Commit History - (may be incomplete: for full details, see links to repositories near top of page) |
Commit | Credits | Log message |
1.1_1 16 Apr 2005 22:35:09 |
remko |
Document jdk - jar directory traversal vulnerability.
Approved by: simon |
1.1_1 16 Apr 2005 16:12:02 |
simon |
Document several mozilla/firefox issues. |
1.1_1 15 Apr 2005 21:47:10 |
simon |
Mark wget >= 1.10.a1 safe from the "wget -- multiple vulnerabilities"
entry.
Info provided by: sf |
1.1_1 13 Apr 2005 23:17:14 |
simon |
Document openoffice -- DOC document heap overflow vulnerability. |
1.1_1 12 Apr 2005 08:24:48 |
simon |
Fix and document insecure temporary file handling in portupgrade.
Security: CAN-2005-0610
Security:
http://vuxml.FreeBSD.org/22f00553-a09d-11d9-a788-0001020eed82.html
Approved by: erwin (mentor), maintainer timeout
OK'ed by: portmgr
Reviewed by: nectar |
1.1_1 10 Apr 2005 19:41:46 |
simon |
Document three GAIM vulnerabilities. |
1.1_1 10 Apr 2005 18:47:06 |
simon |
Document an old PHP issue. |
1.1_1 10 Apr 2005 10:22:18 |
simon |
Document squid -- DoS on failed PUT/POST requests vulnerability.
Submitted by: Devon H. O'Dell <dodell@offmyserver.com> (original version) |
1.1_1 09 Apr 2005 20:42:03 |
pav |
- Fix closing tag on the entry I just touched.
Pointed out by: still Chimera
Blaming: too much bear earlier tonight |
1.1_1 09 Apr 2005 20:38:37 |
pav |
- Add <modified> to the entry I just touched
Prodded by: Chimera |
1.1_1 09 Apr 2005 20:21:48 |
pav |
- CAN-2005-0133 is fixed in clamav-devel-20050408
PR: ports/79688
Submitted by: Renato Botelho <freebsd@galle.com.br> |
1.1_1 05 Apr 2005 20:57:06 |
simon |
Bump modified date for entry modified last commit. |
1.1_1 05 Apr 2005 20:03:49 |
ume |
add CVE name to latest vuln of Cyrus IMAPd. |
1.1_1 05 Apr 2005 19:57:09 |
thierry |
Add an entry for a XSS vulnerabilty fixed in horde-3.0.4. |
1.1_1 04 Apr 2005 20:06:01 |
simon |
Document wu-ftpd -- remote globbing DoS vulnerability. |
1.1_1 03 Apr 2005 06:53:58 |
simon |
Add CVE name to hashash entry. |
1.1_1 02 Apr 2005 23:15:17 |
naddy |
Document hashcash format string vulnerability. |
1.1_1 26 Mar 2005 20:49:40 |
simon |
Document clamav -- zip handling DoS vulnerability.
Approved by: portmgr (blanket, VuXML) |
1.1_1 24 Mar 2005 14:15:05 |
nectar |
Document Wine information disclosure.
Based on an entry that was
Submitted by: Devon H. O'Dell <dodell@offmyserver.com>
Approved by: portmgr (blanket, VuXML) |
1.1_1 24 Mar 2005 14:08:28 |
nectar |
Document the most serious of the recently disclosed
Mozilla/Firefox/Thunderbird vulnerabilities.
Based on entries that were
Submitted by: Devon H. O'Dell <dodell@offmyserver.com>
Approved by: portmgr (blanket, VuXML) |
1.1_1 23 Mar 2005 18:29:15 |
nectar |
Document Sylpheed buffer overflow.
Reminded by: netchild
Approved by: portmgr (blanket, VuXML) |
1.1_1 21 Mar 2005 21:19:21 |
simon |
Document xv -- filename handling format string vulnerability.
Approved by: portmgr (implicit, VuXML) |
1.1_1 21 Mar 2005 20:27:19 |
simon |
Document kdelibs -- local DCOP denial of service vulnerability.
Approved by: portmgr (implicit, VuXML) |
1.1_1 18 Mar 2005 19:16:10 |
simon |
Mark grip port as fixed for recent vulnerability.
Requested by: ahze |
1.1_1 15 Mar 2005 21:13:28 |
simon |
Document phpmyadmin -- increased privilege vulnerability. |
1.1_1 15 Mar 2005 19:40:24 |
danfe |
Note that recent Quake2-LNX is fixed. |
1.1_1 15 Mar 2005 14:27:02 |
ale |
Recent mysql snapshot import fixed several vulnerabilities. |
1.1_1 14 Mar 2005 21:55:47 |
simon |
Document ethereal -- multiple protocol dissectors vulnerabilities. |
1.1_1 14 Mar 2005 20:19:29 |
simon |
Document "grip -- CDDB response multiple matches buffer overflow
vulnerability". |
1.1_1 14 Mar 2005 19:49:15 |
simon |
Update references for latest MySQL entry:
- Use bid tag for Bugtraq ID reference.
- Add CVE names. |
1.1_1 14 Mar 2005 15:16:35 |
ale |
Document multiple mysql remote vulnerabilities. |
1.1_1 13 Mar 2005 10:31:19 |
thierry |
Add an entry about rxvt-unicode bufer overflow. |
1.1_1 08 Mar 2005 22:52:19 |
simon |
Document two phpMyAdmin issues. |
1.1_1 08 Mar 2005 21:26:23 |
simon |
Document libexif -- buffer overflow vulnerability. |
1.1_1 07 Mar 2005 15:45:13 |
nectar |
Fix invalid date.
Noticed by: Kang Liu <liukang@bjut.edu.cn> |
1.1_1 06 Mar 2005 17:06:32 |
nectar |
Add <modified> date for recent commit to phpbb vulnerability.
Forgotten by: delphij
While here, add msgids for recent phpbb addition. |
1.1_1 05 Mar 2005 15:53:42 |
delphij |
Document a low risk HTML injection (configuration bypass)
vulnerability [1] of phpBB.
(maintainer contacted and is preparing a fix)
[1] http://marc.theaimsgroup.com/?l=bugtraq&m=110987231502274 |
1.1_1 05 Mar 2005 15:42:50 |
delphij |
Add bugtraq bug ID for phpbb vulnerability.
Submitted by: Kang LIU <liukang bjut edu cn> |
1.1_1 04 Mar 2005 18:14:28 |
nectar |
Document two phpnuke vulnerabilities, and a Linux RealPlayer
vulnerability.
Based on entries that were
Submitted by: Devon H. O'Dell <dodell@sitetronics.com> |
1.1_1 03 Mar 2005 22:20:45 |
simon |
- Document ImageMagick -- format string vulnerability.
- Fix typo on older tiff entry. |
1.1_1 02 Mar 2005 13:17:25 |
nobutaka |
Document the privilege escalation vulnerability in uim. |
1.1_1 01 Mar 2005 13:39:29 |
nectar |
Fix typo in linux-tiff version number for
http://vuxml.freebsd.org/8f86d8b5-6025-11d9-a9e7-0001020eed82.html
Reported by: Ian Moore <no-spam@swiftdsl.com.au> |
1.1_1 01 Mar 2005 13:23:53 |
nectar |
Document lighttpd information disclosure bug.
This entry is based on one that was
Submitted by: Devon H. O'Dell <dodell@offmyserver.com> |
1.1_1 28 Feb 2005 13:41:19 |
nectar |
Fix typo in linux-tiff version number for
http://vuxml..freebsd.org/fc7e6a42-6012-11d9-a9e7-0001020eed82.html
Reported by: Ian Moore <no-spam@swiftdsl.com.au> |
1.1_1 28 Feb 2005 10:48:54 |
delphij |
Document latest phpBB critical security vulnerabilities.
Submitted by: Kang LIU <liukang bjut edu cn> |
1.1_1 28 Feb 2005 03:42:01 |
nectar |
Correct the linux-tiff version number for several entries.
Reported by: netchild |
1.1_1 27 Feb 2005 21:24:04 |
simon |
Document curl -- authentication buffer overflow vulnerability. |
1.1_1 27 Feb 2005 20:34:17 |
simon |
- Document cyrus-imapd -- multiple buffer overflow vulnerabilities. [1]
- Use bid tag for a reference in sup entry.
Advice from: ume [1] |
1.1_1 27 Feb 2005 13:21:10 |
hrs |
Document format string vulnerabilities in net/sup. |
1.1_1 26 Feb 2005 21:12:13 |
simon |
- Just use mozilla in title for last entry for consistency.
- Document mozilla -- insecure temporary directory vulnerability. |
1.1_1 26 Feb 2005 20:36:40 |
simon |
Update list of affected mozilla/firefox ports by the web browsers --
window injection vulnerabilities entry. |
1.1_1 26 Feb 2005 14:25:31 |
simon |
Document mozilla & firefox -- arbitrary code execution vulnerability.
Submitted by: Devon H. O'Dell <dodell@sitetronics.com> (original version) |
1.1_1 25 Feb 2005 04:55:52 |
nectar |
Improve the description of the latest phpBB information disclosure
bugs.
Submitted by: delphij (in part) |
1.1_1 24 Feb 2005 15:43:23 |
hrs |
Document a format string vulnerability in mkbold-mkitalic.
Reviewed by: simon |
1.1_1 23 Feb 2005 16:20:58 |
nectar |
Add CVE names for wget. |
1.1_1 23 Feb 2005 15:11:02 |
nectar |
De-confuse latest AWStats entry: rewrite description, and add relevant
references. There were so many bugs, it was hard to keep them straight
(^_^). |
1.1_1 23 Feb 2005 14:37:05 |
nectar |
Format the <topic> of the most recent entry so that it is more
consistent with other entries. |
1.1_1 23 Feb 2005 13:13:44 |
delphij |
Document latest phpbb vulnerabilities.
Discussed with: phpbb maintainer |
1.1_1 23 Feb 2005 05:15:32 |
simon |
Add more references to recent putty vulnerability. |
1.1_1 22 Feb 2005 21:58:36 |
nectar |
The mod_dosevasive port was upgraded. |
1.1_1 22 Feb 2005 19:27:32 |
nectar |
Nit:
- In most recent `unace' entry, replace HTML entity with the Unicode
character. We do not use HTML entities so that a VuXML document may
be processed without using the DTD. (We also avoid character entity
references for more natural grep'ing, sed'ing, and editor searching.)
Corrections:
- An invalid UUID was assigned to a FreeRADIUS vulnerability, and went
undetected since last October. (>_<) Correct it.
- A bnc vulnerability was duplicated. Cancel the older, less informative
entry and update the newer entry. |
1.1_1 22 Feb 2005 15:37:51 |
naddy |
Document unace-1.2b vulnerabilities: buffer overflows, directory traversal. |
1.1_1 20 Feb 2005 20:51:37 |
simon |
For the the recent kdelibs entry; note that dcopidlng is only used at
build time.
Reported by: lofi |
1.1_1 20 Feb 2005 18:53:25 |
simon |
Document heap corruption vulnerabilities in putty. |
1.1_1 19 Feb 2005 12:49:39 |
simon |
Update affected versions of latest postgresql entry now that the ports
have been fixed. |
1.1_1 18 Feb 2005 22:37:35 |
simon |
Document insecure temporary file creation in kdelibs. |
1.1_1 18 Feb 2005 21:55:08 |
simon |
Document format string vulnerability in bidwatcher. |
1.1_1 18 Feb 2005 20:37:19 |
simon |
Document a directory traversal vulnerability in gftp. |
1.1_1 18 Feb 2005 20:14:00 |
simon |
- Document two Opera vulnerabilities.
- Update information about fixed version for Opera with regard to
"Window Injection" issues (based on release notes for Opera 7.54u2). |
1.1_1 17 Feb 2005 21:45:40 |
simon |
Document multiple buffer overflows in postgresql. |
1.1_1 16 Feb 2005 23:39:20 |
simon |
Fix entry date for last commit. |
1.1_1 16 Feb 2005 23:25:23 |
simon |
Document vulnerabilities in awstats. Note that this entry will most
likely be updated soon when more information becomes available. |
1.1_1 15 Feb 2005 20:55:47 |
simon |
Add a few more references to the awstats entry. |
1.1_1 14 Feb 2005 15:44:07 |
nobutaka |
Change affected packages version for the emacs movemail format string
vulnerability since I fixed editors/emacs port by adding a patch
instead of upgrading it to 21.4. |
1.1_1 14 Feb 2005 00:10:36 |
simon |
Document DoS in powerdns. |
1.1_1 13 Feb 2005 23:19:00 |
simon |
Document format string vulnerability in the Emacs movemail utility. |
1.1_1 13 Feb 2005 11:28:52 |
danfe |
- Reflect fixing vulnerability in `net/opendchub'
- Print project's name correctly |
1.1_1 13 Feb 2005 09:59:02 |
simon |
- Fix a cvename that should have been a certvu.
- Delete trailing white space.
- Fix some nearby formatting while I'm here anyway. |
1.1_1 13 Feb 2005 09:21:00 |
simon |
Document two vulnerabilities in ngircd. |
1.1_1 12 Feb 2005 23:53:09 |
simon |
Document mod_python information leakage vulnerability. |
1.1_1 12 Feb 2005 20:40:51 |
simon |
Document mailman directory traversal vulnerability. |
1.1_1 11 Feb 2005 23:29:31 |
nectar |
Expand HTML entity reference in latest VuXML entry. |
1.1_1 11 Feb 2005 21:59:05 |
naddy |
Document enscript-{a4,letter,letterdj} vulnerabilities. |
1.1_1 11 Feb 2005 13:37:26 |
danfe |
Vulnerability in unrtf is fixed now. |
1.1_1 08 Feb 2005 21:33:54 |
simon |
Document privilege escalation vulnerability in postgresql. |
1.1_1 08 Feb 2005 18:14:45 |
simon |
Document multiple protocol dissectors vulnerabilities in ethereal. |
1.1_1 08 Feb 2005 14:49:58 |
nectar |
Add another squid issue.
PR: ports/76967
Submitted by: Thomas-Martin Seck <tmseck@netcologne.de> |
1.1_1 08 Feb 2005 14:43:51 |
nectar |
Add CERT Vulnerability Note reference for one squid issue,
and correct the reference for another one [1].
Reported by: Thomas-Martin Seck <tmseck@netcologne.de> [1] |
1.1_1 08 Feb 2005 13:48:12 |
nectar |
Add CVE name for squid confusing empty ACL issue. |
1.1_1 07 Feb 2005 20:02:30 |
nectar |
Add US-CERT Vulnerability Note references for recent squid issues. |
1.1_1 04 Feb 2005 04:26:10 |
perky |
Add missing <code> markups in a citation from PSF-2005-001. |
1.1_1 04 Feb 2005 04:09:11 |
perky |
Add an entry for PSF-2005-001,
"SimpleXMLRPCServer.py allows unrestricted traversal" |
1.1_1 03 Feb 2005 22:30:59 |
marcus |
Update the entry for CAN-2005-0064 to indicate that gpdf 2.8.3 has a fix
for this vulnerability. |
1.1_1 02 Feb 2005 18:59:10 |
nectar |
Note that perl does not have a suidperl by default. |
1.1_1 02 Feb 2005 17:38:45 |
nectar |
Note vulnerabilities in perl. |
1.1_1 02 Feb 2005 15:46:17 |
nectar |
Add Bugtraq ID for evolution issue. |
1.1_1 01 Feb 2005 17:03:31 |
nectar |
Add CVE name for squid WCCP issue. |
1.1_1 01 Feb 2005 14:14:55 |
nectar |
Add a <modified> tag to the perl File::Path issue since the affected
versions were changed.
Forgotten by: tobez |
1.1_1 01 Feb 2005 13:38:16 |
tobez |
Narrow perl File::Path vulnerability version range a bit. |
1.1_1 01 Feb 2005 09:03:52 |
niels |
Documented vulnerabilities found in the newspost, newsfetch and newsgrab ports.
http://people.freebsd.org/~niels/issues/newspost-20050114.txt
http://people.freebsd.org/~niels/issues/newsgrab-20050114.txt
http://people.freebsd.org/~niels/issues/newsfetch-20050119.txt
Approved by: nectar (mentor) |