<feed xmlns='http://www.w3.org/2005/Atom'>
<title>ports/security, branch 2021Q1</title>
<subtitle>FreeBSD ports tree</subtitle>
<id>https://cgit-dev.freebsd.org/ports/atom?h=2021Q1</id>
<link rel='self' href='https://cgit-dev.freebsd.org/ports/atom?h=2021Q1'/>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/'/>
<updated>2021-04-06T10:54:17Z</updated>
<entry>
<title>security/openssl: Fix /dev/crypto issue with 1.1.1k</title>
<updated>2021-04-06T10:54:17Z</updated>
<author>
<name>Bernard Spil</name>
<email>brnrd@FreeBSD.org</email>
</author>
<published>2021-04-06T10:39:33Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=48f05c509b86f1ce4a7c9be31ed8adc891870734'/>
<id>urn:sha1:48f05c509b86f1ce4a7c9be31ed8adc891870734</id>
<content type='text'>
PR:		254643
Reported by:	&lt;cryx-freebsd h3q com&gt;
Reviewed by:	wollman
</content>
</entry>
<entry>
<title>MFH: r569572 r569597</title>
<updated>2021-03-30T20:58:35Z</updated>
<author>
<name>Sunpoet Po-Chuan Hsieh</name>
<email>sunpoet@FreeBSD.org</email>
</author>
<published>2021-03-30T20:58:35Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=b4758833c2b9a7589a36306b63aed3afbf75bd35'/>
<id>urn:sha1:b4758833c2b9a7589a36306b63aed3afbf75bd35</id>
<content type='text'>
Update to 3.7.2

Changes:	https://git.lysator.liu.se/nettle/nettle/blob/master/NEWS

Build and install example applications

- Bump PORTREVISION for package change
</content>
</entry>
<entry>
<title>MFH: r569247</title>
<updated>2021-03-26T08:15:42Z</updated>
<author>
<name>Bernard Spil</name>
<email>brnrd@FreeBSD.org</email>
</author>
<published>2021-03-26T08:15:42Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=30f801444f188f14cfc7eeaf0915f28e9b21a34e'/>
<id>urn:sha1:30f801444f188f14cfc7eeaf0915f28e9b21a34e</id>
<content type='text'>
security/openssl: Security update to 1.1.1k

PR:		254551
Submitted by:	Pascal Christen &lt;pascal christen hostpoint ch&gt;
Security:	5a668ab3-8d86-11eb-b8d6-d4c9ef517024

Approved by:	ports-secteam (blanket)
</content>
</entry>
<entry>
<title>MFH: r566134</title>
<updated>2021-03-21T00:56:45Z</updated>
<author>
<name>Jan Beich</name>
<email>jbeich@FreeBSD.org</email>
</author>
<published>2021-03-21T00:56:45Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=1c9253e006a79999f49f919bc9c30e5728f37e7e'/>
<id>urn:sha1:1c9253e006a79999f49f919bc9c30e5728f37e7e</id>
<content type='text'>
security/nss: update to 3.62

Changes:	https://developer.mozilla.org/docs/Mozilla/Projects/NSS/NSS_3.62_release_notes
Changes:	https://hg.mozilla.org/projects/nss/shortlog/NSS_3_62_RTM
</content>
</entry>
<entry>
<title>MFH: r568629</title>
<updated>2021-03-17T19:33:46Z</updated>
<author>
<name>Cy Schubert</name>
<email>cy@FreeBSD.org</email>
</author>
<published>2021-03-17T19:33:46Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=9eefc17f0845e2d275edef588fcb503769b81277'/>
<id>urn:sha1:9eefc17f0845e2d275edef588fcb503769b81277</id>
<content type='text'>
security/wpa_supplicant: fix for P2P provision vulnerability

Latest version available from: https://w1.fi/security/2021-1/

Vulnerability

A vulnerability was discovered in how wpa_supplicant processes P2P
(Wi-Fi Direct) provision discovery requests. Under a corner case
condition, an invalid Provision Discovery Request frame could end up
reaching a state where the oldest peer entry needs to be removed. With
a suitably constructed invalid frame, this could result in use
(read+write) of freed memory. This can result in an attacker within
radio range of the device running P2P discovery being able to cause
unexpected behavior, including termination of the wpa_supplicant process
and potentially code execution.

Vulnerable versions/configurations

wpa_supplicant v1.0-v2.9 with CONFIG_P2P build option enabled

An attacker (or a system controlled by the attacker) needs to be within
radio range of the vulnerable system to send a set of suitably
constructed management frames that trigger the corner case to be reached
in the management of the P2P peer table.

Note: The P2P option is not default.

Security:	https://w1.fi/security/2021-1/\
	wpa_supplicant-p2p-provision-discovery-processing-vulnerability.txt
</content>
</entry>
<entry>
<title>MFH: r561297</title>
<updated>2021-03-17T19:26:41Z</updated>
<author>
<name>Cy Schubert</name>
<email>cy@FreeBSD.org</email>
</author>
<published>2021-03-17T19:26:41Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=84bc1563e22358db4bb1cd5c3bbbe38902e7445f'/>
<id>urn:sha1:84bc1563e22358db4bb1cd5c3bbbe38902e7445f</id>
<content type='text'>
Fix build on llvm10 and gcc.

PR:		252577
Reported by:	David Sieborger &lt;drs-freebsd _ sieborger.nom.za&gt;
</content>
</entry>
<entry>
<title>MFH: r565117 r568572</title>
<updated>2021-03-17T16:15:19Z</updated>
<author>
<name>Bernard Spil</name>
<email>brnrd@FreeBSD.org</email>
</author>
<published>2021-03-17T16:15:19Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=d779838e2ca2ada4a736f7a7256bd4a7255fe34b'/>
<id>urn:sha1:d779838e2ca2ada4a736f7a7256bd4a7255fe34b</id>
<content type='text'>
security/libressl: Bugfix update to 3.2.4

 * See errata 013 from OpenBSD 6.8
 * Various interoperability issues and memory leaks were discovered in
   libcrypto and libssl

security/libressl: Security fix for potential use-after-free

Security:	eeca52dc-866c-11eb-b8d6-d4c9ef517024

Approved by:	ports-secteam (blanket)
</content>
</entry>
<entry>
<title>MFH: r563905 r565324 r568584</title>
<updated>2021-03-16T16:49:36Z</updated>
<author>
<name>Yuri Victorovich</name>
<email>yuri@FreeBSD.org</email>
</author>
<published>2021-03-16T16:49:36Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=0ac59fd229e08df75ecfa76ee4dbcd78d55e5e84'/>
<id>urn:sha1:0ac59fd229e08df75ecfa76ee4dbcd78d55e5e84</id>
<content type='text'>
security/tor: Update 0.4.4.6 -&gt; 0.4.4.7

Reported by:	upstream notification

security/tor: Update 0.4.4.7 -&gt; 0.4.5.6

Changelog: https://lists.torproject.org/pipermail/tor-announce/2021-February/000214.html
- contains major and minor bugfixes and new features.

Port options LTTNG,USDT,LOG_DEBUG backported from security/tor-devel.
LIB_DEPENDS is fixes in STATIC_TOR option.

Reported by:	upstream notification

security/tor: Update 0.4.5.6 -&gt; 0.4.5.7

Changelog: https://gitweb.torproject.org/tor.git/tree/ChangeLog?h=tor-0.4.5.7 (security release)

Reported by:	upstream notification
</content>
</entry>
<entry>
<title>MFH: r567271</title>
<updated>2021-03-04T00:06:57Z</updated>
<author>
<name>Dmitry Marakasov</name>
<email>amdmi3@FreeBSD.org</email>
</author>
<published>2021-03-04T00:06:57Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=2d74867af86cacc50686b15c9baf4dde1cd10da0'/>
<id>urn:sha1:2d74867af86cacc50686b15c9baf4dde1cd10da0</id>
<content type='text'>
- Fix signal used in reload command

PR:		253965
Submitted by:	admin@support.od.ua
</content>
</entry>
<entry>
<title>MFH: r560298 r560302 r561371 r562151 r562559 r563142 r563143 r563149 r565356 r565465 r566011 r566182</title>
<updated>2021-02-25T18:32:27Z</updated>
<author>
<name>Piotr Kubaj</name>
<email>pkubaj@FreeBSD.org</email>
</author>
<published>2021-02-25T18:32:27Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=2c78b9754cd0638c4ba990970302077829c534b1'/>
<id>urn:sha1:2c78b9754cd0638c4ba990970302077829c534b1</id>
<content type='text'>
finance/quickfix: fix build on non-x86

Code uses x86 assembly, but makes it possible to use Boost atomic.

multimedia/zoneminder: enable on powerpc64

net/mpich: fix build on powerpc64

Neither __BYTE_ORDER nor __BIG_ENDIAN are defined:
In file included from src/mpi/datatype/typerep/dataloop/looputil.c:10:
./src/mpi/datatype/typerep/dataloop/looputil.h:57:2: error: This code assumes that __BYTE_ORDER and __BIG_ENDIAN are defined
#error This code assumes that __BYTE_ORDER and __BIG_ENDIAN are defined

editors/libreoffice: fix build on powerpc64 elfv2

This set of patches is applied only on powerpc* architectures.

Submitted by:	afsilva
Approved by:	tier 2 blanket

security/openconnect-gui: fix checksum

emulators/riscv-isa-sim: enable on powerpc64

sysutils/linuxfdisk: enable on powerpc64

graphics/openfx-arena: enable on powerpc64

multimedia/arcan: enable LUAJIT on powerpc64

It builds fine with luajit-openresty.

games/libretro-desmume2015: fix build on non-x86 / ARM

JIT is only for x86 and ARM.

astro/opencpn: fix build on powerpc64*

Use GCC unconditionally on powerpc64*:
In file included from /usr/lib/clang/11.0.1/include/xmmintrin.h:13:
/usr/lib/clang/11.0.1/include/mmintrin.h:33:5: error: use of undeclared identifier '__builtin_ia32_emms'; did you mean '__builtin_isless'?
    __builtin_ia32_emms();

editors/libreoffice6: backport powerpc* patches to libreoffice6

Approved by:	tier 2 blanket
</content>
</entry>
</feed>
