Commit Graph

32902 Commits

Author SHA1 Message Date
Thomas Zander 35fb3834f0 Document CVE-2020-28896 for mutt 2.0.2.
PR:		251278
Submitted by:	dereks@lifeofadishwasher.com
Security:	CVE-2020-28896
2020-11-21 14:41:33 +00:00
Mikael Urankar 9eb7c77ae2 security/masscan: fix build on !x86
Only include x86 header on x86

PR:		250899
Approved by:	taguchi.ch@gmail.com (maintainer timeout)
2020-11-21 13:37:33 +00:00
Jesper Schmitz Mouridsen ef158e1d5c security/lxqt-sudo Update to 0.16.0 2020-11-21 12:25:22 +00:00
Jesper Schmitz Mouridsen 1f65f2aa2b security/lxqt-openssh-askpass Update to 0.16.0 2020-11-21 12:19:11 +00:00
Sunpoet Po-Chuan Hsieh 0283ac519d Convert REINPLACE_CMD to patch files 2020-11-21 09:37:32 +00:00
Sunpoet Po-Chuan Hsieh 62880b4f29 Update to 2.4.8
Changes:	https://github.com/a2o/snoopy/blob/master/ChangeLog
2020-11-21 09:18:28 +00:00
Sunpoet Po-Chuan Hsieh 631dccee8c Update to 1.5.0
Changes:	http://git.gnupg.org/cgi-bin/gitweb.cgi?p=libksba.git;a=blob;f=NEWS;hb=HEAD
2020-11-21 09:18:24 +00:00
Yuri Victorovich bee8a29d93 security/fizz: Update 2020.11.02.00 -> 2020.11.16.00 2020-11-20 07:19:31 +00:00
Bryan Drewery 4bc67aef47 - Add pkg-config dependency which avoids some maintainer testing errors
and also removes a few unneeded library links such as -lcurses.
- libfido2 package is broken with pkg-config and base ssl. Workaround this
  by not using pkg-config for that library for now.
- Add USES=localbase to simplify some options
- Make crypt(3) MD5 password support optional but still on-by-default.  The
  default in FreeBSD changed in 10.0 but that does not mean
- Enable -Werror
- Remove some old baggage from the port build
 o The zlib version check has not been needed for a while.
 o sshd.8 has not had %%PREFIX%% or %$RC_SCRIPT_NAME%% since 2011
   and is not worth more patches/complexity.
 o The strnvis(3) problem noted in r311891 was fixed in OpenSSH 7.4.
 o autoreconf is run so it makes no sense to patch configure for -ldes
 o --with-md5-passwords is not needed as our crypt(3) supports it
   natively.  This is only relevant without PAM.
2020-11-20 03:41:56 +00:00
Adam Weinberger e5fd1ed281 security/testssl.sh: Update to 3.0.3
* Update certificate stores
* manpage fix (Karl)
* minor speedups for some vulnerability tests
* bash 5.1 fix
* Secure Client-Initiated Renegotiation false positive fix
* BREACH is now medium
* invalid JSON fix and other JSON improvements (David)
* Adding native Android 7 handshake instead of Chrome which has TLS 1.3 (Christoph)
* Header flag X-XSS-Protection is now labled as INFO
* No cyan colors in HHHTP header flags anymore, colons added
* Dockerfile improvments
2020-11-19 16:11:53 +00:00
Dag-Erling Smørgrav 5ee50d2378 Upgrade to 0.36 2020-11-19 01:26:20 +00:00
Craig Leres 7683bab387 security/broccoli: Explicitly deprecate due to dependency on lang/python27
Given its dependency on lang/python27, lets deprecate broccoli
itself to give ports that depend it a little warning.

(It looks like security/barnyard2 is the only one left.)

PR:		249760
Reported by:	swills
2020-11-19 00:48:32 +00:00
Craig Leres 4ef455dd32 security/zeek: Remove deprecated security/broccoli option
Upstream confirms that support for the broccoli protocol will be
removed in a future version of zeek. And given that security/broccoli
requires python2 which will be deprecated at the end of December,
lets remove broccoli support from zeek now.
2020-11-19 00:34:21 +00:00
Alex Dupre 66d204da2c Update to 1.27.0 release. 2020-11-18 13:23:47 +00:00
Rene Ladan f4130f4ab2 security/sudo: readd option for SSSD, reverting r553505 2020-11-18 12:22:20 +00:00
Cy Schubert 43044915a8 Update 1.18.2 --> 1.18.3 2020-11-18 04:15:06 +00:00
Cy Schubert a0d7c357ac Update 1.17.1 --> 1.17.2 2020-11-18 04:15:03 +00:00
Rene Ladan 195affec9d security/sssd: update to 1.16.5
This fixes several security vulnerabilities and unexpires
the port because it moves to Python 3.

PR:		241347
Submitted by:	lukas.slebodnik@intrak.sk (initial patch)
MFH:		2020Q4
Security:	CVE-2018-16838
Security:	CVE-2019-3811
2020-11-17 20:42:16 +00:00
Piotr Kubaj 5407692917 security/wolfssl: fix build on big-endian
Merge upstream patch to fix build on big-endian architectures.

Also unmark mips and mips64 as broken, now builds fine.

MFH:		2020Q4 (fix build blanket)
2020-11-17 16:06:06 +00:00
Adam Weinberger 860d7ad91d security/gnupg: Update to 2.2.24
* Allow Unicode file names on Windows almost everywhere.  Note that
    it is still not possible to use Unicode strings on the command
    line.  This change also fixes a regression in 2.2.22 related to
    non-ascii file names.  [#5098]

  * Fix localized time printing on Windows.  [#5073]

  * gpg: New command --quick-revoke-sig.  [#5093]

  * gpg: Do not use weak digest algos if selected by recipient
    preference during sign+encrypt.  [4c181d51a6]

  * gpg: Switch to AES256 for symmetric encryption in de-vs mode.
    [166e779634]

  * gpg: Silence weak digest warnings with --quiet.  [#4893]

  * gpg: Print new status line CANCELED_BY_USER for a cancel during
    symmetric encryption.  [f05d1772c4]

  * gpg: Fix the encrypt+sign hash algo preference selection for
    ECDSA.  This is in particular needed for keys created from
    existing smartcard based keys.  [aeed0b93ff]

  * agent: Fix secret key import of GnuPG 2.3 generated Ed25519 keys.
    [#5114]

  * agent: Keep some permissions of private-keys-v1.d.  [#2312]

  * dirmngr: Align sks-keyservers.netCA.pem use between ntbtls and
    gnutls builds.  [e4f3b74c91]

  * dirmngr: Fix the pool keyserver case for a single host in the
    pool.  [72e04b03b1a7]

  * scd: Fix the use case of verify_chv2 by CHECKPIN.  [61aea64b3c]

  * scd: Various improvements to the ccid-driver.  [#4616,#5065]

  * scd: Minor fixes for Yubikey [25bec16d0b]

  * gpgconf: New option --show-versions.

  * w32: Install gpg-check-pattern and example profiles.  Install
    Windows subsystem variant of gpgconf (gpgconf-w32).

  * i18n: Complete overhaul and completion of the Italian translation.
    Thanks to Denis Renzi.

  * Require Libgcrypt 1.8 because 1.7 has long reached end-of-life.

  Release-info: https://dev.gnupg.org/T5052
2020-11-17 14:12:10 +00:00
Bryan Drewery 4cff3f057d - Add blacklistd(8) support.
This differs slightly from base as it uses the current NetBSD
  hook points.
  This is off-by-default as it needs testing and has issues that may cause
  crashes.  One such issue is the use of private bl_create() symbol from
  libblacklist.  It is also unclear if the hook points are sufficient
  or proper after the libssh refactoring in 8.x.

PR:		223628 (patch rewritten as it no longer applied)
2020-11-17 01:45:11 +00:00
Bryan Drewery 7a31807051 - Add and enable FIDO/U2F support for security keys by default.
This feature came in 8.2, is enabled by default on OpenBSD,
  and suggested to be enabled by default for packages.
2020-11-16 23:36:48 +00:00
Bryan Drewery c1eea6f3b3 - Slightly reduce diff with base
- No functional changes.

PR:		223010
Submitted by:	brnrd (earlier patch)
2020-11-16 22:25:28 +00:00
Bryan Drewery f1a66569e8 - bindresvport support hasn't been used since 7.8 2020-11-16 20:39:13 +00:00
Bryan Drewery 121e399cae - Remove sctp patch missed in r466577 2020-11-16 20:36:17 +00:00
Bryan Drewery b773b7cade - Update to 8.4p1 (skipped 8.3)
- https://www.openssh.com/txt/release-8.3
 - https://www.openssh.com/txt/release-8.4

PR:		239807, 250319
Sponsored by:	Dell EMC
2020-11-16 19:39:34 +00:00
Dima Panov d99a0c551f VuXML: document mozjpeg and libjpeg-turbo recent vulnerabilities
PR:		250190
Submitted by:	daniel.engberg.lists@pyret.net
2020-11-16 11:13:14 +00:00
Mikael Urankar 98812670ff security/botan2: fix build on arm
processor_rng is only implemented on x86 and powerpc64

PR:		251160
Approved by:	Ralf van der Enden (maintainer)
2020-11-16 10:21:25 +00:00
Li-Wen Hsu 23d381418c security/keepassxc: Update to 2.6.2
PR:		250582
Approved by:	maintainer timeout
2020-11-16 02:44:38 +00:00
Jason E. Hale e572cd2816 security/pinentry: Users who enable the non-default GNOME3 option will now
have to install security/pinentry-gnome3 manually. This has been done to break
a dependency loop that was introduced in r553735 where security/gcr added a
build dependency on security/gnupg.

Before r553735:
security/gnupg -> security/pinentry -> security/pinentry-gnome3 -> security/gcr

After r553735:
security/gnupg -> security/pinentry -> security/pinentry-gnome3 -> security/gcr
-> security/gnupg

Now:
security/gnupg -> security/pinentry
security/pinentry-gnome3 -> security/gcr -> security/gnupg

A pkg-message has been added to remind users of the GNOME3 option to install the
required package manually and to deinstall it if no longer needed.

PR:		250945
Reported by:	<sdalu@sdalu.com>
2020-11-15 20:37:58 +00:00
Rene Ladan a1d58205a0 Remove expired ports:
2020-11-15 archivers/py-pyliblzma: Uses deprecated version of python
2020-11-15 databases/postgis23: Upstream no longer maintained
2020-11-15 databases/py-htsql: Uses deprecated version of python
2020-11-15 devel/bzr-fastimport: Uses deprecated version of python
2020-11-15 devel/py-ToscaWidgets: Uses deprecated version of python
2020-11-15 devel/py-calendar: Uses deprecated version of python
2020-11-15 devel/py-distorm: Uses deprecated version of python
2020-11-15 devel/py-fabric1: Uses deprecated version of python
2020-11-15 devel/py-rcsparse: Uses deprecated version of python
2020-11-15 devel/pyrex: Uses deprecated version of python
2020-11-15 japanese/py-tegaki: Uses deprecated version of python
2020-11-15 math/py-networkx1: Obsolete, please use math/py-networkx instead
2020-11-15 misc/py-progressbar231: Uses deprecated version of python
2020-11-15 multimedia/py-kaa-imlib2: Uses deprecated version of python
2020-11-15 multimedia/py-kaa-metadata: Uses deprecated version of python
2020-11-15 net-im/libtelepathy: Uses deprecated version of python
2020-11-15 security/py-mcrypt: Uses deprecated version of python
2020-11-15 www/py-beautifulsoup32: Uses deprecated version of python
2020-11-15 www/py-evernote: Uses deprecated version of python
2020-04-01 www/py-meld3: EOLed upstream
2020-11-15 www/py-requestbuilder: Uses deprecated version of python
2020-11-15 x11-toolkits/py-SquareMap: Uses deprecated version of python
2020-11-15 18:37:28 +00:00
Sunpoet Po-Chuan Hsieh 8f6db480cb Update to 6.3.1
- Update WWW

Changes:	https://github.com/IdentityPython/pysaml2/releases
2020-11-15 18:06:20 +00:00
Sunpoet Po-Chuan Hsieh 91a2132f1d Update to 2020.11.8
Changes:	https://github.com/certifi/python-certifi/commits/master
2020-11-15 18:06:15 +00:00
Sunpoet Po-Chuan Hsieh d6b37b70c3 Update to 0.15.2
Changes:	https://github.com/lepture/authlib/releases
2020-11-15 18:06:11 +00:00
Sunpoet Po-Chuan Hsieh 70c6949dc8 Update USES=python for py-dns-lexicon 3.5.0 update 2020-11-15 18:03:30 +00:00
Sunpoet Po-Chuan Hsieh 8e68bdf04e Update to 5.5.2
Changes:	https://github.com/keybase/client/releases
2020-11-15 17:58:51 +00:00
Sunpoet Po-Chuan Hsieh d84e805129 Add py-webauthn 0.4.7
PyWebAuthn is a Python module which can be used to handle WebAuthn registration
and assertion. Currently, WebAuthn is supported in Firefox, Chrome, and Edge.

WWW: https://github.com/duo-labs/py_webauthn
2020-11-15 17:55:59 +00:00
Dmitry Marakasov c5977c3033 - Update to 2.17.2
- Fix building in presence of older version of botan2 installed in the system by importing upstream patch

PR:		251106
Submitted by:	tremere@cainites.net (maintainer)
Reported by:	amdmi3, acupuncture@cgocable.ca, fastmint@hush.com
2020-11-15 14:07:14 +00:00
Guido Falsi 4d0426bd4c Add databases/courier-authlib-sqlite port to install sqlite support
for courier-authlib

Suggested by:	Ewout Boks <ewout@boks.com>
2020-11-15 12:31:00 +00:00
Mark Linimon 53b4486491 Mark as BROKEN on aarch64 (runaway build, seen on both emulated hardware
and real hardware).

While here, pet portlint.

Reported by:	mikael
Approved by:	portmgr (tier-2 blanket)
2020-11-15 09:29:28 +00:00
Mark Linimon 7ea3033324 Mark various ports BROKEN on aarch64.
Obtained from:	local run @lonesome.com
2020-11-15 09:06:24 +00:00
Vanilla I. Shu b0ae5c9f20 Update to 0.55.0.
PR:		251139
Submitted by:	maintainer
2020-11-15 05:07:39 +00:00
Kurt Jaeger 2126289e89 security/vuxml: add entries for databases/mantis
PR:		251141
Submitted by:	Zoltan Alexanderson Besse <zab@zltech.eu>
2020-11-14 21:02:16 +00:00
Yuri Victorovich f58989f07f security/highwayhash: Update g20200803 -> g20201021 2020-11-14 08:34:37 +00:00
Cy Schubert cb24eb07f4 Update to the latest MIT KRB5 commit on github. 2020-11-14 05:59:25 +00:00
Yuri Victorovich cf1e69d23a security/cowrie: Update 2.1.0 -> 2.2.0
Reported by:	portscout
2020-11-14 04:46:50 +00:00
Piotr Kubaj e61e061eb1 security/snort2pfcd: fix build on GCC architectures
cc1: error: unrecognized command line option "-Wimplicit-fallthrough"
cc1: error: unrecognized command line option "-Wcovered-switch-default"
cc1: error: unrecognized command line option "-Wno-noexcept-type"
cc1: error: unrecognized command line option "-Wstring-conversion"

Tested to build with Clang.
2020-11-14 03:09:34 +00:00
Jan Beich 573d99c343 security/nss: update to 3.59
Changes:	https://developer.mozilla.org/docs/Mozilla/Projects/NSS/NSS_3.59_release_notes
Changes:	https://hg.mozilla.org/projects/nss/shortlog/NSS_3_59_RTM
ABI:		https://abi-laboratory.pro/tracker/timeline/nss/
2020-11-13 20:33:48 +00:00
Eugene Grosbein e414badd97 security/ipsec-tool: minor port cleanup
Remove non-existing configure options --enable-debug and --with-pkgversion.
Remove option NATTF that changed --enable-natt=yes to --enable-natt=kernel
that is exactly same for FreeBSD releases since 8.0-RELEASE.
2020-11-13 13:35:56 +00:00
Fukang Chen fb508d8168 security/py-ecdsa: Update to 0.16.0
- Update to 0.16.0
- Add test target
- Pet portlint

Changelog:

    https://github.com/warner/python-ecdsa/releases/tag/python-ecdsa-0.16.0

Reviewed by:	koobs
Approved by:	koobs (ports, mentor, maintainer)
Differential Revision:	https://reviews.freebsd.org/D27187
MFH:	No (API changes, unclear on compatibility)
2020-11-13 03:29:37 +00:00