Commit History - (may be incomplete: for full details, see links to repositories near top of page) |
Commit | Credits | Log message |
1.1_1 06 Oct 2010 05:36:56 |
pgollucci |
- Fix a minor typo
Reported by: stas |
1.1_1 06 Oct 2010 05:29:50 |
pgollucci |
Document devel/apr1's apr-util vunerabilities
Security: http://secunia.com/advisories/41701
Reviewed by: secteam (cperciva) via irc |
1.1_1 02 Oct 2010 11:16:58 |
niels |
Documented phpMyFaq XSS vulnerability
PR: ports/151055
Submitted by: Florian Smeets <flo@smeets.im>
Approved by: itetcu (mentor, implicit)
Security: http://www.phpmyfaq.de/advisory_2010-09-28.php |
1.1_1 28 Sep 2010 18:04:46 |
thierry |
Report an XSS vulnerability in ftp/horde-gollem. |
1.1_1 28 Sep 2010 17:48:19 |
thierry |
Report a XSS vulnerability in mail/horde-dimp. |
1.1_1 28 Sep 2010 17:30:10 |
thierry |
Report a XSS vulnerability in mail/horde-imp. |
1.1_1 28 Sep 2010 17:09:35 |
thierry |
Report 2 vulnerabilities in www/horde-base. |
1.1_1 26 Sep 2010 13:32:10 |
niels |
Documented remote code execution vulnerability in OpenX
PR: ports/150610
Approved by: itetcu (mentor, implicit)
Security: ttp://blog.openx.org/09/security-update/ |
1.1_1 24 Sep 2010 20:24:37 |
niels |
Documented squid denial of service vulnerability
PR: ports/150364
Submitted by: Thomas-Martin Seck <tmseck@web.de>
Approved by: itetcu (mentor, implicit)
Security: CVE-2010-3072
Security: http://www.squid-cache.org/Advisories/SQUID-2010_3.txt |
1.1_1 22 Sep 2010 17:45:56 |
nox |
Update to 10.1r85 resp. 9.0r283 [1].
Security:
http://www.freebsd.org/ports/portaudit/8a34d9e6-c662-11df-b2e1-001b2134ef46.html
PR: ports/150832 [2]
Submitted by: pointyhat via pav [1], Tsurutani Naoki
<turutani@scphys.kyoto-u.ac.jp> [2] |
1.1_1 17 Sep 2010 20:07:07 |
delphij |
Correct discovery date, my bad :( |
1.1_1 17 Sep 2010 19:31:59 |
delphij |
Document django XSS vulnerability. |
1.1_1 15 Sep 2010 15:37:24 |
decke |
- Add libxul as affected package to the latest mozilla entry
Approved by: beat (co-mentor) |
1.1_1 10 Sep 2010 13:41:57 |
jadawin |
- Fix CVE name for webkit-gtk2 |
1.1_1 10 Sep 2010 13:03:20 |
kwm |
Document webkit-gtk2 - multiple vulnerabilities.
Also add 1 extra CVE to the previous webkit-gtk2 entry that was fixed but
didn't make it to the release notes. |
1.1_1 09 Sep 2010 03:13:09 |
shaun |
Belatedly (and perhaps pointlessly) document [1]:
vim6 -- heap-based overflow while parsing shell metacharacters
While here, prepare this old port for termination with DEPRECATED.
PR: ports/129300 [1]
Submitted by: Eygene Ryabinkin <rea-fbsd@codelabs.ru> [1] |
1.1_1 08 Sep 2010 06:51:06 |
beat |
- Document mozilla -- multiple vulnerabilities |
1.1_1 07 Sep 2010 18:11:49 |
wxs |
Document sudo Runas group vulnerability. |
1.1_1 04 Sep 2010 16:20:33 |
bapt |
- wget 1.12_1 is also concerned |
1.1_1 03 Sep 2010 13:57:14 |
bapt |
- Add wget entry CVE-2010-2252
- Add lftp entry CVE-2010-2251 |
1.1_1 31 Aug 2010 14:53:00 |
jadawin |
- Document p5-libwww vulnerability (remote servers can create .(dot) files) |
1.1_1 25 Aug 2010 07:49:08 |
niels |
Documented quagga vulnerabilities (stack overflow, DoS)
Approved by: itetcu (mentor,implicit)
Security: http://www.openwall.com/lists/oss-security/2010/08/24/3
Security: http://www.quagga.net/news2.php?y=2010&m=8&d=19#id1282241100 |
1.1_1 24 Aug 2010 16:26:54 |
skv |
Document "bugzilla" - information disclosure, denial of service. |
1.1_1 23 Aug 2010 07:12:57 |
lwhsu |
- Fix version range of phpMyAdmin
Submitted by: Marko Njezic <mr.max AT maxempire.com> |
1.1_1 22 Aug 2010 17:19:50 |
danfe |
Adjust the version range in previous entry: 1.0.1 is also vulnerable, and
fix minor whitespace nit while here. |
1.1_1 22 Aug 2010 12:30:07 |
kwm |
Add entry for OpenTTD denial of server vulnability.
Reviewed by: danfe@ (OpenTTD maintainer) |
1.1_1 21 Aug 2010 21:30:32 |
niels |
- Added corkscrew: overflow condition due to insecure sscanf usage
- Fixed SLiM title: /SLiM/slim/
Approved by: itetcu (mentor, implicit)
Security: http://people.freebsd.org/~niels/issues/corkscrew-20100821.txt |
1.1_1 21 Aug 2010 12:42:18 |
lwhsu |
- Add phpMyAdmin's CVE-2010-3056 entry |
1.1_1 20 Aug 2010 23:34:13 |
stas |
- Fix date of the latest ruby entry. |
1.1_1 20 Aug 2010 21:00:34 |
niels |
Added CVE to SLiM vulnerability
Approved by: itetcu (mentor, implicit)
Security: CVE-2010-2945 |
1.1_1 19 Aug 2010 21:11:53 |
niels |
- Document SLiM insecure PATH assignment issue
- Removed space from vlc title
Approved by: itetcu (implicit, mentor)
Security: http://seclists.org/oss-sec/2010/q3/198 |
1.1_1 18 Aug 2010 06:36:26 |
stas |
- Document recent WEBrick XSS vulnerability in ruby. |
1.1_1 17 Aug 2010 12:50:38 |
bapt |
- Add security/isolate entry
PR: ports/148911
Submitted by: Steve Wills <steve _at_ mouf.net> (maintainer)
Approved by: tabthorpe (mentor) |
1.1_1 15 Aug 2010 17:10:53 |
shaun |
Fix krb5 entry (86b8b655-4d1a-11df-83fb-0015587e2cc1) version range
mark-up.
Submitted by: Peggy Wilkins via freebsd-ports |
1.1_1 14 Aug 2010 22:43:51 |
gabor |
- Fix last entry by adding the forgotten package name.
(Hint: always run make validate before committing to this file)
Forgotten by: jsa, kwm |
1.1_1 14 Aug 2010 20:51:52 |
jsa |
Document VLC CVE-2010-2937.
Approved by: kwm (mentor) |
1.1_1 13 Aug 2010 20:15:54 |
nox |
Update to 10.1r82 resp. 9.0r280.
Security:
http://www.freebsd.org/ports/portaudit/e19e74a4-a712-11df-b234-001b2134ef46.html |
1.1_1 13 Aug 2010 15:23:18 |
shaun |
Document opera -- multiple vulnerabilities. |
1.1_1 09 Aug 2010 09:10:12 |
beat |
- Belatedly document firefox -- Dangling pointer crash regression from plugin
parameter array fix
Approved by: miwi |
1.1_1 04 Aug 2010 14:47:39 |
wxs |
Whitespace fixes. |
1.1_1 04 Aug 2010 09:32:27 |
lwhsu |
- Fix Piwik entry's <name> tag
Pointed out by: jadawin |
1.1_1 04 Aug 2010 09:18:12 |
lwhsu |
- Add Piwik CVE-2010-2786 entry |
1.1_1 31 Jul 2010 12:00:24 |
kuriyama |
Previous vuln affects only apache-2.2.x |
1.1_1 29 Jul 2010 23:03:53 |
gabor |
- Document libmspack and cabextract vulnerability |
1.1_1 26 Jul 2010 01:42:21 |
kuriyama |
Add entry for apache. |
1.1_1 23 Jul 2010 00:37:11 |
wxs |
Document buffer overflow when parsing gitdir.
While here, tidy up a whitespace problem. |
1.1_1 21 Jul 2010 22:25:34 |
glarkin |
- Document www/codeigniter file upload class vulnerability
Approved by: secteam (timeout - 1 week)
Security: http://codeigniter.com/news/codeigniter_1.7.2_security_patch/ |
1.1_1 21 Jul 2010 12:46:17 |
beat |
- Document mozilla -- multiple vulnerabilities
Approved by: remko |
1.1_1 19 Jul 2010 00:07:23 |
kwm |
Add vte as package name, instead of empty. |
1.1_1 18 Jul 2010 23:28:32 |
kwm |
Document vte title set+query attack vulnerability.
While here add the CVE numbers to the webkit-gtk2 entry I forgot in the
previous commit.
PR: ports/148678
Submitted by: Janne Snabb <snabb@epipe.com> |
1.1_1 18 Jul 2010 22:44:05 |
kwm |
Document webkit-gtk2 vulnerabilities.
Security: http://blog.kov.eti.br/?p=116 |
1.1_1 10 Jul 2010 08:34:16 |
decke |
- Document redmine vulnerabilities
Approved by: miwi (secteam)
Security: http://www.redmine.org/news/41 |
1.1_1 07 Jul 2010 09:13:02 |
nemoliu |
- Update to 3.1.1
- VuXML entry for PNG decoder security vulnerability
- License information
PR: ports/147871
Approved by: Pavel Pankov <pankov_p@mail.ru> (maintainer)
Feature safe: yes |
1.1_1 06 Jul 2010 21:39:10 |
delphij |
Add bogofilter heap underrun on malformed base64 input.
Submitted by: mandree
PR: ports/148408
Feature safe: yes |
1.1_1 06 Jul 2010 04:38:12 |
miwi |
- Cleanup a bit
Feature safe: yes |
1.1_1 05 Jul 2010 15:41:27 |
skv |
Document "bugzilla" - information disclosure.
Feature safe: yes |
1.1_1 30 Jun 2010 21:00:07 |
makc |
Document multiple vulnerabilities in irc/kvirc*
Approved by: remko@
Feature safe: yes |
1.1_1 28 Jun 2010 17:38:13 |
delphij |
Add bid reference for libpng entry.
Feature safe: yes |
1.1_1 28 Jun 2010 16:18:53 |
dinoex |
- graphics/png CVE-2010-1205
Feature safe: yes |
1.1_1 28 Jun 2010 00:46:12 |
wen |
- Document moodle -- multiple vulnerabilities
Reviewed by: delphij@, miwi@
Feature safe: yes |
1.1_1 27 Jun 2010 21:14:28 |
rene |
Document mDNSResponder -- corrupted stack crash when parsing bad resolv.conf
This only happens on a system where one has a system where
resolv.conf is writable by an untrusted user or where mdnsd is setuid
and can be tricked into opening an alternate resolv.conf.
PR: ports/147007
Submitted by: jmallett@
Approved by: tabthorpe (mentor)
Feature safe: yes |
1.1_1 25 Jun 2010 23:29:50 |
shaun |
Document opera -- Data URIs can be used to allow cross-site scripting.
Assume opera-devel is vulnerable too, although snapshots aren't
mentioned in the advisory, and it's months out of date.
Feature safe: yes |
1.1_1 24 Jun 2010 12:54:49 |
niels |
- Cancelled movemail symlink vulnerability (doesnt affect our ports)
- Added entry for multiple vulnerabilities in cacti 0.8.7f
- Updated ziproxy entry to satisfy "make tidy"
Approved by: itetcu (mentor, implicit)
Feature safe: yes |
1.1_1 23 Jun 2010 18:01:10 |
beat |
- Document mozilla -- multiple vulnerabilities
Feature safe: yes
Approved by: delphij |
1.1_1 18 Jun 2010 00:38:36 |
delphij |
vuln 4e8344a3-ca52-11de-8ee8-00215c6a37bb has been fixed with
php4-gd-4.4.9_4.
Requested by: Michael Gmelin <mg bindone de> |
1.1_1 16 Jun 2010 12:42:09 |
erwin |
Fix typo in previous revision. |
1.1_1 16 Jun 2010 12:13:30 |
miwi |
- Cleanup, Formating |
1.1_1 16 Jun 2010 09:31:35 |
dinoex |
add CVE-2009-2347 tiff |
1.1_1 15 Jun 2010 19:46:47 |
nox |
Document linux-flashplugin -- multiple vulnerabilities.
Reviewed by: tmclaugh |
1.1_1 14 Jun 2010 03:04:22 |
miwi |
- Cleanup / Whitespace fixes |
1.1_1 12 Jun 2010 17:22:38 |
erwin |
Remove empty package in previous revision. |
1.1_1 12 Jun 2010 16:44:34 |
dinoex |
- report FAX3 decoder buffer overrun |
1.1_1 03 Jun 2010 00:10:57 |
wxs |
Document sudo secure path vulnerability. We are not vulnerable to this by
default but a user could build sudo with SUDO_SECURE_PATH defined or turn
it on in sudoers. |
1.1_1 02 Jun 2010 11:24:45 |
pav |
- Update to 3.0.1
PR: ports/147195
Submitted by: Pavel Pankov <pankov_p@mail.ru> (maintainer) |
1.1_1 02 Jun 2010 06:20:29 |
wen |
- Document two mediawiki security vulnerabilities
Approved by: delphij@(ports-security override) |
1.1_1 14 May 2010 18:28:43 |
decke |
- Document multiple redmine vulnerabilities
Approved by: miwi (secteam), beat (co-mentor)
Security: http://www.redmine.org/news/39 |
1.1_1 13 May 2010 09:12:02 |
niels |
Updated tomcat entry (CVE-2010-1157) with fixed version information.
This makes sure that the correct older versions are marked vulnerable
Approved by: itetcu (mentor, implicit)
Security:
http://www.vuxml.org/freebsd/3383e706-4fc3-11df-83fb-0015587e2cc1.html |
1.1_1 12 May 2010 09:46:13 |
niels |
- Added 109 missing CVE names to 60 VuXML entries
- Fixed Tomcat55 entry to mark current PORTREVISION vulnerable
PR: ports/146418
Approved by: itetcu (mentor, implicit)
Security: http://people.freebsd.org/~niels/vuxml/ |
1.1_1 07 May 2010 19:53:26 |
niels |
Added wireshark (DoS) and piwik (XSS) issues
Approved by: itetcu (mentor, implicit)
Security: http://www.wireshark.org/security/wnpa-sec-2010-03.html
Security: http://www.wireshark.org/security/wnpa-sec-2010-04.html
Security: http://piwik.org/blog/2010/04/piwik-0-6-security-advisory/ |
1.1_1 06 May 2010 19:44:56 |
niels |
Added spamass-milter remote command execution vulnerability
Approved by: itetcu (mentor, implicit)
Security: CVE-2010-1132
Security:
http://archives.neohapsis.com/archives/fulldisclosure/2010-03/0139.html |
1.1_1 05 May 2010 19:12:37 |
niels |
- Added mediawiki and lxr vulnerabilities
- Fixed vlc topic format (lower case, portname first)
PR: ports/146337
Approved by: itetcu (mentor, implicit)
Security:
http://lists.wikimedia.org/pipermail/mediawiki-announce/2010-April/000090.html
Security:
http://sourceforge.net/mailarchive/message.php?msg_name=E1NS2s4-0001PE-F2%403bkjzd1.ch3.sourceforge.com |
1.1_1 04 May 2010 20:46:06 |
niels |
Added 38 missing CVE names to 24 VuXML entries
(256 CVE names to go)
Approved by: itetcu (mentor, implicit)
Security: http://people.freebsd.org/~niels/vuxml/ |
1.1_1 02 May 2010 15:32:40 |
niels |
Added 34 missing CVE names to 24 VuXML entries
(294 CVE names to go)
Approved by: miwi (secteam)
Security: http://people.freebsd.org/~niels/vuxml/ |
1.1_1 02 May 2010 00:52:40 |
sylvio |
- VideoLAN has released 1.0.6 to address serveral vulnerabilities they discoverd
while working towards the 1.1.0 release. These vulnerabilities could potentially
allow for a specially crafted file to execute code.
PR: ports/146099
Submitted by: Joseph S. Atkinson <jsa@wickedmachine.net> (maintainer) |
1.1_1 30 Apr 2010 04:25:33 |
dinoex |
- fix version for apache+mod_ssl |
1.1_1 30 Apr 2010 04:24:30 |
dinoex |
- fix info for apache+mod_ssl |
1.1_1 28 Apr 2010 21:09:45 |
makc |
Mark kdebase3 as safe now. |
1.1_1 27 Apr 2010 05:46:00 |
niels |
- Documented multiple Joomla! vulnerabilities
- Added new reference to the recent cacti issue
Approved by: remko (secteam)
Security: http://developer.joomla.org/security/ |
1.1_1 24 Apr 2010 21:14:58 |
niels |
Documented vulnerabilities in moodle, tomcat55, tomcat66 and cacti
PR: ports/146021
PR: ports/146022
Approved by: remko (secteam)
Security: http://seclists.org/bugtraq/2010/Apr/200
Security: http://docs.moodle.org/en/Moodle_1.9.8_release_notes
Security: http://www.bonsai-sec.com/en/research/vulnerability.php |
1.1_1 23 Apr 2010 18:16:18 |
niels |
Documented emacs movemail vulnerability and marked the seperate
mail/movemail port vulnerable to an old format string vulnerability.
Approved by: remko (secteam)
Security: http://www.ubuntu.com/usn/USN-919-1 |
1.1_1 21 Apr 2010 20:19:12 |
niels |
Added krb5 double free vulnerability
Approved by: remko (secteam)
Security: http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2010-004.txt
Security: CVE-2010-1320 |
1.1_1 20 Apr 2010 21:03:51 |
niels |
Documented the following vulnerabilities:
- png: libpng decompression denial of service
- e107: code execution and XSS vulnerabilities
- pidgin: multiple remote denial of service vulnerabilities
- fetchmail: denial of service vulnerability
PR: ports/145885
PR: ports/145857
Approved by: remko (secteam)
Security: CVE-2010-0996
Security: CVE-2010-0997
Security: CVE-2010-1167
Security: CVE-2010-0277
Security: CVE-2010-0420
Security: CVE-2010-0423
Security: CVE-2010-0205 |
1.1_1 19 Apr 2010 19:06:23 |
niels |
Documented the following vulnerabilities:
- curl: libcurl buffer overflow vulnerability
- irssi: multiple vulnerabilities
- ejabberd: queue overload denial of service vulnerability
Approved by: remko (secteam)
Security: http://curl.haxx.se/docs/adv_20100209.html
Security: http://support.process-one.net/browse/EJAB-1173
Security: http://xforce.iss.net/xforce/xfdb/57790
Security: http://xforce.iss.net/xforce/xfdb/57791 |
1.1_1 19 Apr 2010 07:13:42 |
niels |
- Added three krb5 vulnerabilities
- Fixed indent on mahara entry
- Fixed title of KDM entry
Approved by: remko (secteam)
Security: http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2010-001.txt
Security: http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2010-002.txt
Security: http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2010-003.txt |
1.1_1 18 Apr 2010 19:00:29 |
niels |
Document mahara sql injection vulnerability
Approved by: remko (secteam)
Security: http://www.debian.org/security/2010/dsa-2030 |
1.1_1 16 Apr 2010 02:25:07 |
wxs |
Correct CVE entry. The advisory from Todd[0] says CVE 2010-0426, which is
the entry assigned to the original sudoedit vulnerability[1]. The new
one (CVE-2010-1163) was just assigned. I believe the one assigned by CVE
folks is the proper one to use.
[0]: http://sudo.ws/sudo/alerts/sudoedit_escalate2.html
[1]: 018a84d0-2548-11df-b4a3-00e0815b8da8 |
1.1_1 15 Apr 2010 20:53:03 |
wxs |
- Document sudo privilege escalation bug. This is similar to
018a84d0-2548-11df-b4a3-00e0815b8da8. |
1.1_1 14 Apr 2010 21:46:52 |
avilla |
- Do not match x11/kdebase4 in latest KDM vulnerability.
Approved by: tabthorpe (mentor) |
1.1_1 14 Apr 2010 19:04:39 |
avilla |
- Document KDM local privilege escalation vulnerability.
Approved by: tabthorpe (mentor), delphij (secteam) |
1.1_1 06 Apr 2010 17:53:39 |
glarkin |
- Document dojo - cross-site scripting and other vulnerabilities
- Document ZendFramework - security issues in bundled Dojo library
Approved by: secteam (remko)
Security:
http://dojotoolkit.org/blog/post/dylan/2010/03/dojo-security-advisory/
Security: http://framework.zend.com/security/advisory/ZF2010-07 |