notbugAs an Amazon Associate I earn from qualifying purchases.
Want a good read? Try FreeBSD Mastery: Jails (IT Mastery Book 15)
Want a good monitor light? See my photos
All times are UTC
Ukraine
The recently imposed "must be logged in" restriction is a response to increased bot traffic on the site. This affects search, commits, and vuxml pages.
Search engines are not blocked. Try using "site:www.freshports.org" and your search terms.
Port details
vuxml Vulnerability and eXposure Markup Language DTD
1.1_6 security on this many watch lists=33 search for ports that depend on this port Find issues related to this port Report an issue related to this port View this port on Repology. pkg-fallout 1.1_6Version of this port present on the latest quarterly branch.
Maintainer: ports-secteam@FreeBSD.org search for ports maintained by this maintainer
Port Added: 2004-02-12 14:24:23
Last Update: 2026-06-20 06:39:47
Commit Hash: 168937a
People watching this port, also watch:: gnupg, libxml2, nmap, curl, postfix
Also Listed In: textproc
License: BSD2CLAUSE
WWW:
https://vuxml.freebsd.org/
Description:
VuXML (the Vulnerability and eXposure Markup Language) is an XML application for documenting security bugs and corrections within a software package collection such as the FreeBSD Ports Collection. This port installs the DTDs required for validating VuXML documents.
Homepage    cgit ¦ Codeberg ¦ GitHub ¦ GitLab ¦ SVNWeb

Manual pages:
FreshPorts has no man page information for this port.
pkg-plist: as obtained via: make generate-plist
Expand this list (13 items)
Collapse this list.
  1. /usr/local/share/licenses/vuxml-1.1_6/catalog.mk
  2. /usr/local/share/licenses/vuxml-1.1_6/LICENSE
  3. /usr/local/share/licenses/vuxml-1.1_6/BSD2CLAUSE
  4. @xmlcatmgr share/xml/dtd/vuxml/catalog
  5. @xmlcatmgr share/xml/dtd/vuxml/catalog.xml
  6. share/xml/dtd/vuxml/vuxml-10.dtd
  7. share/xml/dtd/vuxml/vuxml-11.dtd
  8. share/xml/dtd/vuxml/vuxml-model-10.mod
  9. share/xml/dtd/vuxml/vuxml-model-11.mod
  10. share/xml/dtd/vuxml/xml1.dcl
  11. @owner
  12. @group
  13. @mode
Collapse this list.
USE_RC_SUBR (Service Scripts)
  • no SUBR information found for this port
Dependency lines:
  • vuxml>0:security/vuxml
To install the port:
cd /usr/ports/security/vuxml/ && make install clean
To add the package, run one of these commands:
  • pkg install security/vuxml
  • pkg install vuxml
NOTE: If this package has multiple flavors (see below), then use one of them instead of the name specified above.
PKGNAME: vuxml
Flavors: there is no flavor information for this port.
distinfo:
SHA256 (vuxml/vuxml-10.dtd) = 6a635ad2cf45f52361c8c2a29a689157fad4d00519045485bc822d34e04a524e SIZE (vuxml/vuxml-10.dtd) = 2986 SHA256 (vuxml/vuxml-model-10.mod) = 051fed00b52bedde8ee901003fc29f7b95cd904157e31ceef34e6b06f2d1a14a

Expand this list (11 items)

Collapse this list.

SIZE (vuxml/vuxml-model-10.mod) = 10599 SHA256 (vuxml/vuxml-11.dtd) = 12b50061d7bb34cecffede2e08d439e4469324376d55aeb7c73eb6aab0f36af1 SIZE (vuxml/vuxml-11.dtd) = 3063 SHA256 (vuxml/vuxml-model-11.mod) = a40777208625a3029c6f416aeeea733f614802a6a5f26035a4e445a09e61a47c SIZE (vuxml/vuxml-model-11.mod) = 13282 SHA256 (vuxml/xml1.dcl) = 343efa94c4e1302e85e08b2d1791d86e50aac1ecdbc3161daecac100e4726847 SIZE (vuxml/xml1.dcl) = 7372 SHA256 (vuxml/catalog) = 479a69cf02995603443fd1f3b5b33f97811670931f87f53be99a727d664abc66 SIZE (vuxml/catalog) = 549 SHA256 (vuxml/catalog.xml) = 7b2e2850f57264eeba0ccd3d1fc161b9d5ce3071ae0ec51b9da7fa956f2a6509 SIZE (vuxml/catalog.xml) = 2150

Collapse this list.


Packages (timestamps in pop-ups are UTC):
vuxml
ABIaarch64amd64armv6armv7i386powerpcpowerpc64powerpc64le
FreeBSD:13:latest1.1_61.1_61.1_51.1_61.1_6n/an/an/a
FreeBSD:13:quarterly1.1_61.1_61.1_61.1_61.1_6n/an/an/a
FreeBSD:14:latest1.1_61.1_61.1_61.1_61.1_61.1_6-1.1_6
FreeBSD:14:quarterly1.1_61.1_6-1.1_61.1_61.1_61.1_61.1_6
FreeBSD:15:latest1.1_61.1_6n/a1.1_6n/an/a1.1_61.1_6
FreeBSD:15:quarterly1.1_61.1_6n/a-n/an/a--
FreeBSD:16:latest1.1_61.1_6n/a-n/an/a--
Dependencies
NOTE: FreshPorts displays only information on required and default dependencies. Optional dependencies are not covered.
Runtime dependencies:
  1. xmlcatmgr : textproc/xmlcatmgr
  2. xsltproc : textproc/libxslt
  3. VERSION : textproc/xhtml-modularization
  4. xhtml-basic10.dtd : textproc/xhtml-basic
  5. python3.11 : lang/python311
There are no ports dependent upon this port

Configuration Options:
No options to configure
Options name:
security_vuxml
USES:
python:run
FreshPorts was unable to extract/find any pkg message
Master Sites:
Expand this list (1 items)
Collapse this list.
  1. http://www.vuxml.org/dtd/vuxml-1/
Collapse this list.

Number of commits found: 8086 (showing only 100 on this page)

[First Page]  «  47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57  »  [Last Page]

Commit History - (may be incomplete: for full details, see links to repositories near top of page)
CommitCreditsLog message
1.1_1
19 Feb 2013 23:53:08
Revision:312608Original commit files touched by this commit
flo search for other commits by this committer
- update firefox to 19.0
- update firefox-esr, thunderbird, linux-firefox, linux-thunderbird to 17.0.3
- update linux-seamonkey to 2.16
- update nspr to 4.9.5
- update nss to 3.14.3
- add DuckDuckGo search plugin to firefox [1]
- mark kompozer deprecated
- clang fixes for www/libxul19 [2]

Security:	http://www.vuxml.org/freebsd/e3f0374a-7ad6-11e2-84cd-d43d7e0c7c02.html
Submitted by:	DuckDuckGo [1], dim [2]
In collaboration with:	Jan Beich <jbeich@tormail.org>
1.1_1
19 Feb 2013 00:19:14
Revision:312537Original commit files touched by this commit
zi search for other commits by this committer
- Fix version range for recent ruby vulnerabilities
(d3e96508-056b-4259-88ad-50dc8d1978a6 and c79eb109-a754-45d7-b552-a42099eb2265)
due to missing port epoch in package range

Submitted by:	Matthias Andree <mandree@FreeBSD.org>
1.1_1
17 Feb 2013 19:58:29
Revision:312441Original commit files touched by this commit
eadler search for other commits by this committer
Combine ranges into one entry to prevent false positives
1.1_1
17 Feb 2013 16:47:06
Revision:312428Original commit files touched by this commit
swills search for other commits by this committer
- Document rubygem-rack issue
1.1_1
17 Feb 2013 16:33:19
Revision:312426Original commit files touched by this commit
swills search for other commits by this committer
- Document activemodel issue
1.1_1
17 Feb 2013 10:28:54
Revision:312408Original commit files touched by this commit
lwhsu search for other commits by this committer
Document Jenkins Security Advisory 2013-02-16
1.1_1
16 Feb 2013 17:03:28
Revision:312377Original commit files touched by this commit
rm search for other commits by this committer
- add entry for dns/poweradmin

PR:		175704
Submitted by:	Edmondas Girkantas <eg@fbsd.lt> (maintainer of dns/poweradmin)
1.1_1
16 Feb 2013 14:41:44
Revision:312355Original commit files touched by this commit
swills search for other commits by this committer
- Document ruby json issue
1.1_1
16 Feb 2013 04:29:14
Revision:312323Original commit files touched by this commit
swills search for other commits by this committer
- Document vulnerability in rdoc
1.1_1
08 Feb 2013 19:18:41
Revision:311950Original commit files touched by this commit
eadler search for other commits by this committer
Update flash to the latest version

PR:		ports/175159
Submitted by:	Tsurutani Naoki <turutani@scphys.kyoto-u.ac.jp>
1.1_1
08 Feb 2013 08:44:15
Revision:311921Original commit files touched by this commit
miwi search for other commits by this committer
- Fix whitespaces
1.1_1
07 Feb 2013 02:10:29
Revision:311808Original commit files touched by this commit
eadler search for other commits by this committer
Fix vuxml build
1.1_1
06 Feb 2013 20:06:18
Revision:311791Original commit files touched by this commit
dinoex search for other commits by this committer
- report openssl vulnerabilities
1.1_1
01 Feb 2013 22:42:55
Revision:311404Original commit files touched by this commit
flo search for other commits by this committer
- update databases/mariadb-server to 5.3.12 [1]
- update databases/mariadb55-server 5.5.29 [2]

PR:		ports/175764 [1]
PR:		ports/175767 [2]
Submitted by:	Geoffroy Desvernay <dgeo@centrale-marseille.fr> (maintainer) [1]
Submitted by:	Alexandr Kovalenko <never@nevermind.kiev.ua> (maintainer) [2]
Security:	8c773d7f-6cbb-11e2-b242-c8600054b392
1.1_1
01 Feb 2013 08:50:40
Revision:311359Original commit files touched by this commit
dinoex search for other commits by this committer
- report opera 12.12 vulnerabilities
1.1_1
30 Jan 2013 18:34:03
Revision:311253Original commit files touched by this commit
pawel search for other commits by this committer
Document devel/upnp vulnerabilities
1.1_1
29 Jan 2013 20:02:38
Revision:311185Original commit files touched by this commit
delphij search for other commits by this committer
Document wordpress multiple vulnerabilities.
1.1_1
25 Jan 2013 09:37:56
Revision:310972Original commit files touched by this commit
cs search for other commits by this committer
Fix last entry: version 2.3.4 is also affected
1.1_1
25 Jan 2013 02:08:57
Revision:310957Original commit files touched by this commit
wxs search for other commits by this committer
Fix whitespace in previous commit.
1.1_1
25 Jan 2013 01:26:37
Revision:310956Original commit files touched by this commit
cs search for other commits by this committer
XSS vulnerability in py-django-cms
1.1_1
23 Jan 2013 12:52:49
Revision:310862Original commit files touched by this commit
rene search for other commits by this committer
Document vulnerabilities in www/chromium < 24.0.1312.56

Obtained
from:	http://googlechromereleases.blogspot.nl/search/label/Stable%20updates
1.1_1
20 Jan 2013 20:58:13
Revision:310718Original commit files touched by this commit
flo search for other commits by this committer
- update www/drupal6 to 6.28
- update www/drupal7 to 7.19

Security:	http://www.vuxml.org/freebsd/1827f213-633e-11e2-8d93-c8600054b392.html
Approved by:	portmgr (beat)
1.1_1
16 Jan 2013 19:16:10
Revision:310514Original commit files touched by this commit
rea search for other commits by this committer
VuXML: add newly-allocated CVE for SQUID-2012:1

New CVE was allocated for the underfixed DoS and added possible
infinite loop in Squid 3.2 and 3.1.
1.1_1
16 Jan 2013 19:13:32
Revision:310513Original commit files touched by this commit
rea search for other commits by this committer
VuXML: document buffer overflow in ettercap (CVE-2013-0722)
Reviewed by:	simon@
1.1_1
16 Jan 2013 19:11:43
Revision:310512Original commit files touched by this commit
rea search for other commits by this committer
VuXML: document recent security manager bypass in Java 7.x
Reviewed by:	glewis@, simon@
1.1_1
16 Jan 2013 07:39:28
Revision:310476Original commit files touched by this commit
delphij search for other commits by this committer
Properly limit the match for PHP 5.3.x and 5.2.x versions.

Noticed by:	remko
1.1_1
15 Jan 2013 22:06:19
Revision:310468Original commit files touched by this commit
delphij search for other commits by this committer
Apply version ranges of php53 and php52 to php5 as well.
1.1_1
11 Jan 2013 14:11:28
Revision:310235Original commit files touched by this commit
zi search for other commits by this committer
- Fix discovery date on nagios vulnerability  	(CVE-2012-6096)
1.1_1
11 Jan 2013 09:53:42
Revision:310225Original commit files touched by this commit
rea search for other commits by this committer
www/squid3x: upgrade to 3.1.23 and 3.2.6

Squid 3.1.23 is effectively Squid 3.1.22_2 with the final fix for
CVE-2012-5643 applied.

Squid 3.2.6 also received that abovementioned fix, but in comparison
with 3.2.5 from ports it has another change that fixes handling the
"tcp_outgoing_tos" directive for BSD-like systems, including FreeBSD,
  http://bugs.squid-cache.org/show_bug.cgi?id=3731

VuXML entry for SQUID:2012-1 (aka CVE-2012-5643) was also updated to
reflect the proper version specifications from the updated advisory,
  http://www.squid-cache.org/Advisories/SQUID-2012_1.txt

Approved by:	Thomas-Martin Seck <tmseck@web.de>
Security:	http://portaudit.freebsd.org/c37de843-488e-11e2-a5c9-0019996bc1f7.html
QA page:	http://codelabs.ru/fbsd/ports/qa/www/squid31/3.1.23
QA page:	http://codelabs.ru/fbsd/ports/qa/www/squid32/3.2.6
1.1_1
11 Jan 2013 01:16:14
Revision:310216Original commit files touched by this commit
zi search for other commits by this committer
- Document vulnerability in net-mgmt/nagios (CVE-2012-6096)
1.1_1
11 Jan 2013 00:32:48
Revision:310212Original commit files touched by this commit
rene search for other commits by this committer
Document vulnerabilities in www/chromium < 24.0.1312.52

Obtained
from:	http://googlechromereleases.blogspot.nl/search/label/Stable%20updates
1.1_1
09 Jan 2013 23:28:20
Revision:310165Original commit files touched by this commit
flo search for other commits by this committer
- update firefox, thunderbird, linux-firefox and linux-thunderbird to 17.0.2
- update firefox-esr, thunderbird-esr and libxul to 10.0.12
- update linux-seamonkey to 2.15

Security:	http://www.vuxml.org/freebsd/a4ed6632-5aa9-11e2-8fcb-c8600054b392.html
1.1_1
09 Jan 2013 15:03:02
Revision:310149Original commit files touched by this commit
sem search for other commits by this committer
Fix <topic> style: common dash style, remove softvare versions
1.1_1
09 Jan 2013 03:53:16
Revision:310121Original commit files touched by this commit
swills search for other commits by this committer
- Update rubygem-rails to 3.2.11
- Update ports require by rubygem-rails
- Add vuxml entry for rails security issues

Security:	ca5d3272-59e3-11e2-853b-00262d5ed8ee
Security:	b4051b52-58fa-11e2-853b-00262d5ed8ee
1.1_1
08 Jan 2013 23:46:02
Revision:310114Original commit files touched by this commit
zi search for other commits by this committer
- Properly copy namespace attributes/resolve make validate issues

Reviewed by:	simon@, eadler@
Approved by:	zi (with ports-secteam hat)
1.1_1
08 Jan 2013 05:18:15
Revision:310068Original commit files touched by this commit
lwhsu search for other commits by this committer
Document Jenkins 2013-01-04 Security Advisory
1.1_1
06 Jan 2013 20:37:24
Revision:310013Original commit files touched by this commit
rea search for other commits by this committer
VuXML: extend entry for MoinMoin vulnerabilities fixed in 1.9.6

Use more verbose descriptions from CVE entries and trim citation
from CHANGES to the relevant parts.
1.1_1
06 Jan 2013 18:14:24
Revision:310004Original commit files touched by this commit
lwhsu search for other commits by this committer
Document Django 2012-12-10 vulnerabilty
1.1_1
06 Jan 2013 13:24:39
Revision:309984Original commit files touched by this commit
rea search for other commits by this committer
VuXML: fix r309982

Use proper tags for CVE identifiers.  I should run 'make validate'
_every_ time before committing.
Pointyhat to:	rea
1.1_1
06 Jan 2013 13:10:10
Revision:309982Original commit files touched by this commit
rea search for other commits by this committer
VuXML for MoinMoin issues: add CVE references
1.1_1
05 Jan 2013 12:54:28
Revision:309958Original commit files touched by this commit
crees search for other commits by this committer
Freetype 2.4.8 vulnerabilities were already documented.

While here, correct pkgname

Noticed by:	kwm
1.1_1
05 Jan 2013 11:29:01
Revision:309954Original commit files touched by this commit
crees search for other commits by this committer
Mark moinmoin vulnerable

Security:	http://www.debian.org/security/2012/dsa-2593

document freetype vulnerabilities

Security:	CVE-2012-(1126-1144)
1.1_1
04 Jan 2013 07:30:10
Revision:309917Original commit files touched by this commit
erwin search for other commits by this committer
Bump copyright to 2013.
1.1_1
03 Jan 2013 19:46:51
Revision:309904Original commit files touched by this commit
flo search for other commits by this committer
Add correct version numbers to the recent asterisk entry

Pointy hat to:	flo
1.1_1
03 Jan 2013 19:41:31
Revision:309903Original commit files touched by this commit
flo search for other commits by this committer
- update net/asterisk to 1.8.19.1
- update net/asterisk10 to 10.11.1
- update net/asterisk11 to 10.1.2
- add vuln.xml entry

Security:	f7c87a8a-55d5-11e2-a255-c8600054b392
1.1_1
02 Jan 2013 12:28:47
Revision:309813Original commit files touched by this commit
crees search for other commits by this committer
Note charybdis and ircd-ratbox vulnerabilities

PR:		ports/174878
Security:	http://www.ratbox.org/ASA-2012-12-31.txt
1.1_1
30 Dec 2012 23:13:04
Revision:309700Original commit files touched by this commit
anders search for other commits by this committer
Separate entries for Puppet 2.6 and 2.7.
1.1_1
30 Dec 2012 20:10:42
Revision:309688Original commit files touched by this commit
cs search for other commits by this committer
Add OTRS vulnerabilities
1.1_1
29 Dec 2012 19:53:47
Revision:309629Original commit files touched by this commit
rea search for other commits by this committer
VuXML entries for Tomcat: split into three distinct ones

They affect different Tomcat versions from 7.x branch, so don't let
users of VuXML be fooled on the affected software for each vulnerability.

Feature safe:	yes
1.1_1
28 Dec 2012 18:17:22
Revision:309576Original commit files touched by this commit
rea search for other commits by this committer
VuXML: add entry for DoS in Squid's cachemgr.cgi

Feature safe:	yes
Submitted by:	Thomas-Martin Seck <tmseck@web.de>
1.1_1
18 Dec 2012 16:34:14
Revision:309196Original commit files touched by this commit
bdrewery search for other commits by this committer
Remove invalid entry
1.1_1
18 Dec 2012 16:28:57
Revision:309195Original commit files touched by this commit
dinoex search for other commits by this committer
- add entry for opera 12.11
1.1_1
14 Dec 2012 09:09:16
Revision:308891Original commit files touched by this commit
delphij search for other commits by this committer
Fix typo.

Noticed by:	mandree
1.1_1
14 Dec 2012 03:51:08
Revision:308880Original commit files touched by this commit
jgh search for other commits by this committer
- add url block in references for 1657a3e6-4585-11e2-a396-10bf48230856
1.1_1
14 Dec 2012 00:41:42
Revision:308874Original commit files touched by this commit
delphij search for other commits by this committer
Update linux-f10-flashpulgin11 to 11.2r202.258 to address multiple
vulnerabilities that could cause a crash and potentially allow an
attacker to take control of the affected system.

Submitted by:	Tsurutani Naoki <turutani scphys kyoto-u ac jp>
1.1_1
12 Dec 2012 11:33:17
Revision:308757Original commit files touched by this commit
rene search for other commits by this committer
Document vulnerabilities in www/chromium < 23.0.1271.97

Obtained
from:	http://googlechromereleases.blogspot.nl/search/label/Stable%20updates
1.1_1
05 Dec 2012 23:52:36
Revision:308355Original commit files touched by this commit
zi search for other commits by this committer
- Fix recent vulnerability entry for www/tomcat[67]

Reported by:	Victor Balada Diaz <victor@bsdes.net>
Feature safe:	yes
1.1_1
05 Dec 2012 18:47:24
Revision:308343Original commit files touched by this commit
zi search for other commits by this committer
- Document recent vulnerabilities in www/tomcat6 and www/tomcat7

Requested by:	Victor Balada Diaz <victor@bsdes.net>
Feature safe:	yes
1.1_1
05 Dec 2012 07:46:03
Revision:308317Original commit files touched by this commit
erwin search for other commits by this committer
Update to the latest patch level from ISC:

  BIND 9 nameservers using the DNS64 IPv6 transition mechanism are
  vulnerable to a software defect that allows a crafted query to
  crash the server with a REQUIRE assertion failure.  Remote
  exploitation of this defect can be achieved without extensive
  effort, resulting in a denial-of-service (DoS) vector against
  affected servers.

Security:	2892a8e2-3d68-11e2-8e01-0800273fe665
		CVE-2012-5688
Feature safe:	yes
1.1_1
03 Dec 2012 22:49:43
Revision:308178Original commit files touched by this commit
mandree search for other commits by this committer
Add URL for recent bogofilter heap vuln', CVE-2012-5468, aka. vuln vid=
f524d8e0-3d83-11e2-807a-080027ef73ec

Feature safe: yes
1.1_1
03 Dec 2012 20:16:21
Revision:308171Original commit files touched by this commit
mandree search for other commits by this committer
Update bogofilter to new upstream release 1.2.3.
Security update to fix a heap corruption bug with invalid base64 input,
reported and fixed by Julius Plenz, FU Berlin, Germany.

Feature safe:   yes
Security:       CVE-2012-5468
Security:       f524d8e0-3d83-11e2-807a-080027ef73ec
1.1_1
30 Nov 2012 09:13:32
Revision:308000Original commit files touched by this commit
rene search for other commits by this committer
Document vulnerabilities in www/chromium < 23.0.1271.95

Obtained
from:	http://googlechromereleases.blogspot.nl/search/label/Stable%20updates
Feature safe:	yes
1.1_1
29 Nov 2012 20:33:20
Revision:307978Original commit files touched by this commit
ohauer search for other commits by this committer
www/yahoo-ui
 - fix CVE-2012-5881

security/vuxml
 - adjust version (we have only 2.8.2 in the tree)

Feature safe: yes

Approved by:	glarkin (maintainer) explicit
1.1_1
28 Nov 2012 14:37:24
Revision:307907Original commit files touched by this commit
wxs search for other commits by this committer
Fix date in yahoo-ui entry.

Noticed by:	dvl@
Feature safe:	yes
1.1_1
27 Nov 2012 20:09:35
Revision:307861Original commit files touched by this commit
ohauer search for other commits by this committer
- document www/yahoo-ui security issue and mark port forbidden [1]
  pet portlint (maintainer is already notified)

- adjust CVE entries for bugzilla (CVE-2012-5475 was rejected) [2]

Feature safe: yes

Security:	CVE-2012-5881 [1][2]
		CVE-2012-5882 [1][2]
		CVE-2012-5883 [2]

Approved by:	glarkin (implicit) [1]
1.1_1
27 Nov 2012 10:02:25
Revision:307828Original commit files touched by this commit
rene search for other commits by this committer
Describe new vulnerabilities in www/chromium < 23.0.1271.91

Obtained
from:	http://googlechromereleases.blogspot.nl/search/label/Stable%20updates
Feature safe:	yes
1.1_1
25 Nov 2012 15:42:23
Revision:307747Original commit files touched by this commit
flo search for other commits by this committer
- Update backports patch to 20121114
- Bump PORTREVISION

Changes:
- CVE-2006-7243
PHP before 5.3.4 accepts the \0 character in a pathname, which might allow
context-dependent attackers to bypass intended access restrictions by placing a
safe file extension after this character, as demonstrated by .php\0.jpg at the
end of the argument to the file_exists function

Secuity 3761df02-0f9c-11e0-becc-0022156e8794 fixed by check in fopen functions
for strlen(filename) != filename_len

- CVE-2012-4388
The sapi_header_op function in main/SAPI.c does not properly determine a pointer
(Only the first 15 lines of the commit message are shown above View all of this commit message)
1.1_1
25 Nov 2012 04:02:29
Revision:307733Original commit files touched by this commit
wxs search for other commits by this committer
Add entries for the following advisories:

FreeBSD-SA-12:08.linux
FreeBSD-SA-12:07.hostapd
FreeBSD-SA-12:06.bind

Feature safe:	yes
1.1_1
22 Nov 2012 20:27:45
Revision:307666Original commit files touched by this commit
dinoex search for other commits by this committer
- opera -- execution of arbitrary code
Feature safe: yes
1.1_1
21 Nov 2012 14:35:31
Revision:307616Original commit files touched by this commit
mm search for other commits by this committer
Document new vulnerability in www/lighttpd 1.4.31

Feature safe:	yes
1.1_1
20 Nov 2012 23:01:15
Revision:307606Original commit files touched by this commit
flo search for other commits by this committer
- Update firefox and thunderbird to 17.0
- Update seamonkey to 2.14
- Update ESR ports and libxul to 10.0.11
- support more h264 codecs when using GSTREAMER with YouTube
- Unbreak firefox-esr, thunderbird-esr and libxul on head >= 1000024 [1]
- Buildsystem is not python 3 aware, use python up to 2.7 [2]

PR:		ports/173679 [1]
Submitted by:	swills [1], demon [2]
In collaboration with:	Jan Beich <jbeich@tormail.org>
Security:	d23119df-335d-11e2-b64c-c8600054b392
Approved by:	portmgr (beat)
Feature safe:	yes
1.1_1
18 Nov 2012 12:51:26
Revision:307535Original commit files touched by this commit
jase search for other commits by this committer
- Fix copy and paste error in latest weechat entry
  (81826d12-317a-11e2-9186-406186f3d89d)

Feature safe:	yes
1.1_1
18 Nov 2012 12:46:40
Revision:307534Original commit files touched by this commit
jase search for other commits by this committer
- Document new vulnerability in irc/weechat and irc/weechat-devel

Feature safe:	yes
1.1_1
14 Nov 2012 19:29:42
Revision:307425Original commit files touched by this commit
ohauer search for other commits by this committer
- bugzilla security updates to version(s)
  3.6.11, 4.0.8, 4.2.4

Summary
=======

The following security issues have been discovered in Bugzilla:

* Confidential product and component names can be disclosed to
  unauthorized users if they are used to control the visibility of
  a custom field.

* When calling the 'User.get' WebService method with a 'groups'
  argument, it is possible to check if the given group names exist
  or not.
(Only the first 15 lines of the commit message are shown above View all of this commit message)
1.1_1
13 Nov 2012 18:17:13
Revision:307387Original commit files touched by this commit
jase search for other commits by this committer
- Update recent weechat entry (e02c572f-2af0-11e2-bb44-003067b2972c)

- Document assigned CVE Identifier
- Document workaround for vulnerable versions

Feature safe:	yes
1.1_1
12 Nov 2012 21:47:27
Revision:307348Original commit files touched by this commit
rene search for other commits by this committer
Document vulnerabilities in two typo3 components.

Obtained
from:	http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2012-005/
Feature safe:	yes
1.1_1
12 Nov 2012 13:07:31
Revision:307335Original commit files touched by this commit
madpilot search for other commits by this committer
Fix typo.

Feature safe:	yes
1.1_1
12 Nov 2012 13:04:37
Revision:307334Original commit files touched by this commit
madpilot search for other commits by this committer
- Update to 2.7.1
- Convert to new options framework
- Document US-CERT VU#268267
- Trim Makefile headers

PR:		ports/173226
Submitted by:	Hirohisa Yamaguchi <umq@ueo.co.jp> (maintainer)
Feature safe:	yes
1.1_1
10 Nov 2012 15:17:31
Revision:307286Original commit files touched by this commit
swills search for other commits by this committer
- Improve latest ruby entry slightly

Feature safe:	yes
1.1_1
10 Nov 2012 14:45:55
Revision:307282Original commit files touched by this commit
jase search for other commits by this committer
- Modify recent e02c572f-2af0-11e2-bb44-003067b2972c entry

- Add constraints to vulnerable versions
- Add additional references
- Improve topic
- Correct description

Feature safe:	yes
1.1_1
10 Nov 2012 04:55:47
Revision:307263Original commit files touched by this commit
eadler search for other commits by this committer
Apply an upstream patch that fixes a security hole
when receiving a special colored message.

The maintainer was contacted but due to the nature of
the issue apply the patch ASAP.

Approved by:	secteam-ports (swills)
Security:	e02c572f-2af0-11e2-bb44-003067b2972c
Feature safe:	yes
1.1_1
10 Nov 2012 04:00:41
Revision:307261Original commit files touched by this commit
swills search for other commits by this committer
- Update lang/ruby19 to 1.9.3p327
- Document security issue in earlier versions

Security:	5e647ca3-2aea-11e2-b745-001fd0af1a4c
Feature safe:	yes
1.1_1
09 Nov 2012 23:02:15
Revision:307259Original commit files touched by this commit
jgh search for other commits by this committer
- clarification that ASF reported issue for:
 - 152e4c7e-2a2e-11e2-99c7-00a0d181e71d
 - 4ca26574-2a2c-11e2-99c7-00a0d181e71d

Feature safe:	yes
1.1_1
09 Nov 2012 19:09:32
Revision:307247Original commit files touched by this commit
jgh search for other commits by this committer
- document tomcat vulnerabilities

Feature safe:	yes
1.1_1
09 Nov 2012 04:31:14
Revision:307221Original commit files touched by this commit
eadler search for other commits by this committer
Update latest version and document security issues

PR:	ports/173487
Submitted by:	 Tsurutani Naoki <turutani@scphys.kyoto-u.ac.jp>
Security:	4b8b748e-2a24-11e2-bb44-003067b2972c
Feature safe:	yes
1.1_1
07 Nov 2012 10:15:19
Revision:307128Original commit files touched by this commit
rene search for other commits by this committer
Document new vulnerabilities in www/chromium < 23.0.1271.64

Obtained
from:	http://googlechromereleases.blogspot.nl/search/label/Stable%20updates
Feature safe:	yes
1.1_1
06 Nov 2012 20:45:14
Revision:307094Original commit files touched by this commit
crees search for other commits by this committer
Document opera vulnerabilities

Feature safe:	yes
1.1_1
05 Nov 2012 17:55:45
Revision:307020Original commit files touched by this commit
eadler search for other commits by this committer
Fix minor typo

Feature safe:	yes
1.1_1
05 Nov 2012 17:53:51
Revision:307018Original commit files touched by this commit
eadler search for other commits by this committer
Update latest version and document security issues

PR:	ports/172619
Submitted by:	tijl
Security:	36533a59-2770-11e2-bb44-003067b2972c
Feature safe:	yes
1.1_1
03 Nov 2012 11:59:52
Revision:306911Original commit files touched by this commit
crees search for other commits by this committer
Correct plural of "vulnerability"

Feature safe:	yes
1.1_1
02 Nov 2012 18:45:32
Revision:306878Original commit files touched by this commit
ohauer search for other commits by this committer
- update apache22 to version 2.22.23
- trim vuxml/Makefile header

with hat apache@

Feature safe: yes

Security:       CVE-2012-2687
1.1_1
02 Nov 2012 18:08:19
Revision:306877Original commit files touched by this commit
olgeni search for other commits by this committer
Add entry for webmin < 1.600_1 (potential XSS attack).

Feature safe:	yes
1.1_1
02 Nov 2012 03:17:18
Revision:306834Original commit files touched by this commit
bdrewery search for other commits by this committer
- Document ruby vulnerabilities:
 * CVE-2012-4464 + CVE-2012-4466
   $SAFE escaping vulnerability about Exception#to_s / NameError#to_s
 * CVE-2012-4522
   Unintentional file creation caused by inserting an illegal NUL character

Reviewed by:	eadler
Feature safe:	yes
1.1_1
01 Nov 2012 14:10:55
Revision:306803Original commit files touched by this commit
flo search for other commits by this committer
Update to 3.8.15

Security:	4b738d54-2427-11e2-9817-c8600054b392
Feature safe:	yes
1.1_1
30 Oct 2012 21:01:17
Revision:306716Original commit files touched by this commit
rm search for other commits by this committer
- update to 7.16 [1]

while here:
- trim Makefile header
- remove indefinite article in COMMENT
- remove IGNORE_WITH_PHP and IGNORE_WITH_PGSQL since
  we have not this versions in the tree anymore
- fix pkg-plist
- add vuxml entry

PR:		173211
Submitted by:	Rick van der Zwet <info at rickvanderzwet dot nl> [1]
Approved by:	Nick Hilliard <nick at foobar dot org> (maintainer)
Security:	2adc3e78-22d1-11e2-b9f0-d0df9acfd7e5
Feature safe:   yes
1.1_1
28 Oct 2012 17:03:29
Revision:306558Original commit files touched by this commit
flo search for other commits by this committer
- Update www/firefox{,-i18n} to 16.0.2
- Update seamonkey to 2.13.2
- Update ESR ports and libxul to 10.0.10
- Update nspr to 4.9.3
- Update nss to 3.14
- with GNOMEVFS2 option build its extension, too [1]
- make heap-committed and heap-dirty reporters work in about:memory
- properly mark QT4 as experimental (needs love upstream)
- *miscellaneous cleanups and fixups*

mail/thunderbird will be updated once the tarballs are available.

PR:		ports/173052 [1]
Security:	6b3b1b97-207c-11e2-a03f-c8600054b392
Feature safe:	yes
In collaboration with:	Jan Beich <jbeich@tormail.org>
1.1_1
26 Oct 2012 08:46:40
Revision:306428Original commit files touched by this commit
rea search for other commits by this committer
mail/exim: upgrade to 4.80.1

This is bugfix-only release, it eliminates remote code execution
in the DKIM code.

Security: http://www.vuxml.org/freebsd/b0f3ab1f-1f3b-11e2-8fe9-0022156e8794.html
QA page: http://codelabs.ru/fbsd/ports/qa/mail/exim/4.80.1
Feature safe: yes
1.1_1
25 Oct 2012 19:31:50
Revision:306393Original commit files touched by this commit
rm search for other commits by this committer
- add CVE reference (still in reserved state) for recent django vulnerabilty

Feature safe:	yes
1.1_1
25 Oct 2012 10:12:42
Revision:306376Original commit files touched by this commit
rm search for other commits by this committer
- update django ports to 1.3.4 and 1.4.2, that fixing couple of security issues.
  All users are encouraged to upgrade immediately.
- add vuxml entry

changes common for both ports:
- trim Makefile header
- strict python version to 2.x only
- utilize options framework multiple choice feature to let user to choose
  database backends needed. Make SQLITE option default
- shorten description of HTMLDOCS_DESC to make it fit into dialog screen
- SITELIBDIR -> PKGNAMEPREFIX change in dependencies
- convert NOPORTDOCS condition to optionsng
- tab -> space change in pkg-descr

PR:		173017
Submitted by:	rm (myself)
Approved by:	lwhsu (maintainer, by mail)
Security:	5f326d75-1db9-11e2-bc8f-d0df9acfd7e5
Feature safe:   yes
1.1_1
22 Oct 2012 02:37:08
Revision:306252Original commit files touched by this commit
wxs search for other commits by this committer
Document multiple wireshark vulnerabilities.

Feature safe:	yes

Number of commits found: 8086 (showing only 100 on this page)

[First Page]  «  47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57  »  [Last Page]