Commit graph

23406 commits

Author SHA1 Message Date
Wen Heping
3d94e7c664 - Pass maintainership to submitter
PR:		210646
Submitted by:	yuri@rawbw.com
2016-06-28 01:35:24 +00:00
Wen Heping
698bbd3adb - Pass maintainership to submitter
PR:		210646
Submitted by:	yuri@rawbw.com
2016-06-28 00:48:01 +00:00
Rene Ladan
a01b22a052 Reset ports maintained by bf@ until he has time again to work on them.
PR:		210474
Submitted by:	jbeich
With hat:	portmgr-secretary
2016-06-27 21:30:34 +00:00
Kurt Jaeger
665abd49cf security/doas: 5.9p1 -> 5.9p2
- fixed a bug where, when the user authenticates successfully as root,
  only the user's effective user id (euid) becomes zero (0).
  This leads to file permission errors when performing upgrades or
  other file-oriented operations.
- introduced gmake as a dependency as it is needed to process upstream's
  makefile.

PR:		210596
Submitted by:	jsmith@resonatingmedia.com (maintainer)
2016-06-27 18:58:52 +00:00
Hajimu UMEMOTO
95a8532354 Insert tab. No functional change. 2016-06-27 16:35:24 +00:00
Mathieu Arnold
06b4ea3876 Replace bsd.openssl.mk with USES=ssl
Add a qa hint about needing, or not, USES=ssl.

Fix ports doing silly things, like including bsd.openssl.mk directly.

PR:		210322
Submitted by:	mat
Exp-run by:	antoine
Sponsored by:	Absolight
Differential Revision:	https://reviews.freebsd.org/D6866
2016-06-27 11:31:10 +00:00
Hajimu UMEMOTO
5be1ac2b13 Add new port -- YubiKey PIV Manager
Tool for configuring your PIV-enabled YubiKey.
2016-06-27 10:07:14 +00:00
Ryan Steinmetz
59ec42f63e - Update to 5.33 2016-06-27 00:23:14 +00:00
Jason Unovitch
1a2f0c90a9 Document remote denial of service via FileUpload component in Tomcat
PR:		209669 [1]
Reported by:	Geoffroy Desvernay <dgeo@centrale-marseille.fr> [1]
Reported by:	Roger Marquis <marquis@roble.com>
Security:	CVE-2016-3092
Security:	https://vuxml.FreeBSD.org/freebsd/cbceeb49-3bc7-11e6-8e82-002590263bf5.html
2016-06-26 18:13:40 +00:00
Sunpoet Po-Chuan Hsieh
96d68f1b99 - Update to 1.11.1
Changes:	https://github.com/capistrano/sshkit/blob/master/CHANGELOG.md
2016-06-26 17:23:45 +00:00
Sunpoet Po-Chuan Hsieh
8e5bf17fb0 - Update to 2.2.0
Changes:	https://github.com/google/oauth2client/releases
		https://github.com/google/oauth2client/blob/master/CHANGELOG.md
2016-06-26 17:16:31 +00:00
Sunpoet Po-Chuan Hsieh
e14a27169e - Update to 1.058
Changes:	http://search.cpan.org/dist/Net-SSLGlue/Changes
2016-06-26 17:15:46 +00:00
Jason Unovitch
1561ed7189 Document Wordpress vulnerabilities fixed in 4.5.3
PR:             210480 [1]
PR:             210581
Reported by:	Mihail Timofeev <9267096@gmail.com> [1]
Security:	CVE-2016-5832
Security:	CVE-2016-5833
Security:	CVE-2016-5834
Security:	CVE-2016-5835
Security:	CVE-2016-5836
Security:	CVE-2016-5837
Security:	CVE-2016-5838
Security:	CVE-2016-5839
Security:	https://vuxml.FreeBSD.org/freebsd/bfcc23b6-3b27-11e6-8e82-002590263bf5.html
2016-06-25 23:17:46 +00:00
Jason Unovitch
777e8f5f5c Docment security issues fixed in PHP 7.0.8, 5.6.23, and 5.5.37
PR:		210491
PR:		210502
Reported by:	Vladimir Krstulja <vlad-fbsd@acheronmedia.com>
Reported by:	Philip Jocks <freebsdbugs@filis.org>
Security:	CVE-2015-8874
Security:	CVE-2016-5766
Security:	CVE-2016-5767
Security:	CVE-2016-5768
Security:	CVE-2016-5769
Security:	CVE-2016-5770
Security:	CVE-2016-5771
Security:	CVE-2016-5772
Security:	CVE-2016-5773
Security:	https://vuxml.FreeBSD.org/freebsd/66d77c58-3b1d-11e6-8e82-002590263bf5.html
2016-06-25 22:18:23 +00:00
Ollivier Robert
c18e71f49d Fix filename in distinfo.
PR:		210553
Submitted by:	t@tobik.me
2016-06-25 11:41:18 +00:00
Hajimu UMEMOTO
af3fd373da Add new port -- Yubico PIV tool
The Yubico PIV tool is used for interacting with the Privilege and
Identification Card (PIV) application on a YubiKey.

With it you may generate keys on the device, importing keys and
certificates, and create certificate requests, and other operations. A
shared library and a command-line tool is included.
2016-06-25 11:11:13 +00:00
Antoine Brodin
77b7623135 Hook doas to the build 2016-06-25 07:59:49 +00:00
Ollivier Robert
1a4601bd17 Change PORTREVISION to something sensible as upstream did not change.
Reported by:	mat
2016-06-24 23:17:39 +00:00
Bernard Spil
6a8398dd65 security/py-certbot: Complete renaming from letsencrypt
- Rename relevant occurences in pkg-descr and pkg-message

PR:		210508
2016-06-24 21:21:08 +00:00
Ollivier Robert
33d3d55396 Missed the fact that ${ETCDIR} includes the port's name.
Submitted by:	@mordin_ on Twitter.
2016-06-24 21:00:07 +00:00
Ollivier Robert
d0474ec82b Update to commit 720db72 to fix a security issue.
Reported by:	Bryan Steele (@canadianbryan on Twitter)
2016-06-24 20:34:30 +00:00
Jan Beich
bb2dc31bc5 security/nss: update to 3.25
Changes:	https://developer.mozilla.org/docs/Mozilla/Projects/NSS/NSS_3.25_release_notes
2016-06-24 15:14:56 +00:00
Ollivier Robert
f93bc3ba8f New port: security/doas
The doas program allows users to run commands as another user (usually
root). The doas program was written by the OpenBSD team to provide a
lightweight, simplified (and more secure) alternative to the sudo command.

Original upstream (OpenBSD) source:
http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/doas/

FreeBSD version: https://github.com/slicer69/doas

NOTE: I added the two patch files to workaround issues mentioned in the PR
about hardcoding of /usr/local.

PR:		210473
Submitted by:	jsmith@resonatingmedia.com
Modified by:	jrm@ftfl.ca (see PR) and me (roberto)
2016-06-24 00:07:13 +00:00
Grzegorz Blach
a4d75e55ce Update to 2.5 2016-06-23 17:21:52 +00:00
Mark Felder
9a1238559a Fix vuxml
I didn't validate after updating "foo reports:" line

Pointyhat:	me
2016-06-23 16:55:18 +00:00
Mark Felder
ba1a8bd8c2 Document libarchive vulnerabilities
PR:		210493
Security:	CVE-2015-8934
Security:	CVE-2016-4300
Security:	CVE-2016-4301
Security:	CVE-2016-4302
2016-06-23 16:25:47 +00:00
Mark Felder
5439f8dea9 Add piwik XSS to vuxml
No further information is available. No CVE has been assigned.

PR:		210458
2016-06-23 15:52:40 +00:00
Bernard Spil
d7c96981b8 security/py-certbot: Rename from py-letsencrypt and update
- Move security/py-letsencrypt to security/py-certbot
  - Update security/py-acme to 0.8.1
  - Update security/py-certbot to 0.8.1
  - Update python dependencies

PR:		209584
2016-06-23 10:22:35 +00:00
Torsten Zuehlsdorff
8b62234838 Change all occurrences of xmj@chaot.net to johannes@perceivon.net as the owner requested.
This only affects "Created by" lines with one exception: devel/uclcmd. There the maintainer is changed. This was overlooked in r416918.

Approved by: junovitch (mentor)
2016-06-23 09:48:53 +00:00
Baptiste Daroussin
7361664043 Prefer relative symlinks to make the package relocation friendly 2016-06-23 06:36:18 +00:00
Ryan Steinmetz
cc6fd7f10e - Update to 2.9.8.3 2016-06-23 01:56:42 +00:00
Renato Botelho
89ace70eb9 Update security/sudo to 1.8.17p1
MFH:		2016Q2
Sponsored by:	Rubicon Communications (Netgate)
2016-06-23 00:55:19 +00:00
Jan Beich
2d4c884669 security/tor-devel: update to 0.2.8.4.r
Changes:	https://blog.torproject.org/blog/tor-0284-rc-released
PR:		210348
Submitted by:	Neel Chauhan <neel@neelc.org>
Approved by:	previous timeouts
2016-06-22 15:50:23 +00:00
Jan Beich
c12acdb82b security/eschalot: add new port
PR:		210378
Submitted by:	yuri@rawbw.com

Echalot is a TOR hidden service name generator, it allows one to produce
a (partially) customized vanity .onion address using a brute-force method.

https://github.com/ReclaimYourPrivacy/eschalot
2016-06-22 15:02:01 +00:00
Mathieu Arnold
59bc68ef23 Update to 0.17.
Sponsored by:	Absolight
2016-06-22 13:36:27 +00:00
Edward Tomasz Napierala
0bd3b5d00e Drop maintainership for some of my ports. 2016-06-22 10:12:46 +00:00
Vanilla I. Shu
67b1a1ccf6 Update to 0.037. 2016-06-21 15:50:23 +00:00
Mathieu Arnold
62a3c066e0 Update to 0.80.
Sponsored by:	Absolight
2016-06-21 15:09:17 +00:00
Mathieu Arnold
48af9870f3 Update to 1.205.
Sponsored by:	Absolight
2016-06-21 15:09:12 +00:00
Mathieu Arnold
8991bc11bd Update to 0.161520.
Sponsored by:	Absolight
2016-06-21 15:09:04 +00:00
Mathieu Arnold
95a28e9c7a Rename all three p5-ReadLine-(Gnu,Perl,TTYtter) to their real names
p5-Term-ReadLine-(Gnu,Perl,TTYtter).

I can't find any reason for p5-ReadLine-Gnu to have been added as
ReadLine-Gnu instead of Term-ReadLine-Gnu twenty years ago.

devel/p5-Term-ReadLine-Perl was added as a dupplicate a few years back
where it should not have, so change its maintainer to be perl@ like
devel/p5-ReadLine-Perl had.

Sponsored by:	Absolight
2016-06-21 13:24:53 +00:00
Vasil Dimov
98a80a35b5 Followup to r417190 - all versions of wget<1.18 are affected 2016-06-21 08:34:27 +00:00
Vasil Dimov
ed08cac60a Document ftp/wget's HTTP to FTP redirection file name confusion vulnerability
PR:		210420
Submitted by:	Vladimir Krstulja <vlad-fbsd@acheronmedia.com>
Security:	CVE-2016-4971
2016-06-21 08:16:47 +00:00
Dirk Meyer
e7994cc754 - fix possible integer overflow and application crash
Security: CVE-2016-2177
MFH:		2016Q2
2016-06-20 19:16:43 +00:00
Mark Felder
aade2eccbb Update vuxml for libxslt vulnerabilities
These vulnerabilities were previously reported by Google as they bundle
libxslt with Chrome. When we patched Chromium to address these
vulnerabilites it was overlooked that we do not bundle libxslt library
with Chromium, but instead use textproc/libxslt. Chromium users have
continued to be vulnerable to these CVEs as a result. This update fixes
the Chromium CVE entry and adds a separate one for libxslt.

PR:		210298
Security:	CVE-2016-1683
Security:	CVE-2016-1684
2016-06-20 19:08:31 +00:00
Tijl Coosemans
e079e58681 Update Linux ports to Centos 6.8.
PR:		210373
Submitted by:	Piotr Kubaj <pkubaj@anongoth.pl>
Differential Revision:	https://reviews.freebsd.org/D6891
2016-06-20 17:13:26 +00:00
Mathieu Arnold
7ae7b018cc With the power of USES=dos2unix, get rid of most patches and files
with CRLF.

While there, run make makepatch, rename patches to use the new scheme,
and various fixes.

With hat:	portmgr
Sponsored by:	Absolight
2016-06-20 16:23:28 +00:00
Cy Schubert
becd50be04 Update 1.8.16 --> 1.8.17
PR:		210407
Submitted by:	cy@
Approved by:	garga@
MFH:		2016Q2
2016-06-20 14:03:03 +00:00
Alex Dupre
0a4722baff Update to 0.16.0 release.
PR:		210406
Submitted by:	cmt
2016-06-20 10:55:33 +00:00
Jun Kuriyama
a96d0cea62 - Upgrade to 2.1.13 (minor bugfixes). 2016-06-20 10:49:47 +00:00