Commit Graph

32902 Commits

Author SHA1 Message Date
Mateusz Piotrowski d06ae9b7e0 Update the Angr framework to 9.0.5405
- Angr binaries are now tagged as well. We may consider removing
  ANGR_BINARIES_TAGNAME in the future.
- Remove restrictions on the unicorn version for now. This should prevent
  the port from breaking again in the foreseeable future.

PR:		252042
Reported by:	nc
Event:		January 2021 Bugathon
2021-01-16 21:57:39 +00:00
Neel Chauhan 01718ebb54 security/xray-core: Update to 1.2.2
Approved by:	0mp (mentor, implicit)
2021-01-16 17:24:47 +00:00
Danilo G. Baio eff5460096 security/py-bcrypt: Update to 3.2.0 2021-01-16 12:18:31 +00:00
Antoine Brodin 91783de9c9 Fix build
Reported by:	pkg-fallout
MFH:		2021Q1
2021-01-16 12:07:27 +00:00
Danilo G. Baio ba0d167261 security/libscep: Remove Python 2.7 support and PY_SPHINX
Approved by:	portmgr blanket
2021-01-15 13:25:15 +00:00
Yuri Victorovich d3606a2568 security/py-ospd: Transfer maintainership to acm@ on his request.
Requested by:	acm (via e-mail)
2021-01-14 22:55:10 +00:00
Bradley T. Hughes 5980a700d4 security/vuxml: document Node.js January 2021 Security Releases
https://nodejs.org/en/blog/vulnerability/january-2021-security-releases/

Sponsored by:	Miles AS
2021-01-14 20:37:35 +00:00
Danilo G. Baio b53abbd839 Remove PY_SPHINX from ports using Python 3
Approved by:	 portmgr blanket
Differential Revision:	https://reviews.freebsd.org/D28093
2021-01-14 14:34:38 +00:00
Matthias Fechner e86437da30 Document gitlab vulnerability. 2021-01-14 12:03:01 +00:00
Tobias C. Berner fe7e701091 security/gcr: update to 3.38.1 2021-01-14 10:47:51 +00:00
Thomas Zander 736e76b934 Document integer overflow in wavpack (CVE-2020-35738). 2021-01-14 07:30:32 +00:00
Koichiro Iwao b7b467fb29 Return to pool as per maintainer's request
and I take security/dehydrated.

PR:		252650
Submitted by:	Sascha Holzleiter <sascha@root-login.org>
2021-01-14 07:12:35 +00:00
Steve Wills f53a1320a6 security/please: take maintainership 2021-01-14 03:45:58 +00:00
Lars Engels a9df8fe7bd security/lynis: Update to 3.0.3
MFH:		20201Q1
2021-01-13 20:28:55 +00:00
Li-Wen Hsu 76e4f567ea Document Jenkins Security Advisory 2021-01-13
Sponsored by:	The FreeBSD Foundation
2021-01-13 17:31:59 +00:00
Sergey A. Osokin e8029e4846 Update databases/redis to the recent stable version 6.0.10.
Update CONFLICTS for:
o) databases/redis4
o) databases/redis5
o) databases/redis
o) databases/redis-devel

Connect databases/redis5 to the build.

Bump PORTREVISIONs for dependant ports.
2021-01-13 16:13:24 +00:00
Adriaan de Groot 63ddfd1197 Fix key management in security/kleopatra
This was reported upstream also as
	https://bugs.kde.org/show_bug.cgi?id=415168
there has been a patch languishing there for a long time, which I've
now (re)submitted upstream. It fixes all of the reported problem:
a previous patch by me in FreeBSD ports only dealt with half of them.

PR:		242670
Submitted by:	Andre Heinecke
Reported by:	Gerhard Seibert
2021-01-13 14:02:08 +00:00
Rene Ladan d217e9878f Simplify some ports using PYTHON_MAJOR_VER and Python 3.6+ 2021-01-12 21:25:30 +00:00
Florian Smeets 198cb26d63 Document phpmyfaq vulnerability 2021-01-12 21:20:07 +00:00
Yuri Victorovich 57a191d0a2 security/tor-devel: Update 0.4.5.2-alpha -> 0.4.5.3-rc
Reported by:	upstream notification
2021-01-12 20:12:08 +00:00
Renato Botelho c2e6c0b81f security/sudo: Update to 1.9.5p1
This version fixes a regression introduced by 1.9.5

Changelog: https://www.sudo.ws/stable.html#1.9.5p1

PR:		252598
Submitted by:	cy
MFH:		2021Q1
Sponsored by:	Rubicon Communications, LLC (Netgate)
2021-01-12 12:40:23 +00:00
Adam Weinberger 2b2d7f29bb security/gnupg: Update to 2.2.27
* gpg: Fix regression in 2.2.24 for gnupg_remove function under
   Windows.  [#5230]

 * gpgconf: Fix case with neither local nor global gpg.conf.  [9f37d3e6f3]

 * gpgconf: Fix description of two new options.  [#5221]

 * Build Windows installer without timestamps.  Note that the
   Authenticode signatures still carry a timestamp.

  Release-info: https://dev.gnupg.org/T5234
2021-01-12 04:50:55 +00:00
Cy Schubert bb7030802e Document sudo CVE-2021-23239. 2021-01-12 04:27:21 +00:00
Cy Schubert 4cccd18c6a Fix build on llvm10 and gcc.
PR:		252577
Reported by:	David Sieborger <drs-freebsd _ sieborger.nom.za>
MFH:		2021Q1
2021-01-12 04:27:16 +00:00
Yuri Victorovich 8aaefe0c9d security/fizz: Update 2021.01.04.00 -> 2021.01.11.00 2021-01-11 21:03:05 +00:00
Cy Schubert f8006638b7 Update 1.9.4p2 --> 1.9.5
PR:		252583
Submitted by:	cy
Reported by:	cy
Approved by:	garga (maintainer)
MFH:		2021Q1
Security:	CVE-2021-23239
2021-01-11 20:06:29 +00:00
Rene Ladan 75d659b385 Remove logic for Python < 3.6 for ports using Python 3.6+ 2021-01-11 19:36:17 +00:00
Neel Chauhan 07c9bfaf49 security/xray-core: Update to 1.2.1
Reviewed by:		0mp (mentor)
Approved by:		0mp (mentor)
Differential Revision:	https://reviews.freebsd.org/D28094
2021-01-11 18:26:42 +00:00
Roman Bogorodskiy c964ac1a0a security/libtasn1: add a workaround for clang 10+
When compiled with clang 10+ and -O[2-9], the resulting package
fails to parse certificates.

As a workaround, downgrade optimization to -O1.

Upstream issue: https://gitlab.com/gnutls/libtasn1/-/issues/30

PR:		252548
Reported by:	rozhuk.im@gmail.com
2021-01-11 15:19:09 +00:00
Sunpoet Po-Chuan Hsieh f7865e7aed Update version requirement of RUN_DEPENDS 2021-01-10 23:14:25 +00:00
Sunpoet Po-Chuan Hsieh de459b6ae7 Update version requirement of RUN_DEPENDS 2021-01-10 23:14:21 +00:00
Rene Ladan 0bb581cd3c Remove empty PY_IPADDRESS from ports using Python 3.6+
Also remove one manual declaration (net-mgmt/py-aggregate6)
2021-01-10 16:04:33 +00:00
Rene Ladan 850accd611 Remove empty PY_ENUM34 from ports using Python 3.6+ 2021-01-10 14:05:32 +00:00
Dmitri Goutnik 7e41b27d52 security/go-cve-dictionary: Update to 0.5.5
- Pet portclippy while here

Changes:	https://github.com/kotakanbe/go-cve-dictionary/releases/tag/v0.5.5
PR:		251653
Submitted by:	Alexandru Ciobanu <iscandr@gmail.com> (maintainer)
2021-01-10 12:40:41 +00:00
Sunpoet Po-Chuan Hsieh e0c627447b Document cairosvg vulnerability 2021-01-10 08:26:39 +00:00
Sunpoet Po-Chuan Hsieh 89c6c5a074 Clean up RUN_DEPENDS after r542200 (USES=python:3.6+) 2021-01-10 08:22:34 +00:00
Sunpoet Po-Chuan Hsieh 60a4057867 Remove PYTHON_REL check 2021-01-10 08:22:30 +00:00
Sunpoet Po-Chuan Hsieh 558e5802b6 Clean up RUN_DEPENDS after r559531 (USES=python:3.6+) 2021-01-10 08:22:26 +00:00
Sunpoet Po-Chuan Hsieh d059f1e85a Remove PYTHON_REL check after r559531 (USES=python:3.6+) 2021-01-10 08:22:22 +00:00
Sunpoet Po-Chuan Hsieh d48df51988 Remove PYTHON_REL check after r559531 (USES=python:3.6+) 2021-01-10 08:22:18 +00:00
Torsten Zuehlsdorff c7c9cccfb5 lang/php80: Update from 8.0.0 to 8.0.1
Core:
        Fixed bug #80345 (PHPIZE configuration has outdated PHP_RELEASE_VERSION).
        Fixed bug #72964 (White space not unfolded for CC/Bcc headers).
        Fixed bug #80391 (Iterable not covariant to mixed).
        Fixed bug #80393 (Build of PHP extension fails due to configuration gap with libtool).
        Fixed bug #77069 (stream filter loses final block of data).
    Fileinfo:
        Fixed bug #77961 (finfo_open crafted magic parsing SIGABRT).
    FPM:
        Fixed bug #69625 (FPM returns 200 status on request without SCRIPT_FILENAME env).
    IMAP:
        Fixed bug #80438 (imap_msgno() incorrectly warns and return false on valid UIDs in PHP 8).
        Fix a regression with valid UIDs in imap_savebody().
        Make warnings for invalid message numbers/UIDs between functions consistent.
    Intl:
        Fixed bug #80425 (MessageFormatAdapter::getArgTypeList redefined).
    Opcache:
        Fixed bug #80404 (Incorrect range inference result when division results in float).
        Fixed bug #80377 (Opcache misses executor_globals).
        Fixed bug #80433 (Unable to disable the use of the AVX command when using JIT).
        Fixed bug #80447 (Strange out of memory error when running with JIT).
        Fixed bug #80480 (Segmentation fault with JIT enabled).
        Fixed bug #80506 (Immediate SIGSEGV upon ini_set("opcache.jit_debug", 1)).
    OpenSSL:
        Fixed bug #80368 (OpenSSL extension fails to build against LibreSSL due to lack of OCB support).
    PDO MySQL:
        Fixed bug #80458 (PDOStatement::fetchAll() throws for upsert queries).
        Fixed bug #63185 (nextRowset() ignores MySQL errors with native prepared statements).
        Fixed bug #78152 (PDO::exec() - Bad error handling with multiple commands).
        Fixed bug #66878 (Multiple rowsets not returned unless PDO statement object is unset()).
        Fixed bug #70066 (Unexpected "Cannot execute queries while other unbuffered queries").
        Fixed bug #71145 (Multiple statements in init command triggers unbuffered query error).
        Fixed bug #76815 (PDOStatement cannot be GCed/closeCursor-ed when a PROCEDURE resultset SIGNAL).
        Fixed bug #79872 (Can't execute query with pending result sets).
        Fixed bug #79131 (PDO does not throw an exception when parameter values are missing).
        Fixed bug #72368 (PdoStatement->execute() fails but does not throw an exception).
        Fixed bug #62889 (LOAD DATA INFILE broken).
        Fixed bug #67004 (Executing PDOStatement::fetch() more than once prevents releasing resultset).
        Fixed bug #79132 (PDO re-uses parameter values from earlier calls to execute()).
    Phar:
        Fixed bug #73809 (Phar Zip parse crash - mmap fail).
        Fixed bug #75102 (`PharData` says invalid checksum for valid tar).
        Fixed bug #77322 (PharData::addEmptyDir('/') Possible integer overflow).
    Phpdbg:
        Fixed bug #76813 (Access violation near NULL on source operand).
    SPL:
        Fixed bug #62004 (SplFileObject: fgets after seek returns wrong line).
    Standard:
        Fixed bug #80366 (Return Value of zend_fstat() not Checked).
        Fixed bug #77423 (FILTER_VALIDATE_URL accepts URLs with invalid userinfo). (CVE-2020-7071)
    Tidy:
        Fixed bug #77594 (ob_tidyhandler is never reset).
    Tokenizer:
        Fixed bug #80462 (Nullsafe operator tokenize with TOKEN_PARSE flag fails).
    XML:
        XmlParser opaque object renamed to XMLParser for consistency with other XML objects.
    Zlib:
        Fixed bug #48725 (Support for flushing in zlib stream).

PR:		252508
Submitted by:	<michael.glaus@hostpoint.ch>, samm
Differential Revision:	D28065
2021-01-09 23:53:20 +00:00
Torsten Zuehlsdorff de35a537f7 lang/php74: Upgrade from 7.4.13 to 7.4.14
Core:
        Fixed bug #74558 (Can't rebind closure returned by Closure::fromCallable()).
        Fixed bug #80345 (PHPIZE configuration has outdated PHP_RELEASE_VERSION).
        Fixed bug #72964 (White space not unfolded for CC/Bcc headers).
        Fixed bug #80362 (Running dtrace scripts can cause php to crash).
        Fixed bug #80393 (Build of PHP extension fails due to configuration gap with libtool).
        Fixed bug #80402 (configure filtering out -lpthread).
        Fixed bug #77069 (stream filter loses final block of data).
    Fileinfo:
        Fixed bug #77961 (finfo_open crafted magic parsing SIGABRT).
    FPM:
        Fixed bug #69625 (FPM returns 200 status on request without SCRIPT_FILENAME env).
    Intl:
        Fixed bug #80425 (MessageFormatAdapter::getArgTypeList redefined).
    OpenSSL:
        Fixed bug #80368 (OpenSSL extension fails to build against LibreSSL due to lack of OCB support).
    Phar:
        Fixed bug #73809 (Phar Zip parse crash - mmap fail).
        Fixed bug #75102 (`PharData` says invalid checksum for valid tar).
        Fixed bug #77322 (PharData::addEmptyDir('/') Possible integer overflow).
    PDO MySQL:
        Fixed bug #80458 (PDOStatement::fetchAll() throws for upsert queries).
        Fixed bug #63185 (nextRowset() ignores MySQL errors with native prepared statements).
        Fixed bug #78152 (PDO::exec() - Bad error handling with multiple commands).
        Fixed bug #70066 (Unexpected "Cannot execute queries while other unbuffered queries").
        Fixed bug #71145 (Multiple statements in init command triggers unbuffered query error).
        Fixed bug #76815 (PDOStatement cannot be GCed/closeCursor-ed when a PROCEDURE resultset SIGNAL).
    Standard:
        Fixed bug #77423 (FILTER_VALIDATE_URL accepts URLs with invalid userinfo). (CVE-2020-7071)
        Fixed bug #80366 (Return Value of zend_fstat() not Checked).
        Fixed bug #80411 (References to null-serialized object break serialize()).
    Tidy:
        Fixed bug #77594 (ob_tidyhandler is never reset).
    Zlib:
        Fixed #48725 (Support for flushing in zlib stream).

PR:		252509
Submitted by:	<michael.glaus@hostpoint.ch>
2021-01-09 23:49:59 +00:00
Jason E. Hale 2353442172 security/*gpgme*: Update to 1.15.1 2021-01-09 22:44:01 +00:00
Matthias Fechner 5058a0d582 Document gitlab vulnerabilities. 2021-01-09 20:06:20 +00:00
Antoine Brodin 8524eefbd1 Remove python 2.7 support from a few ports 2021-01-09 16:34:07 +00:00
Martin Matuska 23c8cf4bcc Update ftp/proftpd to 1.3.7a 2021-01-09 13:52:20 +00:00
Danilo G. Baio 5803da33cc security/py-[acme|certbot]: Update to 1.11.0
Changelog:	https://github.com/certbot/certbot/blob/v1.11.0/certbot/CHANGELOG.md

PR:		252452
Submitted by:	Yasuhiro KIMURA <yasu@utahime.org>
Approved by:	python (with hat)
2021-01-09 13:15:12 +00:00
Dmitri Goutnik b9c8a7feab security/govpn: Unbreak with go1.16
PR:		252520
Approved by:	Sergey Matveev <stargrave@stargrave.org> (maintainer)
2021-01-08 23:51:15 +00:00
Tobias C. Berner 482d8befda Update KDE Plasma Desktop to 5.20.5
Tuesday, 5 January 2021.
Today KDE releases a bugfix update to KDE Plasma 5, versioned 5.20.5. Plasma
5.20 was released in October with many feature refinements and new modules to
complete the desktop experience.

This release adds a month’s worth of new translations and fixes from KDE’s
contributors. The bugfixes are typically small but important and include:

   * Plasma NM: Fix password entry jumping to different networks with wifi scanning, by pausing the scan when appropriate.
   * Plasma PA: Read text color from proper theme.
   * Plasma Workspace: Move keyboard positioning in the keyboard itself.

Announcement:
	https://kde.org/announcements/plasma-5.20.5/
2021-01-08 22:14:43 +00:00
Tobias C. Berner 4fb2cd10f1 Update KDE Release Service ports to 20.12.1
Full changelog:
	https://kde.org/announcements/fulllog_releases-20.12.1/
2021-01-08 19:15:30 +00:00