Commit graph

5933 commits

Author SHA1 Message Date
Simon L. B. Nielsen
ba0075a7a9 Document a format string vulnerability in the apache13 mod_ssl proxy
support.

Approved by:	nectar
2004-10-17 16:38:25 +00:00
Simon L. B. Nielsen
8a254b84a0 - Change a few uses of <url> into <mlist>.
OK'ed by:	nectar

Additional comment to the Tor entry from v. 1.302, it was:

Submitted by:	rik <freebsd-security@rikrose.net> (original version)
2004-10-16 20:31:23 +00:00
Pav Lucistnik
02fff24267 - Quick update to 0.0.8.1, bugfix release, because 0.0.8 was removed
from distsite

Reported by:	Dead Microprocessor <dead.microprocessor@gmail.com>
2004-10-16 16:11:39 +00:00
Pav Lucistnik
45636cdeb0 - Update to 1.8.12 and unbreak on 5.x
PR:		ports/72750
Submitted by:	David Thiel <lx@redundancy.redundancy.org> (maintainer)
2004-10-16 11:56:24 +00:00
Yen-Ming Lee
af86081561 Add clamassassin
Clamassassin is a simple virus filter wrapper for ClamAV for use in procmail
filters and similiar applications. Clamassassin's interface is similiar to
that of spamassassin, making it easy to implement for those familiar with
that tool. Clamassassin is designed with an emphasis on security, robustness
and simplicity.

PR:		72698
Submitted by:	Matt <matt@xtaz.net>
2004-10-16 01:26:41 +00:00
Simon L. B. Nielsen
c8c999eb92 - Document remote DoS and loss of anonymity in Tor.
- Update a Samba entry with new information about vulnerable versions.

Approved by:	nectar
2004-10-15 21:21:08 +00:00
Oliver Lehmann
aac49f07a4 [1]:
- Remove USE_GMAKE (builds okay here with BSD make)
        - Clean up portions of main Makefile (don't need post/pre)
        - Add %%PREFIX%% man page patches
        - Add patch for ipv6_missing.h; removes EAI_MEMORY
          re-definition warnings, and is more FreeBSD-focused
        - Support 'oidentd_conf' rc.subr variable for those who want to
          be able to specify a configuration file.  Also update the
          'required_files' code to work with this too...

[2]:
        - make it work with FreeBSD-5 in combination with option  --reply

PR:		ports/71378 [1]
Submitted By:	Jeremy Chadwick <freebsd@jdc.parodius.com> [1]
Noted By:	Markus Hästbacka <midian@ihme.org> [2]
2004-10-15 17:44:18 +00:00
Kirill Ponomarev
3ed0900d70 Update to 2.4.2.1
PR:		ports/72740
Submitted by:	maintainer
2004-10-15 17:41:04 +00:00
Ade Lovett
0d9fe4811f Kill off automake18, switching to automake19. Requiem Mors Pacem. 2004-10-15 17:32:46 +00:00
Pav Lucistnik
0f1724b9b9 - Don't clobber portsentry.ignore on upgrade
PR:		ports/72689
Requested by:	Alex de Kruijff <freebsd@akruijff.dds.nl>
2004-10-15 16:26:46 +00:00
Clement Laforet
9a353433fd - pwauth must have a SUID bit 2004-10-15 07:48:24 +00:00
Jun Kuriyama
0a13418dd5 - Reduce dependency with perl-5.8.
- Remove bogus space.
2004-10-14 22:23:49 +00:00
Jeremy Messenger
d63f58bc34 -Update to 2.1.3.
-Fix handling of default configuration files (nessusd.conf and nessusd.rules)

PR:		ports/71899
Submitted by:	Udo Schweigert <udo.schweigert@siemens.com> (maintainer)
2004-10-14 21:19:43 +00:00
Joe Marcus Clarke
e6733e191f Update to 0.3.4.
PR:		72679
Submitted by:	maintainer
2004-10-14 18:47:07 +00:00
Jacques Vidrine
d8970b85eb lesstif has been upgraded to a version that is not affected by the
libXpm vulnerability.
2004-10-14 17:52:41 +00:00
Simon L. B. Nielsen
8bb90c2570 Recommit my changes from 1.298 which was accidently removed in 1.299.
Pointy hat to:	josef (who also noticed the problem)
2004-10-14 17:06:55 +00:00
Josef El-Rayes
6ed5232306 Document two seperate security vulnerabilities in
icecast1 and icecast2.

Approved by:	nectar
2004-10-14 16:55:27 +00:00
Simon L. B. Nielsen
cd9281d63e Change the Xerces-C++ entry to match the xerces-c2 port.
Noticed by:	nectar
2004-10-14 16:46:39 +00:00
James E. Housley
3bb4a284ac Update to DAT 4399 2004-10-14 16:17:11 +00:00
Cheng-Lung Sung
dab65494b8 - bump PORTREVISION
- -d option only works as a daemon now.
- remove it from startup script and wait for future release.
- Noticed by <richard AT boysoncom dot com>

Approved by:	co-mentor (vanilla)
2004-10-14 12:31:22 +00:00
Oliver Eikemeier
70ec1e0cb9 - update to 0.80rc4
+ JPEG comment exploit (MS04-028) detection

  *** IMPORTANT ***
  The configruration file for the clamd daemon has changed from
  /usr/local/etc/clamav.conf to /usr/local/etc/clamd.conf.

PR:		72203
Approved by:	Rob Evers <revers@infraqon.nl> (maintainer)
2004-10-14 09:30:47 +00:00
Clement Laforet
98c26311be Add security/pwauth 2.2.8,
A Unix Web Authenticator.
2004-10-14 08:39:54 +00:00
Vanilla I. Shu
184e972a64 Upgrade to 2.1.2.
PR:		ports/71907
Submitted by:	maintainer
2004-10-14 07:02:00 +00:00
Vanilla I. Shu
1949acfa78 Upgrade to 2.0.2
PR:		ports/71263
Submitted by:	maintainer
2004-10-14 06:42:13 +00:00
Vanilla I. Shu
fc0d04e721 Upgrade to 2.0.2.
PR:		ports/71262
Submitted by:	maintainer
2004-10-14 06:39:44 +00:00
Dirk Meyer
24a3891634 - drop maintainership 2004-10-14 05:29:11 +00:00
Dirk Meyer
bedbfc6a1e - add a line why this port exist
- drop maintainership
2004-10-14 05:25:50 +00:00
Cheng-Lung Sung
267ea11079 - update to 0.9.6
- use configure file since 0.8
- lots of options move from rc_sub to conf file

Approved by:	co-mentor (vanilla)
2004-10-14 02:28:25 +00:00
Josef El-Rayes
6851294cd9 Document vulnerability in freeradius.
Approved by:	nectar
2004-10-13 22:00:20 +00:00
Simon L. B. Nielsen
74565720cf - Document DoS in Xerces-C++.
- Fix typo in a mozilla entry.

Approved by:	nectar
2004-10-13 21:50:58 +00:00
Jacques Vidrine
fe3ca65906 It turns out that lesstif has libXpm sneakily embedded. There are at
least three files with this comment at the top:

  * This file contains most of the source files of Xpm, concatenated and with
  * the public names changed (to have an _LtXpm prefix).
2004-10-13 21:12:02 +00:00
Simon L. B. Nielsen
2c8903f2fb Document XSS in wordpress.
Approved by:	nectar
2004-10-13 21:01:12 +00:00
Jacques Vidrine
b6fa2d612e Document integer overflows in libtiff. 2004-10-13 20:39:47 +00:00
Simon L. B. Nielsen
46ce8d4a7b - Document a CUPS local information disclosure.
- Note the impact of the sharutils buffer overflows.

Approved by:	nectar
2004-10-13 17:18:02 +00:00
Josef El-Rayes
cfeccaf435 Document a vulnerability in Zinf (freeamp).
Approved by:	nectar
2004-10-13 16:55:35 +00:00
James E. Housley
6f5563f48a Update to DAT 4398 2004-10-13 16:41:13 +00:00
Pav Lucistnik
390ac6179c - Update to 20041012
PR:		ports/72562
Submitted by:	Tim Bishop <tim@bishnet.net> (maintainer)
2004-10-13 16:11:37 +00:00
Pav Lucistnik
abefd834cf - Update to 4.4.7
PR:		ports/72561
Submitted by:	Tim Bishop <tim@bishnet.net> (maintainer)
2004-10-13 16:10:53 +00:00
Jacques Vidrine
33aa31f3d7 Document libtiff RLE decoder issues. 2004-10-13 16:06:33 +00:00
Kirill Ponomarev
2130669c32 Update to 1.33
PR:		ports/72597
Submitted by:	maintainer
2004-10-13 13:57:23 +00:00
Oliver Eikemeier
7365946a23 - update to version 3.71-PRE1 2004-10-13 13:52:54 +00:00
Markus Brueffer
000b5a807e Update to version 1.5
PR:		ports/72452
Submitted by:	Frank J. Laszlo <laszlof@vonostingroup.com> (maintainer)
2004-10-13 13:49:53 +00:00
Simon L. B. Nielsen
775a8024eb The sharutils buffer overflows has been fixed in sharutils 4.2.1_2. 2004-10-13 10:27:32 +00:00
Sergei Kolobov
25d5793be7 - Update to 1.0.21
- Make security/libtasn1 and security/opencdk into optional dependencies,
  enabled by knobs: WITH_LIBTASN1 and WITH_OPENCDK, respectively.
  Default to using their included versions
2004-10-13 09:08:06 +00:00
Tilman Keskinoz
a8f55bd2f9 Use libtool 15 2004-10-13 07:59:41 +00:00
Michael Nottebrock
4b2d90eef8 Adjust patch. 2004-10-13 03:03:40 +00:00
Edwin Groothuis
49a52357b8 Update: security/samhain 1.8.10b -> 1.8.11
Updating the Samhain integrity checking system from 1.8.10b to 1.8.11.

	Code changes include:

	o for files in the IgnoreAll policy, there are no warnings
	  (anymore) about 'no such user/group' and/or non-printable filenames
	o there is a new option HardlinkOffset=... to specify an
	  offset from the canonical hardlink count for a directory
	o ... and a new option AddOKChars=... to modify the set of
	  characters in a filename for which a warning (about
	  obscure/non-printable) filename is issued.

	Port changes:

	Turn off kernel integrity checking by default - building
	this into packages wouldn't work anyhow, since it would
	only work with an identical kernel as on the build cluster.

PR:		ports/71169
Submitted by:	David Thiel <lx@redundancy.redundancy.org>
2004-10-13 02:04:30 +00:00
Yen-Ming Lee
992f727a2a - add USE_GCC=2.95 and unbreak this port
- remove redundant statement

PR:		72127
Submitted by:	leeym
Approved by:	maintainer timeout
2004-10-13 01:49:45 +00:00
Simon L. B. Nielsen
c94d440a5f Document a vulnerability in sharutils.
Approved by:	nectar
2004-10-12 23:46:41 +00:00
Josef El-Rayes
015e40daad Document 2 DoS attacks possible against
older versions of mail-notifier.

Based on the security advisories
mentioned in the reference links.

Approved by:	nectar
2004-10-12 21:58:58 +00:00