Commit Graph

32902 Commits

Author SHA1 Message Date
Philip Paeps c0dc157724 security/vuxml: add FreeBSD SA-20:31.icmp6 2020-12-02 10:03:09 +00:00
Niclas Zeising 0288a02253 vuxml: document xorg-server vulnerabilities
Document new vulnerabilities in xorg-server and sub ports:
CVE-2020-14360 and CVE-2020-25712

These issues can lead to privileges elevations for authorized clients
on systems where the X server is running privileged.
2020-12-01 19:37:28 +00:00
Dan Langille 86ca213bde Update to 2.8.8
* More dns apis added
* Bug fixes.
* Move CI checks from travis-ci to Github Actions by https://vmactions.org

https://github.com/acmesh-official/acme.sh/releases/tag/2.8.8
2020-12-01 18:36:56 +00:00
Tobias C. Berner 5b591329b2 Update KDE Plasma Desktop to 5.20.4
Tuesday, 1 December 2020.
Today KDE releases a bugfix update to KDE Plasma 5, versioned 5.20.4 Plasma
5.20 was released in October 2020 with many feature refinements and new modules
to complete the desktop experience.

This release adds a month’s worth of new translations and fixes from KDE’s
contributors. The bugfixes are typically small but important and include:

   * Use plasma theme icons in kickoff leave view.
   * Weight main categories properly.
   * Discover: Display title in application page.

Changelog:
	https://kde.org/announcements/plasma-5.20.3-5.20.4-changelog/
2020-12-01 17:40:16 +00:00
Antoine Brodin 49644059a6 Update to 2.2.2 2020-12-01 14:47:20 +00:00
Antoine Brodin 7d517d06c0 Update to 2.1.0 2020-12-01 14:45:20 +00:00
Antoine Brodin 7823ca47a7 Update to 4.11.0 2020-12-01 14:43:14 +00:00
Antoine Brodin 11c6473546 Update to 4.1.0.17 2020-12-01 14:07:39 +00:00
Antoine Brodin 145bc4cf78 Update to 1.2.0.11 2020-12-01 14:07:16 +00:00
Antoine Brodin ff1c5db34f Update to 1.0.5 2020-12-01 14:00:53 +00:00
Cy Schubert cc735bba8a Update to the latest MIT KRB5 commit on github.
This commit captures KRB5-1.19-beta. The beta announcement on
krbdev is as follows:

MIT krb5-1.19-beta1 is now available for download from

         https://web.mit.edu/kerberos/dist/testing.html

The main MIT Kerberos web page is

         https://web.mit.edu/kerberos/

Please send comments to the krbdev list.  We plan for the final
release to occur in about one month.  The README file contains a more
extensive list of changes.

Major changes in 1.19
---------------------

Administrator experience:

* When a client keytab is present, the GSSAPI krb5 mech will refresh
  credentials even if the current credentials were acquired manually.

* It is now harder to accidentally delete the K/M entry from a KDB.

Developer experience:

* gss_acquire_cred_from() now supports the "password" and "verify"
  options, allowing credentials to be acquired via password and
  verified using a keytab key.

* When an application accepts a GSS security context, the new
  GSS_C_CHANNEL_BOUND_FLAG will be set if the initiator and acceptor
  both provided matching channel bindings.

* Added the GSS_KRB5_NT_X509_CERT name type, allowing S4U2Self
  requests to identify the desired client principal by certificate.

* PKINIT certauth modules can now cause the hw-authent flag to be set
  in issued tickets.

* The krb5_init_creds_step() API will now issue the same password
  expiration warnings as krb5_get_init_creds_password().

Protocol evolution:

* Added client and KDC support for Microsoft's Resource-Based
  Constrained Delegation, which allows cross-realm S4U2Proxy requests.
  A third-party database module is required for KDC support.

* kadmin/admin is now the preferred server principal name for kadmin
  connections, and the host-based form is no longer created by
  default.  The client will still try the host-based form as a
  fallback.

* Added client and server support for Microsoft's KERB_AP_OPTIONS_CBT
  extension, which causes channel bindings to be required for the
  initiator if the acceptor provided them.  The client will send this
  option if the client_aware_gss_bindings profile option is set.

User experience:

* The default setting of dns_canonicalize_realm is now "fallback".
  Hostnames provided from applications will be tried in principal
  names as given (possibly with shortname qualification), falling back
  to the canonicalized name.

* kinit will now issue a warning if the des3-cbc-sha1 encryption type
  is used in the reply.  This encryption type will be deprecated and
  removed in future releases.

* Added kvno flags --out-cache, --no-store, and --cached-only
  (inspired by Heimdal's kgetcred).
2020-12-01 04:26:23 +00:00
Yuri Victorovich 0f76a80982 security/fizz: Update 2020.11.23.00 -> 2020.11.30.00 2020-12-01 03:37:39 +00:00
Bernard Spil 49578c5a32 security/libressl-devel: Update to 3.3.0 2020-11-30 17:51:53 +00:00
Kirill Ponomarev d6af5b2fc4 Bump PORTREVISION on *-sbcl ports after lang/sbcl upgrade. 2020-11-30 16:42:24 +00:00
Mark Linimon b200046550 Fails on riscv64 the same way as on aarch64.
Approved by:	portmgr (tier-2 blanket)
Obtained from:	lonesome.com build testing
2020-11-30 15:16:43 +00:00
Mark Linimon 853162a9c1 Fails the same was on riscv64 as the others.
While here, pet portlint.

Obtained from:	lonesome.com build testing
2020-11-30 15:05:46 +00:00
Piotr Kubaj 41f9c08371 security/highwayhash: remove sys/types.h include, move sys/param.h higher
Reported by:	jbeich
2020-11-30 02:00:14 +00:00
Yuri Victorovich f36ea34e04 security/helib: Update 1.1.0 -> 1.2.0
Reported by:	portscout
2020-11-30 01:12:52 +00:00
Piotr Kubaj c10799bffd security/highwayhash: fix build on powerpc64* 2020-11-29 23:22:13 +00:00
Piotr Kubaj ccdc8ee045 security/openssh-portable: fix build on GCC architectures
loginrec.c:763:2: error: 'strncpy' output may be truncated copying 32 bytes from a string of length 511 [-Werror=stringop-truncation]
strncpy(utx->ut_user, li->username,
^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
MIN_SIZEOF(utx->ut_user, li->username));
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
loginrec.c: In function 'record_failed_login':
loginrec.c:1687:2: error: 'strncpy' specified bound 32 equals destination size [-Werror=stringop-truncation]
strncpy(ut.ut_user, username, sizeof(ut.ut_user));
^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
loginrec.c:1696:2: error: 'strncpy' specified bound 256 equals destination size [-Werror=stringop-truncation]
strncpy(ut.ut_host, hostname, sizeof(ut.ut_host));
2020-11-29 02:16:28 +00:00
Matthias Fechner 5eb8e6a316 Update to 1.16.0 which is required for gitlab-ce 13.6. 2020-11-28 15:05:38 +00:00
Bernard Spil 135fdfecd8 security/openssl-devel: Update to 3.0.0 alpha 9 2020-11-27 19:53:54 +00:00
Mikhail Pchelin 70dd5727c4 - update from 1.9.9 to 2.0.0 2020-11-27 18:34:15 +00:00
Piotr Kubaj 4122761a7d security/botan2: fix build on powerpc64
aes_power8.cpp needs VSX too apart from crypto:
src/lib/block/aes/aes_power8/aes_power8.cpp:43:49: error: use of undeclared identifier 'vec_vsx_ld'
   return (Altivec64x2)reverse_vec((Altivec8x16)vec_vsx_ld(0, key));;
                                                ^
src/lib/block/aes/aes_power8/aes_power8.cpp:48:36: error: use of undeclared identifier 'vec_vsx_ld'
   return (Altivec64x2)reverse_vec(vec_vsx_ld(0, src));
2020-11-27 13:51:13 +00:00
Brad Davis 180b14a900 vuxml: Add entry for nomad < 0.12.6 2020-11-27 00:34:50 +00:00
Fernando Apesteguía 6cebfb8984 security/lego: Update to 4.1.3
ChangeLog: https://github.com/go-acme/lego/blob/master/CHANGELOG.md#v413---2020-11-25

PR:	251388
Submitted by:	matt@matthoran.com (maintainer)
2020-11-26 14:08:11 +00:00
Fernando Apesteguía b520078c01 security/maltrail: Update to 0.26
PR:	251382
Submitted by:	m.muenz@gmail.com (maintainer)
2020-11-26 09:00:34 +00:00
Jose Alonso Cardenas Marquez cf1052b347 - Connect new fpc ports 2020-11-25 03:07:58 +00:00
Jose Alonso Cardenas Marquez 4ca1f77d7a - Update to 3.2.0
ChangeLog at:	https://wiki.freepascal.org/FPC_New_Features_3.2.0
2020-11-25 02:57:50 +00:00
Jose Alonso Cardenas Marquez ea03d8c01d - New port: security/fpc-gnutls
Free Pascal unit for GnuTLS
2020-11-25 02:43:25 +00:00
Yuri Victorovich ae900c20fe security/fizz: Update 2020.11.16.00 -> 2020.11.23.00 2020-11-24 23:41:36 +00:00
Guido Falsi d0b960f92c - Update fail2ban to 0.11.2
- Remove patches now included in the upstream code
- Adapt option to not install test files

PR:		251341
Submitted by:	theis@gmx.at (maintainer)
2020-11-24 21:21:00 +00:00
Sunpoet Po-Chuan Hsieh dca829ccd1 Update to 2.4.9
Changes:	https://github.com/a2o/snoopy/blob/master/ChangeLog
2020-11-24 20:49:01 +00:00
Sunpoet Po-Chuan Hsieh 5053732434 Skip libcrypto.pc when using SSL from base system
- Bump PORTREVISION for package change

Differential Revision:	https://reviews.freebsd.org/D27289
Submitted by:	bdrewery
2020-11-24 20:48:56 +00:00
Bryan Drewery 7562494439 - Fix KERB_GSSAPI build; missing prototypes for DH openssl-compat.
PR:		212151 (maybe)
2020-11-24 20:46:20 +00:00
Sunpoet Po-Chuan Hsieh 04202dade7 Fix r555861
Reported by:	bdrewery
2020-11-24 20:35:40 +00:00
Alex Dupre a381618955 Update to 0.21.0 release. 2020-11-24 16:36:06 +00:00
Adam Weinberger 4c1a5e4c97 security/gnupg: Update to 2.2.25
* scd: Fix regression in 2.2.24 requiring gpg --card-status before
    signing or decrypting.  [#5065]

  * gpgsm: Using Libksba 1.5.0 signatures with a rarely used
    combination of attributes can now be verified.  [#5146]

  Release-info: https://dev.gnupg.org/T5140
2020-11-24 15:55:01 +00:00
Matthias Fechner 23d7f42c53 Mark port as broken with ruby 2.7.
The page:
https://github.com/jcs/rubywarden
also tells, that this port will not be maintained anymore.

PR:		244787
2020-11-24 15:53:27 +00:00
Fernando Apesteguía effb3ff40e security/lego: Update to 4.1.2
ChangeLog: https://github.com/go-acme/lego/blob/master/CHANGELOG.md#v412---2020-11-21

PR:	251323
Submitted by:	matt@matthoran.com (maintainer)
2020-11-24 14:24:54 +00:00
Mikael Urankar 4e449e031e lang/rust: Update to 1.48.0
Changes: https://github.com/rust-lang/rust/releases/tag/1.48.0

Reviewed by:	jbeich
Tested by:	bdragon, jbeich, mikael
Differential Revision:	https://reviews.freebsd.org/D27293
2020-11-24 12:48:53 +00:00
Mikael Urankar 7f15bb8a67 security/rustscan: Update to 2.0.1
https://github.com/RustScan/RustScan/releases/tag/2.0.0
  https://github.com/RustScan/RustScan/releases/tag/2.0.1
2020-11-24 10:22:31 +00:00
Cy Schubert 91821a5aab Update to the latest MIT KRB5 commit on github. 2020-11-24 04:47:28 +00:00
Yuri Victorovich a9ddcbcb8a security/tor-devel: Update 0.4.5.1-alpha -> 0.4.5.2-alpha
Reported by:	upstream update notification
2020-11-23 19:46:32 +00:00
Tobias C. Berner 65af483151 Update KDE Frameworks to 5.76
November 07, 2020. KDE today announces the release of KDE Frameworks 5.76.0.

KDE Frameworks are 70 addon libraries to Qt which provide a wide variety of
commonly needed functionality in mature, peer reviewed and well tested
libraries with friendly licensing terms. For an introduction see the KDE
Frameworks release announcement.

This release is part of a series of planned monthly releases making
improvements available to developers in a quick and predictable manner.

Announcement:
	https://kde.org/announcements/kde-frameworks-5.76.0/

PR:		251135
Exp-run by:	antoine
2020-11-23 18:46:43 +00:00
Adam Weinberger 5a6c403e6d vuxml: Add entry for gitea < 1.12.6 2020-11-22 15:48:54 +00:00
Adam Weinberger 4ac577276d security/testssl.sh: Update to 3.0.4 2020-11-22 15:37:04 +00:00
Bradley T. Hughes d05c7ce8f3 security/vuxml: document Node.js November 2020 Security Releases
https://nodejs.org/en/blog/vulnerability/november-2020-security-releases/

Sponsored by:	Miles AS
2020-11-21 22:14:16 +00:00
Mark Felder 69e814771d security/titus: Mark broken with base openssl on < FreeBSD 12
MFH:		2020Q4
2020-11-21 19:03:54 +00:00
Dmitri Goutnik 1c12122198 security/lego: Update to 4.1.1
Changes:	https://github.com/go-acme/lego/blob/master/CHANGELOG.md#v411---2020-11-19
PR:		250963
Submitted by:	Matthew Horan <matt@matthoran.com> (maintainer)
2020-11-21 17:36:37 +00:00