Commit Graph

34402 Commits

Author SHA1 Message Date
Bryan Drewery
02dbfbc676 security/openssh-portable: libfido fix went in 505373243 2021-10-15 20:58:23 -07:00
Yuri Victorovich
c7b824ba23 security/seal: Update 3.6.5 -> 3.7.1
PR:		259191
Approved by:	lwhsu (maintainer)
2021-10-15 14:01:57 -07:00
Bryan Drewery
f4a5ae5fd8 security/openssh-portable: Fix sftp crash
This fixes an error trying to disabling process tracing.

It has been sent upstream.

PR:		259174
Submitted by:	mike at sentex dot net
2021-10-15 10:10:21 -07:00
Bradley T. Hughes
5cc1cb529d security/vuxml: document Node.js October 2021 Security Releases
https://nodejs.org/en/blog/vulnerability/oct-2021-security-releases/

Sponsored by:	Miles AS
2021-10-14 18:31:11 +00:00
Tobias C. Berner
cdf0f44fe2 KDE: Update KDE Plasma Desktop to 5.23
Thursday, 14 October 2021

   25 years ago today, Matthias Ettrich sent an email to the
   de.comp.os.linux.misc newsgroup explaining a project he was working
   on. The latest and direct result of that email (plus a quarter of a
   century of relentless experimentation, development and innovation)
   has just landed in KDE’s repositories.

   This time around, Plasma renews its looks and, not only do you get a
   new wallpaper, but also a gust of fresh air from an updated theme:
   Breeze - Blue Ocean. The new Breeze theme makes KDE apps and tools
   not only more attractive, but also easier to use both on the desktop
   and your phone and tablet.

   Of course, looks are not the only you can expect from Plasma 25AE:
   extra speed, increased reliability and new features have also found
   their way into the app launcher, the software manager, the Wayland
   implementation, and most other Plasma tools and utilities.

   Read on to find out all the details that make the new Plasma 25AE so
   deserving of a celebration [1]

Full announcement:
	[1] https://kde.org/announcements/plasma/5/5.23.0/
2021-10-14 18:25:04 +02:00
Mikael Urankar
01049111d7 security/hs-cryptol: Mark as broken on aarch64. 2021-10-14 17:58:01 +02:00
Po-Chuan Hsieh
19ae2c28eb security/py-pysaml26: Cosmetic change 2021-10-14 03:15:16 +08:00
Po-Chuan Hsieh
191ba0c960 security/py-pysaml24: Cosmetic change 2021-10-14 03:15:09 +08:00
Po-Chuan Hsieh
a26f036303 security/py-pysaml2: Cosmetic change 2021-10-14 03:15:02 +08:00
Po-Chuan Hsieh
14f1f5a3b8 security/py-m2crypto: Cosmetic change 2021-10-14 03:14:55 +08:00
Po-Chuan Hsieh
67ac3124b5 security/py-google-auth: Update to 2.3.0
Changes:	https://github.com/googleapis/google-auth-library-python/releases
2021-10-14 03:14:47 +08:00
Po-Chuan Hsieh
50581669be security/py-certifi: Update to 2021.10.8
Changes:	https://github.com/certifi/python-certifi/commits/master
2021-10-14 03:14:40 +08:00
Po-Chuan Hsieh
b2e2a05633 security/py-asyncssh: Cosmetic change 2021-10-14 03:14:33 +08:00
Po-Chuan Hsieh
7011e5e38e security/totp-cli: Update to 1.1.17
Changes:	https://github.com/yitsushi/totp-cli/releases
2021-10-14 03:12:41 +08:00
Po-Chuan Hsieh
3e43e60de0 security/pgpdump: Cosmetic change 2021-10-14 03:12:34 +08:00
Adam Weinberger
b57a65540f security/gnupg: Update to 2.3.3
Changes:
 * agent: Fix segv in GET_PASSPHRASE (regression).  [#5577]

  * dirmngr: Fix Let's Encrypt certificate chain validation.  [#5639]

  * gpg: Change default and maximum AEAD chunk size to 4 MiB.
    [ad3dabc9fb]

  * gpg: Print a warning when importing a bad cv25519 secret key.
    [#5464]

  * gpg: Fix --list-packets for undecryptable AEAD packets.  [#5584]

  * gpg: Verify backsigs for v5 keys correctly.  [#5628]

  * keyboxd: Fix checksum computation for no UBID entry on disk.
    [#5573]

  * keyboxd: Fix "invalid object" error with cv448 keys.  [#5609]

  * dirmngr: New option --ignore-cert.  [4b3e9a44b5]

  * agent: Fix calibrate_get_time use of clock_gettime.  [#5623]

  * Silence process spawning diagnostics on Windows. [f2b01025c3]

  * Support a gpgconf.ctl file under Unix and use this for the
    regression tests.  [#5999]

  * The Windows installer now also installs the new keyboxd.
    (Put "use-keyboxd" into common.conf to use a fast SQLite
     database instead of the pubring.kbx file.)

  Release-info: https://dev.gnupg.org/T5565
2021-10-13 08:55:40 -06:00
Stefan Eßer
3bc5d5b48c security/vault: Add CPE information
Approved by:	portmgr (blanket)
2021-10-13 15:15:57 +02:00
Stefan Eßer
0e0ecc1712 security/trousers: Add CPE information
Approved by:	portmgr (blanket)
2021-10-13 15:15:48 +02:00
Stefan Eßer
3eb8f3f12a security/rhash: Add CPE information
Approved by:	portmgr (blanket)
2021-10-13 15:15:40 +02:00
Stefan Eßer
9941896ad2 security/py-yara: Add CPE information
Approved by:	portmgr (blanket)
2021-10-13 15:15:31 +02:00
Stefan Eßer
5c9d25f474 security/py-tlslite: Add CPE information
Approved by:	portmgr (blanket)
2021-10-13 15:15:21 +02:00
Stefan Eßer
189613ea8f security/py-rsa: Add CPE information
Approved by:	portmgr (blanket)
2021-10-13 15:15:13 +02:00
Stefan Eßer
a5a29829e6 security/py-pysaml26: Add CPE information
Approved by:	portmgr (blanket)
2021-10-13 15:15:04 +02:00
Stefan Eßer
0252abb249 security/py-pysaml24: Add CPE information
Approved by:	portmgr (blanket)
2021-10-13 15:14:54 +02:00
Stefan Eßer
f3212be182 security/py-pysaml2: Add CPE information
Approved by:	portmgr (blanket)
2021-10-13 15:14:43 +02:00
Stefan Eßer
d9b9636a91 security/py-pycryptodome: Add CPE information
Approved by:	portmgr (blanket)
2021-10-13 15:14:32 +02:00
Stefan Eßer
1b20e5a52a security/py-m2crypto: Add CPE information
Approved by:	portmgr (blanket)
2021-10-13 15:14:22 +02:00
Stefan Eßer
ed1ff746c0 security/py-keyring: Add CPE information
Approved by:	portmgr (blanket)
2021-10-13 15:14:14 +02:00
Stefan Eßer
006a90e1f8 security/py-cryptography: Add CPE information
Approved by:	portmgr (blanket)
2021-10-13 15:14:06 +02:00
Stefan Eßer
3e1e7f33c6 security/py-asyncssh: Add CPE information
Approved by:	portmgr (blanket)
2021-10-13 15:13:55 +02:00
Stefan Eßer
89884d0859 security/pgpdump: Add CPE information
Approved by:	portmgr (blanket)
2021-10-13 15:13:46 +02:00
Stefan Eßer
9651a06e6e security/nikto: Add CPE information
Approved by:	portmgr (blanket)
2021-10-13 15:13:36 +02:00
Stefan Eßer
99a7887687 security/makepasswd: Add CPE information
Approved by:	portmgr (blanket)
2021-10-13 15:13:25 +02:00
Stefan Eßer
9284cb9191 security/heimdal: Add CPE information
Approved by:	portmgr (blanket)
2021-10-13 15:13:16 +02:00
Stefan Eßer
6644157908 security/doas: Add CPE information
Approved by:	portmgr (blanket)
2021-10-13 15:12:46 +02:00
Piotr Kubaj
830b84f555 security/liboqs: fix build on powerpc64le
1. Add FreeBSD's name for 64-bit POWER little endian,
2. Don't use -Werror:
/wrkdirs/usr/ports/security/liboqs/work/liboqs-0.7.0/tests/ds_benchmark.h:142:45: error: implicit conversion from 'long' to 'double' may lose precision [-Werror,-Wimplicit-int-float-conversion]
        return (uint64_t)(time.tv_sec * 1e9 + time.tv_nsec);
2021-10-13 10:48:35 +00:00
Po-Chuan Hsieh
30c3da0412 security/py-josepy: Update to 1.10.0
Changes:	https://github.com/certbot/josepy/blob/master/CHANGELOG.rst
2021-10-13 13:40:07 +08:00
Po-Chuan Hsieh
35f407b7a1 security/py-pysodium: Update to 0.7.10
Changes:	https://github.com/stef/pysodium/releases
2021-10-13 13:37:44 +08:00
Po-Chuan Hsieh
3581a6c459 security/py-google-auth: Update to 2.2.0
Changes:	https://github.com/googleapis/google-auth-library-python/releases
2021-10-13 13:37:35 +08:00
Bryan Drewery
dd274bdd8a security/vuxml: Update OpenSSH CVE-2021-41617 fix for quarterly commit 2021-10-12 14:15:17 -07:00
Bryan Drewery
8d40d32ae3 security/openssh-portable: Fix build without LIBEDIT
This removes a patch that is no longer needed with 8.8p1.

Reported by:	leres
2021-10-12 14:05:45 -07:00
Bryan Drewery
3849667982 security/openssh-portable: Update to 8.8p1
Changelog:	https://www.openssh.com/txt/release-8.8
Security:	CVE-2021-41617
2021-10-12 11:06:52 -07:00
Bryan Drewery
3d46198332 security/vuxml: Document OpenSSH CVE-2021-41617 2021-10-12 11:06:43 -07:00
Tobias Kortkamp
ae22a7846a *: Clean up some things
- Fix typos
- Fix overwritten variables with focus on master/slave ports
- Remove unreferenced variables
- Sort categories
- Remove redundant option descriptions
- Clean up commented PORTREVISION
- Add missing USES

Reported by:	portscan
2021-10-12 17:01:38 +02:00
Tobias Kortkamp
77ae10646b security/afl++: Update to 3.14c
Build two flavors, one compiled with LLVM13 and one with GCC.  Mixing
compilers in the same build is too complicated for casual maintainance.
The flavors are installed into their own prefixes in /usr/local/afl++-gcc
and /usr/local/afl++-llvm which also solves the conflict with
security/afl.

Changes:	https://github.com/AFLplusplus/AFLplusplus/blob/3.14c/docs/Changelog.md#version-314c-release
2021-10-12 17:01:36 +02:00
Dave Cottlehuber
e349d6c6c5 security/vuxml: add CouchDB CVE details
while here, appease `make validate` indentation

Security:	https://docs.couchdb.org/en/stable/cve/2021-38295.html
Sponsored by:	SkunkWerks, GmbH
2021-10-12 13:16:54 +00:00
Daniel Engberg
63f9983963 security/xml-security: Update MASTER_SITES
Use a direct URL to Apache's release archive site as it's not mirrored
by upstream mirror sites

Approved by:	ale (port maintainer), arrowd (mentor)
Differential Revision:	https://reviews.freebsd.org/D32418
2021-10-11 20:48:06 +02:00
Don Lewis
aebbed08fc security/vuxml: topic format consistency
Reformat to be consistent with other entries.
2021-10-11 11:36:00 -07:00
Don Lewis
4d5d4cbf1f security/vuxml: update editors/openoffice-{4,devel} latest entry
Add info about three just announced CVEs.
2021-10-11 11:33:34 -07:00
Mateusz Piotrowski
0eb5ae0798 security/vuxml: Document Ansible vulnerability
Security:	CVE-2021-3620
2021-10-11 19:43:09 +02:00