<feed xmlns='http://www.w3.org/2005/Atom'>
<title>ports/security, branch 2015Q2</title>
<subtitle>FreeBSD ports tree</subtitle>
<id>https://cgit-dev.freebsd.org/ports/atom?h=2015Q2</id>
<link rel='self' href='https://cgit-dev.freebsd.org/ports/atom?h=2015Q2'/>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/'/>
<updated>2015-07-23T16:24:25Z</updated>
<entry>
<title>Shibboleth SP software crashes on well-formed but invalid XML.</title>
<updated>2015-07-23T16:24:25Z</updated>
<author>
<name>Palle Girgensohn</name>
<email>girgen@FreeBSD.org</email>
</author>
<published>2015-07-23T16:24:25Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=7d7c2271f6c957574221e8746e5a356435cd114f'/>
<id>urn:sha1:7d7c2271f6c957574221e8746e5a356435cd114f</id>
<content type='text'>
The Service Provider software contains a code path with an uncaught
exception that can be triggered by an unauthenticated attacker by
supplying well-formed but schema-invalid XML in the form of SAML
metadata or SAML protocol messages. The result is a crash and so
causes a denial of service.

You must rebuild opensaml and shibboleth with xmltooling-1.5.5 or later.
The easiest way to do so is to update the whole chain including
shibboleth-2.5.5 an opensaml2.5.5.

URL:    	http://shibboleth.net/community/advisories/secadv_20150721.txt
Security:	CVE-2015-2684
Approved by:	ports-secteam
</content>
</entry>
<entry>
<title>MFH: 385082,386705,386950</title>
<updated>2015-06-27T14:33:52Z</updated>
<author>
<name>Roman Bogorodskiy</name>
<email>novel@FreeBSD.org</email>
</author>
<published>2015-06-27T14:33:52Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=480c2209a5265393c1a7dad302bf53f7f72caec3'/>
<id>urn:sha1:480c2209a5265393c1a7dad302bf53f7f72caec3</id>
<content type='text'>
- Update to 4.5
- Drop @dirrm* from plist [1]
- Properly register info page [2]

Submitted by:	amdmi3 [1]
Submitted by:	antoine [2]
PR:		199980 [2]

Security:	CVE-2015-2806
Approved by:	ports-secteam (eadler)
</content>
</entry>
<entry>
<title>MFH: r385425</title>
<updated>2015-06-20T00:29:51Z</updated>
<author>
<name>Xin LI</name>
<email>delphij@FreeBSD.org</email>
</author>
<published>2015-06-20T00:29:51Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=a908a517ad2bbe045aa635ff549e065c502374ed'/>
<id>urn:sha1:a908a517ad2bbe045aa635ff549e065c502374ed</id>
<content type='text'>
Update to 0.98.7

Requested by:	garga
Approved by:	ports-secteam@
</content>
</entry>
<entry>
<title>Direct commit to fix the distinfo for security/ossec-hids-* with the older USE_GITHUB support.</title>
<updated>2015-06-13T14:04:34Z</updated>
<author>
<name>Brad Davis</name>
<email>brd@FreeBSD.org</email>
</author>
<published>2015-06-13T14:04:34Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=b4f030d1f8dc20c9e48a4ee2831779877a5a6b63'/>
<id>urn:sha1:b4f030d1f8dc20c9e48a4ee2831779877a5a6b63</id>
<content type='text'>
Approved by:    zi (mentor
Approved by:	ports-secteam (zi)
</content>
</entry>
<entry>
<title>MFH r389271</title>
<updated>2015-06-12T15:09:49Z</updated>
<author>
<name>Brad Davis</name>
<email>brd@FreeBSD.org</email>
</author>
<published>2015-06-12T15:09:49Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=905e167f054bc387f6d3376163504a9c35f5a94f'/>
<id>urn:sha1:905e167f054bc387f6d3376163504a9c35f5a94f</id>
<content type='text'>
  Update security/ossec-hids-* to 2.8.2.

Approved by:	portmgr (erwin)
Approved by:	swills (mentor)
Security:	c470db07-1098-11e5-b6a8-002590263bf5
</content>
</entry>
<entry>
<title>MFH: r388905</title>
<updated>2015-06-09T19:57:04Z</updated>
<author>
<name>Renato Botelho</name>
<email>garga@FreeBSD.org</email>
</author>
<published>2015-06-09T19:57:04Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=d8da2d3d68674b0a67b7d60747ab94d3552fc69e'/>
<id>urn:sha1:d8da2d3d68674b0a67b7d60747ab94d3552fc69e</id>
<content type='text'>
Update to 5.3.2

PR:		200721
Approved by:	strongswan@Nanoteq.com (maintainer)
Security:	CVE-2015-3991
Sponsored by:	Netgate
Approved by:	portmgr (erwin)
</content>
</entry>
<entry>
<title>MFH: r387747</title>
<updated>2015-05-28T17:49:12Z</updated>
<author>
<name>Xin LI</name>
<email>delphij@FreeBSD.org</email>
</author>
<published>2015-05-28T17:49:12Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=9a98ef9382dcd1a870e3230ff7a84a24612470e2'/>
<id>urn:sha1:9a98ef9382dcd1a870e3230ff7a84a24612470e2</id>
<content type='text'>
Apply vendor patch for CVE-2015-2694 (changeset
b0c571e709c72da799ccc15fb5755f7910170e33) to prevent requires_preauth
bypass.

Obtained from:	https://github.com/krb5/krb5/commit/b0c571e709c72da799ccc15fb5755f7910170e33.diff
Security:	CVE-2015-2694
Security:	0b040e24-f751-11e4-b24d-5453ed2e2b49
Approved by:	ports-secteam
</content>
</entry>
<entry>
<title>MFH: r384787 (ale)</title>
<updated>2015-05-22T22:12:11Z</updated>
<author>
<name>Xin LI</name>
<email>delphij@FreeBSD.org</email>
</author>
<published>2015-05-22T22:12:11Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=461f88c8f35b0ca97ef1fb90bc8306b59f0ba935'/>
<id>urn:sha1:461f88c8f35b0ca97ef1fb90bc8306b59f0ba935</id>
<content type='text'>
Update to 5.6.8 release.

PR:		199585
Submitted by:	Franco Fichtner
Approved by:	ports-secteam
</content>
</entry>
<entry>
<title>MFH: r387031</title>
<updated>2015-05-22T16:17:04Z</updated>
<author>
<name>Xin LI</name>
<email>delphij@FreeBSD.org</email>
</author>
<published>2015-05-22T16:17:04Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=8c3c9f31b6ebc687e9ef7ed4c2673911b49833ec'/>
<id>urn:sha1:8c3c9f31b6ebc687e9ef7ed4c2673911b49833ec</id>
<content type='text'>
Fix plist when LIBDANE is defined (PORTREVISION not bumped
because package wouldn't be successful in the case).

Pointy hat to:	delphij
Reported by:	sunpoet
Approved by:	ports-secteam
</content>
</entry>
<entry>
<title>MFH: r387029</title>
<updated>2015-05-22T15:54:56Z</updated>
<author>
<name>Xin LI</name>
<email>delphij@FreeBSD.org</email>
</author>
<published>2015-05-22T15:54:56Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=c3000fa74482814dcd125c1bea1f7bc853d37e44'/>
<id>urn:sha1:c3000fa74482814dcd125c1bea1f7bc853d37e44</id>
<content type='text'>
Update to 3.3.15.

PR:		198875
Approved by:	ports-secteam@ (self)
</content>
</entry>
</feed>
