29739 Commits

Author SHA1 Message Date
Thomas Zander
e4b710fa3c Document two vulnerabilities in vlc < 3.0.7.1, potential remote exploit 2019-06-20 15:54:14 +00:00
Jan Beich
829f1e5856 security/vuxml: mark waterfox < 56.2.11 as vulnerable
https://github.com/MrAlex94/Waterfox/commit/27ce846f9d46
2019-06-20 09:11:48 +00:00
Dmitry Marakasov
d9bc496d8d - Update URL (chase redirect to another GH account, not checksum change)
Approved by:	portmgr blanket
2019-06-20 09:01:59 +00:00
Tijl Coosemans
7b03f0554d Update to 2.16.2. 2019-06-20 08:32:15 +00:00
Antoine Brodin
4dc3414ec7 Depend on legacy libs
Reported by:	pkg-fallout
2019-06-20 07:56:40 +00:00
Mathieu Arnold
383cda2cdf Regular USE_GITHUB cleanup. 2019-06-20 07:12:41 +00:00
Steve Wills
8cc7b88ddb security/sops: Update to 3.3.1
PR:		238521
Submitted by:	Dmitri Goutnik <dg@syrec.org> (maintainer)
2019-06-20 02:52:45 +00:00
Tobias C. Berner
9ad59fa37c Update KDE Plasma Desktop to 5.16.1
Announcement:
	https://kde.org/announcements/plasma-5.16.1.php
2019-06-19 22:19:11 +00:00
Jan Beich
cd7557615e security/vuxml: mark firefox < 67.0.3 as vulnerable 2019-06-19 05:32:28 +00:00
Nikolai Lifanov
a5ccfda760 new port: security/openfortivpn
This is a client for PPP+SSL VPN tunnel services.
It works with Fortinet VPN.
2019-06-18 15:26:00 +00:00
Steve Wills
7685385b30 security/py-service_identity: Update to 18.1.0
PR:		238459
Approved by:	Axel.Rau@Chaos1.DE (maintainer)
2019-06-18 02:00:13 +00:00
Vanilla I. Shu
1e910ea665 Update to 0.064. 2019-06-18 00:01:33 +00:00
Cy Schubert
339ec4eee2 For users who build and install FreeBSD using WITHOUT_WIRELESS
simply altering /etc/rc.conf isn't enough to make use of the ports
versions of hostapd and wpa_supplicant. This is because the rc.d
scripts are not installed when WITHOUT_WIRELESS is specified as a
build option. This patch checks for the rc scripts existence and
if they do not exist, installs the ports versions of the same
scripts, which are added by this revision.

This patch does not change the package in any way and there is no way
to enable this outside of removal of hostapd or wpa_supplicant
(depending on the port). Users who build their own world using the
WITHOUT_WIRELESS flag will almost always not use binary packages. Hence
the automatic detection and install of the rc scripts. Making this an
option would IMO increase the number of bug reports due to people
inadvertently setting or not setting an option.

To enable this a person must:

1. buildworld and installworld -DWITHOUT_WIRELESS
2. Build and install the desired wpa_supplicant and/or hostapd port
   on servers one wishes to install them on.

PR:		238571
2019-06-17 20:15:40 +00:00
Ben Woods
aa053b051a security/keepass: Update to 2.42.1
Changes this release:
  https://keepass.info/news/n190501_2.42.html
2019-06-17 13:28:47 +00:00
Antoine Brodin
d787c84c2c Update to 3.18.2 2019-06-17 09:08:21 +00:00
Kai Knoblich
a1d8d9417c security/py-bro-pkg: Rename to security/py-zkg and update to 2.0.0
The project name of upstream has changed from "Bro" to "Zeek". This also
affects the repositories and offered packages.

* Rename the port to security/py-zkg
* Adapt the text references in COMMENT and pkg-{descr,message} accordingly.
* Update to 2.0.0

Changelog:

https://github.com/zeek/package-manager/blob/v2.0.0/CHANGES

PR:		237634
Submitted by:	Shirkdog <mshirk@daemon-security.com> (maintainer)
Reviewed by:	koobs
2019-06-17 05:51:24 +00:00
Tobias Kortkamp
42b7216d6c Fix version range of recent ImageMagick6 entry
graphics/ImageMagick6 has PORTEPOCH=1 (ImageMagick7 does not) but
it is not included in vuln.xml.  The recent vulnerabilities are
never raised by pkg audit as a result and users are left uninformed
about them.
2019-06-17 05:24:51 +00:00
Joe Marcus Clarke
f093e27678 Add an entry for netatalk3.
Document the netatalk3 remote code execution vulnerability fixed in 3.1.12.

PR:		238573
2019-06-16 17:07:14 +00:00
Sunpoet Po-Chuan Hsieh
06baa10c92 Document GraphicsMagick vulnerability 2019-06-16 10:38:42 +00:00
Sunpoet Po-Chuan Hsieh
bd5f923ec8 Take maintainership 2019-06-16 10:38:30 +00:00
Sunpoet Po-Chuan Hsieh
46454e9220 Update to 1.9.0
Changes:	https://github.com/omniauth/omniauth/commits/master
2019-06-16 10:35:43 +00:00
Sunpoet Po-Chuan Hsieh
0ce571cc88 Update to 1.3.2
Changes:	https://github.com/mattbrictson/airbrussh/releases
2019-06-16 10:35:37 +00:00
Kai Knoblich
77ed2dc624 security/py-fail2ban: Add support for devel/py-pyinotify
* Enable support for devel/py-pyinotify that itself uses devel/libinotify to
  monitor changes in the filesystem. [1]

* Also introduce the new dependency as an additional default option INOTIFY
  while I'm here because it's not a hard requirement for runtime. [2]

PR:		238427
Submitted by:	Dmitry Wagin <dmitry.wagin@ya.ru> [1]
Approved by:	theis@gmx.at (maintainer) [1] [2]
2019-06-16 10:14:21 +00:00
Tobias C. Berner
05fbb99fab Update KDE's Plasma Desktop to 5.16
Announcement:
	https://kde.org/announcements/plasma-5.16.0.php
2019-06-15 15:39:23 +00:00
Rene Ladan
d95c09e2fe security/vuxml: add entry for www/chromium < 75.0.3770.90 2019-06-15 14:06:57 +00:00
Tobias C. Berner
5e29b305d3 Update KDE Frameworks to 5.59.0
Exp-run by:	antoine
PR:		238414
2019-06-15 11:42:56 +00:00
Matthew Seaman
1740ed3d08 Document PMASA-2019-4; CSRF vulnerability in login form 2019-06-14 06:48:51 +00:00
Yuri Victorovich
75a54fb559 security/ridl: ONLY_FOR x86
PR:		238553
Submitted by:	linimon
2019-06-14 00:28:49 +00:00
Adam Weinberger
813c2e9d8f Add entry for Vim/NeoVim arbitrary code execution 2019-06-13 18:41:56 +00:00
Sunpoet Po-Chuan Hsieh
1317944d05 Add NO_ARCH 2019-06-13 15:50:25 +00:00
Sunpoet Po-Chuan Hsieh
59a56f8383 Add NO_ARCH 2019-06-13 15:50:20 +00:00
Sunpoet Po-Chuan Hsieh
285fa4e1b7 Update to 0.30
Changes:	https://metacpan.org/changes/distribution/Authen-Radius
2019-06-13 15:50:15 +00:00
Sunpoet Po-Chuan Hsieh
804d24d3ee Update to 4.1.0
Changes:	https://github.com/keybase/client/releases
2019-06-13 15:48:31 +00:00
Dmitry Marakasov
f498894653 - Update to 2.26.0 2019-06-13 12:07:51 +00:00
Mark Linimon
cfc2d198c7 Add compiler:c++11-lang to USES to fix the following problem on
GCC-based architectures:

  cc1plus: error: unrecognized command line option "-std=gnu++11"

Approved by:	portmgr (tier-2 blanket)
2019-06-13 11:57:37 +00:00
Jochen Neumeister
d579a6de24 Add entry for www/mybb
Sponsored by:	Netzkommune GmbH
2019-06-12 17:17:02 +00:00
Pietro Cerutti
601c019fb3 security/gorilla: remove meaningless 85+ from USES tk 2019-06-12 15:32:22 +00:00
Jung-uk Kim
e98d00dca8 Document the latest Flash Player vulnerability.
https://helpx.adobe.com/security/products/flash-player/apsb19-30.html
2019-06-11 21:11:17 +00:00
Sunpoet Po-Chuan Hsieh
be954ca154 Update to 0.35.2
Changes:	https://gitlab.com/m2crypto/m2crypto/blob/master/CHANGES
		https://gitlab.com/m2crypto/m2crypto/commits/master
2019-06-11 20:19:42 +00:00
Piotr Kubaj
58f017fab7 security/dropbear: update to 2019.78, change maintainer
Update the port to 2019.78 and change maintainer to my FreeBSD address.

Approved by:	mat (mentor)
Differential Revision:	https://reviews.freebsd.org/D20601
2019-06-11 15:57:19 +00:00
Adriaan de Groot
fb172ecfbb Update security/olm to latest upstream release.
Source has moved to gitlab, still under Matrix.org. Release notes at
	https://gitlab.matrix.org/matrix-org/olm/releases
major changes were in 3.1.0 already, Short Authentication String
and public key signing. Various compatibility and build fixes
were also applied.

Also PORTREVISION dependent ports (that I know about). No MFH because
these are feature-based releases, not security updates.

PR:		238384
Submitted by:	Alexander Sieg
Reported by:	Alexander Sieg
2019-06-11 08:02:38 +00:00
Sunpoet Po-Chuan Hsieh
c09def85cb Update to 0.35.1
Changes:	https://gitlab.com/m2crypto/m2crypto/blob/master/CHANGES
		https://gitlab.com/m2crypto/m2crypto/commits/master
2019-06-10 16:47:59 +00:00
Antoine Brodin
29a47f995e Mark BROKEN: unfetchable
Reported by:	pkg-fallout
MFH:		2019Q2
2019-06-10 16:12:56 +00:00
Guido Falsi
e36e3121da Correct home page. 2019-06-10 06:49:32 +00:00
Richard Gallamore
add9abbb69 This is the core component of the python-social-auth
ecosystem, it implements the common interface to
define new authentication backends to third parties
services, implement integrations with web frameworks
and storage solutions.

WWW: https://github.com/python-social-auth/social-core
2019-06-10 00:44:24 +00:00
Sunpoet Po-Chuan Hsieh
d2a4774c84 Update to 0.35.0
Changes:	https://gitlab.com/m2crypto/m2crypto/blob/master/CHANGES
		https://gitlab.com/m2crypto/m2crypto/commits/master
2019-06-09 16:52:41 +00:00
Jan Beich
338d1782dc security/tor: force rebuild after r503790
evutil_secure_rng_add_bytes became nop in r478104 on all FreeBSD
releases due to a bug in arc4random_addrandom ifdef. libevent 2.1.10
hidden it based on configure check. Looks like there were consumers.

PR:		238433
Reported by:	yuri
2019-06-09 11:26:26 +00:00
Cy Schubert
a0129005c0 Update to the latest MIT KRB5 github commmit. 2019-06-09 01:48:55 +00:00
Jochen Neumeister
ee59bcfda3 Set correct Port Name for last drupal7 entry
Sponsored by:	Netzkommune GmbG
2019-06-08 18:52:51 +00:00
Tijl Coosemans
bb5cf6c4f3 Address some portlint warnings in the Linux infrastructure ports.
Eliminate LINUXNAME from port Makefiles.  This was just a helper variable
without special meaning outside port Makefiles but several developers have
copied it to new ports where it was then unused, apparently thinking that
it did have some special meaning.
2019-06-08 15:59:46 +00:00