aboutsummaryrefslogtreecommitdiffstats
path: root/security
Commit message (Collapse)AuthorAgeFilesLines
* - Mark linux-firefox 1.0.7 as fixedsimon2005-10-261-5/+6
| | | | | | | | | wrt. 8665ebb9-2237-11da-978e-0001020eed82 (Mozilla/firefox IDN buffer overflow) [1]. - Correct some of the the earlier linux-firefox entries to match versions before 1.0.7, not after (whoops)... Prodded by: Andrew P. <infofarmer@gmail.com> [1]
* Update to 5.2mnag2005-10-262-3/+3
| | | | | | PR: 87401 Submitted by: Frank Laszlo <laszlof@vonostingroup.com> Approved by: Jonatan B <onatan@gmail.com> (maintainer)
* - Update to 1.3.7ehaupt2005-10-262-6/+18
| | | | | - Provide PORTDOCS - Provide additional master site
* Add misc/compat5x to "openssl -- potential SSL 2.0 rollback".lesi2005-10-261-1/+8
| | | | Reviewed by: simon
* Cosmetic formatting change.cy2005-10-263-3/+3
|
* Adjust port to installl sudoers.conf.sample as a reference sample file.cy2005-10-2612-6/+84
| | | | Conditionally install sudoers.conf.
* Update to 1.13skv2005-10-252-3/+3
| | | | | PR: ports/87713 Submitted by: Christian Lackas <delta at lackas.net>
* - fix build in jaildinoex2005-10-253-0/+6
| | | | | maintainer emailed 2005-10-04 Approved by: (maintainer timeout)
* Fix broken port, capture missing file in pkg-plist.cy2005-10-256-6/+9
| | | | Pointy hat to: me
* Update to 4611jeh2005-10-252-3/+3
|
* Update to 0.2.10krion2005-10-242-3/+3
|
* Also mark xli as vulnerable to xloadimage -- buffer overflows in NIFFsimon2005-10-241-0/+5
| | | | | | image title handling, and latest port version as fixed. Reported by: jkoshy
* For entry libgadu -- multiple vulnerabilities:simon2005-10-241-2/+3
| | | | | - Mark latest centericq port version as fixed. - Fix cite in description.
* - Update to 3.0.19ehaupt2005-10-232-8/+11
| | | | | | | | - Provide aditional master/patch site [1] PR: 87866 Reported by: pointyhat via kris [1] Submitted by: Johan van Selst <johans@stack.nl>
* New style bsd.java.mk.nork2005-10-231-1/+2
| | | | | Submitted by: hq Pointy hat to: myself
* For entry zope28 -- expose RestructuredText functionality to untrustedsimon2005-10-231-3/+5
| | | | | | | | | | users: - Do not match zope 2.7.8 which has been fixed. [1] - Fix typo in topic. - Add another reference. Reported by: Gerhard Schmidt <estartu augusta de> [1]
* Add java_policy 1.4.2, which provides JCE(Java Cryptographynork2005-10-234-0/+55
| | | | | | | Extension) Unlimited Strength Jurisdiction Policy Files. WWW: http://java.sun.com/products/jce/index-14.html I was cheated by: ume
* Update to liedentd 1.1, which is PREFIX-aware.wes2005-10-223-6/+4
|
* Add another reference to clamav -- arbitrary code execution and DoSsimon2005-10-221-0/+2
| | | | vulnerabilities entry.
* - Mark the port IGNORE in addition to DEPRECATED: the port does not buildsergei2005-10-221-0/+1
| | | | | | with the newer security/libprelude dependency Prompted by: kris
* - Mark the port DEPRECATED with expiration in a month:sergei2005-10-211-0/+3
| | | | | | | Prelude project has stopped development of its own NIDS sensor in favor of using Snort (security/snort) which has native support for integration with Prelude as of version 2.4.1 See http://www.prelude-ids.org/article.php3?id_article=124 for details.
* Update to 4609jeh2005-10-212-3/+3
|
* Document x11/xloadimage buffer overflows in NIFF image title handling.naddy2005-10-201-0/+39
|
* - Fix build of openssl-beta on 6.0dinoex2005-10-201-1/+1
|
* Update to 1.1.0 release, add a couple of tunables to the Makefile,ade2005-10-203-7/+9
| | | | | | and bit a little more descriptive in pkg-descr. Submitted by: andrew@arda.homeunix.net (author)
* update to dat 4608jeh2005-10-202-3/+3
|
* Rename all CAN-yyyy-nnnn to CVE-yyyy-nnnn, with the exception of textnectar2005-10-201-688/+688
| | | | | inside <blockquote>s. See <URL:http://www.cve.mitre.org/cve/renumber.html>.
* - Update to 0.6garga2005-10-192-5/+6
| | | | | | | | | | | | | | | | | | | | - Pass maintainership to submitter This version adds the following features: - added '-s' to ssh-agent calls so that they will work for people with non-bash shells. (thanks to Jacob) - Asynchronous mode works. - Asynchronous mode required temp files so we use mktemp to make it safer. - Blocking option in async mode. - All debug messages go to STDERR. - Invoke remote shell (default bash) explicitely. - SIGQUIT (ctrl-\) prints current/remaining host(s). - Modernized all ``'s to $()'s. PR: ports/87664 Submitted by: Frank Laszlo <laszlof@vonostingroup.com>
* . respect PREFIXehaupt2005-10-192-2/+6
| | | | | | | | . bump PORTREVISION PR: 87660, 87638 Reported by: dosirak via kris Submitted by: Michael Ranner <mranner@inode.at> (maintainer)
* For entry: snort -- Back Orifice preprocessor buffer overflow vulnerability:simon2005-10-191-1/+2
| | | | | - Sort references. - Add ISS advisory to references.
* Make PREFIX-safelofi2005-10-191-3/+3
|
* - Document snort -- Back Orifice preprocessor buffer overflow vulnerability.simon2005-10-191-2/+50
| | | | | | - Use standard topic format for webcalendar entry. - Fix package name in webcalendar so it matches the actual package name.
* Update to 1.2.2arved2005-10-192-4/+3
| | | | | | | | Noteworthy changes are: * Made the RNG immune against fork without exec. * Minor changes to some function declarations. Buffer arguments are now typed as void pointer. This should not affect any compilation. * A bug in the definition of gcry_cipher_register has been fixed.
* - Update to 2.4.3, which includes a fix for a potential buffer overflowsergei2005-10-192-6/+6
| | | | | | | | | | in the Back Orifice preprocessor. - Transfer maintainership to the submitter, who seems to be tracking Snort development much closer than I do, and submitted most of the Snort update PRs in last couple of years PR: ports/87628 Submitted by: Linh Pham <question+fbsdports@closedsrc.org>
* - Update to 0.10garga2005-10-192-3/+3
| | | | | PR: ports/87613 Submitted by: maintainer
* - Update to 0.9.0sergei2005-10-193-23/+48
| | | | | - Chase libprelude version bump - Convert to USE_AUTOTOOLS, use libtool 1.5
* Update to 4607jeh2005-10-192-3/+3
|
* - Update to 0.9.0sergei2005-10-184-100/+29
| | | | | | | | - Database support options moved to separate security/libpreludedb port, which is has been added as dependency - The port now uses GnuTLS instead of OpenSSL (indirectly, via libprelude dependency) - Convert to USE_AUTOTOOLS
* Update to 0.13.tobez2005-10-183-4/+5
|
* Update to 4606jeh2005-10-182-3/+3
|
* Add a check to see if WITH_MILTER is not set (and don't build milterlawrance2005-10-171-1/+1
| | | | | | | | in that case). PR: ports/85834 Submitted by: Vivek Khera <vivek@khera.org> Approved by: blaz@si.FreeBSD.org (maintainer)
* Add p5-GD-SecurityImage, a Perl5 module for creating CAPTCHA security imagesehaupt2005-10-175-0/+55
| | | | | | PR: 87494 Submitted by: Rod Taylor <ports@rbt.ca> Approved by: novel (mentor) (implicit)
* Respect $PREFIXvs2005-10-161-0/+3
| | | | | PR: ports/87509 Submitted by: maintainer
* Update to 0.2.9krion2005-10-163-7/+5
|
* Correct description.ade2005-10-161-1/+1
| | | | Submitted by: andrew@arda.homeunix.net (author)
* - new option WITHOUT_OPENSSL_SSE2dinoex2005-10-161-0/+4
| | | | | http://www.openssl.org/docs/crypto/OPENSSL_ia32cap.html Suggested by: Grant Swenson
* - update stable to 0.9.7idinoex2005-10-164-32/+4
|
* - force 0.9.7 for FREEBSD 6.0 RELEASEdinoex2005-10-161-0/+8
| | | | Requested by: portmgr (kris)
* This now links dynamically to the dependencies since they now provide them.kris2005-10-151-3/+3
| | | | Switch from BUILD_DEPENDS to LIB_DEPENDS and bump PORTREVISION.
* - Document www/webcalendar vulnerability.sem2005-10-151-0/+23
|
* - Document www/gallery2 vulnerability.sem2005-10-151-0/+35
|
* Add security/libpreludedb:sergei2005-10-156-0/+149
| | | | | | This library provides a framework for easy access to the Prelude database. WWW: http://www.prelude-ids.org/
* - Respect NOPORTDOCSsergei2005-10-153-10/+28
| | | | | | - Fix pkg-plist if WITH_PERL/WITH_PYTHON are defined - Properly clean up (extra directories) at deinstall - Bump PORTREVISION
* Upgrade to DAT 4605jeh2005-10-152-3/+3
|
* - use new option namedinoex2005-10-141-1/+1
|
* Fix package list when use LIBUNRARmnag2005-10-143-40/+18
| | | | | | | | | If use LIBUNRAR don't need archivers/unrar Remake patches to work without autotools Bump PORTREVISION PR: 87338 Approved by: Rob <rob@debank.tv> (maintainer)
* - new option WITH_OPENSSL_STABLE=yesdinoex2005-10-141-10/+8
| | | | - updated CONFLICTS
* - create slave port for openssl 0.9.7dinoex2005-10-142-0/+20
|
* - binary compatability patchdinoex2005-10-143-1/+29
| | | | | PR: 87419 Submitted by: Phil Oleson
* Update to DAT 4604jeh2005-10-142-3/+3
|
* - Update to 4.33ehaupt2005-10-139-289/+86
| | | | | | | | - Nuke files/* PR: 87247 Submitted by: Demin Alexander <support@spectrum.ru> (maintainer) Approved by: novel (mentor)
* Update to 0.03ehaupt2005-10-132-3/+3
| | | | | | | PR: 86739 Submitted by: ehaupt Approved by: maintainer timeout (15 days), novel (mentor)
* Remove pkg-message, the one in WRKDIR is used.edwin2005-10-132-6/+1
|
* New port: security/webfwlog Web-based firewall log analyzeredwin2005-10-137-0/+207
| | | | | | | | | | | | | | | | Webfwlog is a web-based firewall log analysis and reporting tool, and supports ipfilter and ipfw log file formats. It is interactive and allow the user to "drill-down" from a summary report to packet details logged. It also has great flexibility in the format of the output and which logged records are included. Sample report definitions are included and are saved in a database (MySQL or PostgreSQL) and can be modified by the user. More info at: http://www.webfwlog.net PR: ports/80352 Submitted by: Bob Hockney <zeus@ix.netcom.com>
* Improve last couple of entries:simon2005-10-131-13/+17
| | | | | | | | | - Use standard topic format. - Fix packagename in phpmyadmin and zone entries. - Fix indention and remove EOL white-space. - Make lead in a bit more verbose. - Add more references to phpmyadmin issue. - Remove some redundant quoted text in zope issue.
* - Update to 1.2sem2005-10-133-3/+4
| | | | | PR: ports/87327 Submitted by: maintainer
* BROKEN: Installs file outside of PREFIXkris2005-10-133-0/+6
|
* Update to DAT 4603jeh2005-10-132-3/+3
|
* Add entry for opensslmnag2005-10-121-3/+57
| | | | Remove entry about safe mode in phpmyadmin
* Fix build on perl < 5.6skv2005-10-121-1/+8
| | | | | PR: ports/87315 Submitted by: lth
* Add python as a secondary categorylioux2005-10-121-1/+1
|
* - update to 0.9.7g and 0.9.8adinoex2005-10-124-64/+8
|
* - Security Fix: CAN-2005-2969dinoex2005-10-123-2/+58
| | | | Security: http://www.openssl.org/news/secadv_20051011.txt
* Fix using of libunrar in OPTIONS variable.vsevolod2005-10-121-1/+1
| | | | Noted by: ache
* Fix a couple of problems on 64 bit platforms by importing 2.5:csjp2005-10-122-3/+3
| | | | | | | | | | | | | | | | | | | | | | | | | Summary: o Call va_start/va_end for each call to va_arg(). I have no idea why this works on i386 but it shouldn't. This un-busts termlog on 64 bit platforms. o When allocating snp descriptors, allocate the proper size. Currently we are allocating sizeof(struct utmp) when we really should be allocating sizeof(struct snp_d). I can only imagine how this happen, but I am going to guess it was a cut-and-paste-o. This helps un-busts termlog on 64 bit architectures. Fixes Submitted by: Eirik ?verby While we are here: o Open tty line with O_NONBLOCK o Close the line fd after we attach to it as we dont need it. This closes an fd leak. o Remove comment about fd leak Approved by: kris
* Add entry for phpmyadmin (PMASA-2005-4)mnag2005-10-121-0/+29
|
* Fix typo with range valuesmnag2005-10-121-1/+1
|
* Add entry from zope28mnag2005-10-121-0/+30
|
* Allow clamav to use rar 3 archives using archivers/libunrar.vsevolod2005-10-122-1/+3255
| | | | | | PR: 86510 Submitted by: Alex Samorukov <samm@os2.kiev.ua>, Rob <r.evers@nedstat.com> (maintainer)
* - Update to 3.26.0 to fix fetching [1]erwin2005-10-123-12/+8
| | | | | | | | | | | - Reset maintainer - Remove now useless check for FreeBSD 3.x - Make sure the example configuration file only gets deinstalled if not changed. PR: 74263 Submitted by: freebsd@simplerezo.com [1], distsurvey [1] Approved by: maintainer timeout (11 months)
* Update to DAT 4602jeh2005-10-122-3/+3
|
* - Update to 0.6.6garga2005-10-125-36/+52
| | | | | PR: ports/87259 Submitted by: maintainer
* - Update to 0.06 [1]erwin2005-10-122-10/+16
| | | | | | | | - Mark IGNORE for perl < 5.6.0 PR: 85283 Submitted by: Alex Kapranoff <kappa@rambler-co.ru> [1] Approved by: maintainer timeout
* Fix MASTER_SITE I botched in the previous commitvs2005-10-111-1/+1
| | | | Submitted by: maintainer
* Update to DAT 4601jeh2005-10-112-3/+3
|
* Upgrade to 5.0edwin2005-10-114-29/+24
| | | | Submitted by: B3r3n <B3r3n@free.fr>
* Update to 0.6.2mnag2005-10-103-12/+21
| | | | | PR: 86576 Approved by: anders (maintainer timeout, 14 days)
* Update to DAT 4600jeh2005-10-102-3/+3
|
* Fix MASTER_SITES and use MAKE_ARGS instead of patch.vs2005-10-102-13/+2
| | | | | PR: ports/87193 Submitted by: maintainer
* Reset bouncing maintainer address, remove stale mastersite.linimon2005-10-101-3/+2
| | | | Source: distfile survey
* For libxine -- format string vulnerability entry:simon2005-10-101-5/+6
| | | | | - Add reference to xine security announcement. - Fix indention on a few lines.
* Add gwee, a tool to exploit command execution vulnerabilities in web scripts.ehaupt2005-10-104-0/+42
| | | | | | PR: 80639 Submitted by: chinsan <chinsan@mail2000.com.tw> Approved by: novel (mentor)
* Add an entry for libxine format string vulnerability.nobutaka2005-10-101-0/+31
|
* Warren requested that this port be removed. I've just un-MAINTAINER-izedfenner2005-10-091-1/+1
| | | | it to avoid slush troubles.
* Mark older revisions linux_base-suse 9.3 as vulnerable to kdebase --simon2005-10-091-0/+5
| | | | Kate backup file permission leak.
* Remove WWW: None.fenner2005-10-091-1/+0
|
* - Fix handling of & sign, it need to be escaped for XML storagepav2005-10-093-1/+55
| | | | | | | | | PR: ports/85240 Submitted by: Maurice Castro <maurice@sphinx.clari.net.au> Approved by: maintainer timeout (anders, 17 days) - While here, fix runtime crash on 64bit platforms by explicitly declaring getenv() (via including <stdlib.h> header)
* - Set CONFLICTS with krb4 and krb5pav2005-10-091-2/+4
| | | | | | | | - Portlint PR: ports/85025 Submitted by: lofi Approved by: maintainer timeout (nectar, 7 weeks)
* - Set CONFLICTS with heimdal and krb5pav2005-10-091-2/+4
| | | | | | | | - Portlint PR: ports/85026 Submitted by: lofi Approved by: maintainer timeout (nectar, 7 weeks)
* - Set CONFLICTS with heimdal and krb4pav2005-10-094-4/+12
| | | | | | | | - Portlint PR: ports/85027 Submitted by: lofi Approved by: maintainer timeout (cy, 7 weeks)
* - Fix pkg-plistlawrance2005-10-084-9/+12
| | | | | | | - Minor tweaking and cleanups PR: ports/85989 Submitted by: Graham Todd <gtodd@bellanet.org> (maintainer)
* Update to 0.8.marcus2005-10-084-11/+11
|
* Update master sites.ehaupt2005-10-084-4/+0
| | | | | | PR: 87035 Submitted by: Udo Schweigert <udo.schweigert@siemens.com> Approved by: novel (mentor)
* Update master sites.ehaupt2005-10-084-4/+0
| | | | | | PR: 87034 Submitted by: Udo Schweigert <udo.schweigert@siemens.com> (maintainer) Approved by: novel (mentor)
* - Update to 2.4.1sergei2005-10-078-179/+58
| | | | | | | - Snort distribution no longer includes rules - download them seperately (or consider using security/oinkmaster to simplify that process) - Change default config dir to ${PREFIX}/etc/snort (to avoid cluttering) - Install database schemas scripts into EXAMPLESDIR
* - Update to 0.9.0sergei2005-10-074-130/+124
| | | | | | | - libprelude now always depends on GnuTLS - Add two new knobs - WITH_PERL and WITH_PYTHON - to install Perl and Python bindings, respectively (both knobs are off by default) - Remove patch we no longer need
* - Mark cfengine's arbitrary file overwriting vulnerability as fixed in 2.1.6_1sergei2005-10-071-0/+6
| | | | - Add another possible variant of package name - cfengine2
* Remove trailing backslash from MASTER_SITES which caused thefenner2005-10-071-2/+2
| | | | | | | MASTER_SITE_SUBDIR= line to be treated as 4 more sites. Add slash to MASTER_SITE_SUBDIR using the group syntax. (The file's not there anyway, but at least it's looking in the right spot now.)
* Remove obsolete mastersites.linimon2005-10-071-6/+0
| | | | | Source: distfile survey Approved by: maintainer
* Update to 20051006mnag2005-10-072-3/+3
| | | | | PR: 87001 Submitted by: Tim Bishop <tim@bishnet.net> (maintainer)
* Update to 4.6.1mnag2005-10-074-5/+8
| | | | | PR: 87000 Submitted by: Tim Bishop <tim@bishnet.net> (maintainer)
* Change MAINTAINER address for my ports.ehaupt2005-10-068-8/+8
| | | | Approved by: novel (mentor)
* - Update to 1.6.39barner2005-10-063-11/+10
| | | | | | | | - Use DATADIR - Pass maintainership to submitter Submitted by: Emanuel Haupt <ehaupt@FreeBSD.org> Approved by: Dominic Marks <dom@goodforbusiness.co.uk> (old maintainer)
* Add an entry for UW-IMAP Mailbox Name Handling Remote Buffer Overflowthierry2005-10-061-0/+35
| | | | Vulnerability (CAN-2005-2933).
* Update to 0.7mnag2005-10-063-11/+9
| | | | | | PR: 86929 Submitted by: Philippe Rocques <phil@teaser.fr> (maintainer) Approved by: pav (mentor)
* New portmnag2005-10-066-0/+92
| | | | | | | | | | The Authen::CyrusSASL module provides a simple class that allows you to send request to the cyrus-sasl's authen daemon. This module is based on the Authen::Radius module with the similar interface. PR: 86943 Submitted by: Attila Nagy <bra@fsn.hu> Approved by: pav (mentor)
* Add credit for recent ftp/weex incidentehaupt2005-10-051-1/+1
| | | | Approved by: novel (mentor)
* - Update to 1.1 (minor bugfixes)sergei2005-10-052-6/+5
|
* [maintainer update] update security/pamtesteredwin2005-10-052-3/+3
| | | | | | | update security/pamtester to 0.1.2 PR: ports/86905 Submitted by: Andrew Thompson <thompsa@FreeBSD.org>
* Update 1.8.1 --> 1.8.2cy2005-10-056-9/+9
|
* Update 1.4.1 --> 1.4.2cy2005-10-0516-132/+12
|
* Update to DAT 4596jeh2005-10-052-3/+3
|
* Update update_dat to use fetch and be a little more robust. Thanks tojeh2005-10-051-16/+14
| | | | Sztankay Zsolt for the work.
* Update to 20051003mnag2005-10-042-25/+24
| | | | | | | Unmark FORBIDDEN PR: 86878 Approved by: rob@debank.tv (maintainer), pav (mentor)
* rinetd >= 0.62_1 has no more vulnerabilitiesgarga2005-10-041-2/+5
|
* - bump SHLIB versiondinoex2005-10-041-2/+3
| | | | | | | The API of openssl 0.9.8 ist compatible but not identical. This version bump might break build of all ports that try to include the opessl in base at the same time. That ports should be fixed.
* Changelog:clsung2005-10-043-8/+5
| | | | | | | | | | | | - Fixed major performance problems with recent versions of GNU C++ - Added an implementation of the X9.31 PRNG - Removed the X9.17 and FIPS 186-2 PRNG algorithms - Changed defaults to use X9.31 PRNGs as global PRNG objects - Some cleanups related to the engine code and more (see http://botan.randombit.net/logs/log-14.php) PR: 86589 Submitted by: az (New committer today. Welcome to the zoo :) )
* Update to 4595jeh2005-10-042-3/+3
|
* o Fix whitespace (to tab)mich2005-10-032-6/+6
| | | | | | | o Fix path to database files problem [1] o use %%DATADIR%% while we are here Submitted by: andreas[1]
* Add references to three squid entries.remko2005-10-031-5/+15
| | | | | Submitted by: Thomas-Martin Seck <tmseck at netcologne dot de> (except for the bid's which i added myself).
* Use the <freebsdpr> tag to markup a PR in weex -- remote format stringsimon2005-10-031-1/+1
| | | | vulnerability entry.
* Document a format string vulnerability in ftp/weex.jylefort2005-10-031-0/+30
|
* Document picasm -- buffer overflow vulnerability.simon2005-10-021-0/+33
|
* - Fix MASTER_SITESdinoex2005-10-021-1/+2
|
* Add an URL to the entry of the japanese/uim.nobutaka2005-10-021-1/+1
|
* Document japanese/uim privilege escalation vulnerability.nobutaka2005-10-021-0/+31
|
* Document cfengine -- arbitrary file overwriting vulnerability.simon2005-10-011-0/+32
|
* Mark zsync <= 0.4.1 vulnerable to the zlib buffer overflow vulnerability.remko2005-10-011-0/+5
| | | | Inspired by: gordon's commit
* Add more references to unace -- multiple vulnerabilities entry.simon2005-10-011-0/+3
|
* Add CVE name to an older ProZilla entry.simon2005-10-011-0/+2
|
* Reset maintainer who had turned in his commit bit some time back as he nolinimon2005-10-011-1/+1
| | | | | | longer had time to work on FreeBSD. We appreciate the help in the past. Approved by: alex (former maintainer)
* Update to DAT 4594jeh2005-10-012-3/+3
|
* Update to 1.12skv2005-10-012-3/+3
|
* - Use DOCSDIR, PORTDOCS and NOPORTDOCSgarga2005-09-302-18/+8
| | | | | - Remove one line pkg-plist - Take maintainership
* With portmgr hat on, reset maintainer. There have been several maintainerlinimon2005-09-301-1/+1
| | | | timeouts, and no response to email for more than 2 weeks.
* Update to 2.5.5mnag2005-09-302-17/+16
| | | | Approved by: olive@oban.frmug.org (maintainer via email), pav (mentor)
* Add more references for latest phpmyfaq entry.simon2005-09-301-0/+9
|
* - Add a note that new entries, per convention, should be added to thesimon2005-09-301-5/+11
| | | | | | | | | | | | start of this file. For latest phpmyfaq entry: - Use port directory name as first part of topic. - No need to include information about affected releases in topic (it's somewhat redundant and makes the title longer). - Reindent body with standard FreeBSD Doc Project (more or less) style.
* Document vulnerabilities in www/phpmyfaqvsevolod2005-09-291-0/+25
|
* Update to 4592jeh2005-09-292-3/+3
|
* - Update to 1.1.1-9. For a list of changes since 1.1.0-7 please see themarius2005-09-288-61/+34
| | | | | | | | installed ChangeLog. - Remove the references to the no longer available free license key for private use from pkg-descr and pkg-message. Approved by: netchild
* Chase updated mastersite.linimon2005-09-281-1/+1
| | | | Source: distfile survey
* Remove obsolete mastersite.linimon2005-09-282-3/+1
| | | | Source: distfile survey
* - update to 3.0.18dinoex2005-09-282-21/+11
| | | | | | | | - unbreak on >= 7.0 - set new maintainer Johan van Selst PR: 86645 Submitted by: Johan van Selst
* make it compilable with OpenSSL 0.9.8.ume2005-09-281-0/+12
| | | | | PR: ports/86452 Submitted by: Dirk Meyer <dirk.meyer__at__dinoex.sub.org>
* - s/malloc.h/stdlib.h/ on some files to fix build on amd64 - 7.x [1]garga2005-09-284-37/+7
| | | | | | | | | - change some patches to REINPLACE_CMD [2] PR: ports/86638 [1] Submitted by: maintainer [1] Reworked by: me [2] Approved by: maintainer [2]
* Update to 4590jeh2005-09-272-3/+3
|
* Add tthsum 1.1.0, a command-line utility for generating and checking TTHgarga2005-09-267-0/+88
| | | | | | | message digests. PR: ports/86555 Submitted by: Emanuel Haupt <ehaupt@critical.ch>
* -Remove MANCOMPRESSED macro as it's not requiredcsjp2005-09-251-1/+6
| | | | | | | | | -Introduce do-install target which will use INSTALL_MAN and INSTALL_PROGRAM macros to install the files. This should fix packet build failures. Approved by: kris
* Add a missing dependency.tobez2005-09-251-1/+3
| | | | | Submitted by: Kevin Golding <kevin@caomhin.demon.co.uk> PR: 86556
* - update to 1.03leeym2005-09-252-4/+4
| | | | - assign maintainer to perl@
* Update to 0.32.novel2005-09-242-4/+5
| | | | | PR: 86513 Submitted by: David Thiel (maintainer)
* Add linux_base-suse-9.3 to the zlib entry.remko2005-09-241-0/+5
| | | | Inspired by: trevors commit.
* Mark FORBIDDEN due to arbitrary code execution vulnerability.simon2005-09-241-0/+2
| | | | | Security: http://vuxml.FreeBSD.org/271498a9-2cd4-11da-a263-0001020eed82.html With hat: secteam
* Document clamav -- arbitrary code execution and DoS vulnerabilities.simon2005-09-241-0/+39
|
* - Be consistent and call entries "firefox & mozilla", not the other waysimon2005-09-241-2/+12
| | | | | | around. - Mark latest linux-mozilla port as fixed for recent mozilla vulnerabilities.
* - Document mozilla & firefox -- multiple vulnerabilities.simon2005-09-241-0/+147
| | | | | - Add Mozilla Foundation Security Advisory references to two other firefox/mozilla entries.
* Update to 4589jeh2005-09-242-3/+3
|
* Checking MACHINE_ARCH is deprecated.trevor2005-09-241-1/+1
|
* search.cpan.org redirect reduction canonicalization project, pass 3:fenner2005-09-231-1/+1
| | | | | | | | Refer to all modules using their /dist/Foo/ path instead of via the mishmash of old author path, new author path, module documentation, etc. These are mostly stragglers that should have been caught in pass 2. This pass brought to you by Bill's 102-degree fever during pass 2.
* Update to 4588jeh2005-09-232-3/+3
|
* - presrve downloaded cvd files on deinstalldinoex2005-09-222-6/+6
| | | | Approved by: Rob Evers
* Fix DISTNAME variable.vsevolod2005-09-221-1/+1
| | | | | Reported by: Jin-Shan Tseng <tjs@cdpa.nsysu.edu.tw> Pointy hat to: vsevolod
* Add real references to urban -- stack overflow vulnerabilities.simon2005-09-221-5/+3
|
* Update to 2.0.10 [1]vsevolod2005-09-222-4/+6
| | | | | | | Feed portlint PR: 86426 [1] Submitted by: David Thiel (maintainer) [1]
* Document mozilla & firefox -- command line URL shell command injection.simon2005-09-221-0/+87
|
* - mark BROKEN for FreeBSD >= 7dinoex2005-09-221-2/+8
| | | | - drop maintainership
* Add CVE name for tor -- diffie-hellman handshake flaw.simon2005-09-221-0/+2
|
* Correct package name for entry bind -- buffer overrun vulnerability.simon2005-09-221-1/+2
|
* Add CVE name to an older CUPS issue.simon2005-09-221-0/+2
|
* search.cpan.org redirect reduction canonicalization project, pass 2:fenner2005-09-225-5/+5
| | | | | | | | Refer to all modules using their /dist/Foo/ path instead of via the mishmash of old author path, new author path, module documentation, etc. This pass brought to you by loving, painstaking hand editing.
* search.cpan.org redirect reduction canonicalization project, pass 1:fenner2005-09-2215-15/+15
| | | | | | | | URLs automatically rewritten from /search?dist=Foo or /dist/Foo to /dist/Foo/ (note trailing slash). After a 2002(!) reorganization, this is the preferred way to refer to modules on search.cpan.org. This pass brought to you by http://people.freebsd.org/~fenner/fix-search
* Update to 4587jeh2005-09-212-3/+3
|
* Update to 0.31mnag2005-09-212-3/+3
| | | | | | PR: ports/86386 Submitted by: David Thiel <lx@redundancy.redundancy.org> (maintainer) Approved by: pav (mentor)
* Upgrade termlog. This fixes termlog on -CURRENT and hopefully the snpcsjp2005-09-212-3/+3
| | | | | | | fixes in -CURRENT will be MFC'ed to RELENG_6 so it will work on all releases again. Approved by: petef
* - update to 0.22leeym2005-09-212-4/+4
|
* Fix build with milter on FreeBSD 4.X.simon2005-09-211-0/+16
|
* update to 2.5.3oliver2005-09-213-17/+18
| | | | | | PR: 86331 Submitted by: oliver Approved by: maintainer
* Update to 4586jeh2005-09-212-3/+3
|
* Update to 4585jeh2005-09-202-3/+3
|
* Reset maintainership of Seamus Venasse who has not responded for some time.erwin2005-09-204-4/+4
| | | | | | | Thank you for your efforts in the past! Noticed by: tobez Approved by: portmgr (self)
* - Update to 0.87pav2005-09-206-38/+4
| | | | | | | | | PR: ports/86276 Submitted by: dawnshade <h-k@mail.ru> Approved by: maintainer timeout (3 days) timeout rushed by simon (secteam hat) Security: CAN-2005-2919, CAN-2005-2920, http://www.secunia.com/advisories/16848/
* - update default to 0.9.8dinoex2005-09-201-15/+18
| | | | - new option WITH_OPENSSL_097
* Fix BUILD_DEPENDS on libpcap for -STABLE, it was overriding the dependencyse2005-09-201-1/+1
| | | | on libnet-devel ...
* Update to 4584jeh2005-09-202-3/+3
|
* Add missed dependency from textproc/py-libxml2 [1]vsevolod2005-09-202-10/+91
| | | | | | | Convert to static plist. PR: 86335 Submitted by: rik <freebsd-ports@rikrose.net>
* Fix the htdig entry, the port version and the VuXML version did notremko2005-09-201-1/+1
| | | | | | align. Reported by: Nic Bellamy <nic at bellamy dot co dot nz>
* Fix the squirrelmail entry since only versions prior to 1.4.5 wereremko2005-09-201-1/+2
| | | | | | affected. Bump modification date accordingly. Reported by: Avinash Piare <avinash at piare dot org>
* Fixed plist.lth2005-09-191-1/+0
| | | | Reported by: pointyhat via kris
* Pamsfs is a PAM module that logs a user into a SFS server onpav2005-09-185-0/+145
| | | | | | | | system login. The primary reason for doing this is to allow users' home-directories to be located on a SFS server. PR: ports/86095 Submitted by: David Thiel <lx@redundancy.redundancy.org>
* FreeBSD 6 no longer adds debug.if_* sysctl variables in its default kernelvs2005-09-186-3/+18
| | | | | | | | (according to the release notes), so our heuristic assumes the module is missing and tries to load it, which fails as the module already exists. PR: ports/86286 Submitted by: maintainer
* Document the following items:remko2005-09-181-0/+60
| | | | | | | o apache -- Certificate Revocation List (CRL) off-by-one vulnerability o squirrelmail -- _$POST variable handling allows for various attacks Reviewed by: simon
* Add p5-Digest-SHA 5.31, Perl extension for SHA-1/224/256/384/512.lth2005-09-185-0/+47
| | | | | PR: ports/84570 Submitted by: Travis Campbell <hcoyote@ghostar.org>
* Fixed plistlth2005-09-171-1/+1
| | | | Reported by: pointyhat via kris
* Update to 0.6.0mnag2005-09-176-140/+15
| | | | | | | | Submitted to ports@ for test. Without reply. PR: ports/83748 Submitted by: Marcus Grando <marcus@corp.grupos.com.br> Approved by: pav (mentor), anders (maintainer timeout, 58 days)
* Update my emailmnag2005-09-175-6/+6
| | | | Approved by: pav (mentor)
* Update to 3.2.2mnag2005-09-163-11/+11
| | | | Approved by: pav (mentor)
* - Update to 3.93garga2005-09-162-3/+3
| | | | | PR: ports/86113 Submitted by: maintainer
* ClusterSSH controls a number of xterm windows via a single graphicalpav2005-09-164-0/+35
| | | | | | | | console window to allow commands to be interactively run on multiple servers over an ssh connection. PR: ports/84970 Submitted by: David Thiel <lx@redundancy.redundancy.org>
* - Add an entry on possible DOS condition regarding NTLM in squidpav2005-09-161-0/+28
| | | | | PR: ports/86179 Submitted by: Thomas-Martin Seck <tmseck@netcologne.de>
* Udate to DAT 4582jeh2005-09-162-3/+3
|
* Add p5-Crypt-NULL 1.02, perl implementation of the NULL encryptionlth2005-09-155-0/+39
| | | | | | | algorithm. PR: ports/84629 Submitted by: TAKAHASHI Kaoru <kaoru@kaisei.org>
* Update to 0.6.1vsevolod2005-09-153-4/+3
| | | | Submitted by: Yvan Vanhullebus (maintainer)
* - Firewalk port really depends on net/libnet-devel, but the check can be ↵vs2005-09-152-1/+14
| | | | | | | | | satisfied by net/libnet. - BIOCIMMEDIATE is undefined in some cases. PR: ports/86132 Submitted by: Michael Scheidell via maintainer
* Update to 0.4.5.marcus2005-09-154-6/+6
|
* - Update to 0.9.6pav2005-09-155-27/+23
| | | | | | PR: ports/83453 Submitted by: Janos Mohacsi <janos.mohacsi@bsd.hu> Approved by: bms (maintainer; blanket)
* - Remove dependencies on security/pf, it was removed. pf is in base sincepav2005-09-151-4/+2
| | | | | | 502106 Pointy hat to: pav
* - Remove security/pf and security/authpf ports. They were only useful onpav2005-09-1521-1392/+0
| | | | | | FreeBSD 5.0 - 5.2.1. Requested by: mlaier (maintainer) via linimon
* Document X11 server -- pixmap allocation vulnerability.lesi2005-09-151-0/+33
| | | | Reviewed by: simon
* Update to DAT 4581jeh2005-09-152-3/+3
|
* Drop maintainership, since I'm buried in the $REALLIFE stuff.krion2005-09-141-1/+1
|
* Add signing-party.jylefort2005-09-144-0/+81
| | | | | | | | | | | | | | | | | | | signing-party is a collection for all kinds of PGP/GnuPG related things, including signing scripts, party preparation scripts, etc. * caff: CA - Fire and Forget signs and mails a key * pgp-clean: removes all non-self signatures from key * pgp-fixkey: removes broken packets from keys * gpg-mailkeys: simply mail out a signed key to its owner * gpg-key2ps: generate PostScript file with fingerprint paper strips * gpglist: show who signed which of your UIDs * gpgsigs: annotates list of GnuPG keys with already done signatures * keylookup: ncurses wrapper around gpg --search WWW: http://pgp-tools.alioth.debian.org/ PR: ports/86077 Submitted by: Johan van Selst <johans@stack.nl>
* - Website is gonepav2005-09-141-1/+0
|
* Document unzip -- permission race vulnerability. [1]remko2005-09-141-1/+35
| | | | | | Update the recent htdig entry with it's corrected version. Reviewed by: simon [1]
* Update to DAT 4580jeh2005-09-142-3/+3
|
* change USE_PERL5 to USE_PERL5_BUILD because perl is only needed during theoliver2005-09-131-1/+1
| | | | | | build process Approved by: maintainer
* - Fix WWWgarga2005-09-131-1/+1
| | | | | PR: ports/86042 Submitted by: Marcus Alves Grando <marcus@corp.grupos.com.br>
* Update to DAT 4579jeh2005-09-132-3/+3
|
* Update to 0.3.6b that fixes build with samba 3.0.20.vsevolod2005-09-122-3/+3
| | | | | PR: 86013 Submitted by: Jean Milanez Melo (maintainer)
* Update to 1.9.19lofi2005-09-123-14/+3
|
* Update to 0.9.12lofi2005-09-123-3/+15
|
* Update to 1.16skv2005-09-122-3/+3
|
* Update to 1.11skv2005-09-122-3/+3
| | | | Changes: http://search.cpan.org/src/GAAS/Digest-1.11/Changes
* - Revive CONFLICTS with gnutls-devel [1]novel2005-09-112-4/+3
| | | | | | | - Do not build static libraries [2] Requested by: kris [1] vs [2]
* Document firefox & mozilla -- buffer overflow vulnerability.simon2005-09-111-0/+97
| | | | Prodded by: pav
* - Replace .error with IGNORE to prevent INDEX build failurespav2005-09-111-12/+3
|
* - Only for FreeBSD 4.X and 5.Xpav2005-09-111-0/+4
| | | | Reported by: krismail
* Update to DAT 4578jeh2005-09-102-3/+3
|
* - Update WWWpav2005-09-101-4/+1
|
* - Update to 2.1.0pav2005-09-102-7/+3
| | | | | PR: ports/85899 Submitted by: Rob Evers <rob@debank.tv> (maintainer)
* Don't CONFLICTS with gnutls-devel since it has been removed.novel2005-09-091-2/+0
|
* Update to 0.9.6lawrance2005-09-0923-503/+118
| | | | | | | | | | | | - Add rcng startup - No longer touch pksd.conf, only pksd.conf.sample - Ensure the port builds against db2 from ports by deleting the included version. Add post-patch bits to help this happen. - Submitter takes maintainership PR: ports/85802 Submitted by: Graham Todd <gtodd@bellanet.org> (new maintainer) Approved by: Jason Harris <jharris@widomaker.com> (maintainer)
* Give maintainership to submitterlawrance2005-09-091-1/+1
| | | | | PR: ports/85870 Submitted by: Daniel Roethlisberger <daniel@roe.ch>
* Update to DAT 4577jeh2005-09-092-3/+3
|
* Update to version 3.90krion2005-09-082-3/+4
|
* Assign maintainership to daniel@roe.chkrion2005-09-081-1/+1
| | | | | PR: ports/85855 Submitted by: Daniel Roethlisberger <daniel@roe.ch>
* Update to DAT 4576jeh2005-09-082-3/+3
|
* s/BROKEN/IGNORE/lawrance2005-09-071-1/+1
| | | | | | | | | | | Reported by: linimon Log: Mark broken for OSVERSION >= 500000. Does not build without S/Key libraries and headers. PR: ports/85256 Submitted by: Christoph Weber-Fahr <wefa@tnd37.tnd.arcor.net>
* Mark broken for OSVERSION >= 500000. Does not build withoutlawrance2005-09-071-0/+4
| | | | | | | S/Key libraries and headers. PR: ports/85256 Submitted by: Christoph Weber-Fahr <wefa@tnd37.tnd.arcor.net>
* Forgot to uncomment OPTIONS after testing.novel2005-09-071-4/+4
| | | | Noted by: David Thiel <lx@redundancy.redundancy.org>