Commit Graph

10505 Commits

Author SHA1 Message Date
Shaun Amott
6974f265d6 Update phpSysInfo entry: the current version (2.5.3) is affected. 2007-08-01 00:47:02 +00:00
Martin Wilke
60ebdbd581 Update mozilla entry
- Marked seamonkey as safe

Submitted by:	John E. Hein <jhein@timing.com>
Reviewed by:	simon
2007-07-31 22:21:22 +00:00
Martin Wilke
b39b792f74 Update the xpdf entry
- Marked poppler as save
2007-07-31 14:43:22 +00:00
Martin Wilke
168c561a7d Update xpdf entry
- Marked cups-base as safe
- Add poppler as affected port

Reviewed by:	simon
2007-07-31 13:33:33 +00:00
Martin Wilke
8d605e2e9f - Fix tcpdump entry 2007-07-31 11:31:29 +00:00
Martin Wilke
46aa01e61c Document xpdf -- stack based buffer overflow
Reviewed by:	simon/remko
2007-07-31 11:30:03 +00:00
Martin Wilke
7eda652de0 - Fix a typo
Submitted by:	shaun
2007-07-31 09:49:44 +00:00
Martin Wilke
cc98183b55 - Document tcpdump -- remote integer underflow vulnerability
Reviewed by:	remko
2007-07-31 07:50:55 +00:00
Tom McLaughlin
a66bfc3e1b Update to 1.6.9p2
- Environment handling fix.
2007-07-30 15:01:47 +00:00
Alexander Botero-Lowry
4942ce5a7d - Make Python 2.5.1 the default Python version
- Add significantly better support in bsd.python.mk for working with
   Python Eggs and the easy_install system

Tested by:	pointyhat runs
Approved by:	pav (portmgr)
Most work by:	perky
Thanks to:	pav
2007-07-30 09:42:28 +00:00
Marcelo Araujo
c0741176d6 - Update to 0.0.22.
Approved by:	pav (portmgr, in mentor's absence)
2007-07-30 01:14:26 +00:00
Martin Wilke
f49264b6a1 - Document mutt -- buffer overflow vulnerability
Reviewed by:	remko
2007-07-29 18:28:31 +00:00
Chin-San Huang
22a1335f7a - Only for i386 arch.
Submitted by:	maintainer
Approved by:	maintainer
2007-07-29 11:58:14 +00:00
Martin Wilke
030df73f0c - Document p5-Net-DNS -- multiple Vulnerabilities
Reviewed by:	remko
2007-07-29 11:29:45 +00:00
Martin Wilke
e4cf269412 - Document phpsysinfo -- url Cross-Site Scripting 2007-07-28 21:52:30 +00:00
Martin Wilke
600c251319 - Document drupal -- Cross site request forgeries
- Document drupal -- Multiple cross-site scripting vulnerabilities

Submitted by:	nick@foobar.org
Reviewed by:	simon
2007-07-28 15:28:15 +00:00
Martin Wilke
ed239f1cb3 - Document vim -- Command Format String Vulnerability
Approved by:	simon
2007-07-27 18:04:48 +00:00
Michael Nottebrock
5aa71449ba -fPIC on amd64. 2007-07-27 15:19:01 +00:00
Chin-San Huang
c68800dd9c Add chntpw 070409, utility to set the password and edit registry on
Microsoft NT system.

PR:		ports/114897
Submitted by:	buganini at gmail.com
Approved by:	rafan (mentor, implicit)
2007-07-27 14:41:07 +00:00
Stefan Eßer
7e12772d4a I had forgotten to remove the BROKEN tag when committing the two patches
that ought to make the port compile with gcc-4.2 and thus with -current.
2007-07-27 13:35:22 +00:00
Munechika SUMIKAWA
1350a1110b Fix pkg-plist. 2007-07-27 01:55:07 +00:00
Tom McLaughlin
d2fa7c9224 Fix PORTVERSION
Noticed by:	ume
2007-07-27 01:00:55 +00:00
Martin Wilke
c7ba758c45 - Document libvorbis - Multiple memory corruption flaws
Submitted by:	lx@
Reviewed by:	simon
2007-07-26 22:06:21 +00:00
Tom McLaughlin
59a1468866 - Update to 1.6.9p1
* Worked around a bug in some PAM implementations that caused a crash
    when no tty was present.
  * Fixed a crash on some platforms in the error logging function.
- Change default pam session stack to pam_permit like su does [1]
- Grab maintainership

Sugested by:	des [1]
2007-07-26 15:53:40 +00:00
Dirk Meyer
b82d3d9d38 - take maintainership 2007-07-25 11:50:59 +00:00
Cheng-Lung Sung
9b79dc3cb4 Lasso is a free software C library aiming to implement the Liberty
Alliance standards; it defines processes for federated identities,
single sign-on and related protocols. Lasso is built on top of
libxml2, XMLSec and OpenSSL and is licensed under the GNU General
Public License  (with an OpenSSL exception).

WWW:	http://lasso.entrouvert.org/

PR:		ports/114639
Submitted by:	Gea-Suan Lin <gslin at gslin.org>
2007-07-25 07:18:22 +00:00
Rong-En Fan
c925c340dd - Remove --mandir and --infodir from CONFIGURE_ARGS. They are now default
in bsd.port.mk.

Tested with:	my tinderbox on i386 6
Approved by:	portmgr
2007-07-24 15:10:14 +00:00
Xin LI
cc5b3ad300 Document XSS vulnerabilities in several tomcat versions;
update affected tomcat versions for CVE-2005-2090.
2007-07-24 14:31:49 +00:00
Xin LI
0aff17bab7 The previous vuxml entry applies to jakarta-tomcat 4.0.x as well, so mark
it as affected as well.  Since there is no newer release I have used 4.1.0
as the "fixed" version.
2007-07-24 14:17:06 +00:00
Xin LI
60df6f7e74 Document multiple vulnerabilities found in www/tomcat41 2007-07-24 13:54:49 +00:00
Renato Botelho
e64ed70c91 - Update to 20070724
PR:		ports/114854
Submitted by:	delphij
2007-07-24 13:35:11 +00:00
Xin LI
7cdfd867bf Document dokuwiki spellchecker XSS vulnerabilities 2007-07-24 08:00:32 +00:00
Cheng-Lung Sung
b737ff7d38 - Update to 2.7.0
Update includes:
- Target-based stream reassembly, including handling of TCP dataoverlaps and
  anomalous TCP header flags on a per-destination basis. 11 different
  target-based policies are supported. See README.stream5 for specific
  configuration options for operating system targets.
- UDP session tracking
- Option to emulate Stream4 flushing behaviour
- Stream5 replaces BOTH Stream4 and Flow -- should disable both of these when
  Stream5 is enabled.
- Security and memory footprint improvements

PR:		ports/114806
Submitted by:	Robin Gruyters <r dot gruyters_AT_yirdis dot nl>
2007-07-24 07:05:49 +00:00
Cheng-Lung Sung
30fef67d39 - Update to 0.32
- return maintainership

PR:		ports/114347
Submitted by:	Gea-Suan Lin <gslin_AT_gslin dot org>
2007-07-24 07:04:40 +00:00
Pav Lucistnik
be032e5ddb - Update to 0.6.3
- Transfer maintainership

PR:		ports/113401
Submitted by:	Mark D. Foster <mark@foster.cc>
Approved by:	maintainership change - linimon (portmgr)
2007-07-23 13:54:06 +00:00
Martin Matuska
c09c9f90d5 - change maintainer to Matthew Fuller <fullermd@over-yonder.net>
PR:		ports/114751
Submitted by:	Ulf Lilleengen <lulf@stud.ntnu.no> (maintainer)
Approved by:	new maintainer, garga (mentor, implicit)
2007-07-23 10:39:02 +00:00
Rong-En Fan
f935a609c5 - Set --mandir and --infodir in CONFIGURE_ARGS if the configure script
supports them.  This is determined by running ``configure --help'' in
  do-configure target and set the shell variable _LATE_CONFIGURE_ARGS
  which is then passed to CONFIGURE_ARGS.
- Remove --mandir and --infodir in ports' Makefile where applicable
  Few ports use REINPLACE_CMD to achieve the same effect, remove them too.
- Correct some manual pages location from PREFIX/man to MANPREFIX/man
- Define INFO_PATH where necessary
- Document that .info files are installed in a subdirectory relative to
  PREFIX/INFO_PATH and slightly change add-plist-info to use INFO_PATH and
  subdirectory detection.

PR:		ports/111470
Approved by:	portmgr
Discussed with:	stas (Mk/*), gerald (info related stuffs)
Tested by:	pointyhat exp run
2007-07-23 09:36:51 +00:00
Tom McLaughlin
bc14907a9c - Fix segfault when there is no TTY when executing. [1]
- Temporarilly disable session entry in default pam file because
  pam_lastlog causes users to appear as though they have logged out in
  system logs. [2]

Reported by:	yarodin@gmail.com [1], Paul Fraser <pfraser@gmail.com> [2]
Submitted by:	Todd Miller [1]
2007-07-23 03:54:05 +00:00
Munechika SUMIKAWA
f66127525b Upgrade to 20070720a. 2007-07-23 03:30:21 +00:00
Rong-En Fan
58c41ab013 - Retire security/metasploit-devel since security/metasploit is now
up-to-date

PR:		ports/114196
Submitted by:	Yonatan <onatan at gmail.com> (maintainer)
2007-07-23 02:11:22 +00:00
Rong-En Fan
f2ad74c74f - Update to 3.0
- Dynamically generate pkg-plist

PR:		ports/114196
Submitted by:	Yonatan <onatan at gmail.com> (maintainer)
2007-07-23 02:07:27 +00:00
Rong-En Fan
61101326ba - Sync security/metasploit with security/metasploit-devel for the coming
3.0 update

PR:		ports/114196
Submitted by:	Yonatan <onatan at gmail.com> (maintainer)
2007-07-23 02:04:25 +00:00
Stefan Eßer
08cc138a29 Fix path to file to patch, I had accidently committed the patch with
an absolute path that was correct only on my development system.
2007-07-22 19:30:35 +00:00
Mark Linimon
f456835eca Mark ports that depend on misc/compat3x as deprecated. If anyone wants to
update these to later versions, they should do so now.
2007-07-22 08:38:04 +00:00
Mark Linimon
1c609bc523 Switch dependency from databases/py-MySQLdb-devel to databases/py-MySQLdb,
because the latter is now more up-to-date.

Forgotten by:	mnag
2007-07-22 04:52:30 +00:00
Stefan Eßer
056c4f7b50 Fix build with gcc-4.2: Declare a function and an operator in the
correct scope. This patch was found on the PLD commit list archived
under URL:

http://www.mail-archive.com/pld-cvs-commit@lists.pld-linux.org/msg104002.html
2007-07-21 21:09:29 +00:00
Simon L. B. Nielsen
cf5d8266ed Fix last commit: the name tag was empty.
Reported by:	FreshPorts via Dan Langille
Pointyhat to:	delphij
2007-07-21 15:09:39 +00:00
Xin LI
c22df82ca0 Document lighttpd multiple vulnerabilities 2007-07-21 14:10:50 +00:00
Tom McLaughlin
ff833c5c46 Update to 1.6.9
Application changes:
- PAM, since present, is used by default.
- Environment variable handling has changed significantly.
- Sudo checks the user's supplemental group vector so nsswitch order is
  no longer important for group based rules.
(See UPGRADE and CHANGING under share/doc/sudo/ for more.)

Port changes:
- PAM file is no longer clobered on reinstall.
- OPIE option has been removed due to PAM being used by default.
- Selected documentation is now installed.
2007-07-21 03:15:13 +00:00
Gabor Kovesdan
758558ff31 - Make a dependency version more accurate. According to pkg_version(1)
the current one is fine, but it is reported that portupgrade(1)
  has troubles with the current way.  No PORTREVISION bump, as it just blocked
  the upgrade, but we don't want to require people to rebuild again.

Reported by:	Aurelien Croc <aurelien@ap2c.org>
2007-07-20 21:11:33 +00:00