user who is authenticated with SWAT into
   clicking a manipulated URL on a different web page, it is possible to manipulate
   SWAT.

   In order to be vulnerable, the attacker needs to know the victim's password.
   Additionally SWAT must have been installed and enabled either as a standalone
   server launched from inetd or xinetd, or as a CGI plugin to Apache. If SWAT has
   not been installed or enabled (which is the default install state for Samba)
   this advisory can be ignored.


Changes since 3.6.11:
--------------------

o   Kai Blin <kai@samba.org>
    * BUG 9576: CVE-2013-0213: Fix clickjacking issue in SWAT.
    * BUG 9577: CVE-2013-0214: Fix potential XSRF in SWAT.
2013-01-30 11:42:54 +00:00
taca
da0322a097 Update samba35 to 3.5.21.
==============================
                   Release Notes for Samba 3.5.21
			 January 30, 2013
                   ==============================


This is a security release in order to address
CVE-2013-0213 (Clickjacking issue in SWAT) and
CVE-2013-0214 (Potential XSRF in SWAT).

o  CVE-2013-0213:
   All current released versions of Samba are vulnerable to clickjacking in the
   Samba Web Administration Tool (SWAT). When the SWAT pages are integrated into
   a malicious web page via a frame or iframe and then overlaid by other content,
   an attacker could trick an administrator to potentially change Samba settings.

   In order to be vulnerable, SWAT must have been installed and enabled
   either as a standalone server launched from inetd or xinetd, or as a
   CGI plugin to Apache. If SWAT has not been installed or enabled (which
   is the default install state for Samba) this advisory can be ignored.

o  CVE-2013-0214:
   All current released versions of Samba are vulnerable to a cross-site
   request forgery in the Samba Web Administration Tool (SWAT). By guessing a
   user's password and then tricking a user who is authenticated with SWAT into
   clicking a manipulated URL on a different web page, it is possible to manipulate
   SWAT.

   In order to be vulnerable, the attacker needs to know the victim's password.
   Additionally SWAT must have been installed and enabled either as a standalone
   server launched from inetd or xinetd, or as a CGI plugin to Apache. If SWAT has
   not been installed or enabled (which is the default install state for Samba)
   this advisory can be ignored.


Changes since 3.5.20:
---------------------

o   Kai Blin <kai@samba.org>
    * BUG 9576: CVE-2013-0213: Fix clickjacking issue in SWAT.
    * BUG 9577: CVE-2013-0214: Fix potential XSRF in SWAT.
2013-01-30 11:41:44 +00:00
ryoon
d4e3df3a48 Set MAINTAINER as me. 2013-01-30 11:37:41 +00:00
ryoon
d2d7a4aa9f Fix PR pkg/47363.
Import 3.2 version of cvsps as devel/cvsps3.

From README,
The 3.x versions have changed significantly.  In 2012, CVS use is declining
swiftly (GNU CVS hasn't been updated since 2004) and the original use case
for this tool - browsing change sets in a live CVS repository - is obsolete.
The 3.x versions are more focused on the --fast-export mode.
2013-01-30 11:34:58 +00:00
wiz
18b94011fa + glpk-4.48, libproxy-1.4.11, phpmyadmin-3.5.6, py-sip-4.14.3,
qemu-1.3.1, wireshark-1.8.5.
2013-01-30 10:49:57 +00:00
wiz
8952b3c28f Updated devel/doxygen to 1.8.3.1 2013-01-30 10:41:54 +00:00
wiz
40a7e5a135 Update to 1.8.3.1:
Changes

    Changed to way the search results for multiple projects can be
    linked together. A project is now no longer identified by the
    tag files name but via new option EXTERNAL_SEARCH_ID giving a
    bit more flexibility.
    Disabled the disk cache for member data. Allows removing quite
    some complexity in doxygen and is not really needed now that
    64bit systems with >4GB RAM are becoming more common. Let me
    know if you think you benefit from this caching.
    id 691607: Using $relpath$ in a custom footer could lead to
    ambiguities when followed by a name that could also be a marker,
    like 'search'. Now $relpath^ should be used instead. $relpath$
    is still supported for backward compatibility.

New features

    You can now use EXTENSION_MAPPING on files without any extension
    using no_extension as placeholder (thanks to Jason Majors for
    the patch).
    To make navindex section inside a layout file that links to a
    specific URL you can use usergroup with the url attribute.
    To make navindex section without any link inside a layout file
    you can use usergroup with special title [none].

And lots of bugfixes.
2013-01-30 10:41:43 +00:00
wiz
9c7d7d99ea Updated x11/pixman to 0.28.2 2013-01-30 10:21:30 +00:00
wiz
275e75a5dc Update to 0.28.2:
0.28.2:

This stable release in the 0.28 series contains fixes for 64 bit
Windows, clang, and PowerPC on MacOS and OpenBSD.

0.28.0:
A new major release 0.28.0 of the pixman rendering library is now
available. Highlights of this release:

  * Support for sRGB coded images [Antti Lankila]

  * New API for fast glyph rendering [Soren Sandmann]

  * Faster bilinear scaling on iwMMX, Loongson and MMX [Matt Turner]

  * More fast paths in the MIPS DSPr2 backend [Nemanja Lukic]

  * Faster scaling in general and on SSE2 in particular [Siarhei
    Siamashka]
2013-01-30 10:21:22 +00:00
wiz
240e340e40 Updated x11/xkeyboard-config to 2.8 2013-01-30 09:18:15 +00:00
wiz
45686a2332 Update to 2.8:
Khaled Hosny (1):
      Allow Alt R to be used for next group again

Mathieu Boespflug (1):
      Add altwin:swap_alt_win option.

Michal Nazarewicz (1):
      Remove redundant definition in pl(dvp).

Parag Nemade (3):
      Correct the eurosign group to currencysign group
      Align keymappings in Jhelum keymap with m17n pa-jhelum keymap
      Add Rupee Sign default on some Indic xkb maps

Peter Hutterer (1):
      =?UTF-8?q?rules:=20remove=20ml=20=E2=86=92=20in(mal)=20ma?=
=?UTF-8?q?pping?=

Sergey V. Udaltsov (22):
      Added euro to Polish layout
      Added Silesian
      configuration for IBM 142 Italian variant
      il(lyx) should have proper mapping of numeric keys
      Added us(workman)
      More polish on us(workman)
      Cleanup for descriptions
      added de(legacy)
      A couple of missing chars in gr(polytonic), added on levels 3, 4
      fixed comment
      Fixed Congolese layout, 2 missing symbols
      Removed invalid layout
      Updated typography symbols
      Using configure.ac
      Added pl(colemak)
      Bumping version before freese - 2.7.99
      Forgot to remove the actual ad layout
      Fixed 2 minor typos (thanks to Alex Shopov)
      Missing hyphen
      SunOpen -> XF86Open
      Updated translations before release                                                                                                                                            Preparing 2.8

Stephan Hilb (1):
      Always use fake keycode bindings for level3 and level5

javier (8):
      Update keycodes and geometry for Sun Keyboards
      Update XKB symbols specific for Sun Keyboards
      Fix compat for Japanese Sun keyboards
      Update XKB rules specific for Sun Keyboards
      Remove tuv layout for Sun Keyboards
      Add Models and one option for Sun Keyboards
      Add Sun keyboard layout variants
      Add sun_type layout variants into base.extras
2013-01-30 09:18:07 +00:00
wiz
114778d468 Updated x11/xev to 1.2.1 2013-01-29 22:05:31 +00:00
wiz
d854c81110 Update to 1.2.1:
This release adds a "-event" option that can be used to filter which events are
printed.  For example, to listen only for RandR events, use "xev -event randr".
The -event parameter can be specified multiple times.  Please see the manual
page for the list of available event filters.

This release also contains a few code fixes.

Aaron Plattner (2):
      Add a -event parameter to control the event mask
      xev 1.2.1

Alan Coopersmith (2):
      Fix clang warnings about converting size_t to int and back again
      Use strncasecmp instead of a tolower loop & strncmp
2013-01-29 22:05:23 +00:00
is
bdf2a443a7 Fix the VARBASE propagation to all utilities. Without this, we tried
to log to /spool/fax/Faxlog.
2013-01-29 16:56:39 +00:00
drochner
27cef7204f libupnp update 2013-01-29 16:23:39 +00:00
drochner
a4c802b42e update to 1.6.18
changes:
-fix multiple buffer overflows (CVE-2012-5958..65)
-more bugfixes, Compilation optimisation
2013-01-29 16:22:47 +00:00
taca
c8d0051879 Note update of mail/fml package to 20121230. 2013-01-29 15:51:42 +00:00
taca
491e1b1eb4 Update fml to 7.98.18-20121230.
7.98.18 hack base to catch up perl 5.16 changes, cpan modules ..
	7.98.17 update modules: cpan modules, IM et.al (to be planned).
	7.98.16 FML::Install is enhanced.
2013-01-29 15:51:06 +00:00
taca
c9f63ffbdd Note update of mail/fml4 package to 4.0.3.20040215nb4. 2013-01-29 15:49:22 +00:00
taca
9f22655254 Allow '+' character in local-part.
Bump PKGREVISION.
2013-01-29 15:48:55 +00:00
taca
2c3a04ff6b Note update of Ruby on Rails 3.0.20.
devel/ruby-activesupport3	3.0.20
	devel/ruby-activemodel		3.0.20
	www/ruby-activeresource3	3.0.20
	databases/ruby-activerecord3	3.0.20
	www/ruby-actionpack3		3.0.20
	mail/ruby-actionmailer3		3.0.20
	devel/ruby-railties		3.0.20
	www/ruby-rails3			3.0.20
2013-01-29 15:45:47 +00:00
taca
80f85c99f4 Update ruby-rails3 to 3.0.20.
No change except version.
2013-01-29 15:42:58 +00:00
taca
aa34b166b8 Update ruby-railties to 3.0.20.
No change except version.
2013-01-29 15:42:26 +00:00
taca
c4bee02197 Update ruby-actionmailer3 to 3.0.20.
No change except version.
2013-01-29 15:41:49 +00:00
taca
9c9fb8eb9c Update ruby-actionpack3 to 3.0.20.
No change except version.
2013-01-29 15:41:17 +00:00
taca
a59478e564 Update ruby-activerecord3 to 3.0.20.
No change except version.
2013-01-29 15:40:43 +00:00
taca
fc14638459 Update ruby-activeresource3 to 3.0.20.
No change except version.
2013-01-29 15:39:33 +00:00
taca
3340fae8ed Update ruby-activemodel to 3.0.20.
Fix CVE-2013-0333.

There is a vulnerability in the JSON  code for Ruby on Rails which
allows attackers to bypass authentication systems, inject arbitrary
SQL, inject and execute arbitrary code, or perform a DoS attack on a
Rails application.

## Rails 3.0.20 (unreleased)

* Fix XML serialization of methods that return nil to not be
  considered as YAML (GH #8853 and GH #492)
2013-01-29 15:38:40 +00:00
taca
7fafbba2d1 Update ruby-activesupport3 to 3.0.20.
Fix CVE-2013-0333.

There is a vulnerability in the JSON  code for Ruby on Rails which
allows attackers to bypass authentication systems, inject arbitrary
SQL, inject and execute arbitrary code, or perform a DoS attack on a
Rails application.

## Rails 3.0.20 (unreleased)

* Fix XML serialization of methods that return nil to not be
  considered as YAML (GH #8853 and GH #492)
2013-01-29 15:37:52 +00:00
taca
90a5251e13 Start update of Ruby on Rails 3.0.20. 2013-01-29 15:36:12 +00:00
wiz
aad78bd31d Whitespace cleanup for pkglint. 2013-01-29 15:35:04 +00:00
wiz
679281b676 regen 2013-01-29 15:34:55 +00:00
wiz
eb654d7c2c Add comment. 2013-01-29 15:34:47 +00:00
tsutsui
717479c3b7 Always use atomic_ops(3) on NetBSD even on arm, i.e. kill Linux-ARM'ism.
Fixes configure failure on NetBSD/arm 6.0.

Also add patch comment.
2013-01-29 15:02:24 +00:00
imil
3457b9027b Updated naxsi, the Web Application Firewall module to version 0.49
* Added support for runtime modifiers
* Minor bugfixes
2013-01-29 12:36:40 +00:00
wiz
c4be3aa2ab Added fonts/courier-prime version 1.203 2013-01-29 08:09:37 +00:00
wiz
f284e51db3 + courier-prime. 2013-01-29 08:00:25 +00:00