aboutsummaryrefslogtreecommitdiffstats
path: root/security
Commit message (Collapse)AuthorAgeFilesLines
* - Update security/clamav to 0.92garga2007-12-2011-18/+60
| | | | | | | | | | - Add a new OPTION (RAR) because unrar code is optional to fix a license issue - Some cosmetic changes - Chase library version bump and bump PORTREVISION of all dependant ports Approved by: portmgr (pav) Security: CVE-2007-6335, CVE-2007-6336, CVE-2007-6337
* Document wireshark -- multiple vulnerabilities.simon2007-12-201-0/+83
|
* Document opera -- multiple vulnerabilities.simon2007-12-201-0/+43
|
* Document peercast -- buffer overflow vulnerability.simon2007-12-201-0/+32
|
* - Update to 0.06gabor2007-12-202-4/+4
|
* - Update to 0.14gabor2007-12-202-4/+4
|
* - Replace -lc_r with ${PTHREAD_LIBS}pav2007-12-201-1/+1
| | | | Pointy hat to: pav
* Unbreak vuln.xml: & -> &simon2007-12-181-1/+2
| | | | Pointy hat to: brooks
* Upgrade to Ganglia 3.0.6.brooks2007-12-181-0/+28
| | | | | | | Release 3.0.5 contained minor bug fixes. 3.0.6 corrects XSS vulnerabilities in the webfrontend. Security: vid:fee7e059-acec-11dc-807f-001b246e4fdf
* XORSearchedwin2007-12-185-0/+61
| | | | | | | | | | | | | | | | | | | | | | XORSearch is a program to search for a given string in an XOR or ROL encoded binary file. An XOR encoded binary file is a file where some (or all) bytes have been XORed with a constant value (the key). A ROL (or ROR) encoded file has it bytes rotated by a certain number of bits (the key). XOR and ROL/ROR encoding is used by malware programmers to obfuscate strings like URLs. XORSearch will try all XOR keys (0 to 255) and ROL keys (1 to 7) when searching. I programmed XORSearch to include key 0, because this allows to search in an unencoded binary file (X XOR 0 equals X). If the search string is found, XORSearch will print it until the 0 (byte zero) is encountered or until 50 characters have been printed, which ever comes first. 50 is the default value, it can be changed with option -l. Unprintable characters are replaced by a dot. WWW: http://blog.didierstevens.com/programs/xorsearch/ Author: Didier Stevens
* - Utilize SF macrotabthorpe2007-12-171-2/+2
| | | | | | | - Pass maintainership to submitter PR: ports/118777 Submitted by: Philippe Audeoud <jadawin tuxaco.net>
* - Update to 0.2.0.12-alphamiwi2007-12-172-4/+4
| | | | | PR: 118699 Submitted by: Peter Thoenen <peter.thoenen@yahoo.com> (maintainer)
* - Convert rc scripts to the new style.araujo2007-12-166-43/+77
| | | | | | | | - Bump PORTREVISION. PR: ports/116966 Submitted by: Dave Grochowski <malus.x@gmail.com> (maintainer) Approved by: stas (mentor, implicit)
* - Update to 2.5.3gabor2007-12-162-4/+6
| | | | | | | | | | This is a maintainance release. Release notes: http://www.ijs.si/software/amavisd/release-notes.txt PR: ports/118631 [1], ports/118732 [2] Submitted by: Olli Hauer <ohauer@gmx.de> [1], Michael Scheidell <scheidell@secnap.net> [2]
* - Update to 3.05sat2007-12-162-4/+4
|
* - Update to 1.2.11johans2007-12-162-7/+10
|
* - Update to 0.4.13johans2007-12-162-7/+7
|
* - Update to 2.6.7johans2007-12-162-4/+4
|
* - List QT componentspav2007-12-151-3/+2
| | | | | | | - Try if it builds now PR: ports/117658 Submitted by: Mark D. Foster <mark@foster.cc> (maintainer)
* - Update to 0.7miwi2007-12-153-4/+5
| | | | | PR: 118028 Submitted by: Dave Grochowski <malus.x@gmail.com> (maintainer)
* Sort references section for last commit.remko2007-12-151-1/+2
|
* - Mark latest linux-firefox/seamonkey-devel snapshots as safesat2007-12-141-6/+20
| | | | | | - Add (linux-)flock and linux-*-devel to latest firefox advisory - Note that the tradition of covering more gecko ports with firefox-related advisories should probably be kept up
* - Chase libpurple shlib bumppav2007-12-132-2/+2
| | | | Pointy hat to: marcus
* Update pidgin to 2.3.1, and chase the shared lib version bump. Seemarcus2007-12-132-2/+2
| | | | http://developer.pidgin.im/wiki/ChangeLog for the list of changes.
* Document qemu -- Translation Block Local Denial of Service Vulnerabilitynox2007-12-131-0/+34
|
* - Update to 1.3.9miwi2007-12-133-6/+4
| | | | | PR: 118166 Submitted by: Linh Pham <question+fbsdports@closedsrc.org> (maintainer)
* Document drupal -- SQL injection vulnerabilityremko2007-12-121-0/+37
| | | | Submitted by: Nick Hilliard <nick at netability dot ie>
* Document samba -- buffer overflow vulnerability.remko2007-12-121-0/+36
|
* Remove redundant "A" in the latest entryremko2007-12-121-1/+1
|
* - Update to 20071212garga2007-12-123-11/+30
| | | | | | | | | | - Unrar code was removed from clamav source due to license problems, and a patch was created. I've added an UNRAR option, Off by default. - Cosmetic changes - Fix rc.d/clamav-milter to change socket permissions after startup. It fixes proclems when sendmail or postfix cannot connect to this socket. [1] Submitted by: Chris St Denis <chris@smartt.com> by email
* - Fix previous commitmiwi2007-12-121-6/+8
| | | | | - Sorting - more referencs
* - Missed a section - smbftpdbeech2007-12-121-1/+1
| | | | Pointyhat to: Self
* - Document smbftpd - format string vulnerability.beech2007-12-121-0/+27
| | | | | Requested by: linimon Approved by: linimon (mentor)
* Update to 2.20.2.marcus2007-12-122-5/+5
|
* - Update to 0.5.3sat2007-12-123-7/+12
|
* - Fix build on FreeBSD 8johans2007-12-121-0/+1
| | | | Reported by: pointyhat via pav
* Update to 0.18.lx2007-12-122-4/+4
|
* Update to 0.9.22 release.ale2007-12-122-4/+4
|
* Update to 2.4.1. Also fix a rather silly uninstall message, reportedlx2007-12-123-5/+5
| | | | by brd@.
* Update to 1.4.lx2007-12-124-12/+138
|
* Fix the build when net/lam installed in system.mezz2007-12-122-8/+8
| | | | | | PR: ports/117623 and ports/114871 Reported by: Alexander Vasyanin <avasyanin@mail.ru> Koji Yokota <yokota@res.otaru-uc.ac.jp>
* Document jetty - multiple vulnerabilitiesremko2007-12-101-0/+44
| | | | | | | PR: ports/118524 Submitted by: Nick Barkas <snb at threerings dot net> with minor modifications by me Approved by: portmgr (secteam blanket)
* Update to 2007.12.07 with fix security issue.nork2007-12-091-1/+2
| | | | | | | Security: VuXML ID: 821afaa2-9e9a-11dc-a7e3-0016360406fa CVE-2007-6036 http://aluigi.altervista.org/adv/live555x-adv.txt Approved by: portmgr (erwin)
* Document liveMedia -- DoS vulnerabilityremko2007-12-091-0/+34
| | | | | | Submitted by: Rafae«l Careé <funm at videolan dot org> with modifications by me Approved by: portmgr (secteam blanket)
* Update to reflect the squid issue has been assigneddelphij2007-12-071-1/+2
| | | | | | CVE-2007-6239. Approved by: portmgr (ports-security blanket)
* - Update gnu-finger entrymiwi2007-12-051-1/+1
| | | | | | * Fix cvename handling Approved by: portmgr (ports-security blanket)
* http://nvd.nist.gov/nvd.cfm?cvename=CVE-1999-1165: gnu-finger is old,linimon2007-12-051-0/+28
| | | | | | | creaky, and not for use in production environments. Submitted by: tabthorpe Approved by: portmgr (self)
* Update to reflect an updated www/squid30 version which is nodelphij2007-12-051-1/+1
| | | | | | longer vulnerable. Approved by: portmgr (ports-security blanket)
* - Chase rubygem-activerecord updatepav2007-12-051-1/+1
| | | | | | Missed by: miwi Reported by: pointyhat Approved by: portmgr (hat)
* Update to reflect an updated www/squid version which is nodelphij2007-12-051-1/+2
| | | | | | longer vulnerable. Approved by: portmgr (ports-security blanket)
* Document squid denial of service vulnerability. This can bedelphij2007-12-051-0/+31
| | | | | | triggered from trusted squid client only. Approved by: portmgr (ports-security blanket)
* PORTREVISION bump in support of pkg-plist revision 1.5.cy2007-12-041-1/+1
| | | | Approved by: portsmgr (ewin)
* Correct chmod location.cy2007-12-021-2/+2
| | | | Approved by: portmgr (linimon)
* Remove the rsync entry for now. Better way of handlingdelphij2007-12-021-39/+0
| | | | | | | | | this is still under discussion, as the vendor patch does not automatically resolve problem for customized configuration that have chroot = no. Requested by: pav Approved by: portmgr (ports-security blanket)
* Document rsync security bypass vulnerability.delphij2007-12-021-0/+39
| | | | Approved by: portmgr (ports-security blanket)
* Make the rubygem-rails -- JSON XSS vulnerability entry valid UTF-8 (atsimon2007-12-011-2/+2
| | | | | | | | least the special chars doesn't look like UTF-8 as per emacs or freshports). Reported by: freshports via dvl Approved by: portmgr (secteam blanket)
* - Update to 0.10lwhsu2007-12-013-4/+15
| | | | | | | | | - Unbreak on HEAD/7 (re-add a needed patch) PR: ports/118066 Submitted by: Peter Johnson <johnson.peter AT gmail.com> (maintainer) Reported by: pointyhat (pav) Approved by: portmgr (linimon)
* Also cover rubygem-activesupport which is part of rails and isdelphij2007-11-281-0/+5
| | | | | | affected by CVE-2007-3227 as well. Approved by: portmgr (ports-security blanket)
* Document recent Ruby On Rails vulnerabilities.delphij2007-11-281-0/+56
| | | | Approved by: portmgr (ports-security blanket)
* Document ikiwiki improper symlink verification vulnerability.brix2007-11-281-0/+29
| | | | | Reviewed by: remko Approved by: portmgr (erwin), erwin (mentor)
* Document firefox multiple unspecified memory corruption vulnerabilities.delphij2007-11-281-0/+39
| | | | Approved by: portmgr (ports-security blanket)
* Unbreak pthread-related issues on 5.xade2007-11-272-13/+3
| | | | Approved by: portmgr
* Mark as broken on 5.x: fails to find pthread.h.linimon2007-11-251-0/+5
| | | | | | | | | Something in the infrastructure changed in the late July timeframe that actually caused this problem. The only major thing at that time was the autoconf/libtool change, but I can't see how that could have caused this failure mode. It only happens on 5.x; 6.x and 7.x are fine. Approved by: portmgr (self)
* Mark as broken: fails to install.linimon2007-11-254-0/+8
| | | | Approved by: portmgr (self)
* Add sfsrwcd: clients cannot make connections without it.linimon2007-11-232-2/+3
| | | | | | Part of: ports/116966 Submitted by: maintainer, private email Approved by: portmgr (self)
* - Document phpmyadmin -- Cross Site Scriptingmiwi2007-11-221-0/+28
| | | | | Reviewed by: remko Approved by: portmgr (ports-security blanket
* - Update last Samba entry,miwi2007-11-211-1/+3
| | | | | | | | * Add reference to the samba advisories * Fix the PORTVERSION/PORTEPOCH Reviewed by: simon Approved by: portmgr (ports-security blanket)
* Document samba - multiple vulnerabilitiesmiwi2007-11-211-0/+40
| | | | | Reviewed by: remko Approved by: portmgr (ports-security blanket)
* Unmark broken; the missing Objective C header with gcc 4.2 has now beenlinimon2007-11-201-7/+1
| | | | | | | | fixed. PR: ports/117967 Submitted by: maintainer Approved by: portmgr (self)
* postnuke 0.763 is not vulnerable to 35f2679f-52d7-11db-8f1a-000a48049292delphij2007-11-181-2/+2
| | | | | | so mark it as not vulnerable. Approved by: portmgr (ports-security blanket)
* Improve JDK version coverage. We should consider PORTEPOCH'ed versiondelphij2007-11-171-4/+4
| | | | | | separately, so restruct the range. Approved by: portmgr (ports-security blanket)
* Document PHP multiple vulnerabilities that are fixed by php 5.2.5.delphij2007-11-171-0/+44
| | | | Approved by: portmgr (ports-security blanket)
* - Fix c93e4d41-75c5-11dc-b903-0016179b2dd5 entrymiwi2007-11-161-9/+8
| | | | | | Submitted by: glewis Reviewed by: remko Approved by: portmgr (ports-security blanket)
* print/cups-base is vulnerable for all previous versions toerwin2007-11-151-1/+1
| | | | | | | 1.3.3_2, not all coming ones. Submitted by: Andrew Daugherity <ADaugherity@vprmail.tamu.edu> Approved by: portmgr (self)
* - Fix build on FreeBSD 7johans2007-11-151-0/+1
| | | | | Reported by: pointyhead (via pav) Approved by: portmgr (pav)
* Document mt-daapd -- denial of service vulnerability, alsoremko2007-11-141-1/+36
| | | | | | | | | correct the previous entry style wise. Submitted by: Mark D. Foster <mark at foster dot cc> with minor modifications by me. Approved by: portmgr (secteam blanket)
* - Update xpdf -- multiple remote Stream.CC vulnerabilitiesmiwi2007-11-141-1/+2
| | | | | | * Mark cups-base as safe Approved by: portmgr (ports-security blanket)
* o Add a patch for CVE-2007-5846, and add an entry for vuxml.kuriyama2007-11-141-0/+25
| | | | Approved by: portmgr (marcus)
* - Document flac -- media file processing integer overflow vulnerabilitiesmiwi2007-11-131-0/+35
| | | | | | Reviewed by: simon Approved by: portsmgr (ports-security blanket) Thanks to: naddy
* Add an official fix for the chroot mode resolving bug.roam2007-11-133-0/+105
| | | | Approved by: portmgr (pav)
* Unbreak file by closing </li> tag.simon2007-11-131-1/+1
| | | | Approved by: portmgr (secteam blanket)
* Document xpdf arbitrary code execution vulnerability, as documented indelphij2007-11-131-0/+64
| | | | | | CVE-2007-4352, CVE-2007-5392, CVE-2007-5393. Approved by: portmgr (ports-security blanket)
* - Attempt to fix plist on 7.0pav2007-11-131-0/+3
| | | | | Reported by: pointyhat Approved by: portmgr (hat)
* - hcrypto library is only installed on FreeBSD < 7.0pav2007-11-132-23/+29
| | | | | Reported by: pointyhat Approved by: portmgr (hat)
* dinoex@ has choosen to apply a vendor patch that has resolved CVE-2007-4351delphij2007-11-131-1/+2
| | | | | | instead of upgrading to 1.3.4. Mark this updated version as not vulnerable. Approved by: portmgr (ports-security blanket)
* - Make fetchable again. Add my MASTER_SITE_LOCAL to the mix and replacetmclaugh2007-11-121-9/+7
| | | | | | | a number of outdated sites. Notified by: Ferenc Gartner Approved by: portmgr (linimon, erwin)
* Document plone arbitrary code execution vulnerability.delphij2007-11-121-0/+30
| | | | Approved by: portmgr (ports-security blanket)
* - Updated the last gftp entry (we have 2.0.18_6 in the portstree not 2.10.18_6)miwi2007-11-121-1/+2
| | | | | Submitted by: Fabian Keil (via private mail) Approved by: portmgr (ports-security blanket)
* - Document phpmyadmin -- cross-site scripting vulnerabilitymiwi2007-11-111-0/+30
| | | | | Reviewed by: simon Approved by: portmgr (ports-security blanket)
* Document gallery2 multiple vulnerabilities.delphij2007-11-101-0/+35
| | | | Approved by: portmgr (ports-security blanket)
* - Document tikiwiki -- multiple vulnerabilitiesmiwi2007-11-091-0/+50
| | | | | Reviewed by: simon Approved by: portmgr (ports-security blanket)
* Document cups-base remote buffer overflow vulnerability.delphij2007-11-091-0/+33
| | | | Approved by: portmgr (ports-security blanket)
* Make perl entry to cover perl-threaded as well.delphij2007-11-081-1/+6
| | | | | Reported by: Andy Greenwood <greenwood.andy gmail com> Approved by: portmgr (ports-security blanket)
* - Fix pkg-plistmiwi2007-11-082-9/+8
| | | | | Submitted by: pointyhat via linimon Approved by: portmgr (linimon)
* - After last update, sshit keeps exiting with signal 15 due to wrongrafan2007-11-072-5/+62
| | | | | | | | | | | | | hostname regexp. Fix the regexp for hostname matching. - While fixing that, fix IPv6 regexp, too. - Reduce syslog level from ERROR to INFO for most informational messages. These changes are submitted to author for inclusion in next version. - Grab maintainership as current maintainer does not use it anymore. - Bump PORTREVISION. Approved by: portmgr (linimon), maintainer via irc
* - Document perl -- regular expressions unicode data buffer overflowmiwi2007-11-071-0/+29
| | | | | Reviewed by: simon/tobez Approved by: portmgr (blanket) (ports-security blanket)
* Document pcre arbitrary code execution vulnerability.delphij2007-11-071-0/+37
| | | | Approved by: portmgr (ports-security blanket)
* - perdition entry - correct rangebeech2007-11-061-1/+1
| | | | Approved by: portmgr (pav) linimon (mentor)
* - Add entry for mail/perditionbeech2007-11-061-0/+31
| | | | | PR: ports/117796 Approved by: portmgr (pav), linimon (mentor)
* - gftp -- multiple vulnerabilitiesmiwi2007-11-061-0/+33
| | | | | Reviewed by: simom Approved by: portmgr (blanket) (ports-security blanket)
* - Update dirproxy -- remote denial of servicemiwi2007-11-051-1/+6
| | | | | | | | * Add net/dirproxy with the same affect * Update net/dirproxy-devel as safe Reviewed by: simon Approved by: portmgr (blanket) (ports-security blanket)
* - dirproxy -- remote denial of servicemiwi2007-11-041-0/+30
| | | | | Reviewed by: remko Approved by: portmgr (blanket) (ports-security blanket)
* - Fix discovery date on my previous commitmiwi2007-11-011-1/+1
| | | | Approved by: portmgr (ports-security blanket)
* - document wordpress -- cross-site scriptingmiwi2007-11-011-0/+36
| | | | | Reviewed by: simon Approved by: portmgr (ports-security blanket)
* Extend coverage to OpenLDAP 2.4.x series which is affected accordingdelphij2007-11-011-0/+2
| | | | | | to CVS history. Approved by: portmgr (ports-security blanket)
* Document openldap multiple vulnerabilities.delphij2007-11-011-0/+29
| | | | Approved by: portmgr (ports-security blanket)
* Bump modified date for entry updated in last commit.simon2007-11-011-1/+1
| | | | Approved by: portmgr (secteam blanket)
* Update vuxml to reflect that mod_jk and mod_jk-ap2 havegirgen2007-11-011-1/+4
| | | | | | different portepochs. Approved by: portmgr (pav)
* - Update mozilla -- code execution via Quicktime media-link filesmiwi2007-10-311-1/+2
| | | | | | | PR: 117704 Submitted by: John Hein <jhein@timing.com> Reviewed by: simon Approved by: portmgr (blanket) secteam (blanket via simon)
* gnutls-devel is now older than gnutls, so in order not to update or delete itnovel2007-10-311-0/+2
| | | | | | during the freeze, mark it IGNORE. Approved by: portmgr (linimon)
* Chase opencdk shared lib version change.novel2007-10-311-2/+3
| | | | Approved by: portmgr (pav) (as a part of security/opencdk commit)
* Update to 0.6.0 - the versioin compatible with the current versionnovel2007-10-314-17/+19
| | | | | | | of gnutls in ports. Therefore, it fixes the problem described in ports/117671. Approved by: portmgr (pav)
* - Update to 1.17miwi2007-10-302-7/+5
| | | | | PR: 117659 Submitted by: TAKAHASHI Kaoru <kaoru@kaisei.org> (maintainer)
* Update to 0.7.3lofi2007-10-302-5/+5
|
* - Update to version 2.0.2.alepulver2007-10-303-13/+19
| | | | | | - Update the NAT-T patch notice (in pre-everything). Submitted by: Matthew Grooms <mgrooms@shrew.net> (maintainer, via e-mail)
* Update to KDE 3.5.8lofi2007-10-304-6/+98
|
* Fix build for OpenSSL 0.9.8.cy2007-10-308-28/+20
| | | | | PR: 117552 Submitted by: Hirohisa Yamaguchi <umq@umo.co.jp>
* This program uses a brute force algorithm to guess your encryptedmiwi2007-10-304-0/+40
| | | | | | | | | | | compressed file's password. If you forget your encrypted file password, this program is the solution. This program can crack zip,7z and rar file passwords. WWW: http://sourceforge.net/projects/rarcrack PR: ports/117630 Submitted by: Philippe Audeoud <jadawin at tuxaco.net>
* Fix build under 7.0-PRERELEASE.cy2007-10-3012-4/+76
|
* - Update www and master sitessat2007-10-302-12/+7
|
* Update to 1.1.novel2007-10-302-4/+4
|
* Update to stunnel-4.21.roam2007-10-307-18/+29
|
* Update to 2.0.2.novel2007-10-304-8/+47
|
* Update to 1.12mat2007-10-292-4/+4
|
* Re-add a file (for cracklib support) that was inadvertently removed withshaun2007-10-291-0/+21
| | | | | | | | the last update. PR: ports/117351 [1], ports/116864 [2] Submitted by: Koji Yokota <yokota@res.otaru-uc.ac.jp> [1], Matthias Andree <matthias.andree@gmx.de> [2]
* - Update my mail address.chinsan2007-10-291-1/+1
|
* Add uberkey, a keylogger for x86 systems.chinsan2007-10-294-0/+36
| | | | WWW: http://www.linuks.mine.nu/uberkey/
* Document django DoS issue.delphij2007-10-291-0/+48
|
* - Update to 0.2.0.9-alphamiwi2007-10-282-4/+4
| | | | | | PR: 117582 Submitted by: bf <bf2006a@yahoo.com> Approved by: maintainer
* Update to 0.6.14 release.ale2007-10-282-4/+4
|
* - Add WWW link.chinsan2007-10-281-0/+2
|
* Update f-prot to 4.6.8.tdb2007-10-284-9/+9
|
* - Fix day entry for 498a8731-7cfc-11dc-96e6-0012f06707f0miwi2007-10-271-1/+2
| | | | Reviewed by: simon
* - Fix previous commit by edwin - 500000 != 600000. While here, fix packagingpav2007-10-261-2/+1
| | | | Reported by: pointyhat
* Fix erroneous patch.cy2007-10-268-16/+28
| | | | | PR: 117469 Submitted by: Karen Andrews <dearmiss@optusnet.com.au>
* - Document opera -- multiple vulnerabilitiesmiwi2007-10-261-0/+41
| | | | Reviewed by: remko
* - Update MASTER_SITESmiwi2007-10-251-1/+1
| | | | Submitted by: pointyhat
* - Document drupal --- multiple vulnerabilitiesmiwi2007-10-251-0/+84
| | | | Reviewed by: simon
* - Update to 0.9.16clsung2007-10-254-4/+193
| | | | | | | | | | | | | | | | | | | | | - Added two patches due to some system umask settlement(s). Added file(s): - files/patch-prelude-admin__prelude-admin.c - files/patch-src__prelude-failover.c Changelog libprelude-0.9.16: - Implement prelude-admin list [-l] command, which provide the ability to list existing profile name, permission, registration permission, analyzerID, and Issuer analyzerid. - Implement multiple analyzer deletion in prelude-admin. - Correct printing of IDMEF time field using non local GMT offset. - Patch to avoid struct typespec redefinition, due to variable mispelling. This fixes a compilation problem on OpenBSD 3.8. - Various bug fixes. PR: ports/117417 Submitted by: maintainer (Robin Gruyters)
* - Update to 0.9.10clsung2007-10-252-5/+6
| | | | | | | | | | | | | | | Changelog prelude-manager-0.9.10: - Make threshold act like a real threshold: pass every Nth events in the defined amount of seconds. - Allow mixing Limit and Threshold. - Do not share the tresholding hash accross thresholding plugin instance: previously, the shared hash would result in strange thresholding plugin behavior if you had several instance of thresholding loaded. - Various bug fixes concerning plugin instance un-subscribtion (unsubscribtion of certain plugin was not triggered). PR: ports/117416 Submitted by: maintainer (Robin Gruyters)
* Update to 1.3.delphij2007-10-253-9/+6
| | | | | PR: ports/117459 Approved by: gabor (via IRC)
* Presenting GNOME 2.20.1 and all related works for FreeBSD. The officialmarcus2007-10-2529-293/+386
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | GNOME 2.20 release notes can be found at http://www.gnome.org/start/2.20/notes/en/ . Beyond that, this update includes the new GIMP 2.4 (courtesy of ahze). The GNOME 2.20 update also includes a huge change in the FreeBSD GNOME hierarchy. We are now using the more standard DATADIR of ${PREFIX}/share rather than ${PREFIX}/share/gnome. The result is that fewer patches and hacks are needed to port GNOME components to FreeBSD. This will mean some user changes may be required, so be sure to read /usr/ports/UPDATING for more details. This release and the things we accomplished in it would not have been possible without mezz's crazy idea to collapse DATADIR, and his persistence to make it happen successfully. Ahze and pav also deserve thanks for their work on porting modules and testing the whole ball of wax on pointyhat (respectively). The FreeBSD GNOME team would also like to thank our various testers and contributors: Yasuda Keisuke Frank Jahnke Pawel Worach Brian Gruber Franz Klammer Yuri Pankov Nick Barkas Cristian KLEIN Tony Maher Scot Hetzel Martin Matuska (mm) Benoit Dejean Martin Wilke (miwi) (And anyone else I may have missed) PRs fixed in this release: 111272, 113470, 115995, 116338
* pdfcrack is a command line, password recovery tool for PDF-files.miwi2007-10-244-0/+33
| | | | | | | WWW: http://sourceforge.net/projects/pdfcrack PR: ports/117442 Submitted by: Philippe Audeoud <jadawin at tuxaco.net>
* Update to 1.8.4.marcus2007-10-242-4/+4
| | | | | | | | | | | fix for BUG#291: don't suppress password policy errors which should not be suppressed fix for BUG#312: pam_ldap does not try to reconnect when LDAP server closed the connection PR: 116176 Submitted by: mm
* - Use PLIST_FILES, remove pkg-plisttabthorpe2007-10-242-3/+5
| | | | | | | | | - Bump PORTREVISION - Pass maintainership to submiiter PR: ports/117426 Submitted by: Philippe Audeoud <jadawin tuxaco.net> Approved by: clsung (mentor, implicit)
* Update bsmtrace to 1.1.0.csjp2007-10-242-4/+4
| | | | | | | | | | | | | | | | | | | | | | | | | 1.1.0 fixes a pretty serious bug which resulted in BSM records without pathname tokens being processed in some cases. Additionally, timeout-window and timeout-probability features were added to allow people defining sequences with timeouts to add an element of randomness to the timeout, in theory making it more difficult for people to attack. timeout 60; timeout-window 10; timeout-probability 65; Basically equates to: "This sequence should timeout in a random amount of time, where the probability of the timeout being from 60-70 is 65%" It should be noted that there is a probability of 35% that the value will be completely random. So naturally, the lower the timeout-probability, the more random the timeout will be. Approved by: tmclaugh
* - Update to 0.22clsung2007-10-244-8/+18
| | | | | | | - Reset maintainership PR: ports/117408 Submitted by: Gea-Suan Lin <gslin_AT_gslin dot org>
* - remove option OPENSSL_OVERWRITE_BASEdinoex2007-10-242-47/+11
| | | | it was only supported for FreeBSD 4.x
* - update to 0.9.8gdinoex2007-10-242-4/+4
|
* - Update to 0.6.1miwi2007-10-232-4/+4
| | | | | PR: 117294 Submitted by: Philippe Audeoud <jadawin@tuxaco.net>
* - Update to 0.2.0.7-alphamiwi2007-10-232-4/+4
| | | | | PR: 117328 Submitted by: Peter Thoenen <peter.thoenen@yahoo.com> (maintainer)
* - Document ldapscripts -- Command Line User Credentials Disclosuremiwi2007-10-231-0/+31
| | | | | | | PR: 117152 Submitted by: Ganael Laplanche <ganael.laplanche at martymac.com> (maintainer/author) rafan@ Reviewed by: simon@
* Update 1.6.2 --> 1.6.3cy2007-10-2312-44/+20
| | | | | | | Security: fix CVE-2007-3999, CVE-2007-4743 svc_auth_gss.c buffer overflow fix CVE-2007-4000 modify_policy vulnerability Also: add PKINIT support
* Update to 1.9.4tmclaugh2007-10-234-5/+37
| | | | | | | - Required due to recent update to Mono. Submitted by: Phillip Neumann Approved by: maintainer timeout
* Update to 1.6.9p6tmclaugh2007-10-232-5/+5
| | | | | - Sudo now only prints the password prompt if the process is in the foreground.
* Modify firefox entry to cover linux-* variants.delphij2007-10-231-0/+6
|
* Fix install path of CHANGES.txt when using nikto -update and bump PORTREVISION.itetcu2007-10-221-2/+3
| | | | | PR: ports/117379 Submitted by: Naram Qashat
* Document firefox JavaScript Entrapment vulnerabilities.delphij2007-10-221-0/+33
|
* This port contains the Shrew Soft ike daemon and client tools. Thealepulver2007-10-215-0/+113
| | | | | | | | | | | | software supports ike v1 communications between two gateways or a a client and a gateway. For more information please visit ... WWW: http://www.shrew.net/ PR: ports/116684 Submitted by: mgrooms at shrew.net
* - Update to 1.3.0miwi2007-10-216-90/+69
| | | | | | PR: 117269 Submitted by: Philippe Audeoud <jadawin@tuxaco.net> Approved by: maintainer implicit
* - Fix year entry in 498a8731-7cfc-11dc-96e6-0012f06707f0miwi2007-10-211-2/+2
| | | | | Submitted by: freshports Thanks to: Dan Langille
* OpenFWTK is an application proxy toolkit which inherits the ideologynovel2007-10-2013-0/+355
| | | | | | | | | | | of TIS fwtk and maintains API backwards compatibility. The design goal is to make it simple yet powerful; no performance hacks allowed in the code and library dependencies are reduced to minimum. WWW: http://sourceforge.net/projects/openfwtk PR: ports/117194 Submitted by: Anton Karpov <toxa at toxahost.ru>
* - Add new line between entries.mnag2007-10-191-0/+2
|
* - Add entry about recent phpMyAdmin XSS server_status.php vulnerabilitystas2007-10-181-2/+31
| | | | - Fix URL in my previous entry while I'm here.
* Migration from bison 1.x to 2.xade2007-10-174-5/+8
| | | | | PR: 117086 Tested by: -exp runs
* - Unbreakmiwi2007-10-172-7/+12
| | | | | | | | - Fix build gcc 4.2 PR: 116815 Submitted by: miwi Approved by: maintainer timeout
* - Update patchfiles to match latest release (Nov 2001)johans2007-10-177-63/+136
| | | | | | | | - Fix MASTER_SITES (adding local mirror) The old master sites referenced distinct distfiles with the same filename. Primary site carries the latest version which includes minor bugfixes. Patches in previous commit were broken as they matched the older release.
* - Fix Makefile, update distinfo, bump portrevision (forgotten in prev commit)johans2007-10-172-19/+21
|
* - Fix build with gcc 4.2johans2007-10-174-4/+180
| | | | - Fix plist now that all libraries build
* - Secuurity update to 0.9.8fdinoex2007-10-175-211/+5
| | | | Security: CVE-2007-4995
* - Fix package name in 51b51d4a-7c0f-11dc-9e47-0011d861d5e2 andstas2007-10-171-2/+4
| | | | 229577a8-0936-11db-bf72-00046151137e entries (phpmyadmin->phpMyAdmin).
* - Add entry about phpMyAdmin XSS vulnerability.stas2007-10-171-0/+33
|
* 2007-09-10 security/p5-Digest-SHA2: Has numerious known bugs, deprecated in ↵tabthorpe2007-10-165-45/+0
| | | | favor of Digest::SHA
* Correct build, libtool is a dependency.anders2007-10-161-2/+2
| | | | | PR: ports/116982 Submitted by: Cory R. King <coryking@mozimedia.com>
* Update to 1.11erwin2007-10-162-4/+4
| | | | | PR: 117212 Submitted by: Esa Karkkainen <ejk@iki.fi>
* - Port was building stuffs on post-patch: target, fix it using do build: [1]garga2007-10-161-2/+4
| | | | | | | - Since i'm here, just make it respect PREFIX PR: ports/117106 [1] Submitted by: maintainer [1]
* update to 0.60.2oliver2007-10-152-4/+4
|
* - Add a note "require LDAP" in GPGSM knob for $OPTIONS. This may helpkuriyama2007-10-131-1/+2
| | | | | | | | to reduce confusion when "WITHOUT_LDAP and WITH_GPGSM selected, but OpenLDAP dependency exists" situcation. PR: ports/116558 Reported by: Jo Rhett <jrhett@netconsonance.com>
* nagios-plugins -- Long Location Header Buffer Overflow Vulnerabilitymiwi2007-10-131-0/+31
| | | | Reviewed by: simon
* Update to 1.05 release.ale2007-10-132-4/+4
|
* Reset delta@lackas.net due to maintainer-timeouts and no response to email.linimon2007-10-121-1/+1
| | | | Hat: portmgr
* - Fix compilation with gcc 4.2johans2007-10-121-7/+5
| | | | | - Note: testfile still fails, but does exactly the same with old gcc might be a broken test - leaving this to somebody with ruby-foo
* - Fix compilation on FreeBSD 7 (openssl issues)johans2007-10-121-7/+7
| | | | | - Fix libnss option - Grab maintainership (and feed patches upstream)
* - Update to 20071011 to reflect 0.92RC2garga2007-10-123-5/+5
|
* Document png -- multiple vulnerabilitiesmiwi2007-10-121-0/+44
| | | | Reviewed by: simon
* Update WWWgarga2007-10-121-1/+1
|
* Fix build under 7.0-CURRENT (gcc 4.2.1 20070719).cy2007-10-113-0/+31
| | | | | PR: 112884 Submitted by: Scot Hetzel<swhetzel@gmail.com>
* Document ImageMagick - Multiple vulnerabilitiesremko2007-10-101-0/+55
| | | | Submitted by: Nick Barkas
* Correct mediawiki package names.remko2007-10-101-7/+1
| | | | Spotted by: Nick Barkas
* - Update to 1.10clsung2007-10-102-4/+4
|
* - Update to 0.9.1084miwi2007-10-104-8/+14
| | | | | PR: 116859 Submitted by: Sergei Vyshenski <svysh@pn.sinp.msu.ru> (maintainer)
* - Update to 0.9.957miwi2007-10-103-7/+6
| | | | | PR: 116860 Submitted by: Sergei Vyshenski <svysh@pn.sinp.msu.ru> (maintainer)
* - Update to 0.9.985miwi2007-10-103-7/+6
| | | | | PR: 116858 Submitted by: Sergei Vyshenski <svysh@pn.sinp.msu.ru> (maintainer)
* - Update to 0.9.1068miwi2007-10-104-14/+6
| | | | | PR: 116863 Submitted by: Sergei Vyshenski <svysh@pn.sinp.msu.ru> (maintainer)
* - Update to 0.9.1068miwi2007-10-103-7/+6
| | | | | PR: 116861 Submitted by: Sergei Vyshenski <svysh@pn.sinp.msu.ru> (maintainer)
* - Update to 0.9.1086miwi2007-10-104-7/+10
| | | | | PR: 116862 Submitted by: Sergei Vyshenski <svysh@pn.sinp.msu.ru> (maintainer)
* - Mark DEPRECATED (distribution is broken and no longer supported.)miwi2007-10-101-1/+3
| | | | | PR: 116870 Submitted by: Sergei Vyshenski <svysh@pn.sinp.msu.ru> (maintainer)
* update to 0.60.1oliver2007-10-103-21/+4
|
* Update to 0.11.7.lx2007-10-102-4/+4
|
* - Dokument jdk/jre -- Applet Caching May Allow Network Access Restrictions ↵miwi2007-10-091-0/+46
| | | | | | to be Circumvented Reviewed by: remko
* Update 0.11 --> 0.13.1cy2007-10-095-39/+14
|
* Document xfs -- multiple vulnerabilities.flz2007-10-081-0/+35
|
* Mark as broken on gcc4.2.linimon2007-10-071-1/+7
|
* Respect OPENSSLBASE.stefan2007-10-072-5/+9
| | | | | PR: 116986 [1], 109041 [2] Submitted by: maintainer [1], supraexpress@globaleyes.net [2]
* - Update security/chntpw to 070923.chinsan2007-10-062-4/+4
| | | | | PR: ports/116967 Submmitter: maintainer
* - Update to 3.04sat2007-10-062-4/+4
|
* - Sort category Makefilessat2007-10-061-2/+2
| | | | | Inspired by: Jason Harris <jharris@widomaker.com> Howto: http://twiki.cenkes.org/Cenkes/SortingCategoryMakefiles
* fix the patch I messed up!oliver2007-10-061-47/+2
| | | | *sigh*
* - Update gsskex patch to 20070927mnag2007-10-052-9/+8
| | | | | | - Update HPN patch to hpn12v19 [1] Notified by: ale [1]
* - Document tcl/tk -- buffer overflow in ReadImage functionmiwi2007-10-051-0/+33
| | | | | | PR: 116881 Submitted by: Nick Barkas <snb@threerings.net> Reviewed by: simon
* Update to 1.04 release.ale2007-10-052-5/+6
|
* - Update to 2.24clsung2007-10-052-6/+5
|
* Remove errornous # DO NOT DELETE lines caused by makedepend(1)edwin2007-10-052-2/+0
|
* - update prelude library dependencyclsung2007-10-051-1/+2
| | | | | PR: ports/116111 Submitted by: Robin Gruyters <r dot gruyters_AT_yirdis dot nl>
* - update dependency on libpreludeclsung2007-10-051-1/+2
| | | | | PR: ports/116110 Submitted by: maintainer (Robin Gruyters)
* - Update to 0.9.13clsung2007-10-053-6/+11
| | | | | | | | | | | | | | | | | | | | | | | | - bump libprelude library Changelog libpreludedb: - Source and Target now use a 16 bits index (required for CorrelationAlert with large number of source/target). CorrelationAlert Alertident now use a 32 bits index (required to link large number of Alert together). - Fix compilation on system without ENOTSUP (fix #227): Include modified patch from Alexandre Anriot <aanriot@atlantilde.com>. - [pgsql] Patch by Pierre Chifflier <chifflier@inl.fr>, that fixes type conversions preventing PostgreSQL to use indexes (fix #225). - [preludedb-admin] Use separate alert / heartbeat command: this is done to have a coherent implementation of the --offset and --count command line options. - [preludedb-admin] Fix --offset with the load command. - [preludedb-admin] Give the delete table a decent size, should speedup the delete command. - [documentation] preludedb-admin manpage (fix #230), by Pierre Chifflier <chifflier@inl.fr>. PR: ports/116109 Submitted by: maintainer (Robin Gruyters)
* - Update to 0.9.9.1clsung2007-10-052-5/+5
| | | | | | | | | | | | - bump libprelude library Changelog prelude-manager: - Fix for new libprelude (0.9.15) runtime warning. - Add documentation for SQLite3 in the template configuration file (S??繅astien Tricaud <toady at gscore.org>). PR: ports/116108 Submitted by: maintainer (Robin Gruyters)
* - Update to 0.9.15.2clsung2007-10-054-16/+20
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | - Updated patch-Makefile.in - Added Man page Changelog libprelude: - prelude-adduser has been renamed to prelude-admin, and now include command to print or send files containing binary IDMEF data. - Brand new failover implementation, Feature a real 'journaling' log, allowing to restart where we were interupted. Allow multiple process to write to the same failover, and is chroot safe. - prelude-admin manpage, thanks to Frederic Motte <fred at ubixis com>. - Use SHA1 in place of MD5 for Analyzer checksum. - Do not set TCP option on UNIX socket, avoid un-necessary warning. - New measure all over the public interface to protect against bad API usage, when a function is not used correctly, a critical warning is triggered. - [logging]: New PRELUDE_LOG_CRIT logging priority. - [logging]: Correctly map Prelude log level to Syslog priority. - [logging]: Improved logging format (include timestamp, level, process pid). - [logging]: New LIBPRELUDE_ABORT variable, useful if you'd like libprelude to abord on critical assertion. - [logging]: Automatically switch to syslog mode if we detect stdout/stderr closure. - [IDMEF-Criteria]: When we try to match a value against a path that is not part of a message using a 'not' operator, the match should succeed (Example: alert.classification.text != 'stuff' should match if the message has no classification object). - [IDMEF-Criteria]: When matching multiple listed values within the same path using a 'not' operator, return an explicit 'no match' if the provided comparison value was found at least once. - [IDMEF-Path] (fix #251): Fixes NULL pointer dereference when the last element of an IDMEF path to an enumeration is not the enumeration itself (S??鞋bastien Tricaud <toady at gscore.org> - Fix a possible race condition with the internal libprelude reference to the program idmef_analyzer_t when asynchronous timer were used. - Workaround possible deadlock at exit on OpenBSD, Linux Glibc. - Only configure libltdl if it is required. - Various bug fixes, minor enhancements. - Write the children PID into specified pidfile (fixes #257). - Fix double free on idmef_criterion_value_t cloned regexp object (thanks to Helmut Azbest <helmut.azbest at gmail.com>). - Allow Python thread to run, while entering libprelude C function. - Return PRELUDE_ERROR_ASSERTION when API check fail, in place of PRELUDE_ERROR_GENERIC. - Make prelude_plugin_unsubcribe() work as expected (call the plugin instance destroy function). - Various bug fixes, minor enhancements. PR: ports/116107 Submitted by: maintainer (Robin Gruyters)
* - This patch fixes broken install.db2007-10-051-1/+1
| | | | | | PR: ports/116875 Reported by: db Submitted by: Maintainer
* Remove always true/always false OSVERSION conditions.edwin2007-10-052-27/+20
|
* Document firebird multiple remote buffer overflow vulnerabilitiesdelphij2007-10-051-0/+28
|
* fix build of courier-authlib-vchkpwoliver2007-10-041-9/+14
|
* Wapiti allows you to audit the security of your web applications.rafan2007-10-044-0/+48
| | | | | | | | | | | | | It performs "black-box" scans, i.e. it does not study the source code of the application but will scans the webpages of the deployed webapp, looking for scripts and forms where it can inject data. Once it gets this list, Wapiti acts like a fuzzer, injecting payloads to see if a script is vulnerable. WWW: http://wapiti.sourceforge.net/ PR: ports/116873 Submitted by: Philippe Audeoud <jadawin at tuxaco.net>
* remove double bsd.port.mkedwin2007-10-041-2/+0
|
* Remove always-false/true conditions based on OSVERSION 500000edwin2007-10-0430-174/+34
|
* Remove support for OSVERSION < 5edwin2007-10-046-33/+6
|
* [PATCH] security/fwbuilder: cleanup non-supported FreeBSD versionsedwin2007-10-033-18/+9
| | | | | | | | | - removed support to 4.X (EOL) - add correct NOPORTDOCS PR: ports/111822 Submitted by: Marcelo Araujo <araujo@bsdmail.org> Approved by: maintainer timeout
* update to 0.60.0oliver2007-10-034-115/+171
|
* Update the bugzilla and mediawiki entries to properly match their correctedremko2007-10-031-5/+6
| | | | | | versions. Prodded by: Nick Barkas (and a few others)
* Update to reflect the fixed version of id3lib.delphij2007-10-021-1/+2
|
* Document id3lib insecure temporary file creation vulnerabilitydelphij2007-10-021-0/+29
|
* Mark as broken with gcc4.2 on 64-bits archs.linimon2007-09-301-0/+6
|
* Fine-tune broken message.linimon2007-09-301-1/+1
|
* Mark as broken on gcc4.2.linimon2007-09-301-1/+7
|
* Remove 4.X cruft.linimon2007-09-301-4/+0
|
* Remove cruft.linimon2007-09-301-34/+0
|
* Also broken with gcc4.2.linimon2007-09-301-1/+5
|
* Mark as broken with gcc4.2.linimon2007-09-301-1/+7
|
* Mark as broken with gcc4.2 on 64-bit archs.linimon2007-09-301-1/+9
|
* Mark as broken: fails to install.linimon2007-09-301-0/+4
|
* Mark as only for i386-6.linimon2007-09-302-0/+14
| | | | | | | Based on: PR: ports/115474 Submitted by: maintainer
* Add USE_PERL5. This will be needed to conditionalize bsd.perl.mk inclusion.linimon2007-09-302-0/+2
| | | | Approved by: maintainer
* [update] security/pam-mysql to 7.0RC1edwin2007-09-304-8/+26
| | | | | | | | | | | Includes fix for correct use of -lmd to find MD5 functions (see: http://sourceforge.net/tracker/index.php?func=detail&aid=1485390&group_id=5741&atid=105741) Note: Used autoconf 2.61 to prevent problems with the upcoming sweep PR: ports/113882 Submitted by: Angelo Turetta <aturetta@bestunion.it> Approved by: maintainer timeout
* Before bsd.port.pre.mk, set either USE_PERL5 or WANT_PERL, depending onlinimon2007-09-301-0/+1
| | | | | whether the perl dependency is unconditional or conditional. This will be needed for the conditional inclusion of bsd.perl.mk.
* Switch autoconf dependencies from 2.53 or 2.59 to 2.61.linimon2007-09-308-11/+16
| | | | | PR: ports/116639 Submitted by: aDe
* Update to 1.2.4.1. Changes include:hrs2007-09-303-20/+20
| | | | - "*grabServer" resource bug has been fixed.
* - Make it work on 64-bit systems.alepulver2007-09-305-8/+138
| | | | | | | - Avoid the build failing when OpenSSL is installed as a port too. PR: ports/94921 Submitted by: Mats Palmgren <mats.palmgren@bredband.net>
* - Turn off keyboard grabbing to avoid mouse pointer lock after returning fromalepulver2007-09-301-0/+58
| | | | | | | the screensaver. PR: ports/103395 Submitted by: Vladimir Grebenschikov <vova@fbsd.ru>
* - Mark BROKEN everywhere: does not compilepav2007-09-291-4/+2
| | | | Reported by: pointyhat
* - cleanup Makefiletabthorpe2007-09-282-34/+8
| | | | | | | - update comment/descripttion to indicate port is a wrapper to Digest::MD5 - pass maintainership to perl@ Approved by: miwi (co-mentor)