notbugAs an Amazon Associate I earn from qualifying purchases.
Want a good read? Try FreeBSD Mastery: Jails (IT Mastery Book 15)
Want a good monitor light? See my photosAll times are UTC
Ukraine
This referral link gives you 10% off a Fastmail.com account and gives me a discount on my Fastmail account.

Get notified when packages are built

A new feature has been added. FreshPorts already tracks package built by the FreeBSD project. This information is displayed on each port page. You can now get an email when FreshPorts notices a new package is available for something on one of your watch lists. However, you must opt into that. Click on Report Subscriptions on the right, and New Package Notification box, and click on Update.

Finally, under Watch Lists, click on ABI Package Subscriptions to select your ABI (e.g. FreeBSD:14:amd64) & package set (latest/quarterly) combination for a given watch list. This is what FreshPorts will look for.

Port details
vuxml Vulnerability and eXposure Markup Language DTD
1.1_6 security on this many watch lists=31 search for ports that depend on this port Find issues related to this port Report an issue related to this port View this port on Repology. pkg-fallout 1.1_6Version of this port present on the latest quarterly branch.
Maintainer: ports-secteam@FreeBSD.org search for ports maintained by this maintainer
Port Added: 2004-02-12 14:24:23
Last Update: 2024-04-25 11:16:00
Commit Hash: 539ca10
People watching this port, also watch:: gnupg, curl, libxml2, nmap, vim
Also Listed In: textproc
License: BSD2CLAUSE
WWW:
https://vuxml.freebsd.org/
Description:
VuXML (the Vulnerability and eXposure Markup Language) is an XML application for documenting security bugs and corrections within a software package collection such as the FreeBSD Ports Collection. This port installs the DTDs required for validating VuXML documents.
Homepage    cgit ¦ Codeberg ¦ GitHub ¦ GitLab ¦ SVNWeb

Manual pages:
FreshPorts has no man page information for this port.
pkg-plist: as obtained via: make generate-plist
Expand this list (13 items)
Collapse this list.
  1. /usr/local/share/licenses/vuxml-1.1_6/catalog.mk
  2. /usr/local/share/licenses/vuxml-1.1_6/LICENSE
  3. /usr/local/share/licenses/vuxml-1.1_6/BSD2CLAUSE
  4. @xmlcatmgr share/xml/dtd/vuxml/catalog
  5. @xmlcatmgr share/xml/dtd/vuxml/catalog.xml
  6. share/xml/dtd/vuxml/vuxml-10.dtd
  7. share/xml/dtd/vuxml/vuxml-11.dtd
  8. share/xml/dtd/vuxml/vuxml-model-10.mod
  9. share/xml/dtd/vuxml/vuxml-model-11.mod
  10. share/xml/dtd/vuxml/xml1.dcl
  11. @owner
  12. @group
  13. @mode
Collapse this list.
Dependency lines:
  • vuxml>0:security/vuxml
To install the port:
cd /usr/ports/security/vuxml/ && make install clean
To add the package, run one of these commands:
  • pkg install security/vuxml
  • pkg install vuxml
NOTE: If this package has multiple flavors (see below), then use one of them instead of the name specified above.
PKGNAME: vuxml
Flavors: there is no flavor information for this port.
distinfo:
SHA256 (vuxml/vuxml-10.dtd) = 6a635ad2cf45f52361c8c2a29a689157fad4d00519045485bc822d34e04a524e SIZE (vuxml/vuxml-10.dtd) = 2986 SHA256 (vuxml/vuxml-model-10.mod) = 051fed00b52bedde8ee901003fc29f7b95cd904157e31ceef34e6b06f2d1a14a

Expand this list (11 items)

Collapse this list.

SIZE (vuxml/vuxml-model-10.mod) = 10599 SHA256 (vuxml/vuxml-11.dtd) = 12b50061d7bb34cecffede2e08d439e4469324376d55aeb7c73eb6aab0f36af1 SIZE (vuxml/vuxml-11.dtd) = 3063 SHA256 (vuxml/vuxml-model-11.mod) = a40777208625a3029c6f416aeeea733f614802a6a5f26035a4e445a09e61a47c SIZE (vuxml/vuxml-model-11.mod) = 13282 SHA256 (vuxml/xml1.dcl) = 343efa94c4e1302e85e08b2d1791d86e50aac1ecdbc3161daecac100e4726847 SIZE (vuxml/xml1.dcl) = 7372 SHA256 (vuxml/catalog) = 479a69cf02995603443fd1f3b5b33f97811670931f87f53be99a727d664abc66 SIZE (vuxml/catalog) = 549 SHA256 (vuxml/catalog.xml) = 7b2e2850f57264eeba0ccd3d1fc161b9d5ce3071ae0ec51b9da7fa956f2a6509 SIZE (vuxml/catalog.xml) = 2150

Collapse this list.


Packages (timestamps in pop-ups are UTC):
vuxml
ABIaarch64amd64armv6armv7i386powerpcpowerpc64powerpc64le
FreeBSD:13:latest1.1_61.1_61.1_51.1_61.1_6-1.1_5-
FreeBSD:13:quarterly1.1_61.1_61.1_61.1_61.1_61.1_61.1_61.1_6
FreeBSD:14:latest1.1_61.1_61.1_61.1_61.1_61.1_6-1.1_6
FreeBSD:14:quarterly1.1_61.1_6-1.1_61.1_61.1_61.1_61.1_6
FreeBSD:15:latest1.1_61.1_6n/a1.1_6n/a1.1_61.1_61.1_6
FreeBSD:15:quarterly--n/a-n/a---
Dependencies
NOTE: FreshPorts displays only information on required and default dependencies. Optional dependencies are not covered.
Runtime dependencies:
  1. xmlcatmgr : textproc/xmlcatmgr
  2. xsltproc : textproc/libxslt
  3. VERSION : textproc/xhtml-modularization
  4. xhtml-basic10.dtd : textproc/xhtml-basic
  5. python3.9 : lang/python39
There are no ports dependent upon this port

Configuration Options:
No options to configure
Options name:
security_vuxml
USES:
python:run
FreshPorts was unable to extract/find any pkg message
Master Sites:
Expand this list (1 items)
Collapse this list.
  1. http://www.vuxml.org/dtd/vuxml-1/
Collapse this list.

Number of commits found: 7243 (showing only 100 on this page)

[First Page]  «  37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47  »  [Last Page]

Commit History - (may be incomplete: for full details, see links to repositories near top of page)
CommitCreditsLog message
1.1_1
25 Jul 2013 18:29:27
Revision:323659Original commit files touched by this commit
bjk (doc committer) search for other commits by this committer
Update to 1.6.5

This is a security release by upstream, and requires configuration changes
in addition to the software update.  See UPDATING.

Reviewed by:	ports-security (zi, remko)
Approved by:	hrs (mentor, ports committer)
1.1_1
24 Jul 2013 20:59:28
Revision:323617Original commit files touched by this commit
lev search for other commits by this committer
  Add <url></url> to references.

Submitted by:	Remko Lodder <remko@FreeBSD.org>
1.1_1
24 Jul 2013 17:18:50
Revision:323611Original commit files touched by this commit
lev search for other commits by this committer
 Update:
   devel/subversion to 1.8.1
   devel/subversion16 to 1.7.11

 These releases fix CVE-2013-4131
 http://subversion.apache.org/security/CVE-2013-4131-advisory.txt

Approved by:	Olli Hauer <ohauer@FreeBSD.org> for devel/subversion17
Security:	CVE-2013-4131
1.1_1
23 Jul 2013 10:32:23
Revision:323525Original commit files touched by this commit
bdrewery search for other commits by this committer
- Update whitespace for 2fbfd455-f2d0-11e2-8a46-000d601460a4

Requested by:	remko
1.1_1
22 Jul 2013 13:24:05
Revision:323445Original commit files touched by this commit
bdrewery search for other commits by this committer
- Update suPHP to 0.7.2
- Document possible privilege escalation

Approved by:	maintainer timeout
Security:	2fbfd455-f2d0-11e2-8a46-000d601460a4
1.1_1
21 Jul 2013 18:54:51
Revision:323410Original commit files touched by this commit
ohauer search for other commits by this committer
- change apache24 version from 2.4.5 to 2.4.6 (2.4.5 was not released)
- add http://www.apache.org/dist/httpd/Announcement2.4.html as reference

requested by remko@
1.1_1
20 Jul 2013 17:11:54
Revision:323351Original commit files touched by this commit
ohauer search for other commits by this committer
- update to apache24-2.4.6
 - new modules: mod_cache_socache, mod_macro and mod_proxy_wstunnel

- add enty to vuxml

SECURITY: CVE-2013-1896 (cve.mitre.org)
 mod_dav: Sending a MERGE request against a URI handled by mod_dav_svn with
 the source href (sent as part of the request body as XML) pointing to a
 URI that is not configured for DAV will trigger a segfault.

SECURITY: CVE-2013-2249 (cve.mitre.org)
 mod_session_dbd: Make sure that dirty flag is respected when saving
 sessions, and ensure the session ID is changed each time the session
 changes. This changes the format of the updatesession SQL statement.
 Existing configurations must be changed.

Changelog:
http://www.apache.org/dist/httpd/CHANGES_2.4.6

with hat apache@

Security:	ca4d63fb-f15c-11e2-b183-20cf30e32f6d
1.1_1
17 Jul 2013 22:09:58
Revision:323190Original commit files touched by this commit
delphij search for other commits by this committer
Document gallery3 multiple vulnerabilities.
1.1_1
17 Jul 2013 22:07:22
Revision:323189Original commit files touched by this commit
eadler search for other commits by this committer
Add missing citation

Requested by:	remko
1.1_1
16 Jul 2013 18:10:12
Revision:323118Original commit files touched by this commit
des search for other commits by this committer
Add two more PHP entries for issues which have already been fixed.
1.1_1
15 Jul 2013 21:06:36
Revision:323080Original commit files touched by this commit
eadler search for other commits by this committer
Update to 11.2r202.291

PR:		ports/179502
Submitted by:	Tsurutani Naoki <turutani@scphys.kyoto-u.ac.jp>
1.1_1
15 Jul 2013 18:25:19
Revision:323071Original commit files touched by this commit
delphij search for other commits by this committer
Document squid 3.x denial of service vulnerability.
1.1_1
15 Jul 2013 09:26:37
Revision:323026Original commit files touched by this commit
cs search for other commits by this committer
Adjust version numbers for OTRS vulnerabilities
1.1_1
14 Jul 2013 22:03:55
Revision:323009Original commit files touched by this commit
eadler search for other commits by this committer
Add missing modified dates from r321329.

I had this sitting for a bit, but forgot to test & commit.

Requested by:	remko
1.1_1
11 Jul 2013 21:28:39
Revision:322798Original commit files touched by this commit
delphij search for other commits by this committer
Wrap long lines.  No content change.
1.1_1
11 Jul 2013 20:35:20
Revision:322797Original commit files touched by this commit
cs search for other commits by this committer
Security vulnerabilities in libzrtp

Security:	04320e7d-ea66-11e2-a96e-60a44c524f57
1.1_1
11 Jul 2013 20:17:34
Revision:322795Original commit files touched by this commit
swills search for other commits by this committer
- Document ruby vulnerability
1.1_1
11 Jul 2013 07:50:27
Revision:322757Original commit files touched by this commit
cs search for other commits by this committer
Add vulnerability on otrs

Security:	e3e788aa-e9fd-11e2-a96e-60a44c524f57
1.1_1
10 Jul 2013 19:01:44
Revision:322728Original commit files touched by this commit
ohauer search for other commits by this committer
- update to apache-2.2.25
- update vuxml with additional CVE-2013-1896 entry

Changes with Apache 2.2.25
  http://www.apache.org/dist/httpd/CHANGES_2.2.25

  *) SECURITY: CVE-2013-1896 (cve.mitre.org)
     mod_dav: Sending a MERGE request against a URI handled by mod_dav_svn with
     the source href (sent as part of the request body as XML) pointing to a
     URI that is not configured for DAV will trigger a segfault. [Ben Reser
     <ben reser.org>]

  *) SECURITY: CVE-2013-1862 (cve.mitre.org)
     mod_rewrite: Ensure that client data written to the RewriteLog is
     escaped to prevent terminal escape sequences from entering the
(Only the first 15 lines of the commit message are shown above View all of this commit message)
1.1_1
10 Jul 2013 14:35:58
Revision:322699Original commit files touched by this commit
rene search for other commits by this committer
Add new vulnerabilities for www/chromium < 28.0.1500.71

Obtained from:	http://googlechromereleases.blogspot.nl/
1.1_1
06 Jul 2013 08:46:40
Revision:322368Original commit files touched by this commit
ohauer search for other commits by this committer
- add fix for CVE-2013-1862
- adjust vuxml
1.1_1
05 Jul 2013 21:06:16
Revision:322357Original commit files touched by this commit
ohauer search for other commits by this committer
- document apache22 CVE-2013-1862 (mod_rewrite)

Update to apache22-2.2.25 is ready to commit.
Until now there is no official announcement from apache.org
so we hold the update back until we have official checksums.
1.1_1
02 Jul 2013 07:43:03
Revision:322159Original commit files touched by this commit
delphij search for other commits by this committer
Fix CVE-2013-2174 for ftp/curl with a patch from vendor for
now so that users can build the port, per popular demands
on mailing list.

The upgrade patch found in ports/172325 is currently under
exp-run.  The changes in this commit against ftp/curl can be
safely reverted before applying that patch, as it's shipped
with new curl release.

Approved by:	portmgr (miwi)
1.1_1
30 Jun 2013 20:49:33
Revision:322099Original commit files touched by this commit
matthew search for other commits by this committer
Security update to 4.0.4.1

ChangeLog:
http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/4.0.4.1/phpMyAdmin-4.0.4.1-notes.html/view

Advisory: http://www.phpmyadmin.net/home_page/security/PMASA-2013-7.php

Security:	1b93f6fe-e1c1-11e2-948d-6805ca0b3d42
1.1_1
28 Jun 2013 11:07:49
Revision:321955Original commit files touched by this commit
girgen search for other commits by this committer
Security update for apache-xml-security-c

URL:	http://santuario.apache.org/secadv.data/CVE-2013-2210.txt
Security:	81da673e-dfe1-11e2-9389-08002798f6ff
Security:	CVE-2013-2210
1.1_1
26 Jun 2013 11:01:35
Revision:321792Original commit files touched by this commit
flo search for other commits by this committer
- update firefox to 22.0
- update firefox-esr, thunderbird and libxul to 17.0.7
- update nspr to 4.10
- OSS support was removed upstream, only ALSA and PulseAudio are supported
  from now on.

Security:	b3fcb387-de4b-11e2-b1c6-0025905a4771
In collaboration with:	Jan Beich <jbeich@tormail.org>
1.1_1
23 Jun 2013 20:14:01
Revision:321649Original commit files touched by this commit
rea search for other commits by this committer
VuXML: document CVE-2013-2174, heap corruption in cURL library
1.1_1
22 Jun 2013 12:49:29
Revision:321570Original commit files touched by this commit
swills search for other commits by this committer
- Update puppet to 3.2.2 which fixes CVE-2013-3567 [1]
- Update puppet27 to 2.7.22 which fixes CVE-2013-3567
- Document security issue

PR:		ports/179816 [1]
Submitted by:	mat [1]
Security:	b162b218-c547-4ba2-ae31-6fdcb61bc763
1.1_1
22 Jun 2013 09:36:10
Revision:321558Original commit files touched by this commit
bf search for other commits by this committer
Correct the CVE-2013-0131 entry, so that the most recent revision of
x11/nvidia-driver-304 is not mistakenly flagged as vulnerable
1.1_1
19 Jun 2013 21:56:57
Revision:321338Original commit files touched by this commit
jgh search for other commits by this committer
- fix formating of 8b97d289-d8cf-11e2-a1f5-60a44c524f57

With Hat:	ports-secteam
1.1_1
19 Jun 2013 21:20:50
Revision:321330Original commit files touched by this commit
eadler search for other commits by this committer
Add extra-validation to the validation target.

While here, test with python2 and permit the script to run with either 2 or 3.

Requested by:	delphij
With Hat:	ports-secteam
1.1_1
19 Jun 2013 21:14:51
Revision:321329Original commit files touched by this commit
eadler search for other commits by this committer
- Fix entry dates for some 'insane' dates.  In some cases a best effort was made
to guess what was meant due to either destroyed svn logs (formatting 'fixes') or
lost to time reports.

With Hat:	ports-secteam
1.1_1
19 Jun 2013 20:46:23
Revision:321322Original commit files touched by this commit
eadler search for other commits by this committer
Add an additional validation script to the vuxml port.
At this point it is not tied to the validate: target because validation fails.

Reviewed by:	simon, delphij
With Hat:	ports-secteam
1.1_1
19 Jun 2013 11:08:02
Revision:321237Original commit files touched by this commit
cs search for other commits by this committer
Fix typo soccat -> socat
1.1_1
19 Jun 2013 11:07:36
Revision:321236Original commit files touched by this commit
cs search for other commits by this committer
Add vulnerability on OTRS
1.1_1
18 Jun 2013 15:50:05
Revision:321198Original commit files touched by this commit
delphij search for other commits by this committer
Fix date for flashpluginwrapper.
1.1_1
18 Jun 2013 15:45:03
Revision:321196Original commit files touched by this commit
delphij search for other commits by this committer
Add entry for SA-13:06.mmap.
1.1_1
18 Jun 2013 15:15:48
Revision:321194Original commit files touched by this commit
girgen search for other commits by this committer
Security update for apache-xml-security-c.
Dependant ports, especially shibboleth2-sp, opensaml2, xmltooling
and log4shib should all be updated.

Security: CVE-2013-2156
1.1_1
17 Jun 2013 03:23:53
Revision:321084Original commit files touched by this commit
bf search for other commits by this committer
Document Tor bug 9072
1.1_1
14 Jun 2013 06:21:14
Revision:320884Original commit files touched by this commit
ak search for other commits by this committer
- Fix typo in dbus entry

Reported by:	Christoph Mallon <christoph.mallon@gmx.de>
1.1_1
13 Jun 2013 19:54:25
Revision:320834Original commit files touched by this commit
kwm search for other commits by this committer
Update to 1.6.12.

I'm not completly sure this affects us, but beter safe then sorry.
While here wordsmith Options description to try to make it clearer.

Security:	CVE-2013-2168
1.1_1
11 Jun 2013 22:44:39
Revision:320654Original commit files touched by this commit
eadler search for other commits by this committer
Update to 11.2r202.291

PR:		ports/179502
Submitted by:	Tsurutani Naoki <turutani@scphys.kyoto-u.ac.jp>
1.1_1
11 Jun 2013 21:03:38
Revision:320642Original commit files touched by this commit
culot search for other commits by this committer
- Document vulnerabilities in www/owncloud

Security:	d7a43ee6-d2d5-11e2-9894-002590082ac6
Obtained from:	http://owncloud.org/about/security/advisories/
1.1_1
07 Jun 2013 15:19:27
Revision:320210Original commit files touched by this commit
flo search for other commits by this committer
Update to 5.3.26

Security:	59e7163c-cf84-11e2-907b-0025905a4770
1.1_1
07 Jun 2013 06:30:39
Revision:320151Original commit files touched by this commit
erwin search for other commits by this committer
Match only the most recent Bind9* version in the latest vulnerability,
older versions are not affected.
1.1_1
06 Jun 2013 10:59:35
Revision:320080Original commit files touched by this commit
erwin search for other commits by this committer
Fix typo in previous revision.
1.1_1
06 Jun 2013 08:36:34
Revision:320060Original commit files touched by this commit
erwin search for other commits by this committer
Add entry for the latest Bind vulnerabilities in CVE-2013-3919.
1.1_1
05 Jun 2013 22:02:14
Revision:320032Original commit files touched by this commit
matthew search for other commits by this committer
Security upgrade to 4.0.3

Advisory: http://www.phpmyadmin.net/home_page/security/PMASA-2013-6.php

ChangeLog:
http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/4.0.3/phpMyAdmin-4.0.3-notes.html/view

Security:	6b97436c-ce1e-11e2-9cb2-6805ca0b3d42
1.1_1
05 Jun 2013 09:02:47
Revision:319965Original commit files touched by this commit
kwm search for other commits by this committer
Update to 0.16.6.

Obtained from:	GNOME dev repo
Security:	CVE-2013-1431
1.1_1
04 Jun 2013 22:30:28
Revision:319933Original commit files touched by this commit
rene search for other commits by this committer
Document vulnerabilities in www/chromium < 27.0.1453.110

Obtained from:	http://googlechromereleases.blogspot.nl/
1.1_1
04 Jun 2013 21:52:40
Revision:319919Original commit files touched by this commit
eadler search for other commits by this committer
- Fix build
- Ensure validation
1.1_1
04 Jun 2013 19:31:30
Revision:319899Original commit files touched by this commit
zeising search for other commits by this committer
Fix security issues in xorg client libraries.
Most libraries were updated to newer versions, in some cases patches
were backported instead.

Most notably, x11/libX11 was updated to 1.6.0

Security:	CVE-2013-1981
		CVE-2013-1982
		CVE-2013-1983
		CVE-2013-1984
		CVE-2013-1985
		CVE-2013-1986
		CVE-2013-1987
		CVE-2013-1988
		CVE-2013-1989
(Only the first 15 lines of the commit message are shown above View all of this commit message)
1.1_1
04 Jun 2013 04:45:23
Revision:319823Original commit files touched by this commit
cy search for other commits by this committer
Update krb5 1.11.2 --> 1.11.3.

This is a bugfix release.

* Fix a UDP ping-pong vulnerability in the kpasswd (password changing)
  service.  [CVE-2002-2443]

* Improve interoperability with some Windows native PKINIT clients.

Security:	CVE-2002-2443
1.1_1
03 Jun 2013 18:29:51
Revision:319798Original commit files touched by this commit
crees search for other commits by this committer
Update to 1.6.2

* Fix buffer overflows in fileserver and ptserver.
* Fix rare file corruption during background sync (Gerrit 8796).
* Fix corrupting clients' metadata cache during certain errors (Gerrit 6957).
* Fix cache corruption when reading from a file another client is simultaneously
writing to (Gerrit 7994).
* Fix fileservers to properly report >2 TiB partitions.

and some other less serious changes.

PR:		ports/179259
Submitted by:	Adam Nowacki <nowak@tepeserwery.pl>
Submitted by:	bjk (maintainer)
Security:	CVE-2013-1794
1.1_1
03 Jun 2013 06:51:43
Revision:319757Original commit files touched by this commit
araujo search for other commits by this committer
- Update to 2.7.4.

More info:
https://github.com/SpiderLabs/ModSecurity/blob/master/CHANGES

PR:		ports/179167
Submitted by:	ohauer@
Security:	9dfb63b8-8f36-11e2-b34d-000c2957946c
1.1_1
01 Jun 2013 19:22:39
Revision:319586Original commit files touched by this commit
rakuco search for other commits by this committer
Remove duplicate optipng vulnerability.

It was separately committed in r315254, so remove the version I added
in r318453.

Reported by:	Alexander Milanov <a@amilanov.com>
1.1_1
01 Jun 2013 16:49:14
Revision:319581Original commit files touched by this commit
mandree search for other commits by this committer
Add two more URLs to openvpn's vulnerability from March 2013 (CVE-2013-2061)

Security: 92f30415-9935-11e2-ad4c-080027ef73ec
1.1_1
01 Jun 2013 16:47:41
Revision:319579Original commit files touched by this commit
mandree search for other commits by this committer
- Backport fix for CVE-2013-2061 to openvpn22 and openvpn20;
  while it is unclear whether it affects OpenSSL-builds at all.
  Let's play it safe.
- Reference CVE-2013-2061 name in OpenVPN's VuXML entry
- Mark 2.0.9_4 <= openvpn < 2.1.0 and 2.2.2_2 < openvpn < 2.3.0 not vulnerable
- Mark openvpn22 deprecated and to expire 2013-09-01.
  (openvpn20 is already marked to expire 2013-07-11.)

Security:	CVE-2013-2061
Security:	92f30415-9935-11e2-ad4c-080027ef73ec
1.1_1
01 Jun 2013 08:08:56
Revision:319558Original commit files touched by this commit
osa search for other commits by this committer
Document passenger vulnerability.
1.1_1
31 May 2013 21:41:56
Revision:319544Original commit files touched by this commit
lev search for other commits by this committer
  Update subversion ports to 1.7.10 and 1.6.23.
  It fixes 3 security issues:

    CVE-2013-1968: fsfs repository corruption caused by newline characters in
filenames
    CVE-2013-2088: contrib hook-scripts can allow arbitrary code execution
    CVE-2013-2112: svnserve remotely triggerable DoS.

Security:	CVE-2013-1968
Security:	CVE-2013-2088
Security:	CVE-2013-2112
1.1_1
31 May 2013 11:33:41
Revision:319486Original commit files touched by this commit
crees search for other commits by this committer
Actually remove bitchx-devel and add a VuXML entry.

Security:	CVE-2007-4584
Security:	CVE-2007-5839
Security:	CVE-2007-5922
1.1_1
28 May 2013 14:23:30
Revision:319314Original commit files touched by this commit
jase search for other commits by this committer
- Document znc null pointer dereference vulnerability.
1.1_1
27 May 2013 00:41:56
Revision:319144Original commit files touched by this commit
ehaupt search for other commits by this committer
Adjust range for socat entry.
1.1_1
26 May 2013 22:01:38
Revision:319138Original commit files touched by this commit
ehaupt search for other commits by this committer
Document socat FD leak vulnerability.

Security:	CVE-2013-3571
1.1_1
26 May 2013 20:34:16
Revision:319136Original commit files touched by this commit
swills search for other commits by this committer
- Add entry for ruby 1.9.3p429
1.1_1
26 May 2013 08:38:26
Revision:319098Original commit files touched by this commit
delphij search for other commits by this committer
Document couchdb XSS vulnerability.

PR:		ports/178985
Submitted by:	wollman
1.1_1
23 May 2013 15:30:08
Revision:318877Original commit files touched by this commit
flo search for other commits by this committer
Update to 2.17.1 as the 2.18 release was postponed / cancelled
1.1_1
23 May 2013 08:20:48
Revision:318853Original commit files touched by this commit
cs search for other commits by this committer
Fix entry date, wrongly entered in revision 318453
1.1_1
23 May 2013 08:02:57
Revision:318851Original commit files touched by this commit
cs search for other commits by this committer
fix typo in recent otrs vulnerability
1.1_1
23 May 2013 07:58:58
Revision:318850Original commit files touched by this commit
cs search for other commits by this committer
Add vulnerabilities

Security:	CVE-2013-2637
		CVE-2013-3551
1.1_1
23 May 2013 07:24:40
Revision:318848Original commit files touched by this commit
matthew search for other commits by this committer
Security Updates

   - www/rt40 to 4.0.13
   - www/rt38 to 3.8.17 [1]

This is a security fix addressing a number of CVEs:

    CVE-2012-4733
    CVE-2013-3368
    CVE-2013-3369
    CVE-2013-3370
    CVE-2013-3371
    CVE-2013-3372
    CVE-2013-3373
    CVE-2013-3374

Users will need to update their database schemas as described in
pkg-message

Approved by:	flo [1]
Security:	3a429192-c36a-11e2-97a9-6805ca0b3d42
1.1_1
22 May 2013 09:14:17
Revision:318751Original commit files touched by this commit
rene search for other commits by this committer
Fix vuxml by using the correct format for CVE names.

Prodded by:	bz on IRC
1.1_1
22 May 2013 08:45:11
Revision:318748Original commit files touched by this commit
rene search for other commits by this committer
List vulnerabilities fixed in www/chromium 27.0.1453.93 (which is the
current version in the Ports Collection).
1.1_1
19 May 2013 14:06:36
Revision:318524Original commit files touched by this commit
rakuco search for other commits by this committer
Patch multiple vulnerabilities in x11-toolkits/plib.

PR:		ports/178710
Submitted by:	Denny Lin <dennylin93@hs.ntnu.edu.tw>
1.1_1
18 May 2013 20:35:07
Revision:318453Original commit files touched by this commit
rakuco search for other commits by this committer
- Update to 0.7.4
- Add VuXML entry
- Trim Makefile header
- Add LICENSE

PR:		ports/177206
Submitted by:	Alexander Milanov <a@amilanov.com>
Approved by:	Thomas Hurst <tom@hur.st> (maintainer)
Security:	a8818f7f-9182-11e2-9bdf-d48564727302
1.1_1
16 May 2013 22:46:39
Revision:318342Original commit files touched by this commit
delphij search for other commits by this committer
Update the recent nginx entry to cover the exact version range and include
information for CVE-2013-2070.
1.1_1
16 May 2013 04:14:31
Revision:318273Original commit files touched by this commit
eadler search for other commits by this committer
Update to the latest version of Adobe Flash
1.1_1
16 May 2013 02:00:38
Revision:318268Original commit files touched by this commit
flo search for other commits by this committer
- update firefox to 21.0
- update firefox-esr and thunderbird to 17.0.6
- WEBRTC now supports PULSEAUDIO
- make linux-firefox work with plugins again (e.g. quakelive)

Security:		4a1ca8a4-bd82-11e2-b7a0-d43d7e0c7c02
In collaboration with:	Jan Beich <jbeich@tormail.org>
1.1_1
14 May 2013 07:15:24
Revision:318140Original commit files touched by this commit
osa search for other commits by this committer
Update ranges according latest available information.

Source:	http://mailman.nginx.org/pipermail/nginx-announce/2013/000114.html
1.1_1
13 May 2013 00:08:14
Revision:317985Original commit files touched by this commit
ashish search for other commits by this committer
- Update emacs entry to correct the version ranges for CVE-2012-3479
1.1_1
07 May 2013 18:58:55
Revision:317627Original commit files touched by this commit
delphij search for other commits by this committer
Update nginx entry to reflect the right version ranges for CVE-2013-2028.

Note that we don't really have nginx 1.3.9 in the ports collection, due
to the recent ports freeze.  The version 1.3.9 is used here just to
better match the original advisory.
1.1_1
07 May 2013 13:32:03
Revision:317606Original commit files touched by this commit
osa search for other commits by this committer
Fix typo.

Found by:	ru
1.1_1
07 May 2013 11:35:19
Revision:317599Original commit files touched by this commit
osa search for other commits by this committer
Document nginx -- a stack-base buffer overflow.
1.1_1
03 May 2013 18:20:43
Revision:317230Original commit files touched by this commit
ohauer search for other commits by this committer
- fix strongSwan discovery date /2013-05-03/2013-04-30/
1.1_1
03 May 2013 18:16:36
Revision:317229Original commit files touched by this commit
ohauer search for other commits by this committer
- update to version 5.0.4 which fixes CVE-2013-2944.
- add entry to vuxml
- add CVE references to jankins vuxml entry

while I'm here remove .sh from rc script

PR:		ports/178266
Submitted by:	David Shane Holden <dpejesh@yahoo.com>
Approved by:	strongswan@nanoteq.com (maintainer)
1.1_1
03 May 2013 16:26:20
Revision:317217Original commit files touched by this commit
lwhsu search for other commits by this committer
Document Jenkins Security Advisory 2013-05-02
1.1_1
02 May 2013 19:41:07
Revision:317143Original commit files touched by this commit
tmseck search for other commits by this committer
- Add the vendor patch for SQUID-2012:1 (CVE-2012-5643) and update VuXML
  information accordingly
- Bump PORTREVISION

PR:		ports/177773
Submitted by:	Kan Sasaki
Approved by:	flo (mentor)
Security:	c37de843-488e-11e2-a5c9-0019996bc1f7
1.1_1
29 Apr 2013 22:41:58
Revision:316854Original commit files touched by this commit
des search for other commits by this committer
Add entry for SA-13:05.nfsserver
1.1_1
27 Apr 2013 20:58:01
Revision:316694Original commit files touched by this commit
nivit search for other commits by this committer
- Document multiple XSS and DDoS vulnerabilities for Joomla!
(2.5.0 <= version < 2.5.10)
1.1_1
24 Apr 2013 20:23:16
Revision:316477Original commit files touched by this commit
matthew search for other commits by this committer
Security updae to 3.5.8.1

Four new serious security alerts were issued today by the phpMyAdmin
them: PMASA-2013-2 and PMASA-2013-3 are documented in this commit to
vuln.xml.

 - Remote code execution via preg_replace().

 - Locally Saved SQL Dump File Multiple File Extension Remote Code
   Execution.

The other two: PMASA-2013-4 and PMASA-2013-5 only affect PMA 4.0.0
pre-releases earlier than 4.0.0-rc3, which are not available through
the ports.
1.1_1
22 Apr 2013 20:57:03
Revision:316276Original commit files touched by this commit
dinoex search for other commits by this committer
- Security update to 1.0.21
Security: CVE-2013-1428
1.1_1
20 Apr 2013 16:01:56
Revision:316157Original commit files touched by this commit
dinoex search for other commits by this committer
- Security fix
Security: CVE-2011-4517 execute arbitrary code on decodes images
Submitted by:   naddy (Christian Weisgerber)
Obtained from:  Fedora
Feature safe: yes
1.1_1
20 Apr 2013 09:24:30
Revision:316134Original commit files touched by this commit
matthew search for other commits by this committer
Document PMASA-2013-1

It turns out that release 3.5.8 (recently updated in ports) was the
cure to an XSS vulnerability.

Feature safe:  yes
1.1_1
19 Apr 2013 18:03:18
Revision:316114Original commit files touched by this commit
delphij search for other commits by this committer
Document roundcube arbitrary file disclosure vulnerability.

Reported by:	Marcelo Gondim <gondim bsdinfo com br>
Feature safe:	yes
1.1_1
18 Apr 2013 04:03:08
Revision:316016Original commit files touched by this commit
dinoex search for other commits by this committer
- add jasper
Feature safe: yes
1.1_1
16 Apr 2013 10:58:16
Revision:315811Original commit files touched by this commit
araujo search for other commits by this committer
- Update to 2.7.3 due a vulnerability that affect all versions 2.x. [1]
- Update MASTER_SITES.
- Convert to optionsNG.
- Trim header.

More info:
https://github.com/SpiderLabs/ModSecurity/blob/master/CHANGES

Reported by:    olli hauer <ohauer@gmx.de> [1]
Approved by:    portmgr (bdrewery)
Security:       2070c79a-8e1e-11e2-b34d-000c2957946c
1.1_1
15 Apr 2013 12:28:58
Revision:315802Original commit files touched by this commit
bdrewery search for other commits by this committer
- Update to 0.85
- Convert to new options framework

sieve-connect was not actually verifying TLS certificate identities matched
the expected hostname. Changes with new version:

Fix TLS verification; find server by own hostname & SRV.

* TLS hostname verification was not actually happening.

* IO::Socket::SSL requirement bumped to 1.14 (was 0.97).

* By default, if no server specified, before falling back to localhost try to
use the current hostname and SRV records in DNS to figure out if Sieve is
available. Checks for sieve, imaps & imap protocol SRV records and honours
(Only the first 15 lines of the commit message are shown above View all of this commit message)
1.1_1
13 Apr 2013 15:44:09
Revision:315796Original commit files touched by this commit
eadler search for other commits by this committer
Replace duplicate vids with a newly generated GUID.
Older duplicates kept their own number.

Approved by:	portmgr (implicit)
With Hat:	ports-secteam
1.1_1
12 Apr 2013 16:19:38
Revision:315791Original commit files touched by this commit
des search for other commits by this committer
Oops, fix the cite URL.

Approved by:	portmgr (tabthorpe)
1.1_1
12 Apr 2013 16:14:22
Revision:315790Original commit files touched by this commit
des search for other commits by this committer
Edit OpenVPN 2.3.1 entry:

 - Replace links to changelog and commit with a link to the official
   announcement (which also links to the commit)

 - Replace the description with a sentence lifted from the
   announcement.

Approved by:	portmgr (tabthorpe)

Number of commits found: 7243 (showing only 100 on this page)

[First Page]  «  37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47  »  [Last Page]