| Commit History - (may be incomplete: see CVSWeb link above for full details) |
| Date | By | Description |
05 Feb 2007 01:08:46
0.2.3
|
pav  |
Populate a new ports-mgmt category. List of moved ports:
devel/portcheckout -> ports-mgmt/portcheckout
devel/portlint -> ports-mgmt/portlint
devel/portmk -> ports-mgmt/portmk
devel/porttools -> ports-mgmt/porttools
misc/instant-tinderbox -> ports-mgmt/instant-tinderbox
misc/porteasy -> ports-mgmt/porteasy
misc/portell -> ports-mgmt/portell
misc/portless -> ports-mgmt/portless
misc/tinderbox -> ports-mgmt/tinderbox
security/jailaudit -> ports-mgmt/jailaudit
security/portaudit -> ports-mgmt/portaudit
security/portaudit-db -> ports-mgmt/portaudit-db
security/vulnerability-test-port -> ports-mgmt/vulnerability-test-port (Only the first 15 lines of the commit message are shown above ) |
30 Jul 2005 20:13:10
0.2.3
|
simon  |
Change MAINTAINER address for ports maintained by the Security Team to
secteam@ instead of security@ to make it more clear that the ports are
not maintained by the freebsd-security@ mailing list. Both addresses
go to the same people. |
03 Jul 2005 21:46:48
0.2.3
|
simon  |
- Set maintainership to security@.
Suggested by: nectar, remko |
14 Jun 2005 23:04:55
0.2.3
|
simon  |
Grab maintainer-ship of portaudit. While I do not currently have any
plans for improvements (though I have ideas) I feel that portaudit is
too important to not have an active maintainer.
Approved by: portmgr (linimon) |
05 Jan 2005 10:51:21
0.2.3
|
thierry  |
Document Horde's XSS vulnerabilities.
Approved by: portmgr (krion). |
27 Oct 2004 13:25:06
0.2.3
|
nectar  |
Create a VuXML entry for Horde XSS help window vulnerability to replace
the portaudit-db entry. |
26 Oct 2004 20:37:44
0.2.3
|
thierry  |
Add an entry for a vulnerability fixed in horde-2.2.7. |
24 Oct 2004 15:46:52
0.2.3
|
lofi  |
Add entries for vulnerabilites in imported xpdf code in kdegraphics
and koffice. |
12 Oct 2004 06:25:06
0.2.3
|
thierry  |
Add an entry for a XSS vulnerability fixed in IMP-3.2.6. |
08 Sep 2004 22:57:10
0.2.3
|
eik  |
- star-devel: privilege escalation
- multi-gnome-terminal: information leak
- usermin: remote shell command injection and insecure installation
- mpg123: layer 2 decoder buffer overflow
Approved by: portmgr (implicit) |
07 Sep 2004 11:44:11
0.2.3
|
eik  |
- XSS vulnerability in phpGroupWare wiki module
- add some references
Approved by: portmgr (implicit) |
03 Sep 2004 23:30:35
0.2.3
|
eik  |
multiple vulnerabilities in LHA |
03 Sep 2004 22:36:18
0.2.3
|
eik  |
grrrr... left the test case intact |
03 Sep 2004 21:27:26
0.2.3
|
eik  |
- add some references
- extend ImageMagick entry
- squid ntlm authentication helper DoS
- multiple vpopmail vulnerabilities
- first attempts to check the base system for vulnerabilities:
+ cvs server code
+ zlib DoS
- BSD license portaudit.xml |
31 Aug 2004 00:43:44
0.2.3
|
eik  |
samba printer change notification request DoS |
30 Aug 2004 11:58:48
0.2.3
|
eik  |
add some references, add ru-gaim |
30 Aug 2004 11:57:42
0.2.3
|
eik  |
multiple vulnerabilities in gaim |
30 Aug 2004 11:07:22
0.2.3
|
eik  |
security bug in rscsi client code
Submitted by: marius |
27 Aug 2004 16:29:58
0.2.3
|
nectar  |
Document NSS SSLv2 server buffer overflow (already referenced in
portaudit.txt). |
27 Aug 2004 15:43:07
0.2.3
|
nectar  |
Document ripMIME decoding bug (already referenced in portaudit.txt). |
27 Aug 2004 11:34:05
0.2.3
|
eik  |
Argh. Duplicate entry for "Scorched 3D server chat box format string
vulnerabilty" |
27 Aug 2004 11:31:21
0.2.3
|
eik  |
Mozilla / NSS S/MIME DoS vulnerability & Scorched 3D server chat box format
string vulnerability |
26 Aug 2004 23:10:50
0.2.3
|
nectar  |
Note sanitize_path bug in rsync (already referenced in portaudit.txt). |
26 Aug 2004 21:34:41
0.2.3
|
nectar  |
Document buffer overflows in SoX (already referenced in portaudit.txt). |
26 Aug 2004 21:15:22
0.2.3
|
nectar  |
Document cookie bug in Konqueror (already referenced in portaudit.txt). |
25 Aug 2004 14:58:01
0.2.3
|
nectar  |
Remove libxine issue which is now documented in the FreeBSD VuXML
document.
Reminded by: eik |
25 Aug 2004 14:10:30
0.2.3
|
eik  |
nss library SSL remote buffer overflow |
25 Aug 2004 12:07:08
0.2.3
|
eik  |
multiple buffer overflows in xv |
24 Aug 2004 00:28:36
0.2.3
|
eik  |
Konqueror cross-domain cookie injection |
24 Aug 2004 00:12:02
0.2.3
|
eik  |
handle some duplicates |
21 Aug 2004 11:45:26
0.2.3
|
eik  |
a2ps: Possible execution of shell commands as local user. |
20 Aug 2004 09:31:09
0.2.3
|
eik  |
correct topic of eda0ade6-f281-11d8-81b0-000347a4fa7d |
20 Aug 2004 09:28:33
0.2.3
|
eik  |
QT 3.x BMP (and possibly other graphics formats) heap-based overflow |
18 Aug 2004 21:01:44
0.2.3
|
eik  |
potential security flaws in mod_ssl |
17 Aug 2004 08:56:37
0.2.3
|
eik  |
move a800386e-ef7e-11d8-81b0-000347a4fa7d to xml |
16 Aug 2004 13:23:39
0.2.3
|
eik  |
ruby CGI::Session insecure file creation |
16 Aug 2004 00:44:59
0.2.3
|
eik  |
multiple phpGroupWare vulnerabilities |
15 Aug 2004 18:22:09
0.2.3
|
eik  |
phpGedView, jftpgw |
13 Aug 2004 18:51:46
0.2.3
|
eik  |
apply xlist not to the own files |
13 Aug 2004 17:48:12
0.2.2
|
eik  |
fix some vuxml duplicates, add sympa unauthorized list creation |
12 Aug 2004 22:32:15
0.2.2
|
lofi  |
Add another entry for kdelibs3 due to another missed patch. |
12 Aug 2004 22:17:31
0.2.2
|
lofi  |
Correct entries for recent kde vuln's and add new entry for kdelibs
(3.2.3_3 didn't have all patches). |
12 Aug 2004 11:45:27
0.2.2
|
eik  |
fix security hole in non-chroot rsync daemon.
<http://www.freebsd.org/ports/portaudit/2689f4cb-ec4c-11d8-9440-000347a4fa7d.html> |
12 Aug 2004 01:08:06
0.2.2
|
eik  |
9fb5bb32-d6fa-11d8-b479-02e0185c0b53 is a duplicate of
40800696-c3b0-11d8-864c-02e0185c0b53 |
11 Aug 2004 23:57:51
0.2.2
|
eik  |
f72ccf7c-e607-11d8-9b0a-000347a4fa7d is a duplicate of
6f955451-ba54-11d8-b88c-000d610a3b12, move references |
11 Aug 2004 02:27:37
0.2.2
|
lofi  |
Factor out all but one of the build switches of the KDE main module ports
into separate ports. The OPTIONS will remain as of yet and trigger dependencies
now, for easy transition.
Update KOffice to version 1.3.2.
Add patches to fix a number of issues, including:
- fix kxkb on Xorg
- fix kdemultimedia WITH_MPEGLIB (now mpeglib_artsplug) compilation on gcc 3.4.2
with optimizations greater than -O
Add security related patches and entries to portaudit.txt. |
10 Aug 2004 09:50:27
0.2.2
|
eik  |
libine "vcd:" input source buffer overflow |
10 Aug 2004 01:56:37
0.2.2
|
eik  |
SpamAssassin DoS & cfengine authentication heap corruption |
07 Aug 2004 10:09:26
0.2.2
|
eik  |
CVStrac arbitrary remote code execution |
06 Aug 2004 13:37:01
0.2.2
|
eik  |
fold entry 7eded4b8-e6fe-11d8-b12f-0a001f31891a into
2de14f7a-dad9-11d8-b59a-00061bc2ad93 |
06 Aug 2004 06:41:01
0.2.2
|
dinoex  |
putty local command execution |
06 Aug 2004 00:35:33
0.2.2
|
eik  |
move abe47a5a-e23c-11d8-9b0a-000347a4fa7d to vuxml, add mozilla to the list of
vulnerable ports |
05 Aug 2004 17:45:52
0.2.2
|
nork  |
o Security Update to 2.2.10-ja-1.0.
o rcNG-ify obtained from net/samba3.
PR: ports/70034
Submitted by: NAKAJI Hiroyuki <nakaji@jp.freebsd.org> (maintainer) |
05 Aug 2004 16:36:32
0.2.2
|
eik  |
add Opera "location" object write access vulnerability |
05 Aug 2004 15:27:36
0.2.2
|
eik  |
move f9e3e60b-e650-11d8-9b0a-000347a4fa7d to vuxml, add mozilla to the list of
vulnerable ports |
05 Aug 2004 05:33:46
0.2.2
|
dinoex  |
back out last commit |
05 Aug 2004 05:31:41
0.2.2
|
dinoex  |
putty local command execution |
04 Aug 2004 21:14:28
0.2.2
|
eik  |
libPNG stack-based buffer overflow and other code concerns |
04 Aug 2004 12:43:15
0.2.2
|
eik  |
Acrobat Reader handling of malformed uuencoded pdf files |
04 Aug 2004 12:18:53
0.2.2
|
eik  |
Squid NTLM authentication helper overflow |
04 Aug 2004 12:10:43
0.2.2
|
eik  |
ripMIME attachment extraction bypass |
02 Aug 2004 18:54:10
0.2.2
|
eik  |
GnuTLS certificate chain verification DoS |
31 Jul 2004 16:00:41
0.2.2
|
eik  |
phpMyAdmin configuration manipulation and code injection |
30 Jul 2004 18:28:06
0.2.2
|
thierry  |
Register a vulnerability in mail/imp3.
This vulnerability only exists when using the Internet Explorer to
access IMP and only when using the inline MIME viewer for HTML messages. |
30 Jul 2004 16:28:22
0.2.2
|
eik  |
Mozilla Firefox certificate spoofing |
30 Jul 2004 11:00:44
0.2.2
|
eik  |
DansGuardian banned extension filter bypass vulnerability |
29 Jul 2004 09:15:20
0.2.2
|
eik  |
add a reference to the SoX buffer overflow entry |
28 Jul 2004 21:33:38
0.2.2
|
eik  |
SoX buffer overflows when handling .WAV files |
28 Jul 2004 10:34:18
0.2.2
|
eik  |
LCDProc buffer overflow/format string vulnerabilities |
27 Jul 2004 11:40:29
0.2.2
|
eik  |
pavuk digest auth buffer overflow |
27 Jul 2004 11:30:43
0.2.2
|
eik  |
add Nessus "adduser" race condition and Dropbear DSS verification bug |
22 Jul 2004 20:08:09
0.2.2
|
eik  |
l2tpd BSS-based buffer overflow |
22 Jul 2004 14:29:21
0.2.2
|
eik  |
phpBB cross site scripting vulnerabilities |
20 Jul 2004 16:48:58
0.2.2
|
eik  |
add subversion-perl, subversion-python |
20 Jul 2004 11:30:55
0.2.2
|
eik  |
subversion access control bypass |
18 Jul 2004 11:49:58
0.2.2
|
eik  |
mod_ssl format string vulnerability |
16 Jul 2004 08:39:25
0.2.2
|
eik  |
Roundup directory traversal |
14 Jul 2004 07:56:16
0.2.2
|
eik  |
wv library datetime field buffer overflow |
14 Jul 2004 00:47:33
0.2.2
|
eik  |
multiple vulnerabilities in Bugzilla |
11 Jul 2004 13:09:03
0.2.2
|
eik  |
correct vulnerable version of linux-png and add a reference |
11 Jul 2004 12:18:58
0.2.2
|
eik  |
libpng row buffer overflow |
09 Jul 2004 15:51:16
0.2.2
|
eik  |
add some references |
08 Jul 2004 15:24:07
0.2.2
|
eik  |
move e5e2883d-ceb9-11d8-8898-000d6111a684 to vuln.xml |
06 Jul 2004 15:52:44
0.2.2
|
eik  |
add some references |
06 Jul 2004 08:17:53
0.2.2
|
eik  |
MySQL versions < 4.1 seem to be unaffected
Reported by: Alexander Vasenin <blacksir@number.ru> |
05 Jul 2004 20:45:32
0.2.2
|
eik  |
add MySQL server authentication bypass / buffer overflow |
05 Jul 2004 16:30:35
0.2.2
|
eik  |
Mark 4aec9d58-ce7b-11d8-858d-000d610a3b12 as a duplicate of the
already existing c63936c1-caed-11d8-8898-000d6111a684. |
03 Jul 2004 07:48:34
0.2.2
|
trhodes  |
Move phpnuke vulnerabilities to VuXML. |
02 Jul 2004 01:48:56
0.2.2
|
eik  |
move "phpMyAdmin code injection" to vuxml |
01 Jul 2004 20:03:36
0.2.2
|
eik  |
phpMyAdmin code injection |
01 Jul 2004 00:39:00
0.2.2
|
eik  |
- SSLtelnet remote format string vulnerability
(guys, this is a public list)
- add some references |
29 Jun 2004 11:33:03
0.2.2
|
eik  |
add MIT Kerberos 5 krb5_aname_to_localname() buffer overflow |
29 Jun 2004 11:21:53
0.2.2
|
eik  |
add isakmpd security association deletion vulnerability |
28 Jun 2004 23:09:24
0.2.2
|
eik  |
add Apache input header folding DoS vulnerability |
28 Jun 2004 10:55:46
0.2.2
|
eik  |
xine-lib RTSP handling vulnerabilities |
28 Jun 2004 04:58:47
0.2.2
|
trhodes  |
Move MoinMoin entry to VuXML. |
28 Jun 2004 02:16:35
0.2.2
|
eik  |
diversify url conversion |
26 Jun 2004 01:40:17
0.2.2
|
eik  |
add portaudit2vuxml.pl to easy the migration of entries to VuXML |
25 Jun 2004 21:01:28
0.2.2
|
trhodes  |
Add an entry for recent isc-dhcp3-server buffer overflows.
Remove the one in portaudit.txt. |
25 Jun 2004 18:18:57
0.2.2
|
trhodes  |
Move giFT-FastTrack to VuXML. |