Commit Graph

33344 Commits

Author SHA1 Message Date
Yuri Victorovich
40624110cf security/fizz: Update 2021.04.19.00 -> 2021.04.26.00 2021-04-26 10:56:31 -07:00
Dmitry Marakasov
b8576ae230 security/osslsigncode: extend BROKEN to FreeBSD 14 2021-04-26 19:40:04 +03:00
Dmitry Marakasov
b7666ce44b security/openscep: extend BROKEN to FreeBSD 14 2021-04-26 19:39:21 +03:00
Palle Girgensohn
7e0f5d9dfd security/shibboleth.sp: add more information to security advisory 2021-04-26 15:30:52 +02:00
Palle Girgensohn
19889886e5 security/shibboleth-sp: Update to 3.2.2
This is a security fix for an issue that has not yet been disclosed. The
vuxml entry will be updated once the CVE is available.

The patch to mitigate the vulnerability was introduced already on
2021-04-23 in the FreeBSD port as 3.2.1_1.

Security:	e4403051-a667-11eb-b9c9-6cc21735f730
2021-04-26 10:51:17 +02:00
Palle Girgensohn
f0d60c4725 security/shibboleth-sp: add entry for upcoming vulnerability
The details are not yet disclosed.
2021-04-26 10:36:36 +02:00
Baptiste Daroussin
fa1271fac8 security/libretls: update to 3.3.2 2021-04-26 05:35:53 +02:00
Po-Chuan Hsieh
1017833afb security/rubygem-googleauth: Update to 0.16.1
Changes:	https://github.com/googleapis/google-auth-library-ruby/releases
2021-04-26 04:36:22 +08:00
Po-Chuan Hsieh
a9d2554d53 security/rubygem-devise-two-factor-rails5: Update to 4.0.0
Changes:	https://github.com/tinfoil/devise-two-factor/blob/master/CHANGELOG.md
2021-04-26 04:36:22 +08:00
Po-Chuan Hsieh
7105364c9f security/rubygem-devise-two-factor: Update to 4.0.0
Changes:	https://github.com/tinfoil/devise-two-factor/blob/master/CHANGELOG.md
2021-04-26 04:36:22 +08:00
Po-Chuan Hsieh
f65bc1edcb security/py-uhashring: Update to 2.1
Changes:	https://github.com/ultrabug/uhashring/commits/master
2021-04-26 04:35:34 +08:00
Po-Chuan Hsieh
33beea6d2b security/py-pysodium: Update to 0.7.8
Changes:	https://github.com/stef/pysodium/releases
2021-04-26 04:35:34 +08:00
Po-Chuan Hsieh
e05a1290ac security/py-google-auth: Update to 1.29.0
Changes:	https://github.com/googleapis/google-auth-library-python/releases
		https://github.com/googleapis/google-auth-library-python/blob/master/CHANGELOG.md
2021-04-26 04:35:34 +08:00
Po-Chuan Hsieh
dbb080e7a4 security/pecl-gnupg: Update to 1.5.0
Changes:	https://pecl.php.net/package-changelog.php?package=gnupg
2021-04-26 04:35:21 +08:00
Po-Chuan Hsieh
4a14de4779 security/libksba: Update to 1.5.1
Changes:	https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libksba.git;a=blob;f=NEWS;hb=HEAD
2021-04-26 04:35:11 +08:00
Po-Chuan Hsieh
f1357a3c0c security/libfido2: List cmake options explicitly 2021-04-26 04:35:11 +08:00
Piotr Kubaj
4181b0995f security/cryptopp: enable SIMD by default on powerpc and powerpc64
Upstream can now check at runtime for SIMD availaibility. Merge upstream commits 91173a287e and 21a40abc5c to implement it.

Local patch is used because upstream patch doesn't apply.

Remove -maltivec and -mvsx, upstream now properly sets those flags on their own.
2021-04-25 16:43:31 +00:00
Yuri Victorovich
e1796aeb9d security/py-SecretStorage: Update 2.3.1 -> 3.3.1 required to unbrereak security/py-keyring
PR:		255395
2021-04-25 08:49:17 -07:00
Piotr Kubaj
a131fc63e9 security/cryptopp: enable SIMD on powerpc64le by default
No point in disabling AltiVec and VSX since both POWER8 and POWER9 have it.
2021-04-25 13:36:35 +00:00
Yuri Victorovich
c9f55aaf93 security/solana: Broken on i386
Reported by:	fallout
2021-04-24 21:06:07 -07:00
Rene Ladan
b661ebb122 Remove expired ports:
2021-04-22 net/samba411: Security Support ends on 03 Dec 2020
2021-04-22 net-im/cordless: Unmaintained and dead upstream, uses the old Discord API which notably has got users banned
2021-04-18 news/plor: listed as "Alpha-release" but last update in 2001; unmaintained
2021-04-20 security/certificate-transparency: Broken for more than 6 months
2021-04-24 17:12:52 +02:00
Yuri Victorovich
557666746c New port: security/solana: Web-scale blockchain for decentralized apps and marketplaces 2021-04-24 03:23:34 -07:00
Neel Chauhan
68b4bcafa9 security/suricata: update to 6.0.2
Changes: https://redmine.openinfosecfoundation.org/versions/162

PR:             255342
Submitted by:   Franco Fichtner <franco AT opnsense DOT org> (maintainer)
2021-04-23 12:53:32 -07:00
Matthias Fechner
6b1899327a security/rubygem-lockbox: Update to 0.6.4.
Update required for gitlab-ce 13.11 update.
2021-04-23 21:06:06 +02:00
Matthias Fechner
e3f40c57f5 security/rubygem-devise-two-factor-rails60: Update to 4.0.0
This update is required for gitlab-ce 13.11.
2021-04-23 21:06:04 +02:00
Palle Girgensohn
ff87b25847 security/shibboleth-sp: Reintroduce direct dependencies to silent Q/A.
The dependencies where previously added indirectly through the
dependency chain via opensaml, bust the Q/A disapproved of that.

Add patch to check for missing DataSealer during cookie recovery.
2021-04-23 21:04:42 +02:00
Yuri Victorovich
e344f57c98 security/hs-cryptol: Fix Makefile format 2021-04-23 00:56:18 -07:00
Yuri Victorovich
57f017dc08 security/hs-cryptol: Update 2.10.0 -> 2.11.0 2021-04-23 00:56:15 -07:00
Adriaan de Groot
f5b283ceb1 Update KDE Plasma to 5.21.4
The april bugfix release for KDE Plasma is here. This wasn't
done immediately for the 5.21.3 ports commit that I landed
yesterday because I wasn't paying attention to latest
releases. Release notes are at
	https://kde.org/announcements/plasma/5/5.21.4/
2021-04-22 23:43:14 +02:00
Tobias C. Berner
a92fa618b0 Update KDE Gear to 21.04
KDE Gear 21.04
Thursday, 22 April 2021

Welcome to KDE Gear ⚙️ 21.04!

KDE produces literally dozens of apps for work, play, education, and
creativity. Kontact, for example, gives you control over all your email,
contact, and agenda; Itinerary keeps you up to date with everything you
need regarding your trips; the KAlgebra graphing calculator works
equally well on your desktop and your phone; Cantor provides you with an
intuitive way of analyzing data and graphing the results; and Kdenlive
makes cutting and building sophisticated-looking videos not only easy,
but fun as well.

These are but a few of the apps releasing new updates today. When
combined with the KDE’s powerful Plasma desktop, they provide you with
most, if not all, the tools you need to be productive in a versatile and
flexible Linux^WFreeBSD environment.

But you don’t even need to run Linux! Many of the apps in this
announcement work on Windows, macOS, and Android as well. This is what
convergent means for KDE: use your favorite apps anywhere, on any
system, on your work computer, mobile or even on your TV!

And, remember: KDE’s apps, the Plasma desktop, Plasma Mobile, Plasma
BigScreen and all the rest of KDE’s software are free and open source.
No licensing, no hidden costs, no spying. Share them with your friends,
install them at work, or use them in your school lab. It is your
software to enjoy where and how you want.

Full announcement and changelogs:
	https://kde.org/announcements/gear/21.04/
2021-04-22 18:47:50 +02:00
Adriaan de Groot
6806658cdf KDE Plasma: update to 5.21.3
This updates the KDE Plasma parts to release 5.21.3. There is one
new port, plasma5-systemmonitor, which is the upcoming replacement
for KDE sysguard. It is not installed by default.

Release notes are at
	https://kde.org/announcements/plasma/5/5.21.3/

Previous commits tidying up DOCS options left some non-
applications consumers without the necessary kdoctools
dependency, so (re)introduce that now.
2021-04-22 09:54:33 +02:00
Craig Leres
53d0f5e5bc security/vuxml: Mark zeek < 4.0.1 as vulnerable as per:
https://github.com/zeek/zeek/releases/tag/v4.0.1

Fix null-pointer dereference when encountering an invalid enum name
in a config/input file that tries to read it into a set[enum]. For
those that have such an input feed whose contents may come from
external/remote sources, this is a potential DoS vulnerability.
2021-04-21 14:40:41 -07:00
Craig Leres
274b20e4c8 security/zeek: Update to 4.0.1 to fix null-pointer dereference and potential DOS
https://github.com/zeek/zeek/releases/tag/v4.0.1

This release fixes the following vulnerability:

 - Fix null-pointer dereference when encountering an invalid enum
   name in a config/input file that tries to read it into a set[enum].
   For those that have such an input feed whose contents may come
   from external/remote sources, this is a potential DoS vulnerability.

Other fixes:

 - Fix mime type detection bug in IRC/FTP file_transferred event
   for file data containing null-bytes

 - Fix potential for missing timestamps in SMB logs

 - Remove use of LeakSanitizer API on FreeBSD where it's unsupported

 - Fix incorrect parsing of ERSPAN Type I

 - Fix incorrect/overflowed n value for SSL_Heartbeat_Many_Requests
   notices where number of server heartbeats is greater than number
   of client heartbeats.

 - Fix missing user_agent existence check in smtp/software.zeek
   (causes reporter.log error noise, but no functional difference)

 - Fix include order of bundled headers to avoid conflicts with
   pre-existing/system-wide installs

 - Fix musl build (e.g. Void, Alpine, etc.)

 - Fix build with -DENABLE_MOBILE_IPV6 / ./configure --enable-mobile-ipv6

 - Add check for null packet data in pcap IOSource, which is an
   observed state in Myricom libpcap that crashes Zeek via null-pointer
   dereference

 - Allow CRLF line-endings in Zeek scripts and signature files

 - Fix armv7 build

 - Fix unserialization of set[function], generally now used by
   connection record removal hooks, and specifically breaking
   intel.log of Zeek clusters

 - Fix indexing of set/table types with a vector

 - Fix precision loss in ASCII logging/printing of large double,
   time, or interval values

 - Improve handling of invalid SIP data before requests

 - Fix copy()/cloning vectors that have holes (indices w/ null
   values)

Reported by:	Jon Siwek
2021-04-21 14:11:05 -07:00
Matthias Andree
47340329e7 security/openvpn: security update to v2.5.2
Changelog:	https://github.com/OpenVPN/openvpn/blob/release/2.5/Changes.rst#overview-of-changes-in-252

Security:       CVE-2020-15078
Security:       efb965be-a2c0-11eb-8956-1951a8617e30
MFH:		2021Q2
2021-04-21 19:48:54 +02:00
Matthias Andree
d1184f27e5 security/vuxml: add devel/openvpn < 2.5.2 entry
Security:	CVE-2020-15078
Security:	efb965be-a2c0-11eb-8956-1951a8617e30
2021-04-21 19:48:54 +02:00
Dan Langille
55f69b2ce5 Switch from Django 3.0 to Django 3.2
PR:		255113
Reported by:	Kai Knoblich <kai@FreeBSD.org>
2021-04-21 14:45:52 +00:00
Tobias Kortkamp
69e938dbc5 security/libressl-devel: Properly define LIBTLS option
Even though users will never see it since it is either excluded or
forced on, let's not rely on options implementation quirks and
define it properly.

Reported by:	portscan
2021-04-21 12:57:21 +02:00
Tobias Kortkamp
6fbfa31c0a security/pkcs11-tools: Properly set BROKEN on 11.x with OpenSSL 1.0.x
Another case of wishful thinking.  In reality the framework does
not support a BROKEN_SSL_11 at the moment.

Reported by:	portscan
2021-04-21 12:57:20 +02:00
Rene Ladan
d70c998cc6 Document new vulnerabilities in www/chromium < 90.0.4430.85
Obtained from:	https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_20.html
2021-04-21 10:11:40 +02:00
Tobias Kortkamp
bdca32c596 Bump USES=cabal ports after 12837690ed 2021-04-21 06:48:23 +02:00
Muhammad Moinur Rahman
886923a37e security/snort3: Update version 3.1.1.0=>3.1.3.0
- Mark BROKEN for 11.X and 12.X. Cannot detect flex from ports. There is
  an ongoing issue at upstream.
  https://github.com/snort3/snort3/issues/168
- Use OPTIONSNG for couple of OPTIONS

Reported by:	adridg
2021-04-20 19:46:10 +00:00
Bryan Drewery
c55e97c0f3 Another openssh version fix for CVE-2021-28041.
Reported by:	leres
2021-04-20 12:28:14 -07:00
Li-Wen Hsu
87da0092a4 Document Jenkins Security Advisory 2021-04-20
Sponsored by:	The FreeBSD Foundation
2021-04-21 03:26:54 +08:00
Yuri Victorovich
97b9d2f58f security/pkcs11-tools: Broken on 11 with base OpenSSL due to version being too old
Also add comment about the workaround for missing symbols in /usr/lib/libcrypto.so.

Reported by:	fallout
2021-04-20 11:31:36 -07:00
Fernando Apesteguía
d8d3b983df security/fbopenssl: Remove from tree
Abandoned upstream, last release back in 2005.
Broken for more than 3 months

References:
https://sourceforge.net/projects/modgssapache/files/fbopenssl/
https://portsfallout.com/fallout?port=security%2Ffbopenssl$

PR:	255162
Reported by:	daniel.engberg.lists@pyret.net
2021-04-20 18:53:46 +02:00
Bryan Drewery
da89336b8d Fix openssh version in entry for CVE-2021-28041
Reported by:	leres
2021-04-20 08:37:57 -07:00
Adam Weinberger
c260503847 security/gnupg: Update to 2.3.1 2021-04-20 10:15:41 -04:00
Antoine Brodin
053fd2c7af security/py-plaso: update to 20210412 2021-04-20 11:07:54 +00:00
Antoine Brodin
393f5f623c security/py-dfvfs: update to 20210213 2021-04-20 10:59:14 +00:00
Antoine Brodin
b03d97af60 security/py-artifacts: update to 20210404 2021-04-20 10:46:00 +00:00