aboutsummaryrefslogtreecommitdiff
path: root/security
Commit message (Collapse)AuthorAgeFilesLines
* This commit was manufactured by cvs2svn to create tag 'RELEASE_7_0_0'.release/7.0.0cvs2svn2008-02-24202-9490/+1364
| | | | | Notes: svn path=/head/; revision=207820 svn path=/tags/RELEASE_7_0_0/; revision=207821; tag=release/7.0.0
* Document jetty - multiple vulnerabilitiesRemko Lodder2007-12-101-0/+44
| | | | | | | | | | PR: ports/118524 Submitted by: Nick Barkas <snb at threerings dot net> with minor modifications by me Approved by: portmgr (secteam blanket) Notes: svn path=/head/; revision=202929
* Update to 2007.12.07 with fix security issue.Norikatsu Shigemura2007-12-091-1/+2
| | | | | | | | | | Security: VuXML ID: 821afaa2-9e9a-11dc-a7e3-0016360406fa CVE-2007-6036 http://aluigi.altervista.org/adv/live555x-adv.txt Approved by: portmgr (erwin) Notes: svn path=/head/; revision=202927
* Document liveMedia -- DoS vulnerabilityRemko Lodder2007-12-081-0/+34
| | | | | | | | | Submitted by: Rafae«l Careé <funm at videolan dot org> with modifications by me Approved by: portmgr (secteam blanket) Notes: svn path=/head/; revision=202924
* Update to reflect the squid issue has been assignedXin LI2007-12-071-1/+2
| | | | | | | | | CVE-2007-6239. Approved by: portmgr (ports-security blanket) Notes: svn path=/head/; revision=202921
* - Update gnu-finger entryMartin Wilke2007-12-051-1/+1
| | | | | | | | | * Fix cvename handling Approved by: portmgr (ports-security blanket) Notes: svn path=/head/; revision=202911
* http://nvd.nist.gov/nvd.cfm?cvename=CVE-1999-1165: gnu-finger is old,Mark Linimon2007-12-051-0/+28
| | | | | | | | | | creaky, and not for use in production environments. Submitted by: tabthorpe Approved by: portmgr (self) Notes: svn path=/head/; revision=202910
* Update to reflect an updated www/squid30 version which is noXin LI2007-12-051-1/+1
| | | | | | | | | longer vulnerable. Approved by: portmgr (ports-security blanket) Notes: svn path=/head/; revision=202907
* - Chase rubygem-activerecord updatePav Lucistnik2007-12-041-1/+1
| | | | | | | | | Missed by: miwi Reported by: pointyhat Approved by: portmgr (hat) Notes: svn path=/head/; revision=202902
* Update to reflect an updated www/squid version which is noXin LI2007-12-041-1/+2
| | | | | | | | | longer vulnerable. Approved by: portmgr (ports-security blanket) Notes: svn path=/head/; revision=202900
* Document squid denial of service vulnerability. This can beXin LI2007-12-041-0/+31
| | | | | | | | | triggered from trusted squid client only. Approved by: portmgr (ports-security blanket) Notes: svn path=/head/; revision=202898
* PORTREVISION bump in support of pkg-plist revision 1.5.Cy Schubert2007-12-031-1/+1
| | | | | | | Approved by: portsmgr (ewin) Notes: svn path=/head/; revision=202887
* Correct chmod location.Cy Schubert2007-12-021-2/+2
| | | | | | | Approved by: portmgr (linimon) Notes: svn path=/head/; revision=202877
* Remove the rsync entry for now. Better way of handlingXin LI2007-12-021-39/+0
| | | | | | | | | | | | this is still under discussion, as the vendor patch does not automatically resolve problem for customized configuration that have chroot = no. Requested by: pav Approved by: portmgr (ports-security blanket) Notes: svn path=/head/; revision=202876
* Document rsync security bypass vulnerability.Xin LI2007-12-011-0/+39
| | | | | | | Approved by: portmgr (ports-security blanket) Notes: svn path=/head/; revision=202872
* Make the rubygem-rails -- JSON XSS vulnerability entry valid UTF-8 (atSimon L. B. Nielsen2007-12-011-2/+2
| | | | | | | | | | | least the special chars doesn't look like UTF-8 as per emacs or freshports). Reported by: freshports via dvl Approved by: portmgr (secteam blanket) Notes: svn path=/head/; revision=202871
* - Update to 0.10Li-Wen Hsu2007-11-303-4/+15
| | | | | | | | | | | | - Unbreak on HEAD/7 (re-add a needed patch) PR: ports/118066 Submitted by: Peter Johnson <johnson.peter AT gmail.com> (maintainer) Reported by: pointyhat (pav) Approved by: portmgr (linimon) Notes: svn path=/head/; revision=202868
* Also cover rubygem-activesupport which is part of rails and isXin LI2007-11-281-0/+5
| | | | | | | | | affected by CVE-2007-3227 as well. Approved by: portmgr (ports-security blanket) Notes: svn path=/head/; revision=202851
* Document recent Ruby On Rails vulnerabilities.Xin LI2007-11-281-0/+56
| | | | | | | Approved by: portmgr (ports-security blanket) Notes: svn path=/head/; revision=202850
* Document ikiwiki improper symlink verification vulnerability.Henrik Brix Andersen2007-11-271-0/+29
| | | | | | | | Reviewed by: remko Approved by: portmgr (erwin), erwin (mentor) Notes: svn path=/head/; revision=202845
* Document firefox multiple unspecified memory corruption vulnerabilities.Xin LI2007-11-271-0/+39
| | | | | | | Approved by: portmgr (ports-security blanket) Notes: svn path=/head/; revision=202844
* Unbreak pthread-related issues on 5.xAde Lovett2007-11-262-13/+3
| | | | | | | Approved by: portmgr Notes: svn path=/head/; revision=202839
* Mark as broken on 5.x: fails to find pthread.h.Mark Linimon2007-11-251-0/+5
| | | | | | | | | | | | Something in the infrastructure changed in the late July timeframe that actually caused this problem. The only major thing at that time was the autoconf/libtool change, but I can't see how that could have caused this failure mode. It only happens on 5.x; 6.x and 7.x are fine. Approved by: portmgr (self) Notes: svn path=/head/; revision=202834
* Mark as broken: fails to install.Mark Linimon2007-11-244-0/+8
| | | | | | | Approved by: portmgr (self) Notes: svn path=/head/; revision=202822
* Add sfsrwcd: clients cannot make connections without it.Mark Linimon2007-11-232-2/+3
| | | | | | | | | Part of: ports/116966 Submitted by: maintainer, private email Approved by: portmgr (self) Notes: svn path=/head/; revision=202803
* - Document phpmyadmin -- Cross Site ScriptingMartin Wilke2007-11-211-0/+28
| | | | | | | | Reviewed by: remko Approved by: portmgr (ports-security blanket Notes: svn path=/head/; revision=202787
* - Update last Samba entry,Martin Wilke2007-11-211-1/+3
| | | | | | | | | | | * Add reference to the samba advisories * Fix the PORTVERSION/PORTEPOCH Reviewed by: simon Approved by: portmgr (ports-security blanket) Notes: svn path=/head/; revision=202780
* Document samba - multiple vulnerabilitiesMartin Wilke2007-11-211-0/+40
| | | | | | | | Reviewed by: remko Approved by: portmgr (ports-security blanket) Notes: svn path=/head/; revision=202779
* Unmark broken; the missing Objective C header with gcc 4.2 has now beenMark Linimon2007-11-201-7/+1
| | | | | | | | | | | fixed. PR: ports/117967 Submitted by: maintainer Approved by: portmgr (self) Notes: svn path=/head/; revision=202763
* postnuke 0.763 is not vulnerable to 35f2679f-52d7-11db-8f1a-000a48049292Xin LI2007-11-181-2/+2
| | | | | | | | | so mark it as not vulnerable. Approved by: portmgr (ports-security blanket) Notes: svn path=/head/; revision=202742
* Improve JDK version coverage. We should consider PORTEPOCH'ed versionXin LI2007-11-171-4/+4
| | | | | | | | | separately, so restruct the range. Approved by: portmgr (ports-security blanket) Notes: svn path=/head/; revision=202739
* Document PHP multiple vulnerabilities that are fixed by php 5.2.5.Xin LI2007-11-161-0/+44
| | | | | | | Approved by: portmgr (ports-security blanket) Notes: svn path=/head/; revision=202737
* - Fix c93e4d41-75c5-11dc-b903-0016179b2dd5 entryMartin Wilke2007-11-161-9/+8
| | | | | | | | | Submitted by: glewis Reviewed by: remko Approved by: portmgr (ports-security blanket) Notes: svn path=/head/; revision=202733
* print/cups-base is vulnerable for all previous versions toErwin Lansing2007-11-141-1/+1
| | | | | | | | | | 1.3.3_2, not all coming ones. Submitted by: Andrew Daugherity <ADaugherity@vprmail.tamu.edu> Approved by: portmgr (self) Notes: svn path=/head/; revision=202717
* - Fix build on FreeBSD 7Johan van Selst2007-11-141-0/+1
| | | | | | | | Reported by: pointyhead (via pav) Approved by: portmgr (pav) Notes: svn path=/head/; revision=202712
* Document mt-daapd -- denial of service vulnerability, alsoRemko Lodder2007-11-141-1/+36
| | | | | | | | | | | | correct the previous entry style wise. Submitted by: Mark D. Foster <mark at foster dot cc> with minor modifications by me. Approved by: portmgr (secteam blanket) Notes: svn path=/head/; revision=202705
* - Update xpdf -- multiple remote Stream.CC vulnerabilitiesMartin Wilke2007-11-141-1/+2
| | | | | | | | | * Mark cups-base as safe Approved by: portmgr (ports-security blanket) Notes: svn path=/head/; revision=202703
* o Add a patch for CVE-2007-5846, and add an entry for vuxml.Jun Kuriyama2007-11-141-0/+25
| | | | | | | Approved by: portmgr (marcus) Notes: svn path=/head/; revision=202696
* - Document flac -- media file processing integer overflow vulnerabilitiesMartin Wilke2007-11-131-0/+35
| | | | | | | | | Reviewed by: simon Approved by: portsmgr (ports-security blanket) Thanks to: naddy Notes: svn path=/head/; revision=202687
* Add an official fix for the chroot mode resolving bug.Peter Pentchev2007-11-133-0/+105
| | | | | | | Approved by: portmgr (pav) Notes: svn path=/head/; revision=202681
* Unbreak file by closing </li> tag.Simon L. B. Nielsen2007-11-131-1/+1
| | | | | | | Approved by: portmgr (secteam blanket) Notes: svn path=/head/; revision=202676
* Document xpdf arbitrary code execution vulnerability, as documented inXin LI2007-11-131-0/+64
| | | | | | | | | CVE-2007-4352, CVE-2007-5392, CVE-2007-5393. Approved by: portmgr (ports-security blanket) Notes: svn path=/head/; revision=202671
* - Attempt to fix plist on 7.0Pav Lucistnik2007-11-131-0/+3
| | | | | | | | Reported by: pointyhat Approved by: portmgr (hat) Notes: svn path=/head/; revision=202666
* - hcrypto library is only installed on FreeBSD < 7.0Pav Lucistnik2007-11-122-23/+29
| | | | | | | | Reported by: pointyhat Approved by: portmgr (hat) Notes: svn path=/head/; revision=202653
* dinoex@ has choosen to apply a vendor patch that has resolved CVE-2007-4351Xin LI2007-11-121-1/+2
| | | | | | | | | instead of upgrading to 1.3.4. Mark this updated version as not vulnerable. Approved by: portmgr (ports-security blanket) Notes: svn path=/head/; revision=202646
* - Make fetchable again. Add my MASTER_SITE_LOCAL to the mix and replaceTom McLaughlin2007-11-121-9/+7
| | | | | | | | | | a number of outdated sites. Notified by: Ferenc Gartner Approved by: portmgr (linimon, erwin) Notes: svn path=/head/; revision=202636
* Document plone arbitrary code execution vulnerability.Xin LI2007-11-121-0/+30
| | | | | | | Approved by: portmgr (ports-security blanket) Notes: svn path=/head/; revision=202634
* - Updated the last gftp entry (we have 2.0.18_6 in the portstree not 2.10.18_6)Martin Wilke2007-11-111-1/+2
| | | | | | | | Submitted by: Fabian Keil (via private mail) Approved by: portmgr (ports-security blanket) Notes: svn path=/head/; revision=202628
* - Document phpmyadmin -- cross-site scripting vulnerabilityMartin Wilke2007-11-111-0/+30
| | | | | | | | Reviewed by: simon Approved by: portmgr (ports-security blanket) Notes: svn path=/head/; revision=202623
* Document gallery2 multiple vulnerabilities.Xin LI2007-11-091-0/+35
| | | | | | | Approved by: portmgr (ports-security blanket) Notes: svn path=/head/; revision=202611