Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | - Update to 0.0.8 | pav | 2004-10-12 | 6 | -14/+16 |
| | | | | | PR: ports/72086 Submitted by: rik <freebsd-security@rikrose.net> (maintainer) | ||||
* | - Update to 2.0 | pav | 2004-10-12 | 4 | -5/+36 |
| | | | | | | | - Add gmp dependency on FreeBSD 5.x PR: ports/72172 Submitted by: Marcus Grando <marcus@corp.grupos.com.br> | ||||
* | - Update to 1.34 | pav | 2004-10-12 | 2 | -8/+6 |
| | | | | | | | - Please portlint PR: ports/72036 Submitted by: Daan van de Linde <daan@xs4all.nl> | ||||
* | - Update to 2.4.0 | pav | 2004-10-12 | 2 | -3/+3 |
| | | | | | PR: ports/71896 Submitted by: Olivier Tharan <olive@oban.frmug.org> (maintainer) | ||||
* | Fix build with bind9 in the base system. | marcus | 2004-10-11 | 1 | -3/+8 |
| | | | | | Reported by: pointyhat via kris Approved by: portmgr (implicit) | ||||
* | Fix build on ia64 | krion | 2004-10-10 | 1 | -3/+8 |
| | | | | | | PR: ports/71741 Submitted by: maintainer Approved by: portmgr (implicit) | ||||
* | fix http://vuxml.freebsd.org/92268205-1947-11d9-bc4a-000c41e2cdad.html | ume | 2004-10-09 | 2 | -1/+17 |
| | | | | | | Reported by: nectar Approved by: portmgr (krion) Obtained from: https://bugzilla.andrew.cmu.edu/cgi-bin/cvsweb.cgi/src/sasl/lib/common.c#rev1.104 | ||||
* | Document unsafe use of environmental variable SASL_PATH in cyrus-sasl. | nectar | 2004-10-09 | 1 | -0/+31 |
| | | | | Approved by: portmgr | ||||
* | Mark IGNORE because the package somehow includes a dangling symlink, i.e. | kris | 2004-10-07 | 1 | -0/+2 |
| | | | | | | it is incomplete. Approved by: portmgr (self) | ||||
* | Fix the code so GCC 3.4.2 likes it better, and unbreak. | danfe | 2004-10-06 | 2 | -7/+10 |
| | | | | | Reported by: kris Approved by: portmgr (krion), fjoe (mentor, implicit) | ||||
* | Add some more apache ports. | trhodes | 2004-10-06 | 1 | -2/+14 |
| | | | | | | Fix two errors found by nectar. Approved by: portmgr | ||||
* | Add imp3 issue, add apache13-ssl issue, correct a tag. | trhodes | 2004-10-06 | 1 | -2/+31 |
| | | | | Approved by: portmgr | ||||
* | Note that older packages of bmon were dangerously installed set-user-ID. | nectar | 2004-10-05 | 1 | -0/+25 |
| | | | | Approved by: portmgr | ||||
* | Document GnuTLS denial-of-service (already mentioned in portaudit's | nectar | 2004-10-05 | 1 | -0/+39 |
| | | | | | | database). Approved by: portmgr | ||||
* | Record another PHP vulnerability. | nectar | 2004-10-05 | 1 | -0/+45 |
| | | | | Approved by: portmgr | ||||
* | Record another PHP security issue. | nectar | 2004-10-05 | 1 | -1/+50 |
| | | | | Approved by: portmgr | ||||
* | Note that xv should not be used. | nectar | 2004-10-05 | 1 | -0/+40 |
| | | | | Approved by: portmgr | ||||
* | Note a symlink vulnerability in getmail. | nectar | 2004-10-05 | 1 | -0/+28 |
| | | | | | Submitted by: Shane Kinney <mod6@freebsdhackers.net> Approved by: portmgr | ||||
* | Fill in empty topic from previous commit. | nectar | 2004-10-05 | 1 | -1/+1 |
| | | | | | Noticed by: Shane Kinney <mod6@freebsdhackers.net> Approved by: portmgr | ||||
* | Record FreeBSD-SA-04:15.syscons. | nectar | 2004-10-05 | 1 | -0/+38 |
| | | | | Approved by: portmgr | ||||
* | Add missing PORTEPOCH for samba. | nectar | 2004-10-04 | 1 | -1/+1 |
| | | | | | Noticed by: dinoex Approved by: portmgr | ||||
* | Note racoon certificate verification bug. | nectar | 2004-10-04 | 1 | -0/+26 |
| | | | | | Submitted by: Jon Passki <cykyc@yahoo.com> Approved by: portmgr | ||||
* | Note distcc IP address ACL bug. | nectar | 2004-10-03 | 1 | -1/+27 |
| | | | | | Submitted by: Jon Passi <cykyc@yahoo.com> Approved by: portmgr | ||||
* | Remove a duplicate entry. | nectar | 2004-10-03 | 1 | -56/+5 |
| | | | | | Submitted by: Jon Passki <cykyc@yahoo.com> Approved by: portmgr | ||||
* | Correct the version number for latest Mozilla entry. | nectar | 2004-10-01 | 1 | -4/+4 |
| | | | | | | (cut-n-paste damage) Approved by: portmgr | ||||
* | Document the last few of the relatively recent Mozilla vulnerabilities. | nectar | 2004-10-01 | 1 | -0/+110 |
| | | | | Approved by: portmgr | ||||
* | Correct mangled CVE name: s/8983/0903/ | nectar | 2004-10-01 | 1 | -1/+2 |
| | | | | Approved by: portmgr | ||||
* | Add another two older vulnerabilities affecting Mozilla & co. | nectar | 2004-10-01 | 1 | -8/+161 |
| | | | | | | | | | Continue to try hard to cover past package names: - I missed el-linux-mozillafirebird previously. - Move all the `obsolete' package names into one place for clarity. Approved by: portmgr | ||||
* | Don't forget `ja-samba' also. | nectar | 2004-10-01 | 1 | -0/+1 |
| | | | | Approved by: portmgr | ||||
* | Note samba file disclosure vulnerability. | nectar | 2004-10-01 | 1 | -0/+31 |
| | | | | Approved by: portmgr | ||||
* | Increase USE_GCC to 3.4 for those ports which compile with it. | kris | 2004-09-30 | 2 | -2/+2 |
| | | | | Approved by: portmgr | ||||
* | Fix apache version number entry, bump modified date for apache as well. | trhodes | 2004-09-30 | 1 | -2/+2 |
| | | | | Approved by: portmgr | ||||
* | BROKEN on 5.x: Does not compile | kris | 2004-09-29 | 1 | -0/+4 |
| | | | | Approved by: portmgr (self) | ||||
* | BROKEN on 5.x: Does not compile | kris | 2004-09-29 | 1 | -1/+7 |
| | | | | Approved by: portmgr (self) | ||||
* | Make an initial attempt at covering all Mozilla/Firefox/Thunderbird | nectar | 2004-09-29 | 1 | -9/+36 |
| | | | | | | | package names that we've had. Similar changes need to be made to many other entries, but let's use this one as a test subject first. Approved by: portmgr | ||||
* | Correct spelling of phpnuke package name. | nectar | 2004-09-28 | 1 | -1/+2 |
| | | | | | Reported by: Dan Langille Approved by: portmgr | ||||
* | Note BMP decoder flaws in Mozilla/Firefox/Thunderbird. | nectar | 2004-09-28 | 1 | -0/+48 |
| | | | | Approved by: portmgr | ||||
* | Note stack buffer overflow in Mozilla mail. | nectar | 2004-09-28 | 1 | -1/+41 |
| | | | | Approved by: portmgr | ||||
* | Document Mozilla/Firefox/Thunderbird heap buffer overflows. | nectar | 2004-09-28 | 1 | -0/+57 |
| | | | | Approved by: portmgr | ||||
* | Correct the package name for phpMyAdmin. | nectar | 2004-09-28 | 1 | -1/+2 |
| | | | | | Reported by: Matthew Seaman <m.seaman@infracaninophile.co.uk> Approved by: portmgr | ||||
* | Correct another typo. :-( | kris | 2004-09-28 | 1 | -1/+1 |
| | | | | | | Spotted by: eik Approved by: portmgr (self) XL pointy hat to: self | ||||
* | Correct typo in previous | kris | 2004-09-28 | 1 | -1/+1 |
| | | | | | Approved by: portmgr (self) Pointy hat to: self | ||||
* | Now builds on amd64 | kris | 2004-09-28 | 1 | -2/+2 |
| | | | | Approved by: portmgr (self) | ||||
* | Add CERT Vulnerability Note references to xpm entry. | nectar | 2004-09-27 | 1 | -1/+3 |
| | | | | Approved by: portmgr | ||||
* | Note two older vulnerabilities in PHP. | nectar | 2004-09-27 | 1 | -0/+111 |
| | | | | | Submitted by: Jon Passki <cykyc@yahoo.com> Approved by: portmgr | ||||
* | Note subversion information disclosure vulnerability. | nectar | 2004-09-27 | 1 | -0/+36 |
| | | | | | Submitted by: lev Approved by: portmgr | ||||
* | Add missing PORTEPOCH in a mozilla entry. | nectar | 2004-09-27 | 1 | -3/+5 |
| | | | | | | | Correct package name in an apache entry. Reported by: Dan Langille <dan@langille.org> Approved by: portmgr | ||||
* | BROKEN on 5.x: Does not compile | kris | 2004-09-26 | 4 | -1/+19 |
| | | | | Approved by: portmgr (self) | ||||
* | BROKEN: Does not build | kris | 2004-09-26 | 1 | -0/+2 |
| | | | | Approved by: portmgr (self) | ||||
* | BROKEN on 5.x: Does not compile | kris | 2004-09-26 | 1 | -1/+7 |
| | | | | Approved by: portmgr (self) | ||||
* | Forgot to add <modified> element for last commit. | nectar | 2004-09-25 | 1 | -0/+1 |
| | | | | Approved by: portmgr | ||||
* | Add missing PORTEPOCH on one of the mozilla entries. | nectar | 2004-09-25 | 1 | -1/+1 |
| | | | | | Noticed by: Dan Langille <dan@langille.org> Approved by: portmgr | ||||
* | Document vulnerabilities in lha. | nectar | 2004-09-23 | 1 | -0/+41 |
| | | | | | Reviewed by: dinoex Approved by: portmgr | ||||
* | Lately it seems I like to use dashes in topics... but I should at | nectar | 2004-09-23 | 1 | -19/+19 |
| | | | | | | least be consistent with how many. s/---/--/ Approved by: portmgr | ||||
* | Document mysql buffer overflow. | nectar | 2004-09-23 | 1 | -0/+27 |
| | | | | | Reported by: ale Approved by: portmgr | ||||
* | Update to pam_alreadyloggedin-0.3 to unbreak. There should be no | green | 2004-09-23 | 2 | -12/+4 |
| | | | | | | | | | visible changes. This work was done by Jeremie Le Hen; thanks! Submitted by: Jeremie Le Hen <jeremie@le-hen.org> Approved by: portmgr | ||||
* | Document Mozilla security icon spoofing vulnerability. | nectar | 2004-09-23 | 1 | -0/+39 |
| | | | | Approved by: portmgr | ||||
* | Document Mozilla vulnerability involving NULL bytes in FTP URLs. | nectar | 2004-09-23 | 1 | -1/+46 |
| | | | | | | Also, correct s/firebird/firefox/ in a previously documented issue. Approved by: portmgr | ||||
* | Document Mozilla automatic file upload vulnerability. | nectar | 2004-09-22 | 1 | -3/+28 |
| | | | | Approved by: portmgr | ||||
* | Document mozilla certificate import denial-of-service vulnerability. | nectar | 2004-09-22 | 1 | -0/+48 |
| | | | | Approved by: portmgr | ||||
* | Note a file name disclosure issue in rssh. | nectar | 2004-09-22 | 1 | -0/+38 |
| | | | | | Reported by: leeym Approved by: portmgr | ||||
* | - replace "@dirrm ..." with "@unexec rmdir ..." | leeym | 2004-09-22 | 1 | -1/+1 |
| | | | | | | | | (p5-IO-INET6 will install files in SITE_PERL/PERL_ARCH/auto/IO/Socket/INET6) PR: 70640 Submitted by: leeym Approved by: portmgr (marcus) | ||||
* | Add entry describe GNU Radius denial-of-service vulnerability. | nectar | 2004-09-21 | 1 | -0/+36 |
| | | | | Approved by: portmgr | ||||
* | Add sudoedit vulnerability. | nectar | 2004-09-21 | 1 | -0/+24 |
| | | | | Approved by: portmgr | ||||
* | In latest CVS entry, remove the reference to the exploit. It does | nectar | 2004-09-20 | 1 | -1/+0 |
| | | | | | | | not apply to any of these vulnerabilities, but to the previous CVS vulnerability (CAN-2004-0396). Approved by: portmgr | ||||
* | Oh yeah, add affected FreeBSD versions for CVS issues. | nectar | 2004-09-20 | 1 | -1536/+1534 |
| | | | | Approved by: portmgr | ||||
* | Update CVS entry with some details. | nectar | 2004-09-20 | 1 | -13/+31 |
| | | | | Approved by: portmgr | ||||
* | Add an entry for the mod_proxy buffer overflow existant in apache13. | trhodes | 2004-09-20 | 1 | -0/+25 |
| | | | | Approved by: portmgr | ||||
* | Update to 1.6.8p1 | mharo | 2004-09-19 | 2 | -4/+4 |
| | | | | | Submitted by: many people Approved by: portsmgr (marcus) | ||||
* | - unbreak this port on 5.x | leeym | 2004-09-19 | 2 | -9/+27 |
| | | | | | | PR: 71853 Submitted by: leeym Approved by: portmgr (marcus) | ||||
* | BROKEN on 5.x: Does not compile | kris | 2004-09-19 | 4 | -4/+28 |
| | | | | Approved by: portmgr (self) | ||||
* | Note some fixes for XPM image decoding vulnerabilities. | nectar | 2004-09-18 | 1 | -4/+16 |
| | | | | | | | | Submitted by: lesi Add references to Chris Evans's advisories while I'm at it. Approved by: portmgr | ||||
* | BROKEN on 5.x: Does not compile | kris | 2004-09-18 | 1 | -1/+7 |
| | | | | Approved by: portmgr (self) | ||||
* | BROKEN: Broken pkg-plist | kris | 2004-09-18 | 1 | -0/+2 |
| | | | | Approved by: portmgr (self) | ||||
* | Update to gdk-pixbuf vulnerability to reflect the fixed version of gtk20. | marcus | 2004-09-17 | 1 | -1/+2 |
| | | | | Approved by: portmgr( implicit) | ||||
* | Note that a patched version of webmin 1.150 is now available, thanks | nectar | 2004-09-16 | 1 | -2/+4 |
| | | | | | | | | | | to olengi@. Submitted by: olengi Add a paragraph introducing the Webmin blockquote while I'm here. Approved by: portmgr | ||||
* | Note gdk-pixbuf image decoding issues. | nectar | 2004-09-16 | 1 | -0/+36 |
| | | | | Approved by: portmgr | ||||
* | clement@ has patched Apache 2. | nectar | 2004-09-16 | 1 | -3/+3 |
| | | | | Approved by: portmgr | ||||
* | Note CUPS printer queue browser denial-of-service. | nectar | 2004-09-16 | 1 | -0/+24 |
| | | | | Approved by: portmgr | ||||
* | Note Apache 2 IPv6 address parsing bug. | nectar | 2004-09-15 | 1 | -0/+28 |
| | | | | Approved by: portmgr | ||||
* | Note new libXpm vulnerabilities. | nectar | 2004-09-15 | 1 | -0/+46 |
| | | | | Approved by: portmgr | ||||
* | I appear to have deleted a line at the last minute. Restore it. | nectar | 2004-09-15 | 1 | -0/+1 |
| | | | | Approved by: portmgr | ||||
* | Add mod_dav denial-of-service issue. | nectar | 2004-09-15 | 1 | -0/+28 |
| | | | | Approved by: portmgr | ||||
* | Oops, forgot to note that the previous issue affects only the Apache 2.x | nectar | 2004-09-15 | 1 | -1/+1 |
| | | | | | | series. Approved by: portmgr | ||||
* | Add Apache 2 vulnerability concerning environmental variables in | nectar | 2004-09-15 | 1 | -0/+34 |
| | | | | | | configuration files. Approved by: portmgr | ||||
* | Repair three <freebsdpr> elements. The content of these elements | nectar | 2004-09-15 | 1 | -3/+3 |
| | | | | | | | must be e.g. "ports/46613", not just "46613". Reported by: Matthew Seaman <m.seaman@infracaninophile.co.uk> Approved by: portmgr | ||||
* | Note that some versions of OpenOffice have been corrected. | nectar | 2004-09-15 | 1 | -1/+2 |
| | | | | Approved by: portmgr | ||||
* | Fix botched date entry and correct iDefense URL. | trhodes | 2004-09-14 | 1 | -2/+2 |
| | | | | Approved by: portmgr | ||||
* | Really add Samba 3 vulnerability. | trhodes | 2004-09-14 | 1 | -1/+26 |
| | | | | | | | Remove incorrect URL in mpg123 entry. Approved by: portmgr URL noticed: nectar | ||||
* | Correct version. Note my last commit here was for mpg123 instead of | trhodes | 2004-09-14 | 1 | -1/+1 |
| | | | | | | | samba3. Noticed by: nectar Approved by: portmgr | ||||
* | - There is a WITHOUT_X11 version of ImageMagick that needs to be | nectar | 2004-09-14 | 1 | -2/+221 |
| | | | | | | | | | | | | | | | | | taken into account. - Fix transposed characters in `isakmpd'. Noticed by: Dan Langille <dan@langille.org> - Add CVE name reference for ImageMagick. - Add webmin temporary file handling issue. - Add OpenOffice temporary file handling issue. - Widen the `KDE frame injection' issue to cover Mozilla, Firebird, Netscape, and Opera as well - Add Mozilla/Firebird/Netscape SOAPParameter vulnerability - Add Mozilla/Thunderbird/Netscape POP client vulnerability Approved by: portmgr | ||||
* | Update for recent Samba3 vulnerabilities. | trhodes | 2004-09-14 | 1 | -0/+27 |
| | | | | Approved by: portmgr | ||||
* | - Update to 1.0.20, fixing GnuTLS certificate chain verification DoS | sergei | 2004-09-10 | 3 | -6/+5 |
| | | | | | | | | | | | vulnerability (portaudit ID: 84ab58cf-e4ac-11d8-9b0a-000347a4fa7d), described in the following advisories: - http://www.hornik.sk/SA/SA-20040802.txt - http://secunia.com/advisories/12156 PR: ports/71502 Submitted by: Koop Mast <kwm@rainbow-runner.nl> Approved by: portmgr (eik, marcus) | ||||
* | Typo-fix in a comment | brueffer | 2004-09-09 | 1 | -1/+1 |
| | | | | Approved by: portmgr (krion) | ||||
* | - star-devel: privilege escalation | eik | 2004-09-09 | 2 | -1/+7 |
| | | | | | | | | - multi-gnome-terminal: information leak - usermin: remote shell command injection and insecure installation - mpg123: layer 2 decoder buffer overflow Approved by: portmgr (implicit) | ||||
* | - XSS vulnerability in phpGroupWare wiki module | eik | 2004-09-07 | 2 | -8/+42 |
| | | | | | | - add some references Approved by: portmgr (implicit) | ||||
* | managed to break this just in time for the ports freeze. | arved | 2004-09-04 | 1 | -2/+0 |
| | | | | | Submitted by: lofi, eik Approved by: portmgr (eik) | ||||
* | multiple vulnerabilities in LHA | eik | 2004-09-04 | 1 | -0/+36 |
| | |||||
* | Nuke the gnupg sigchecking code. There are bugs and I don't have the time | arved | 2004-09-04 | 2 | -16/+0 |
| | | | | | | | to work on this now. PR: 66417 Submitted by: Lupe Christoph <lupe@lupe-christoph.de> | ||||
* | grrrr... left the test case intact | eik | 2004-09-04 | 1 | -1/+1 |
| | |||||
* | - update to version 0.5.9 | eik | 2004-09-04 | 3 | -14/+34 |
| | | | | (first attempts to check the base system for vulnerabilities) | ||||
* | - add some references | eik | 2004-09-04 | 3 | -8/+142 |
| | | | | | | | | | | - extend ImageMagick entry - squid ntlm authentication helper DoS - multiple vpopmail vulnerabilities - first attempts to check the base system for vulnerabilities: + cvs server code + zlib DoS - BSD license portaudit.xml | ||||
* | Fix build when using ccache | eik | 2004-09-04 | 1 | -1/+31 |
| | | | | | PR: 71343 Submitted by: Michael Johnson <ahze@ahze.net> | ||||
* | Update to 3.23.0. This release of super fixes a potential root exploit: | obrien | 2004-09-04 | 4 | -17/+12 |
| | | | | | | | http://xforce.iss.net/xforce/xfdb/16458 PR: 71328 Submitted by: Piet Delport <pjd@point45.com> | ||||
* | Add CONFLICTS with openvpn-devel | vs | 2004-09-04 | 3 | -0/+6 |
| | | | | | PR: ports/71337 Submitted by: maintainer | ||||
* | - update to 0.19. | clsung | 2004-09-03 | 2 | -3/+3 |
| | | | | Approved by: vanilla (co-mentor) | ||||
* | Implement a "mgrate" facility that lets one migrate/overwrite the LDAP | marcus | 2004-09-03 | 2 | -8/+59 |
| | | | | | | | | | | | | | | | | | | userPassword field of the user being authenticated. The PAM and LDAP usernames must be the same. This makes "pam_ldap migrate" similar to "pam_smbpass migrate". This has been submitted to PADL in http://bugzilla.padl.com/show_bug.cgi?id=178. [1] Allow pam_ldap to change user passwords under certain circumstances. This has been submitted to PADL in http://bugzilla.padl.com/show_bug.cgi?id=177. [2] All of this is documented further at http://www.iem.pw.edu.pl/~wielebap/ldap/pam_ldap/pam_ldap_doc.pdf. PR: 71289 [1] 71287 [2] Submitted by: Pawel Wieleba <wielebap@iem.pw.edu.pl> | ||||
* | Fix the bus error on startup in -CURRENT and 5.x-BETA. It turns out | roam | 2004-09-02 | 2 | -1/+32 |
| | | | | | | | | | | | | | that the OpenSSL ENGINE code is, well, somewhat less than stellar, especially in combo with malloc's 'j' option. Even without it, though, there are some problems that I don't have time to look into right now. So, disable the OpenSSL ENGINE activation on FreeBSD 5.x, unless the WITH_STUNNEL_SSL_ENGINE knob is turned on. Also, while I'm here, fix the CONFIGURE_TARGET so the GNU configure script does not complain quite so loudly. Bump PORTREVISION for the functionality change (well, I guess you could say "not working" -> "working" is a functionality change ;) | ||||
* | - Update to 20040826 snapshot | vs | 2004-09-02 | 4 | -93/+46 |
| | | | | | | | | | - Fix fetching - Fix -pthread/-lc_r issue for good (courtesy of bsd.autotools.mk, who'd have guessed...) PR: ports/71168 Submitted by: Rob Evers (maintainer), me | ||||
* | Adjust the affected version for imlib now that the 2nd instance of BMP | nectar | 2004-09-02 | 1 | -1/+2 |
| | | | | loader has been corrected. | ||||
* | - Update to 0.44 | pav | 2004-09-02 | 2 | -5/+3 |
| | | | | | PR: ports/71249 Submitted by: Luiz Eduardo Roncato Cordeiro <cordeiro@nic.br> (maintainer) | ||||
* | Update to DAT 4389 | jeh | 2004-09-02 | 2 | -4/+3 |
| | |||||
* | Fix MIT krb5 Security Advisory 2004-002: double-free vulnerabilities | cy | 2004-09-02 | 12 | -4/+128 |
| | | | | | | in KDC and libraries Heads-up by: nectar | ||||
* | The recent commit to the krb5 port brought the version to 1.3.4_1 but | nectar | 2004-09-02 | 1 | -1/+1 |
| | | | | | did not correct one of the existing vulnerabilities. Update the affected range to compensate. | ||||
* | Fix MITKRB5-SA-2004-003: ASN.1 decoder denial-of-service. | cy | 2004-09-01 | 8 | -0/+56 |
| | | | | Heads-up by: nectar | ||||
* | - update to 0.7 | clsung | 2004-09-01 | 2 | -3/+3 |
| | | | | | | | | | | | | | - From ChangeLog - Added support for ESMTP [Andreas Steinmetz] - Fixed crash when too many connections established - Announce ourselves as 'clamsmtp' in EHLO/HELO responses which fixes 'loopback' problems with certain versions of Postfix 1.x - Better IO performance under heavy load - Fixed most warnings when compiled with -Wall - Fixed other minor bugs Approved by: vanilla (co-mentor) | ||||
* | Note recent MIT Kerberos 5 vulnerabilities. | nectar | 2004-09-01 | 1 | -0/+74 |
| | |||||
* | - update to version 3.70 (birthday edition, try the verbose mode) | eik | 2004-09-01 | 2 | -9/+3 |
| | |||||
* | Document imlib2 BMP decoder bug. | nectar | 2004-08-31 | 1 | -0/+27 |
| | |||||
* | Document BMP decoder bugs in imlib1 and ImageMagick. | nectar | 2004-08-31 | 1 | -0/+50 |
| | |||||
* | Update to 1.2.6. | osa | 2004-08-31 | 6 | -58/+58 |
| | | | | | | Utilize DOCSDIR and DATADIR macros. Approved by: kuriyama (maintainer) | ||||
* | Update to 1.7.1. | marcus | 2004-08-31 | 2 | -3/+3 |
| | |||||
* | samba printer change notification request DoS | eik | 2004-08-31 | 1 | -0/+1 |
| | |||||
* | Update to 0.3.3. | marcus | 2004-08-31 | 3 | -3/+11 |
| | | | | | PR: 71156 Submitted by: maintainer | ||||
* | Update to KDE 3.3 | lofi | 2004-08-31 | 6 | -190/+56 |
| | |||||
* | Correct bogus date in mysql entry. (It should be YYYY-MM-DD, not | nectar | 2004-08-30 | 1 | -2/+2 |
| | | | | | | DD-MM-YYYY.) Reported by: robert@openbsd.org | ||||
* | Add more references (particularly CVE names) for issues affecting | nectar | 2004-08-30 | 1 | -8/+24 |
| | | | | | | | SpamAssassin, tnftpd, ruby, mysql. Place text taken from another source inside <blockquote cite="..."> for ruby issue. | ||||
* | Fix location of pkg-config data. | vs | 2004-08-30 | 2 | -1/+12 |
| | | | | | | PR: ports/69149 Submitted by: Konstantin Oznobihin Approved by: maintainer timeout | ||||
* | correct/add some references | eik | 2004-08-30 | 1 | -35/+48 |
| | |||||
* | add some references, add ru-gaim | eik | 2004-08-30 | 1 | -2/+4 |
| | |||||
* | multiple vulnerabilities in gaim | eik | 2004-08-30 | 1 | -4/+4 |
| | |||||
* | I have been having a problem since the update to use update.ini instead | jeh | 2004-08-30 | 2 | -10/+23 |
| | | | | | of readme.txt of flipping between two version of DAT. 'update_dat' now compares the current value with the new one, before updating. | ||||
* | security bug in rscsi client code | eik | 2004-08-30 | 1 | -0/+4 |
| | | | | Submitted by: marius | ||||
* | Update to 2.30. | marcus | 2004-08-30 | 4 | -6/+6 |
| | | | | | PR: 71092 Submitted by: maintainer | ||||
* | - Update to 1.1.7 | pav | 2004-08-30 | 4 | -17/+26 |
| | | | | | PR: ports/71119 Submitted by: bugghy <bugghy@rootshell.be> (maintainer) | ||||
* | Remove -P option from tar. This patch has already been incorporated | linimon | 2004-08-29 | 1 | -0/+1 |
| | | | | | | | into the upstream sources. PR: ports/70806 Submitted by: SANETO Takanori <sanewo at ba2 dot so-net dot ne dot jp> | ||||
* | Add opieprint | mharo | 2004-08-29 | 5 | -17/+40 |
| | | | | output postscript with 100 OPIE passwords credit card sized | ||||
* | Patch the default installation locations to be FreeBSD-friendly. Bump | linimon | 2004-08-28 | 16 | -2/+201 |
| | | | | | | | portrevision. Users should take care when upgrading. PR: ports/70424 Submitted by: Jean Milanez Melo <jmelo at freebsdbrasil dot com dot br> (maintainer) | ||||
* | Add WWW line. | linimon | 2004-08-28 | 1 | -0/+2 |
| | |||||
* | Document NSS SSLv2 server buffer overflow (already referenced in | nectar | 2004-08-27 | 2 | -1/+37 |
| | | | | portaudit.txt). | ||||
* | Document ripMIME decoding bug (already referenced in portaudit.txt). | nectar | 2004-08-27 | 2 | -2/+38 |
| | |||||
* | Update to 0.41 | mat | 2004-08-27 | 3 | -5/+6 |
| | | | | | | PR: 70258 Submitted by: skv Approved by: maintainer timeout | ||||
* | Argh. Duplicate entry for "Scorched 3D server chat box format string ↵ | eik | 2004-08-27 | 1 | -2/+1 |
| | | | | vulnerabilty" | ||||
* | Mozilla / NSS S/MIME DoS vulnerability & Scorched 3D server chat box format ↵ | eik | 2004-08-27 | 1 | -0/+2 |
| | | | | string vulnerability | ||||
* | Remove <modified/> from the gnomevfs vulnerability since it was the same | marcus | 2004-08-27 | 1 | -1/+0 |
| | | | | | | as <entry/> and it needed to be last anyway. Suggested by: nectar | ||||
* | Update the gnomevfs entry to reflect the fixed versions. | marcus | 2004-08-27 | 1 | -2/+3 |
| | |||||
* | Add entry for moinmoin ACL bypass. | trhodes | 2004-08-27 | 1 | -0/+28 |
| | |||||
* | Note sanitize_path bug in rsync (already referenced in portaudit.txt). | nectar | 2004-08-27 | 2 | -1/+32 |
| | |||||
* | Unsafe URI handling in gnome-vfs, MidnightCommander. | nectar | 2004-08-27 | 1 | -0/+38 |
| | |||||
* | Document buffer overflows in SoX (already referenced in portaudit.txt). | nectar | 2004-08-27 | 2 | -1/+30 |
| | |||||
* | Document cookie bug in Konqueror (already referenced in portaudit.txt). | nectar | 2004-08-27 | 2 | -1/+45 |
| | |||||
* | Update to 2.1.1 | sem | 2004-08-27 | 4 | -17/+26 |
| | | | | | PR: ports/70933 Submitted by: maintainer | ||||
* | The tarball was rerolled because of security fix. | sem | 2004-08-27 | 1 | -2/+2 |
| | | | | | PR: ports/70978 Submitted by: Omer Faruk Sen <ofsen@enderunix.org> | ||||
* | - Update to 0.6.6 | pav | 2004-08-27 | 2 | -4/+4 |
| | | | | | PR: ports/70941 Submitted by: Janos Mohacsi <janos.mohacsi@bsd.hu> (maintainer) | ||||
* | Add missed file in pkg-plist | sem | 2004-08-27 | 1 | -0/+1 |
| | |||||
* | Update to 2.1.2 | sem | 2004-08-27 | 10 | -15/+728 |
| | | | | | | | make portlint happy PR: ports/70951 Submitted by: maintainer | ||||
* | support building nmap-3.59a5 WITH_PRERELEASE=yes | eik | 2004-08-26 | 2 | -0/+6 |
| | |||||
* | - Update to 1.4.0 | clsung | 2004-08-26 | 5 | -31/+60 |
| | | | | | | | | - Change MASTER_SITES - fixed build error in 5.x (compare to ports/69194) PR: ports/70444 Approved by: vanilla (co-mentor) | ||||
* | I forgot to change filename, which md5 info is correct for 0.6. | clsung | 2004-08-26 | 1 | -2/+2 |
| | | | | Approved by: vanilla (co-mentor) | ||||
* | Update to DAT 4388 | jeh | 2004-08-26 | 2 | -3/+3 |
| | |||||
* | Update to 20040825 | vs | 2004-08-26 | 2 | -3/+3 |
| | | | | | PR: ports/70947 Submitted by: Tim Bishop (maintainer) | ||||
* | - Fix "make validate" problem when textproc/xhtml-basic is | hrs | 2004-08-25 | 4 | -9/+12 |
| | | | | | | | | installed by adding an SGML declaration and DTDDECL. - Remove the --catalogs option for xmllint(1) in validate.sh. Approved by: nectar (maintainer) PR: ports/63035 | ||||
* | Remove libxine issue which is now documented in the FreeBSD VuXML | nectar | 2004-08-25 | 1 | -1/+0 |
| | | | | | | document. Reminded by: eik | ||||
* | update to 3.9.2. Fixes a remote exploitable buffer overflow: | eik | 2004-08-25 | 3 | -5/+4 |
| | | | | <http://www.freebsd.org/ports/portaudit/207f8ff3-f697-11d8-81b0-000347a4fa7d.html> | ||||
* | nss library SSL remote buffer overflow | eik | 2004-08-25 | 1 | -0/+1 |
| | |||||
* | multiple buffer overflows in xv | eik | 2004-08-25 | 1 | -2/+3 |
| | |||||
* | - update to 0.6 | clsung | 2004-08-25 | 2 | -3/+3 |
| | | | | | | | - Proper adding of customized header - Fixes to documentation Approved by: vanilla (co-mentor) | ||||
* | - Removed now-unneeded patch | sergei | 2004-08-24 | 1 | -11/+0 |
| | |||||
* | - Update to 1.0 | sergei | 2004-08-24 | 2 | -10/+10 |
| | |||||
* | Konqueror cross-domain cookie injection | eik | 2004-08-24 | 1 | -0/+1 |
| | |||||
* | handle some duplicates | eik | 2004-08-24 | 3 | -2/+71 |
| | |||||
* | Place port name in the description. | trhodes | 2004-08-24 | 1 | -1/+2 |
| | | | | Suggested by: eik | ||||
* | fix "too many open files" error when using the -r flag | eik | 2004-08-24 | 2 | -2/+2 |
| | | | | Noted by: nectar | ||||
* | Add libxine vcd URL handling issue. | nectar | 2004-08-24 | 1 | -0/+39 |
| | |||||
* | Add DoS in SpamAssassin. | nectar | 2004-08-23 | 1 | -0/+30 |
| | |||||
* | Add <modified> date for previous commit. | nectar | 2004-08-23 | 1 | -0/+1 |
| | |||||
* | fidogate-ds was also affected by the ``write files as `news' user'' | nectar | 2004-08-23 | 1 | -0/+4 |
| | | | | issue. | ||||
* | Off-by-one error in courier-imap entry. | nectar | 2004-08-23 | 1 | -1/+1 |
| | | | | Noticed by: oliver | ||||
* | Add a more useful reference for the Qt issue. | nectar | 2004-08-23 | 1 | -0/+1 |
| | |||||
* | Add Qt heap overflow issue. | nectar | 2004-08-23 | 1 | -0/+31 |
| | |||||
* | Add a security issue affected courier-imap when run with certain debug | nectar | 2004-08-23 | 1 | -0/+26 |
| | | | | flags. | ||||
* | Add fidogate issue. | nectar | 2004-08-23 | 1 | -0/+26 |
| | |||||
* | Add an issue covering a vulnerability in mysqlhotcopy. | nectar | 2004-08-23 | 1 | -0/+32 |
| | | | | Reported by: robert@openbsd.org | ||||
* | Cancel a VuXML entry for an Apache vulnerability that does not affect | nectar | 2004-08-23 | 1 | -42/+1 |
| | | | | | | FreeBSD. Reminded by: recent conversations :-) | ||||
* | Fix CC, CFLAGS | arved | 2004-08-23 | 1 | -0/+1 |
| | | | | | PR: 70824 Submitted by: Roman Bogorodskiy <bogorodskiy@inbox.ru> | ||||
* | Revert previous commit, I lost the race with arved who fixed the port. | kris | 2004-08-22 | 1 | -6/+1 |
| | | | | Pointy hat to: kris | ||||
* | that should fix the build on freebsd-6 | oliver | 2004-08-22 | 1 | -1/+19 |
| | | | | Reported by: pointyhat (via kris) | ||||
* | Fix the WITHOUT_ knobs to be compliant with the GNOME framework | sem | 2004-08-21 | 2 | -12/+10 |
| | | | | | PR: ports/70451, ports/70452 Submitted by: maintainer | ||||
* | a2ps: Possible execution of shell commands as local user. | eik | 2004-08-21 | 1 | -1/+2 |
| | |||||
* | Delete files forgotten in last repocopy | eik | 2004-08-21 | 9 | -152/+0 |
| | | | | | | | | | Fix typo <http://docs.freebsd.org/cgi/mid.cgi?200408010854.i718sxCc065477> <http://docs.freebsd.org/cgi/mid.cgi?200408010937.i719b446067158> Pointy hat to: sem | ||||
* | cancelled 6fd9a1e9-efd3-11d8-9837-000c41e2cdad: does not affect FreeBSD | eik | 2004-08-21 | 1 | -27/+1 |
| | | | | <http://docs.FreeBSD.org/cgi/mid.cgi?20040817123651.GB930> | ||||
* | BROKEN on 5.x: Does not compile with gcc 3.4.2 | kris | 2004-08-21 | 1 | -1/+6 |
| | |||||
* | Fix build with gcc 3.4 | arved | 2004-08-21 | 1 | -2/+10 |
| | |||||
* | Update to 1.1.6 | sem | 2004-08-20 | 2 | -3/+3 |
| | | | | | PR: ports/70706 Submitted by: maintainer | ||||
* | correct topic of eda0ade6-f281-11d8-81b0-000347a4fa7d | eik | 2004-08-20 | 1 | -1/+1 |
| | |||||
* | QT 3.x BMP (and possibly other graphics formats) heap-based overflow | eik | 2004-08-20 | 1 | -0/+1 |
| | |||||
* | Update to 1.6.8 | mharo | 2004-08-20 | 4 | -21/+9 |
| | |||||
* | My territory, suggested by ijliao. :p | clsung | 2004-08-20 | 3 | -3/+3 |
| | | | | Approved by: vanilla (co-mentor) | ||||
* | Add revelation, a password manager for the GNOME 2 desktop. It stores all | marcus | 2004-08-20 | 5 | -0/+123 |
| | | | | | | | | your account and passwords in a single, secure, place, and give you access to them all through a user-friendly graphical interface. PR: 70653 Submitted by: ports@c0decafe.net <ports@c0decafe.net> | ||||
* | Update to 1.25 | mat | 2004-08-19 | 3 | -29/+67 |
| | | | | | | | | use EXAMPLESDIR PR: 70093 Submitted by: Jeff Putsch <jdputsch@comcast.net> Approved by: maintainer timeout | ||||
* | potential security flaws in mod_ssl | eik | 2004-08-19 | 1 | -4/+6 |
| | |||||
* | Update to DAT 4387 | jeh | 2004-08-19 | 2 | -3/+3 |
| | |||||
* | patch-kmpstat.c is not necessary anymore. | sumikawa | 2004-08-19 | 2 | -28/+0 |
| | | | | | | PR: ports/70620, ports/70622 Submitted by: Helge Oldach <racoonaug04@oldach.net>, Ying-Chieh Chen <yinjieh@csie.nctu.edu.tw> | ||||
* | - update to 3.9p1 | dinoex | 2004-08-18 | 12 | -126/+92 |
| | | | | | | | set PORTVERSION 3.9.0.1 to avoid another bump of PORTEPOCH if 3.9.1p1 come out. - new option OPENSSH_SNAPSHOT | ||||
* | Update to 1.27 | krion | 2004-08-18 | 2 | -3/+3 |
| | | | | | PR: ports/70606 Submitted by: maintainer | ||||
* | Upgrade to 20040818a. | sumikawa | 2004-08-18 | 4 | -6/+6 |
| | |||||
* | Add a pointer to Przemyslaw Frasunek's advisory. | nectar | 2004-08-18 | 1 | -0/+1 |
| | |||||
* | For the lukemftpd/tnftpd issue, add a reference to NetBSD security | nectar | 2004-08-18 | 1 | -0/+1 |
| | | | | advisory now that it is available. | ||||
* | Note a vulnerability in lukemftpd/tnftpd. | nectar | 2004-08-18 | 1 | -0/+47 |
| | |||||
* | Don't require a particular version of libexpat. Use sh(1)'s `echo *' | mi | 2004-08-18 | 2 | -3/+3 |
| | | | | | | instead of spawning off ls(1) in pkg_check.sh. Approved by: maintainer | ||||
* | multiple CVS vulnerabilities | eik | 2004-08-17 | 1 | -0/+51 |
| | |||||
* | move a800386e-ef7e-11d8-81b0-000347a4fa7d to xml | eik | 2004-08-17 | 3 | -9/+36 |
| | |||||
* | Correct the version numbers and dates in the last entry. | knu | 2004-08-17 | 1 | -4/+4 |
| | |||||
* | Add an entry for: | knu | 2004-08-17 | 1 | -0/+30 |
| | | | | Ruby insecure file permissions in the CGI session management | ||||
* | Document a setgid "games" security issue in xonix. Based on a VuXML | nectar | 2004-08-17 | 1 | -0/+30 |
| | | | | | | entry that was Submitted by: robert@OpenBSD.org | ||||
* | - Fix build with gcc 3.4 | pav | 2004-08-17 | 2 | -5/+14 |
| | | | | | | | - Unconfuse doc install PR: ports/70530 Submitted by: Yonatan <Yonatan@Xpert.com> (maintainer) | ||||
* | Update to 2.29. | marcus | 2004-08-17 | 6 | -8/+10 |
| | | | | | PR: 70505 Submitted by: maintainer | ||||
* | Upgrade to 2.1.0. | vanilla | 2004-08-17 | 6 | -47/+51 |
| | | | | | PR: ports/70526 Submitted by: maintainer | ||||
* | ruby CGI::Session insecure file creation | eik | 2004-08-16 | 1 | -1/+2 |
| | |||||
* | Update to 1.0 | mat | 2004-08-16 | 3 | -6/+6 |
| | |||||
* | Update to DAT 4386 | jeh | 2004-08-16 | 2 | -3/+3 |
| | |||||
* | The distfile is now fetchable again, so rescue this port from death row. | kris | 2004-08-16 | 1 | -4/+0 |
| | |||||
* | Don't check the base system when PACKAGE_BUILDING | eik | 2004-08-16 | 1 | -0/+2 |
| | |||||
* | BROKEN: Unfetchable | kris | 2004-08-16 | 1 | -0/+2 |
| | |||||
* | multiple phpGroupWare vulnerabilities | eik | 2004-08-16 | 1 | -0/+2 |
| | |||||
* | phpGedView, jftpgw | eik | 2004-08-16 | 3 | -0/+29 |
| | |||||
* | Correct the version number range affected for ja-samba. | nectar | 2004-08-15 | 1 | -4/+4 |
| | | | | | | Correct the version number range affected for Mozilla 1.8 alphas. Problem hinted at by: eik | ||||
* | Fix build with gcc 3.4 | arved | 2004-08-15 | 1 | -0/+10 |
| | |||||
* | Correct the version number range affected for Mozilla 1.8 alphas. | nectar | 2004-08-15 | 1 | -4/+13 |
| | | | | | | | | | | Problem hinted at by: eik While I'm here, add a CVE name reference and a couple of other relevant Bugzilla links. It is interesting that this security issue was reported as early as 1999. Also, replace the text plagiarized from the Secunia advisory without attribution with a more helpful (maybe?) description of the issue. | ||||
* | Remove -a from the default fetch(1) flags, so that the daily security | eik | 2004-08-15 | 2 | -2/+2 |
| | | | | | | report is not delayed when the distribution site is down. Submitted by: kuriyama | ||||
* | Update to 0.6 | perky | 2004-08-15 | 3 | -3/+6 |
| | |||||
* | take care of $PREFIX/libdata/pkgconfig | oliver | 2004-08-15 | 1 | -0/+1 |
| | |||||
* | Fix build with gcc-3.4 | krion | 2004-08-15 | 2 | -0/+28 |
| | |||||
* | Fix plist. | krion | 2004-08-15 | 2 | -3/+3 |
| | | | | Pet portlint. | ||||
* | Fix plist. | krion | 2004-08-15 | 1 | -2/+3 |
| | |||||
* | Fix plist. | krion | 2004-08-15 | 3 | -0/+6 |
| | |||||
* | Fix build with gcc 3.4 | arved | 2004-08-14 | 1 | -0/+28 |
| | |||||
* | Format string vulnerability in jftpgw. | trhodes | 2004-08-14 | 1 | -0/+28 |
| | | | | Informed by: Robert Nagy <robert@openbsd.org> | ||||
* | apply xlist not to the own files | eik | 2004-08-14 | 2 | -10/+15 |
| | |||||
* | fix man page nits, | eik | 2004-08-14 | 3 | -36/+61 |
| | | | | | | | modify the vulnerability report depending on -q/-v (experimental) PR: 69935, 68942 Submitted by: Chris Pepper <pepper@reppep.com>, Johan Karlsson <k@numeri.campus.luth.se> | ||||
* | Fix RUN_DEPENDS | krion | 2004-08-14 | 1 | -1/+1 |
| | | | | | PR: ports/70419 Submitted by: maintainer | ||||
* | fix some vuxml duplicates, add sympa unauthorized list creation | eik | 2004-08-14 | 3 | -8/+680 |
| | |||||
* | Change MAINTAINER to perl@. | nork | 2004-08-13 | 8 | -8/+8 |
| | | | | | | I welcome bsd.port.mk introduced soon. Inspired by: freebsd-perl@ | ||||
* | - Add WITHOUT_NESSUS_GTK knob. | vs | 2004-08-13 | 8 | -40/+88 |
| | | | | | | | | - Upgrade rc.d script to the rc-ng style; bump PORTREVISION for that. - Add CONFLICTS. PR: ports/69878 Submitted by: Udo Schweigert (maintainer) | ||||
* | - Add WITHOUT_NESSUS_GTK knob. | vs | 2004-08-13 | 8 | -40/+88 |
| | | | | | | | | - Upgrade rc.d script to the rc-ng style; bump PORTREVISION for that. - Add CONFLICTS. PR: ports/69877 Submitted by: Udo Schweigert (maintainer) | ||||
* | Repair broken URL. | nectar | 2004-08-13 | 1 | -1/+1 |
| | | | | Noticed by: simon | ||||
* | Add another entry for kdelibs3 due to another missed patch. | lofi | 2004-08-13 | 1 | -0/+1 |
| | |||||
* | Correct entries for recent kde vuln's and add new entry for kdelibs | lofi | 2004-08-13 | 1 | -1/+3 |
| | | | | (3.2.3_3 didn't have all patches). | ||||
* | Add two issues covering three KDE advisories: two temporary file | nectar | 2004-08-13 | 1 | -0/+67 |
| | | | | handling issues, and a KHTML issue. | ||||
* | The last commit should have changed the comparison tag from <le> to <lt>. | marcus | 2004-08-13 | 1 | -1/+1 |
| |