pkgsrc/net/xymon/PLIST
spz 047bb6ad21 update of xymon and xymonclient from 4.3.17 to 4.3.25
The following security issues are fixed with this update:
* Resolve buffer overflow when handling "config" file requests (CVE-2016-2054)
* Restrict "config" files to regular files inside the $XYMONHOME/etc/ directory
  (symlinks disallowed) (CVE-2016-2055). Also, require that the initial filename
  end in '.cfg' by default
* Resolve shell command injection vulnerability in useradm and chpasswd CGIs
  (CVE-2016-2056)
* Tighten permissions on the xymond BFQ used for message submission to restrict
  access to the xymon user and group. It is now 0620. (CVE-2016-2057)
* Restrict javascript execution in current and historical status messages by
  the addition of appropriate Content-Security-Policy headers to prevent XSS
  attacks. (CVE-2016-2058)
* Fix CVE-2015-1430, a buffer overflow in the acknowledge.cgi script.
  Thank you to Mark Felder for noting the impact and Martin Lenko
  for the original patch.
* Mitigate CVE-2014-6271 (bash 'Shell shock' vulnerability) by
  eliminating the shell script CGI wrappers

Please refer to
https://sourceforge.net/projects/xymon/files/Xymon/4.3.25/Changes/download
for further information on fixes and new features.
2016-02-16 05:58:56 +00:00

429 lines
16 KiB
Text

@comment $NetBSD: PLIST,v 1.7 2016/02/16 05:58:56 spz Exp $
libexec/xymon/ackinfo.cgi
libexec/xymon/acknowledge.cgi
libexec/xymon/acknowledgements.cgi
libexec/xymon/appfeed.cgi
libexec/xymon/bb
libexec/xymon/bbcmd
libexec/xymon/bbdigest
libexec/xymon/bbhostgrep
libexec/xymon/bbhostshow
libexec/xymon/beastat
libexec/xymon/boilerplate.cgi
libexec/xymon/cgi-bin/acknowledgements.sh
libexec/xymon/cgi-bin/appfeed-critical.sh
libexec/xymon/cgi-bin/appfeed.sh
libexec/xymon/cgi-bin/certreport.sh
libexec/xymon/cgi-bin/columndoc.sh
libexec/xymon/cgi-bin/confreport-critical.sh
libexec/xymon/cgi-bin/confreport.sh
libexec/xymon/cgi-bin/criticalview.sh
libexec/xymon/cgi-bin/csvinfo.sh
libexec/xymon/cgi-bin/datepage.sh
libexec/xymon/cgi-bin/eventlog.sh
libexec/xymon/cgi-bin/findhost.sh
libexec/xymon/cgi-bin/ghostlist.sh
libexec/xymon/cgi-bin/history.sh
libexec/xymon/cgi-bin/historylog.sh
libexec/xymon/cgi-bin/hostgraphs.sh
libexec/xymon/cgi-bin/hostlist.sh
libexec/xymon/cgi-bin/nongreen.sh
libexec/xymon/cgi-bin/notifications.sh
libexec/xymon/cgi-bin/perfdata.sh
libexec/xymon/cgi-bin/report.sh
libexec/xymon/cgi-bin/reportlog.sh
libexec/xymon/cgi-bin/showgraph.sh
libexec/xymon/cgi-bin/snapshot.sh
libexec/xymon/cgi-bin/svcstatus.sh
libexec/xymon/cgi-bin/topchanges.sh
libexec/xymon/cgi-secure/ackinfo.sh
libexec/xymon/cgi-secure/acknowledge.sh
libexec/xymon/cgi-secure/chpasswd.sh
libexec/xymon/cgi-secure/criticaleditor.sh
libexec/xymon/cgi-secure/enadis.sh
libexec/xymon/cgi-secure/useradm.sh
libexec/xymon/cgiwrap
libexec/xymon/chpasswd.cgi
libexec/xymon/combostatus
libexec/xymon/confreport.cgi
libexec/xymon/convertnk
libexec/xymon/criticaleditor.cgi
libexec/xymon/criticalview.cgi
libexec/xymon/csvinfo.cgi
libexec/xymon/datepage.cgi
libexec/xymon/enadis.cgi
libexec/xymon/eventlog.cgi
libexec/xymon/ext/xymonnet-again.sh
libexec/xymon/findhost.cgi
libexec/xymon/ghostlist.cgi
libexec/xymon/history.cgi
libexec/xymon/hostgraphs.cgi
libexec/xymon/hostlist.cgi
libexec/xymon/moverrd.sh
libexec/xymon/notifications.cgi
libexec/xymon/perfdata.cgi
libexec/xymon/report.cgi
libexec/xymon/reportlog.cgi
libexec/xymon/rrdcachectl
libexec/xymon/showgraph.cgi
libexec/xymon/snapshot.cgi
libexec/xymon/statusreport.cgi
libexec/xymon/svcstatus.cgi
libexec/xymon/trimhistory
libexec/xymon/useradm.cgi
libexec/xymon/xymon
libexec/xymon/xymon-mailack
${PLIST.snmp}libexec/xymon/xymon-snmpcollect
libexec/xymon/xymon.sh
libexec/xymon/xymoncfg
libexec/xymon/xymoncgimsg.cgi
libexec/xymon/xymoncmd
libexec/xymon/xymond
libexec/xymon/xymond_alert
libexec/xymon/xymond_capture
libexec/xymon/xymond_channel
libexec/xymon/xymond_client
libexec/xymon/xymond_distribute
libexec/xymon/xymond_filestore
libexec/xymon/xymond_history
libexec/xymon/xymond_hostdata
libexec/xymon/xymond_locator
libexec/xymon/xymond_rrd
libexec/xymon/xymond_sample
libexec/xymon/xymondigest
libexec/xymon/xymonfetch
libexec/xymon/xymongen
libexec/xymon/xymongrep
libexec/xymon/xymonlaunch
libexec/xymon/xymonnet
libexec/xymon/xymonpage
libexec/xymon/xymonping
libexec/xymon/xymonproxy
libexec/xymon/xymonreports.sh
man/man1/ackinfo.cgi.1
man/man1/acknowledge.cgi.1
man/man1/appfeed.cgi.1
man/man1/clientupdate.1
man/man1/combostatus.1
man/man1/confreport.cgi.1
man/man1/criticaleditor.cgi.1
man/man1/criticalview.cgi.1
man/man1/csvinfo.cgi.1
man/man1/datepage.cgi.1
man/man1/eventlog.cgi.1
man/man1/findhost.cgi.1
man/man1/ghostlist.cgi.1
man/man1/history.cgi.1
man/man1/hostgraphs.cgi.1
man/man1/logfetch.1
man/man1/orcaxymon.1
man/man1/report.cgi.1
man/man1/reportlog.cgi.1
man/man1/showgraph.cgi.1
man/man1/snapshot.cgi.1
man/man1/statusreport.cgi.1
man/man1/svcstatus.cgi.1
man/man1/xymon.1
man/man1/xymoncfg.1
man/man1/xymoncmd.1
man/man1/xymondigest.1
man/man1/xymongen.1
man/man1/xymongrep.1
man/man1/xymonnet-again.sh.1
man/man1/xymonnet.1
man/man1/xymonpage.cgi.1
man/man1/xymonping.1
man/man5/alerts.cfg.5
man/man5/analysis.cfg.5
man/man5/cgioptions.cfg.5
man/man5/client-local.cfg.5
man/man5/clientlaunch.cfg.5
man/man5/combo.cfg.5
man/man5/critical.cfg.5
man/man5/graphs.cfg.5
man/man5/hosts.cfg.5
man/man5/protocols.cfg.5
man/man5/tasks.cfg.5
man/man5/xymon-xmh.5
man/man5/xymonclient.cfg.5
man/man5/xymonserver.cfg.5
man/man5/xymonweb.5
man/man5/xymonwebaccess.5
man/man7/xymon.7
man/man8/enadis.cgi.8
man/man8/msgcache.8
man/man8/trimhistory.8
man/man8/xymon-mailack.8
man/man8/xymoncgimsg.cgi.8
man/man8/xymond.8
man/man8/xymond_alert.8
man/man8/xymond_capture.8
man/man8/xymond_channel.8
man/man8/xymond_client.8
man/man8/xymond_distribute.8
man/man8/xymond_filestore.8
man/man8/xymond_history.8
man/man8/xymond_hostdata.8
man/man8/xymond_rrd.8
man/man8/xymond_sample.8
man/man8/xymonfetch.8
man/man8/xymonlaunch.8
man/man8/xymonproxy.8
share/examples/xymon/alerts.cfg
share/examples/xymon/analysis.cfg
share/examples/xymon/cgioptions.cfg
share/examples/xymon/client-local.cfg
share/examples/xymon/columndoc.csv
share/examples/xymon/combo.cfg
share/examples/xymon/critical.cfg
share/examples/xymon/critical.cfg.bak
share/examples/xymon/graphs.cfg
share/examples/xymon/holidays.cfg
share/examples/xymon/hosts.cfg
share/examples/xymon/protocols.cfg
share/examples/xymon/rrddefinitions.cfg
share/examples/xymon/snmpmibs.cfg
share/examples/xymon/tasks.cfg
share/examples/xymon/www/gifs/README
share/examples/xymon/www/gifs/arrow.gif
share/examples/xymon/www/gifs/bkg-blue.gif
share/examples/xymon/www/gifs/bkg-clear.gif
share/examples/xymon/www/gifs/bkg-green.gif
share/examples/xymon/www/gifs/bkg-purple.gif
share/examples/xymon/www/gifs/bkg-red.gif
share/examples/xymon/www/gifs/bkg-yellow.gif
share/examples/xymon/www/gifs/blue-ack.gif
share/examples/xymon/www/gifs/blue-recent.gif
share/examples/xymon/www/gifs/blue.gif
share/examples/xymon/www/gifs/clear-recent.gif
share/examples/xymon/www/gifs/clear.gif
share/examples/xymon/www/gifs/favicon-blue.ico
share/examples/xymon/www/gifs/favicon-clear.ico
share/examples/xymon/www/gifs/favicon-green.ico
share/examples/xymon/www/gifs/favicon-purple.ico
share/examples/xymon/www/gifs/favicon-red.ico
share/examples/xymon/www/gifs/favicon-unknown.ico
share/examples/xymon/www/gifs/favicon-yellow.ico
share/examples/xymon/www/gifs/green-ack.gif
share/examples/xymon/www/gifs/green-recent.gif
share/examples/xymon/www/gifs/green.gif
share/examples/xymon/www/gifs/purple-ack.gif
share/examples/xymon/www/gifs/purple-recent.gif
share/examples/xymon/www/gifs/purple.gif
share/examples/xymon/www/gifs/red-ack.gif
share/examples/xymon/www/gifs/red-recent.gif
share/examples/xymon/www/gifs/red.gif
share/examples/xymon/www/gifs/unknown-recent.gif
share/examples/xymon/www/gifs/unknown.gif
share/examples/xymon/www/gifs/xymonbody.css
share/examples/xymon/www/gifs/yellow-ack.gif
share/examples/xymon/www/gifs/yellow-recent.gif
share/examples/xymon/www/gifs/yellow.gif
share/examples/xymon/www/gifs/zoom.gif
share/examples/xymon/www/help/Renaming-430.txt
share/examples/xymon/www/help/about.html
share/examples/xymon/www/help/bb-to-xymon.html
share/examples/xymon/www/help/clonewarn.jpg
share/examples/xymon/www/help/configure.txt
share/examples/xymon/www/help/criticalsystems.html
share/examples/xymon/www/help/critview-detail-acked.jpg
share/examples/xymon/www/help/critview-detail-ackform.jpg
share/examples/xymon/www/help/critview-detail.jpg
share/examples/xymon/www/help/critview-disk.jpg
share/examples/xymon/www/help/critview-green.jpg
share/examples/xymon/www/help/editor-clonemaster.jpg
share/examples/xymon/www/help/editor-diskchanged.jpg
share/examples/xymon/www/help/editor-disksetup.jpg
share/examples/xymon/www/help/editor-main.jpg
share/examples/xymon/www/help/editor-makeclone.jpg
share/examples/xymon/www/help/editor-nohost.jpg
share/examples/xymon/www/help/editor-showclone.jpg
share/examples/xymon/www/help/howtograph.html
share/examples/xymon/www/help/install.html
share/examples/xymon/www/help/known-issues.html
share/examples/xymon/www/help/mainview-acked.jpg
share/examples/xymon/www/help/mainview.jpg
share/examples/xymon/www/help/manpages/index.html
share/examples/xymon/www/help/manpages/man1/ackinfo.cgi.1.html
share/examples/xymon/www/help/manpages/man1/acknowledge.cgi.1.html
share/examples/xymon/www/help/manpages/man1/appfeed.cgi.1.html
share/examples/xymon/www/help/manpages/man1/clientupdate.1.html
share/examples/xymon/www/help/manpages/man1/combostatus.1.html
share/examples/xymon/www/help/manpages/man1/confreport.cgi.1.html
share/examples/xymon/www/help/manpages/man1/criticaleditor.cgi.1.html
share/examples/xymon/www/help/manpages/man1/criticalview.cgi.1.html
share/examples/xymon/www/help/manpages/man1/csvinfo.cgi.1.html
share/examples/xymon/www/help/manpages/man1/datepage.cgi.1.html
share/examples/xymon/www/help/manpages/man1/eventlog.cgi.1.html
share/examples/xymon/www/help/manpages/man1/findhost.cgi.1.html
share/examples/xymon/www/help/manpages/man1/ghostlist.cgi.1.html
share/examples/xymon/www/help/manpages/man1/history.cgi.1.html
share/examples/xymon/www/help/manpages/man1/hostgraphs.cgi.1.html
share/examples/xymon/www/help/manpages/man1/logfetch.1.html
share/examples/xymon/www/help/manpages/man1/orcaxymon.1.html
share/examples/xymon/www/help/manpages/man1/report.cgi.1.html
share/examples/xymon/www/help/manpages/man1/reportlog.cgi.1.html
share/examples/xymon/www/help/manpages/man1/showgraph.cgi.1.html
share/examples/xymon/www/help/manpages/man1/snapshot.cgi.1.html
share/examples/xymon/www/help/manpages/man1/statusreport.cgi.1.html
share/examples/xymon/www/help/manpages/man1/svcstatus.cgi.1.html
share/examples/xymon/www/help/manpages/man1/xymon.1.html
share/examples/xymon/www/help/manpages/man1/xymoncfg.1.html
share/examples/xymon/www/help/manpages/man1/xymoncmd.1.html
share/examples/xymon/www/help/manpages/man1/xymondigest.1.html
share/examples/xymon/www/help/manpages/man1/xymongen.1.html
share/examples/xymon/www/help/manpages/man1/xymongrep.1.html
share/examples/xymon/www/help/manpages/man1/xymonnet-again.sh.1.html
share/examples/xymon/www/help/manpages/man1/xymonnet.1.html
share/examples/xymon/www/help/manpages/man1/xymonpage.cgi.1.html
share/examples/xymon/www/help/manpages/man1/xymonping.1.html
share/examples/xymon/www/help/manpages/man5/alerts.cfg.5.html
share/examples/xymon/www/help/manpages/man5/analysis.cfg.5.html
share/examples/xymon/www/help/manpages/man5/cgioptions.cfg.5.html
share/examples/xymon/www/help/manpages/man5/client-local.cfg.5.html
share/examples/xymon/www/help/manpages/man5/clientlaunch.cfg.5.html
share/examples/xymon/www/help/manpages/man5/combo.cfg.5.html
share/examples/xymon/www/help/manpages/man5/critical.cfg.5.html
share/examples/xymon/www/help/manpages/man5/graphs.cfg.5.html
share/examples/xymon/www/help/manpages/man5/hosts.cfg.5.html
share/examples/xymon/www/help/manpages/man5/protocols.cfg.5.html
share/examples/xymon/www/help/manpages/man5/tasks.cfg.5.html
share/examples/xymon/www/help/manpages/man5/xymon-xmh.5.html
share/examples/xymon/www/help/manpages/man5/xymonclient.cfg.5.html
share/examples/xymon/www/help/manpages/man5/xymonserver.cfg.5.html
share/examples/xymon/www/help/manpages/man5/xymonweb.5.html
share/examples/xymon/www/help/manpages/man5/xymonwebaccess.5.html
share/examples/xymon/www/help/manpages/man7/xymon.7.html
share/examples/xymon/www/help/manpages/man8/enadis.cgi.8.html
share/examples/xymon/www/help/manpages/man8/msgcache.8.html
share/examples/xymon/www/help/manpages/man8/trimhistory.8.html
share/examples/xymon/www/help/manpages/man8/xymon-mailack.8.html
share/examples/xymon/www/help/manpages/man8/xymoncgimsg.cgi.8.html
share/examples/xymon/www/help/manpages/man8/xymond.8.html
share/examples/xymon/www/help/manpages/man8/xymond_alert.8.html
share/examples/xymon/www/help/manpages/man8/xymond_capture.8.html
share/examples/xymon/www/help/manpages/man8/xymond_channel.8.html
share/examples/xymon/www/help/manpages/man8/xymond_client.8.html
share/examples/xymon/www/help/manpages/man8/xymond_distribute.8.html
share/examples/xymon/www/help/manpages/man8/xymond_filestore.8.html
share/examples/xymon/www/help/manpages/man8/xymond_history.8.html
share/examples/xymon/www/help/manpages/man8/xymond_hostdata.8.html
share/examples/xymon/www/help/manpages/man8/xymond_rrd.8.html
share/examples/xymon/www/help/manpages/man8/xymond_sample.8.html
share/examples/xymon/www/help/manpages/man8/xymonfetch.8.html
share/examples/xymon/www/help/manpages/man8/xymonlaunch.8.html
share/examples/xymon/www/help/manpages/man8/xymonproxy.8.html
share/examples/xymon/www/help/stdview-detail-acked.jpg
share/examples/xymon/www/help/upgrade-to-430.txt
share/examples/xymon/www/help/xymon-alerts.html
share/examples/xymon/www/help/xymon-apacheconf.txt
share/examples/xymon/www/help/xymon-clients.png
share/examples/xymon/www/help/xymon-config.html
share/examples/xymon/www/help/xymon-hosts.png
share/examples/xymon/www/help/xymon-mrtg.html
share/examples/xymon/www/help/xymon-tips.html
share/examples/xymon/www/help/xymonmain.png
share/examples/xymon/www/help/xymonprocs.png
share/examples/xymon/www/menu/b2t-blue.gif
share/examples/xymon/www/menu/b2t-grey.gif
share/examples/xymon/www/menu/t2b-blue.gif
share/examples/xymon/www/menu/t2b-grey.gif
share/examples/xymon/www/menu/xymonmenu-blue.css
share/examples/xymon/www/menu/xymonmenu-grey.css
share/examples/xymon/xymon-apache.conf
share/examples/xymon/xymonmenu.cfg
share/examples/xymon/xymonserver.cfg
share/xymon/web/acknowledge_footer
share/xymon/web/acknowledge_form
share/xymon/web/acknowledge_header
share/xymon/web/acknowledgements_footer
share/xymon/web/acknowledgements_form
share/xymon/web/acknowledgements_header
share/xymon/web/chpasswd_footer
share/xymon/web/chpasswd_form
share/xymon/web/chpasswd_header
share/xymon/web/columndoc_footer
share/xymon/web/columndoc_header
share/xymon/web/confreport_back
share/xymon/web/confreport_footer
share/xymon/web/confreport_front
share/xymon/web/confreport_header
share/xymon/web/critack_form
share/xymon/web/critedit_footer
share/xymon/web/critedit_form
share/xymon/web/critedit_header
share/xymon/web/critical_footer
share/xymon/web/critical_header
share/xymon/web/critmulti_header
share/xymon/web/divider_footer
share/xymon/web/divider_header
share/xymon/web/event_footer
share/xymon/web/event_form
share/xymon/web/event_header
share/xymon/web/findhost_footer
share/xymon/web/findhost_form
share/xymon/web/findhost_header
share/xymon/web/ghosts_footer
share/xymon/web/ghosts_header
share/xymon/web/graphs_footer
share/xymon/web/graphs_header
share/xymon/web/hist_footer
share/xymon/web/hist_header
share/xymon/web/histlog_footer
share/xymon/web/histlog_header
share/xymon/web/hostgraphs_footer
share/xymon/web/hostgraphs_form
share/xymon/web/hostgraphs_header
share/xymon/web/hostlist_footer
share/xymon/web/hostlist_form
share/xymon/web/hostlist_header
share/xymon/web/hostsvc_footer
share/xymon/web/hostsvc_header
share/xymon/web/info_footer
share/xymon/web/info_header
share/xymon/web/maint_footer
share/xymon/web/maint_form
share/xymon/web/maint_header
share/xymon/web/maintact_footer
share/xymon/web/maintact_header
share/xymon/web/notify_footer
share/xymon/web/notify_form
share/xymon/web/notify_header
share/xymon/web/perfdata_footer
share/xymon/web/perfdata_form
share/xymon/web/perfdata_header
share/xymon/web/replog_footer
share/xymon/web/replog_header
share/xymon/web/repnormal_footer
share/xymon/web/repnormal_header
share/xymon/web/report_footer
share/xymon/web/report_form
share/xymon/web/report_form_daily
share/xymon/web/report_form_monthly
share/xymon/web/report_form_weekly
share/xymon/web/report_header
share/xymon/web/snapcritical_footer
share/xymon/web/snapcritical_header
share/xymon/web/snapnongreen_footer
share/xymon/web/snapnongreen_header
share/xymon/web/snapnormal_footer
share/xymon/web/snapnormal_header
share/xymon/web/snapshot_footer
share/xymon/web/snapshot_form
share/xymon/web/snapshot_header
share/xymon/web/stdcritical_footer
share/xymon/web/stdcritical_header
share/xymon/web/stdnongreen_footer
share/xymon/web/stdnongreen_header
share/xymon/web/stdnormal_footer
share/xymon/web/stdnormal_header
share/xymon/web/topchanges_footer
share/xymon/web/topchanges_form
share/xymon/web/topchanges_header
share/xymon/web/trends_footer
share/xymon/web/trends_form
share/xymon/web/trends_header
share/xymon/web/useradm_footer
share/xymon/web/useradm_form
share/xymon/web/useradm_header
share/xymon/web/zoom.js