pkgsrc/security
seb c387ecacba * Add patch from http://www.openssl.org/news/secadv_20030317.txt:
Researchers have discovered a timing attack on RSA keys, to which
OpenSSL is generally vulnerable, unless RSA blinding has been turned
on.

Typically, it will not have been, because it is not easily possible to
do so when using OpenSSL to provide SSL or TLS.

The enclosed patch switches blinding on by default. Applications that
wish to can remove the blinding with RSA_blinding_off(), but this is
not generally advised. It is also possible to disable it completely by
defining OPENSSL_NO_FORCE_RSA_BLINDING at compile-time.

The performance impact of blinding appears to be small (a few
percent).

This problem affects many applications using OpenSSL, in particular,
almost all SSL-enabled Apaches. You should rebuild and reinstall
OpenSSL, and all affected applications.

The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2003-0147 to this issue.

* Add patch from http://www.openssl.org/news/secadv_20030319.txt:

Czech cryptologists Vlastimil Klima, Ondrej Pokorny, and Tomas Rosa
have come up with an extension of the "Bleichenbacher attack" on RSA
with PKCS #1 v1.5 padding as used in SSL 3.0 and TLS 1.0.  Their
attack requires the attacker to open millions of SSL/TLS connections
to the server under attack; the server's behaviour when faced with
specially made-up RSA ciphertexts can reveal information that in
effect allows the attacker to perform a single RSA private key
operation on a ciphertext of its choice using the server's RSA key.
Note that the server's RSA key is not compromised in this attack.

* Bump PKGREVISION.
2003-03-21 18:40:48 +00:00
..
AiCA Move pkg/ files into package's toplevel directory 2001-11-01 00:57:41 +00:00
aide Update to 0.9: 2002-11-13 22:58:20 +00:00
AiSSLtelnet Move pkg/ files into package's toplevel directory 2001-11-01 00:57:41 +00:00
amavis Complete standardization of messages according to latest pkglint. 2002-09-24 12:29:55 +00:00
amavis-perl Updated amavis-perl to 20020531 2002-08-22 11:27:16 +00:00
apg Adjust format a bit: 2001-11-11 06:17:26 +00:00
arirang update HOMEPAGE for www.monkey.org -> monkey.org move 2002-09-05 00:18:20 +00:00
audit-packages Change directory before ${FETCH_CMD} as mk/bsd.pkg.mk does. This avoids a 2002-12-13 11:18:14 +00:00
avcheck Import avcheck-0.9 2002-08-23 11:47:48 +00:00
cfs Whitespace fix 2002-12-23 16:24:59 +00:00
crack Fix binary package, from Urban Boquist in pkg/17892. 2002-08-09 13:03:19 +00:00
cy-login Initial import of security/cy-login. 2003-03-19 21:09:46 +00:00
cy2-login Initial import of security/cy2-login. 2003-03-19 22:28:23 +00:00
cy2-ntlm Initial import of security/cy2-ntlm. 2003-03-19 22:28:53 +00:00
cyrus-sasl Add a section to deal with SASL plugins, and clarify where this file 2003-03-19 21:07:54 +00:00
cyrus-sasl2 Rearrange the Makefile logic so that we can easily create Cyrus SASL 2.x 2003-03-19 22:25:05 +00:00
ddos-scan Move pkg/ files into package's toplevel directory 2001-11-01 00:57:41 +00:00
dsniff www.monkey.org moved to monkey.org. pilot <pilot@monkey.org> 2002-09-05 00:13:39 +00:00
egd Use buildlink2. Use perl5/module.mk. 2002-10-28 00:05:42 +00:00
flawfinder Update to 1.22. 2003-03-09 18:11:05 +00:00
fortify Move pkg/ files into package's toplevel directory 2001-11-01 00:57:41 +00:00
fressh Initialize a variable to make it compile with gcc 2.95.3. Closes pkg/15832. 2002-05-20 15:22:00 +00:00
fsh Update fsh to 1.2. Changes since 1.1: 2003-03-05 21:59:34 +00:00
gnupg USE_PKGLOCALEDIR=yes 2003-01-10 07:39:46 +00:00
gpa Merge packages from the buildlink2 branch back into the main trunk that 2002-08-25 21:48:57 +00:00
gpgme Updated to latest stable version 0.3.15. 2003-03-11 00:11:31 +00:00
gtk-systrace GTK interface to systrace(1). 2002-12-18 03:49:56 +00:00
hackbot hackbot 2.15 provided by Niilo Kajander in pkg/19151 2002-11-26 13:40:17 +00:00
isakmpd fix some format strings for 64 bit systems so this can build with -Werror 2003-02-08 17:06:26 +00:00
john Adjust format a bit: 2001-11-11 06:17:26 +00:00
keychain Updated keychain to 2.0.2 2003-01-18 05:58:58 +00:00
kssh Initial import of kssh-0.7. 2003-02-16 11:12:21 +00:00
kth-krb4 Whitespace fix 2002-12-23 16:24:59 +00:00
libbf Move pkg/ files into package's toplevel directory 2001-11-01 00:57:41 +00:00
libcrack Unused. 2002-10-09 23:32:33 +00:00
libdes s/INSTALL_*/BSD_INSTALL_*/ in patches, remove unnecessary MAKE_ENV. 2003-01-19 09:04:02 +00:00
libgcrypt do not disable asm on alpha. fixes recently noted compile problems 2003-02-08 23:01:02 +00:00
libidea Move pkg/ files into package's toplevel directory 2001-11-01 00:57:41 +00:00
libident s/INSTALL_*/BSD_INSTALL_*/ in patches, remove unnecessary MAKE_ENV. 2003-01-19 09:04:02 +00:00
libmcrypt Unneeded after 2.5.6 update. 2003-03-05 08:49:29 +00:00
libnasl Update nessus{-core,-libraries,-plugins} and libnasl to 1.2.7. 2002-12-19 18:30:12 +00:00
logcheck Remove (partly obsolete) homepage URLs from DESCR. 2002-08-15 09:39:18 +00:00
mcrypt Update to 2.6.4. 2003-03-05 08:44:56 +00:00
mhash Update to version 0.8.17: 2002-11-13 22:53:42 +00:00
mirrordir Instead of including bsd.pkg.install.mk directly in a package Makefile, 2003-01-28 22:03:00 +00:00
msu Fix distinfos (server holding distfiles replaced and original distfiles lost) 2003-01-02 12:33:07 +00:00
msudir Fix distinfos (server holding distfiles replaced and original distfiles lost) 2003-01-02 12:33:07 +00:00
nessus Update nessus{-core,-libraries,-plugins} and libnasl to 1.2.7. 2002-12-19 18:30:12 +00:00
nessus-core Update nessus{-core,-libraries,-plugins} and libnasl to 1.2.7. 2002-12-19 18:30:12 +00:00
nessus-libraries Update nessus{-core,-libraries,-plugins} and libnasl to 1.2.7. 2002-12-19 18:30:12 +00:00
nessus-plugins remove entry for "lib/nessus/plugins_factory". Reported by Bernd Ernesti 2002-12-30 12:13:33 +00:00
netramet enable IPv6. 2002-04-03 02:09:54 +00:00
nfsbug Provide a better rule for platforms to build this on. Basically only 1.5B 2002-02-11 17:07:59 +00:00
openssh Instead of including bsd.pkg.install.mk directly in a package Makefile, 2003-01-28 22:03:00 +00:00
openssl * Add patch from http://www.openssl.org/news/secadv_20030317.txt: 2003-03-21 18:40:48 +00:00
otpcalc buildlink1 -> buildlink2 2002-11-15 00:15:02 +00:00
p0f Make this package honor PKG_SYSCONFDIR. Bump PKGREVISION. 2003-02-02 21:32:11 +00:00
p5-Crypt-Blowfish Convert to buildlink2. Use perl5/module.mk. 2002-10-06 22:31:03 +00:00
p5-Crypt-CBC Use buildlink2. Use perl5/module.mk. 2002-10-20 17:45:59 +00:00
p5-Crypt-DES Convert to buildlink2. Use perl5/module.mk. 2002-10-06 22:31:03 +00:00
p5-Crypt-DES_EDE3 Convert to buildlink2. Use perl5/module.mk. 2002-10-06 22:31:03 +00:00
p5-Crypt-DSA Use buildlink2. Use perl5/module.mk. 2002-10-27 21:20:37 +00:00
p5-Crypt-IDEA Use buildlink2. Use perl5/module.mk. 2002-10-06 22:26:49 +00:00
p5-Crypt-OpenPGP Use buildlink2. Use perl5/module.mk. 2002-10-27 21:20:37 +00:00
p5-Crypt-Primes Use buildlink2. Use perl5/module.mk. 2002-10-27 21:20:37 +00:00
p5-Crypt-Random Use buildlink2. Use perl5/module.mk. 2002-10-27 21:20:37 +00:00
p5-Crypt-Rijndael Convert to buildlink2. Use perl5/module.mk. 2002-10-06 22:31:03 +00:00
p5-Crypt-RIPEMD160 Convert to buildlink2. Use perl5/module.mk. 2002-10-06 22:31:03 +00:00
p5-Crypt-RSA Use buildlink2. Use perl5/module.mk. 2002-10-27 21:20:37 +00:00
p5-Crypt-Twofish Convert to buildlink2. Use perl5/module.mk. 2002-10-06 22:31:03 +00:00
p5-Digest-HMAC Use buildlink2. Use perl5/module.mk. 2002-10-20 17:45:59 +00:00
p5-Digest-MD2 Updated to p5-Digest-MD2-2.01 2003-01-31 10:50:49 +00:00
p5-Digest-MD4 Convert to buildlink2. Use perl5/module.mk. 2002-10-06 22:31:03 +00:00
p5-Digest-MD5 Update from 2.20 to 2.22. 2003-01-09 15:52:04 +00:00
p5-Digest-Nilsimsa convert to use test target from bsd.pkg.mk 2003-02-17 15:27:58 +00:00
p5-Digest-SHA1 Updated to p5-Digest-SHA1-2.02 2003-01-31 10:48:41 +00:00
p5-IO-Socket-SSL Updated to p5-IO-Socket-SSL-0.91 2002-09-27 09:35:43 +00:00
p5-Net-SSLeay Pass prefix to openssl as argument to the configure stage: helps 2003-03-05 11:42:53 +00:00
p5-SHA Convert to buildlink2. Use perl5/module.mk. 2002-10-06 22:31:03 +00:00
p5-SSLeay Updated to p5-SSLeay-0.47 2003-02-09 08:09:08 +00:00
p5-Tie-EncryptedHash Use buildlink2. Use perl5/module.mk. 2002-10-27 20:48:55 +00:00
pakemon Update MASTER_SITES and HOMEPAGE. 2002-10-07 23:49:28 +00:00
PAM fix compilation problems on systems that don't have ldconfig. 2003-02-09 16:16:56 +00:00
pam-ldap Update to 150. Last version was 77, so ChangeLog would be too big to add 2002-07-13 21:35:15 +00:00
pam-smbpass Merge packages from the buildlink2 branch back into the main trunk that 2002-08-25 21:48:57 +00:00
pgp2 (1) Publicly export the value of _OPSYS_RPATH_NAME as RPATH_FLAG; 2003-03-14 19:37:30 +00:00
pgp5 Correct man page xrefs pgp(1) -> pgp5(1). 2002-08-25 15:18:41 +00:00
pgpdump Update pgpdump to 0.17 2002-06-28 23:48:11 +00:00
php4-mcrypt Use the libmcrypt package instead of the obsolete libmcrypt22 one. 2003-03-05 09:07:23 +00:00
php4-mhash - make this work with apache2 2002-11-05 07:33:13 +00:00
pks Instead of including bsd.pkg.install.mk directly in a package Makefile, 2003-01-28 22:03:00 +00:00
portsentry Install more documentation. Bump to 1.0nb1. 2002-06-01 12:33:20 +00:00
priv Replace "true" by "${TRUE}". 2002-12-09 16:01:10 +00:00
pscan Do not list homepage in DESCR 2002-08-06 01:49:11 +00:00
py-amkCrypto update to 1.9a4 2002-10-28 11:53:29 +00:00
py-cryptkit Strip the ".buildlink" from the names of the python application and 2002-09-21 23:46:45 +00:00
py-gnupg Strip the ".buildlink" from the names of the python application and 2002-09-21 23:46:45 +00:00
pyca Initial import of of security/pyca. 2002-10-18 17:06:00 +00:00
qident Move pkg/ files into package's toplevel directory 2001-11-01 00:57:41 +00:00
racoon Replace IGNORE with PKG_FAIL_REASON or PKG_SKIP_REASON as appropriate. 2002-12-07 02:38:52 +00:00
rats Update ratas to 2.1 2002-09-30 13:52:55 +00:00
rc5des This package installs binaries compiled for the NetBSD 1.2 and 1.3 releases 2002-04-12 15:17:22 +00:00
rid Make this package honor PKG_SYSCONFDIR. Bump PKGREVISION. 2003-02-02 19:47:35 +00:00
rsaref Unused. 2002-10-25 12:19:37 +00:00
ruby-acl Simplify document arrangement. 2002-01-03 15:21:38 +00:00
ruby-digest Make ruby-digest module need ruby 1.6.6 or later. 2002-01-15 16:43:50 +00:00
ruby-openssl buildlink1 -> buildlink2. 2002-10-25 09:36:24 +00:00
ruby-tcpwrap Move pkg/ files into package's toplevel directory 2001-11-01 00:57:41 +00:00
scanssh www.monkey.org moved to monkey.org. pilot <pilot@monkey.org> 2002-09-05 00:13:39 +00:00
seahorse GConf2's buildlink2.mk now creates a gconftool-2 wrapper which prevents the 2003-02-18 20:52:05 +00:00
sfs Initial import of sfs-0.7.2 into the NetBSD Packages Collection. 2003-03-17 21:01:47 +00:00
skey Allow this to build on Darwin. Also use the new USE_PERL5 semantics. 2002-08-28 03:10:04 +00:00
smimemsg Move pkg/ files into package's toplevel directory 2001-11-01 00:57:41 +00:00
smtpd Add patch to reopen stdout/stderr to /dev/null to quelch whining about 2002-11-30 14:56:53 +00:00
sniff Move pkg/ files into package's toplevel directory 2001-11-01 00:57:41 +00:00
snortsnarf add newline to end of perl script. while I'm here, clean up 2003-02-05 06:29:54 +00:00
srp_client buildlink1 -> buildlink2. 2002-10-09 19:45:26 +00:00
ssh (1) Publicly export the value of _OPSYS_RPATH_NAME as RPATH_FLAG; 2003-03-14 19:37:30 +00:00
ssh-askpass Move pkg/ files into package's toplevel directory 2001-11-01 00:57:41 +00:00
ssh-ip-tunnel Move pkg/ files into package's toplevel directory 2001-11-01 00:57:41 +00:00
ssh2 Instead of including bsd.pkg.install.mk directly in a package Makefile, 2003-01-28 22:03:00 +00:00
ssldump Update to version 0.9b3. Okay'ed by hubertf. 2002-12-01 21:48:09 +00:00
sslwrap Merge packages from the buildlink2 branch back into the main trunk that 2002-08-25 21:48:57 +00:00
stunnel Updated stunnel to 4.04 (upgrade to 4.03 provided by Juan RP in pkg/19310) 2003-01-18 08:33:42 +00:00
sudo Instead of including bsd.pkg.install.mk directly in a package Makefile, 2003-01-28 22:03:00 +00:00
tcp_wrappers Make this work on IRIX. 2002-12-24 04:23:09 +00:00
tct Trivially use buildlink2. 2002-11-24 22:23:12 +00:00
tkpasman Change my email address to the NetBSD one (hispabsd.org -> netbsd.org). 2003-01-03 15:26:54 +00:00
tripwire Split up installation of directories to please SunOS /usr/ucb/install 2003-01-06 07:44:11 +00:00
uvscan Instead of including bsd.pkg.install.mk directly in a package Makefile, 2003-01-28 22:03:00 +00:00
winbind Instead of including bsd.pkg.install.mk directly in a package Makefile, 2003-01-28 22:03:00 +00:00
xdm-krb4 Use new IMAKE_MAN_PATH variables in PLISTs to make these packages more 2003-03-03 02:45:51 +00:00
zebedee Merge packages from the buildlink2 branch back into the main trunk that 2002-08-25 21:48:57 +00:00
Makefile Add and enable cy2-{login,ntlm}. 2003-03-19 22:29:30 +00:00