| Commit History - (may be incomplete: see CVSWeb link above for full details) |
| Date | By | Description |
12 Feb 2012 04:17:13
1.1_1
|
eadler  |
Inform users of the XSS issue in the latest version of WebCalendar.
It seems that there has been no response from the vendor
and users may want to switch to an alternate product that fits their needs. |
11 Feb 2012 18:17:27
1.1_1
|
wxs  |
Whitespace fixes. |
11 Feb 2012 10:50:39
1.1_1
|
beat  |
- Document mozilla -- use after free in nsXBLDocumentInfo::ReadPrototypeBindings |
11 Feb 2012 04:55:42
1.1_1
|
eadler  |
Inform bip users of buffer overflow (CVE-2012-0806) |
11 Feb 2012 01:27:56
1.1_1
|
eadler  |
Inform users of the private information disclosure bug in surf (CVE-2012-0842)
Reviewed by: dougb |
10 Feb 2012 10:26:07
1.1_1
|
jadawin  |
Fix style
Reported by: flo@ via irc |
10 Feb 2012 10:11:49
1.1_1
|
jadawin  |
Document last glpi vulnerabilities
Submitted by: Mathias Monnerville <mathias@monnerville.com> via email |
09 Feb 2012 12:48:48
1.1_1
|
rene  |
Document new Chromium < 17.0.963.46 vulnerabilities.
Obtained from:
http://googlechromereleases.blogspot.com/search/label/Stable%20updates
Security: fe1976c2-5317-11e1-9e99-00262d5ed8ee |
07 Feb 2012 23:11:21
1.1_1
|
delphij  |
Document Drupal core multiple vulnerabilities. |
07 Feb 2012 04:13:47
1.1_1
|
wxs  |
Fix up 3fd040be-4f0b-11e1-9e32-0025900931f by giving a better description. |
06 Feb 2012 12:01:22
1.1_1
|
skv  |
Document "bugzilla" - multiple vulnerabilities. |
04 Feb 2012 08:40:01
1.1_1
|
delphij  |
Document PHP remote code vulnerability. |
03 Feb 2012 06:33:03
1.1_1
|
rm  |
Add vuxml entry for mathopd directory traversal vulnerability.
PR: 164717
Submitted by: Michiel Boland <michiel at boland dot org>
Security: 6e7ad1d7-4e27-11e1-8e12-90e6ba8a36a2 |
02 Feb 2012 18:34:24
1.1_1
|
jgh  |
- adjust ordering for latest apache entry
Spotted by: remko |
02 Feb 2012 14:02:59
1.1_1
|
wxs  |
MITRE is spelled in all capital letters. |
02 Feb 2012 01:32:18
1.1_1
|
jgh  |
document latest Apache vulnerabilities
PR: ports/164675
Reviewed by: crees, eadler
Approved by: crees (mentor) |
01 Feb 2012 09:46:07
1.1_1
|
flo  |
document recent mozilla vulnerabilities |
31 Jan 2012 13:34:00
1.1_1
|
wxs  |
Correct versions for sudo format string vulnerability.
Noticed by: pluknet@ |
30 Jan 2012 16:36:43
1.1_1
|
wxs  |
Document sudo format string vulnerability. |
30 Jan 2012 03:03:39
1.1_1
|
wxs  |
Document missing FreeBSD Security Advisories:
- SA-11:01.mountd
- SA-11:04.compress
- SA-11:09.pam_ssh
- SA-11:10.pam
Modify existing entries to document (add/adjust modified tag for all):
- SA-11:06.bind
- Add FreeBSD package and freebsdsa
- SA-11:07.chroot
- Add FreeBSD package
- SA-11:08.telnetd
- Add FreeBSD package, freebsdsa and a relevant URL |
29 Jan 2012 23:39:42
1.1_1
|
zi  |
- Adjust formatting for 93688f8f-4935-11e1-89b4-001ec9578670 |
28 Jan 2012 13:30:39
1.1_1
|
zi  |
- Document vulnerabilities in mail/postfixadmin (CVE-2012-0811, CVE-2012-0812) |
28 Jan 2012 08:01:53
1.1_1
|
miwi  |
- Cleanup & Formating |
26 Jan 2012 12:32:02
1.1_1
|
zi  |
- Document vulnerability in converters/mpack |
26 Jan 2012 12:17:57
1.1_1
|
zi  |
- Document vulnerabilities in print/acroread9 (prior to 9.4.7) |
24 Jan 2012 11:02:34
1.1_1
|
rene  |
- update entry fixed in chromium-16.0.912.75 (CVE-2011-3925)
- add entry for vulnerabilities fixed in chromium-16.0.912.77
Security: CVE-2011-[3924-3928] |
24 Jan 2012 04:18:07
1.1_1
|
wxs  |
Fix build while chanting "I will run make validate". :(
Pointyhat to: wxs@ |
24 Jan 2012 04:01:02
1.1_1
|
wxs  |
Add CVE for recent spamdyke buffer overflows. |
23 Jan 2012 22:02:32
1.1_1
|
wxs  |
Document multiple vulnerabilities in wireshark, all of which have
already been fixed in our port. |
23 Jan 2012 21:26:01
1.1_1
|
wxs  |
Whitespace cleanup. |
23 Jan 2012 21:25:21
1.1_1
|
wxs  |
- Document buffer overflows in spamdyke. |
23 Jan 2012 14:08:34
1.1_1
|
wxs  |
Fixup to please "make tidy". No need to wrap this line. |
23 Jan 2012 13:52:39
1.1_1
|
wxs  |
- Add CVE for spamdyke STARTTLS plaintext injection. |
22 Jan 2012 14:59:21
1.1_1
|
sunpoet  |
- Fix affected rubygem-rack version: add ,3 as PORTEPOCH=3 is restored |
22 Jan 2012 02:49:22
1.1_1
|
zi  |
- Correct package range in 5c5f19ce-43af-11e1-89b4-001ec9578670
- Add databases/redis to the affected list for
91be81e7-3fea-11e1-afc7-2c4138874f7d |
21 Jan 2012 01:38:36
1.1_1
|
zi  |
- Fix formatting/topic in 91be81e7-3fea-11e1-afc7-2c4138874f7d
Reviewed by: wxs |
20 Jan 2012 21:43:40
1.1_1
|
zi  |
- Document security vulnerability in security/openssl (CVE-2012-0050) |
20 Jan 2012 19:24:00
1.1_1
|
jgh  |
fix uuid on latest tomcat vulnerability
Approved by: crees, rene (implicit) |
20 Jan 2012 18:41:16
1.1_1
|
delphij  |
- Fix modified date;
- Add more ruby variants. |
20 Jan 2012 18:28:10
1.1_1
|
delphij  |
Update 91be81e7-3fea-11e1-afc7-2c4138874f7d to cover ruby+no-pthreads as
well.
Spotted by: Kevin Oberman <kob6558 gmail.com> |
20 Jan 2012 00:14:42
1.1_1
|
flo  |
- document asterisk remote crash vulnerability |
19 Jan 2012 19:51:53
1.1_1
|
jgh  |
Document recent vulnerability of Apache Tomcat Server.
Approved by: rene (mentor) |
19 Jan 2012 18:33:42
1.1_1
|
delphij  |
Sigh, should have used <lt> instead of <gt>.
Pointy hat to: delphij |
19 Jan 2012 18:27:36
1.1_1
|
delphij  |
php52-exif no longer vulnerable to CVE-2011-4566 as of 5.2.17_6 |
19 Jan 2012 09:16:00
1.1_1
|
knu  |
Fix the version range for ruby. The stock version is affected. |
19 Jan 2012 09:13:30
1.1_1
|
knu  |
There was no patch release in rubygem-rack 1.3.5_*, so just say < 1.3.6. |
19 Jan 2012 07:32:11
1.1_1
|
sunpoet  |
- Fix affected rubygem-rack version: it should be _3 for PORTREVISION=3 |
17 Jan 2012 09:53:13
1.1_1
|
danfe  |
Fix CVE URL in recent OpenTTD entry. |
17 Jan 2012 08:36:56
1.1_1
|
danfe  |
Unexpand (convert leading spaces to tabs when possible). |
17 Jan 2012 08:31:38
1.1_1
|
danfe  |
Document recent vulnerability of OpenTTD game server.
Reported by: Ilya Arkhipov |
16 Jan 2012 09:57:28
1.1_1
|
knu  |
PHP5 had its own entry for this vulnerability, so remove this.
Pointed out by: ohauer |
16 Jan 2012 03:23:44
1.1_1
|
knu  |
Add node < 0.6.7 (for V8). |
16 Jan 2012 03:20:39
1.1_1
|
knu  |
Add v8 < 3.8.5 (CVE-2011-5037). |
16 Jan 2012 03:16:01
1.1_1
|
knu  |
Add PHP < 5.3.9 (CVE-2011-4885). |
16 Jan 2012 03:03:49
1.1_1
|
knu  |
Add Multiple implementations denial-of-service via hash algorithm collision.
Currently only JRuby, Ruby, and Rack are mentioned. More to follow. |
14 Jan 2012 10:01:38
1.1_1
|
mm  |
Add missing URL reference to last commit |
14 Jan 2012 09:46:31
1.1_1
|
mm  |
Add relevant FFmpeg vulnerabilities from Ubuntu USN-1320-1 |
14 Jan 2012 04:36:22
1.1_1
|
miwi  |
- clean up |
14 Jan 2012 02:47:41
1.1_1
|
zi  |
- Document vulnerabilities in security/openssl
-- CVE-2011-4108, CVE-2011-4109, CVE-2011-4576
-- CVE-2011-4577, CVE-2011-4619, CVE-2012-0027 |
13 Jan 2012 12:10:37
1.1_1
|
zi  |
- Document vulnerability in net/isc-dhcp42-server (CVE-2011-4868) |
12 Jan 2012 21:56:20
1.1_1
|
delphij  |
Document PowerDNS DoS vulnerability.
PR: ports/164066
Submitted by: Ralf van der Enden <tremere cainites.net> |
11 Jan 2012 18:32:21
1.1_1
|
delphij  |
Document PHP multiple vulnerabilities. |
09 Jan 2012 18:13:37
1.1_1
|
rene  |
Document a untrusted local library exploit in games/torcs.
Security: CVE-2010-3384 |
09 Jan 2012 02:26:53
1.1_1
|
wxs  |
Document spamdyke STARTTLS plaintext injection vulnerability. |
07 Jan 2012 23:44:17
1.1_1
|
simon  |
Remove HTML entity from a VuXML entry as they are not allowed in
VuXML, only Unicode charecter entities are allowed.
This should fix the portaudit build.
If anyone care enough to insert the correct umlaut, feel free to fix. |
06 Jan 2012 18:35:42
1.1_1
|
rene  |
Add new vulnerabilities for www/chromium.
Security: CVE-2011-[3919,3921-3922] |
05 Jan 2012 18:52:28
1.1_1
|
delphij  |
Fix build. |
05 Jan 2012 17:29:25
1.1_1
|
ohauer  |
- document bugzilla and bugzilla3 security issues |
03 Jan 2012 23:50:36
1.1_1
|
delphij  |
Document wordpress xss vulnerability.
Feature safe: yes |
30 Dec 2011 01:05:34
1.1_1
|
cy  |
Add additional MITKRB5 reference.
Security: MITKRB5-SA-2011-008
Feature safe: yes |
29 Dec 2011 14:26:25
1.1_1
|
remko  |
Fix build by adding a reference to the original URL. |
29 Dec 2011 13:04:24
1.1_1
|
crees  |
Document XSS vulnerability in net-mgmt/zabbix-frontend
PR: ports/163691
Obtained from: https://support.zabbix.com/browse/ZBX-4015
Security: ZBX-4015 |
28 Dec 2011 12:24:32
1.1_1
|
mm  |
Document remote DoS vulnerability in lighttpd HTTP authentication
Security: CVS-2011-4362 |
27 Dec 2011 04:00:15
1.1_1
|
eadler  |
- Fix most of the duplicate words in vuxml, a few affect 'blockquotes' but that
should be okay as no information is lost. |
26 Dec 2011 23:23:29
1.1_1
|
wxs  |
Don't wrap a couple of lines. No other entries wrap these lines, so when
in Rome... |
26 Dec 2011 23:00:58
1.1_1
|
wxs  |
Whitespace cleanup in a BIND topic. |
26 Dec 2011 22:42:26
1.1_1
|
wxs  |
Fix the build. Missing a quote on the blockquote citation and a missing </p>. |
26 Dec 2011 21:51:03
1.1_1
|
cy  |
Document CVE-2011-4862 (FreeBSD-SA-11:08.telnetd) as it affects krb5-appl too.
Security: CVE-2011-4862, FreeBSD-SA-11:08.telnetd
Feature safe: yes |
23 Dec 2011 20:37:32
1.1_1
|
delphij  |
Add vuxml entry for proftpd chroot vulnerability.
Feature safe: yes |
22 Dec 2011 12:11:17
1.1_1
|
zi  |
- Document recent vulnerabilities in databases/phpmyadmin (PMASA-2011-19 and
PMASA-2011-20) |
21 Dec 2011 12:40:43
1.1_1
|
beat  |
- Also fix SeaMonkey version range |
21 Dec 2011 11:28:37
1.1_1
|
beat  |
- Fix cvename in latest mozilla vulnerability |
21 Dec 2011 07:48:50
1.1_1
|
beat  |
- Document mozilla -- multiple vulnerabilities |
19 Dec 2011 13:15:50
1.1_1
|
sem  |
unbound DoS vulnerability |
18 Dec 2011 14:24:38
1.1_1
|
miwi  |
- Cleanup
* correct line limit
* sort cvename |
18 Dec 2011 13:30:50
1.1_1
|
zi  |
- Correct package name in previous commit
Reported by: crees@ |
18 Dec 2011 13:07:02
1.1_1
|
zi  |
- Document vulnerabilities in www/typo3 and www/typo345 |
14 Dec 2011 04:07:06
1.1_1
|
zi  |
- Document security/krb5 vulnerability as described in MITKRB5-SA-2011-007 |
14 Dec 2011 03:52:28
1.1_1
|
zi  |
- Add CVE for recent asterisk vulnerabilities
Feature safe: yes |
13 Dec 2011 20:35:32
1.1_1
|
delphij  |
Document Opera multiple vulnerabilities.
Requested by: tabthorpe
Feature safe: yes |
13 Dec 2011 20:17:29
1.1_1
|
rene  |
Document vulnerabilities fixed in Chromium 16.0.912.63
Security: CVE-2011-[3903-3917] |
13 Dec 2011 17:45:46
1.1_1
|
mandree  |
Add cvename tag with content CVE-2011-4607 for PuTTY password 'vulnerability'.
Feature safe: yes
Submitted by: eadler |
13 Dec 2011 17:34:52
1.1_1
|
zi  |
- Correct package name for asterisk18
Feature safe: yes |
12 Dec 2011 19:57:18
1.1_1
|
mandree  |
Update PuTTY to new upstream security and bug fix release 0.62,
and add a new VuXML entry.
Changelog:
http://lists.tartarus.org/pipermail/putty-announce/2011/000017.html
Security: bbd5f486-24f1-11e1-95bc-080027ef73ec
Feature safe: yes |
09 Dec 2011 01:52:43
1.1_1
|
zi  |
- Document asterisk vulnerabilities
Feature safe: yes |
07 Dec 2011 23:49:09
1.1_1
|
zi  |
- Document vulnerabilities in isc-dhcp: CVE-2011-4539
Feature safe: yes |
01 Dec 2011 21:03:31
1.1_1
|
dougb  |
Update to version 3.4.8
This is the formal release of the fix to CVE-2011-4634, but there are
no code differences from the preliminary fixes released in 3.4.8-rc1
except for the updated version number.
PMSA-2011-18 has now been published; vuxml entry attached.
PR: ports/163001
Submitted by: Matthew Seaman <m.seaman@infracaninophile.co.uk> (maintainer)
Feature safe: yes |
30 Nov 2011 09:31:36
1.1_1
|
pav  |
- Add a link to a nice documentation in PH
Suggested by: dougb
Feature safe: yes |
30 Nov 2011 08:45:12
1.1_1
|
pav  |
- Add a quick guide to adding a new entry to this unfriendly file
Feature safe: yes |
19 Nov 2011 15:13:49
1.1_1
|
dinoex  |
- mark 1.3.41+2.8.31_4 as not vulnerable
Feature safe: yes |