Commit graph

16429 commits

Author SHA1 Message Date
Eygene Ryabinkin
ba15cdb935 VuXML: document cross-site scripting in SquidClamav 2012-08-25 11:37:59 +00:00
Eygene Ryabinkin
dceeb16c74 VuXML: document DoS in SquidGuard
SquidGuard can be crashed via the specially-crafted URL
when external URL checker is used.
2012-08-25 10:07:39 +00:00
Roman Bogorodskiy
898c7be42e - Properly define deprecated functions to remove warnings in other
ports
- Avoid installing multiple copies of the GPLv2 and LGPL21 licenses
- Bump PORTREVISION

PR:		170488
Submitted by:	Jason E. Hale <bsdkaffee@gmail.com>
Approved by:	Hirohisa Yamaguchi (maintainer)
2012-08-25 08:33:55 +00:00
Eygene Ryabinkin
4a6a3e8277 VuXML: document INN plaintext command injection vulnerability 2012-08-24 20:13:53 +00:00
Thomas Abthorpe
7a49f28845 - Reset maintainer due to mail bounces
With hat:	portmgr
2012-08-24 12:44:52 +00:00
Alex Dupre
78814883e7 Update to 1.12.5 release. 2012-08-23 14:56:42 +00:00
Tom Judge
fbdf0baff1 Upgrade to 4.41.
Changes: http://clamtk.sourceforge.net/CHANGES

Approved by:	eadler (mentor)
2012-08-23 03:09:32 +00:00
Eygene Ryabinkin
cfe35f60ca VuXML: document CVE-2012-3525 in jabberd 2.x 2012-08-22 21:10:10 +00:00
Eygene Ryabinkin
c810204482 VuXML: fix whitespace in my previous rssh entry 2012-08-22 20:01:19 +00:00
Eygene Ryabinkin
d000b2b27d VuXML: document rssh vulnerabilities fixed in version 2.3.3 2012-08-22 20:00:31 +00:00
Doug Barton
235e0c0890 Fix problem introduced in r302141. The directory for the unpacked source
files is unversioned, so it conflicts with the name of the rc.d script in
WRKDIR after SUB_FILES is applied.
2012-08-21 21:00:33 +00:00
Eygene Ryabinkin
2718265a6b rssh: document arbitrary code execution, CVE-2012-3478 2012-08-21 20:56:44 +00:00
Beat Gaetzi
df286e7d89 - Mark BROKEN: does not configure
configure: error: libgnutls is required in order to build libprelude.

Reported by:	pointyhat
2012-08-21 18:28:42 +00:00
Hiroki Sato
12aedcaf95 Update to v1.2.3. 2012-08-20 09:57:33 +00:00
Wesley Shields
b5f6705857 Put libotr entry back. I added the cited URL to the references. 2012-08-20 01:40:39 +00:00
Doug Barton
7e54cf1aa1 Remove the improperly formatted libotr entry. Someone with more knowledge
and experience needs to take care of this, I'm clearly not competent.
2012-08-19 21:47:45 +00:00
Olli Hauer
63f3e3b0d4 - remove www/apache20 and devel/apr0
- s/USE_APACHE= 20+/USE_APACHE= 22+/
- unify s/YES/yes/
- cleanup APACHE_VERSION <= 22 usage
- add entry to MOVED

with hat apache@
2012-08-18 14:29:08 +00:00
Doug Barton
6b3e2bd2ee 14 August 2012 libotr version 3.2.1 released
Versions 3.2.0 and earlier of libotr contain a small heap write overrun
(thanks to Justin Ferguson for the report), and a large heap read overrun
(thanks to Ben Hawkes for the report).

Add a vuxml entry, and tune up the notes about adding a new entry.
2012-08-18 08:39:39 +00:00
Wesley Shields
c9e0bf5215 Document OpenTTD DoS. 2012-08-18 03:07:42 +00:00
Wesley Shields
44a29d76f9 Document multiple wireshark vulnerabilities.
Two are from 1.8.1 (CVE-2012-4048 and CVE-2012-4049). The remaining are
from 1.8.2 which is not in ports yet.
2012-08-18 02:30:28 +00:00
Jason Helfman
9cf373f5ef The PostgreSQL Global Development Group today released security updates for all active branches
of the PostgreSQL database system, including versions 9.1.5, 9.0.9, 8.4.13 and 8.3.20. This
update patches security holes associated with libxml2 and libxslt, similar to those affecting
other open source projects. All users are urged to update their installations at the first
available opportunity.

This security release fixes a vulnerability in the built-in XML functionality, and a vulnerability
in the XSLT functionality supplied by the optional XML2 extension. Both vulnerabilities allow
reading of arbitrary files by any authenticated database user, and the XSLT vulnerability
allows writing files as well. The fixes cause limited backwards compatibility issues.
These issues correspond to the following two vulnerabilities:

CVE-2012-3488: PostgreSQL insecure use of libxslt
CVE-2012-3489: PostgreSQL insecure use of libxml2
This release also contains several fixes to version 9.1, and a smaller number of fixes to older versions, including:

Updates and corrections to time zone data
Multiple documentation updates and corrections
Add limit on max_wal_senders
Fix dependencies generated during ALTER TABLE ADD CONSTRAINT USING INDEX.
Correct behavior of unicode conversions for PL/Python
Fix WITH attached to a nested set operation (UNION/INTERSECT/EXCEPT).
Fix syslogger so that log_truncate_on_rotation works in the first rotation.
Only allow autovacuum to be auto-canceled by a directly blocked process.
Improve fsync request queue operation
Prevent corner-case core dump in rfree().
Fix Walsender so that it responds correctly to timeouts and deadlocks
Several PL/Perl fixes for encoding-related issues
Make selectivity operators use the correct collation
Prevent unsuitable slaves from being selected for synchronous replication
Make REASSIGN OWNED work on extensions as well
Fix race condition with ENUM comparisons
Make NOTIFY cope with out-of-disk-space
Fix memory leak in ARRAY subselect queries
Reduce data loss at replication failover
Fix behavior of subtransactions with Hot Standby
2012-08-17 19:39:51 +00:00
Wesley Shields
e31c65f93a Update to 1.8.5p3 2012-08-17 18:25:23 +00:00
Andrej Zverev
0b7ec36324 - dictionary.rfc2869 was missed from installation.
- bump PORTREVISION.

Reported by: Alexander Yamshanov <alexander@yamshanov.ru>
2012-08-17 09:43:22 +00:00
Matthew Seaman
40bb79cd29 Document the latest phpMyAdmin vulnerability PMSA-2012-4 2012-08-17 07:27:04 +00:00
Renato Botelho
b153af3794 Update to 20120815 2012-08-15 21:26:18 +00:00
Bryan Drewery
f4ebd140ed - Update www/typo3 to 4.7.4 [1]
- Convert to new options framework [1]
- Update www/typo345 to 4.5.19 [2]
- Update www/typo346 to 4.6.12 [3]
- Changes: https://typo3.org/news/article/typo3-4519-4612-and-474-released/
- Document security vulnerabilities [4]
  https://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2012-004/

PR:		ports/170650 [1]
PR:		ports/170647 [2]
PR:		ports/170649 [3]
Submitted by:	Helmut Schneider <jumper99@gmx.de> (maintainer)
Security:	48bcb4b2-e708-11e1-a59d-000d601460a4 [4]
Approved by:	eadler (mentor)
2012-08-15 19:45:50 +00:00
Thomas Abthorpe
83fc7a83ad - Reassign nork@ ports to the heap
- Thank you for your years of service, we hope to see you back

Approved by:	portmgr
2012-08-15 19:26:13 +00:00
Roman Bogorodskiy
68a1991ea3 - Drop automatic dependency detection [1]
- Do not link to -lphread directly [2]
- Use USE_PKGCONFIG [2]
- Pet portlint by removing ABI number references [2]
- Drop no longer actual --with-lzo=no switch, lzo support
  is disabled by default anyway [2]
- Bump PORTREVISION

PR:		170390 [2]
Submitted by:	Jason E. Hale [2], A.J. Kehoe IV (Nanoman) [1]
2012-08-15 13:57:01 +00:00
Matthias Andree
32fc11f5a8 Document CVE-2012-3482 for fetchmail, one DoS and one information disclosure
vulnerability in non-default NTLM code.

Also see ports/170613 which is pending maintainer feedback.
2012-08-14 23:17:56 +00:00
Thomas Abthorpe
d3fbddc569 - Reassign ports to the heap due to a mail bounce
With hat:	portmgr
2012-08-14 18:19:34 +00:00
Sofian Brabez
ad03b6f1fb - Update to 0.3.0
PR:		ports/170633
Submitted by:	Kubilay Kocak <koobs.freebsd at gmail.com> (maintainer)
2012-08-14 14:47:15 +00:00
Michael Scheidell
3e90241571 - Update security/gpa to 0.9.3 bugfix release
- Clean up COMMENT
- Drop ABI numbers from LIB_DEPENDS
- pkg-config is needed for build
- Make sure we are picking up version 2.x of gpg during configure
- Convert to OPTIONSng

PR:		ports/170570
Submitted by:	Jason E. Hale <bsdkaffee@gmail.com> (maintainer)
2012-08-14 12:01:37 +00:00
Jung-uk Kim
21a73f7f81 Belatedly add an entry for the recent IcedTea-Web updates. 2012-08-13 17:57:26 +00:00
Ruslan Makhmatkhanov
16483bfa1f Import Zope 2.13.16 and update this release required dependencies:
- devel/py-DateTime: 3.0b3 -> 3.0
- security/py-AccessControl: 2.13.7 -> 2.13.8
2012-08-13 16:26:38 +00:00
Jun Kuriyama
d18e4a3b19 Revert previous tty patch until matured. 2012-08-13 14:17:35 +00:00
Wen Heping
991f8397ec - Update to 1.6.1
- Adjust USE_PYTHON versions (Py3k ready)

PR:		170547
Submitted by:	Kubilay Kocak <koobs.freebsd@gmail.com> (maintainer)
2012-08-12 13:12:59 +00:00
Roman Bogorodskiy
533ecc2a4f Document libcloud MITM vuln.
Security:	CVE-2012-3446
2012-08-11 17:41:52 +00:00
Doug Barton
f7a26a6ba9 Fix post r302141: The files in USE_RC_SUBR are already included in SUB_FILES
I caught most of these, but missed this one, apologies
2012-08-11 10:59:54 +00:00
Matthew Seaman
b03266ae28 Document the latest phpmyadmin security problem. 2012-08-11 08:11:17 +00:00
Rene Ladan
34df9d85b1 - Document vulnerabilities in www/chromium 20.0.1132.57 and 21.0.1180.60.
- Keep the latest chromium vulnerabilies on top.
2012-08-10 14:38:47 +00:00
Rene Ladan
4e78c3b86e Document two vulnerabilities in www/chromium < 21.0.1180.75 related to the
builtin PDF viewer.

Obtained from:	http://googlechromereleases.blogspot.com/search/label/Stable%20updates
2012-08-10 08:08:27 +00:00
Steve Wills
b73b27a91a - Update rails and friends to 3.2.8
- Document security issue in 3.2.7 [1]

Submitted by:	bdrewery [1]
Reviewed by:	swills [1]
Security:	31db9a18-e289-11e1-a57d-080027a27dbf
2012-08-10 02:50:53 +00:00
Ryan Steinmetz
b4a6cb421f - Update to 2.9.3.1 2012-08-10 01:29:39 +00:00
Cy Schubert
d9852fb0c7 Secunia Advisory SA38292, ISS X-Force sudosh-replay-bo (55903), replay() function buffer overflow.
Security:	Secunia Advisory SA38292, ISS X-Force sudosh-replay-bo (55903)
2012-08-09 19:47:19 +00:00
Wesley Shields
2fdff35d2f Document old sudosh buffer overflow.
Noticed by:	Diego Linke
2012-08-09 15:43:08 +00:00
Wesley Shields
ca224f62a4 Fix up whitespace in 10f38033-e006-11e1-9304-000000000000.
Replace broken vid in 10f38033-e006-11e1-9304-000000000000 with one that is
correct.
2012-08-07 15:57:26 +00:00
Sunpoet Po-Chuan Hsieh
ede3b7e806 - Disable live tests (without prompt)
- Eliminate harmless library detection messages

Reported by:	Alexander Wittig <alexander@wittig.name>
2012-08-07 04:14:43 +00:00
Ryan Steinmetz
8102923545 - Document FreeBSD-SA-12:05.bind 2012-08-07 02:02:25 +00:00
Bryan Drewery
ae65c5073f Document CVE-2012-3386 for devel/automake
Approved by:	eadler (mentor)
2012-08-06 22:44:13 +00:00
Sunpoet Po-Chuan Hsieh
f0b2bdf083 - Update to 0.64
- Update LICENSE

Changes:	http://search.cpan.org/dist/Crypt-SSLeay/Changes
2012-08-06 19:16:18 +00:00