Commit History - (may be incomplete: for full details, see links to repositories near top of page) |
Commit | Credits | Log message |
1.1_1 04 Sep 2009 08:18:06
 |
miwi  |
- Mark seamonkey as safe |
1.1_1 04 Sep 2009 08:02:40
 |
miwi  |
- Update latest Opera entry,
* add missing linux-opera
* fix topic |
1.1_1 04 Sep 2009 07:26:23
 |
jadawin  |
- Fix vuxml build
Pointyhat to: me |
1.1_1 04 Sep 2009 07:12:24
 |
jadawin  |
- Fix vuxml build
Pointyhat to: itetcu |
1.1_1 04 Sep 2009 05:59:39
 |
itetcu  |
Add an atry for opera < 10.00
PR: 138449
Submitted by: maintainer |
1.1_1 02 Sep 2009 12:32:23
 |
miwi  |
- Fix cvenames |
1.1_1 02 Sep 2009 11:42:22
 |
miwi  |
- Document dnsmasq -- TFTP server remote code injection vulnerability
PR: 138418 (based on)
Submitted by: Matthias Andree <matthias.andree@gmx.de> |
1.1_1 25 Aug 2009 08:20:28
 |
kuriyama  |
- I cannot confirm these vulns can be affected to 1.3.x and 2.0.x
lines. Limit this entry to 2.2.x until confirmed. |
1.1_1 25 Aug 2009 06:47:18
 |
kuriyama  |
Add apache-2.2.12 fixes. |
1.1_1 22 Aug 2009 11:48:56
 |
beat  |
- Mark thunderbird 2.0.0.23 and higher as safe
Approved by: secteam (miwi) |
1.1_1 20 Aug 2009 19:37:44
 |
wxs  |
- Document pidgin, libpurple, and finch memory corruption.
PR: ports/137997
Submitted by: Armin Pirkovitsch <armin@frozen-zone.org> |
1.1_1 17 Aug 2009 14:37:29
 |
wxs  |
- Document NUL byte problem in gnutls and gnutls-devel
- Document multiple vulnerabilities in older versions[1]
Note: These have all been fixed with the exception of the NUL byte problem
in gnutls-devel.
PR: [1]: ports/134785
Submitted by: [1]: Eygene Ryabinkin <rea-fbsd@codelabs.ru>
Reviewed by: miwi |
1.1_1 17 Aug 2009 13:26:56
 |
mnag  |
- memcached -- memcached stats maps Information Disclosure Weakness
PR: 134206
Submitted by: Mark Foster <mark___foster.cc> |
1.1_1 13 Aug 2009 09:55:14
 |
miwi  |
- Update latest wordpress entry
* add wordpress-mu which was also affected
- Mark latest fetchmail entry as safe |
1.1_1 12 Aug 2009 14:57:25
 |
skreuzer  |
Document remote admin password reset vulnerability in wordpress <= 3.8.3
Reviewed by: simon |
1.1_1 11 Aug 2009 14:54:15
 |
amdmi3  |
- Document fetchmail -- improper SSL certificate subject verification |
1.1_1 11 Aug 2009 13:35:16
 |
skreuzer  |
Fix typo in affected version number for vid
739b94a4-838b-11de-938e-003048590f9e
Submitted by: Roberto Nunnari <robi@nunnisoft.ch> (Private eMail)
Reviewed by: simon |
1.1_1 07 Aug 2009 21:24:48
 |
skreuzer  |
- Fix improper formatting reported by miwi
- Add additioinal reference url for vid 739b94a4-838b-11de-938e-003048590f9e
reported by miwi
Reviewed by: miwi |
1.1_1 07 Aug 2009 20:06:24
 |
skreuzer  |
Document com_mailto Timeout Issue in www/joomla15 |
1.1_1 07 Aug 2009 16:30:31
 |
simon  |
Cleanup whitespace and XML format using 'make tidy' and a bit manual
editing. |
1.1_1 07 Aug 2009 16:25:53
 |
simon  |
When running the tidy target:
- Pipe ouput into vuln.xml.tidy instead of stdout.
- Don't hide what command we are running so it's clear where the tidy
version of the output went. |
1.1_1 07 Aug 2009 13:18:43
 |
simon  |
Various affects fixes to the last 3 Mozilla/Firefox entries to make then
match correctly against package names. In particular the port name
instead of package name was used in a couple of places. For Seamonkey
and Thunderbird where no known fixes exist don't include a fixed
version. |
1.1_1 07 Aug 2009 10:48:56
 |
miwi  |
- Update previous subversion entry,
add missing p5-subversion and py-subversion |
1.1_1 07 Aug 2009 09:31:30
 |
miwi  |
- Fix latest firefox entry.
Reported by: b.f <bf1793@gmail.com> |
1.1_1 06 Aug 2009 21:41:57
 |
simon  |
Document subversion -- heap overflow vulnerability. |
1.1_1 05 Aug 2009 23:23:27
 |
simon  |
Add a few CVE names to the 'squid -- several remote denial of service
vulnerabilities' entry. |
1.1_1 05 Aug 2009 23:19:37
 |
simon  |
Document bugzilla -- product name information leak. |
1.1_1 04 Aug 2009 23:15:12
 |
miwi  |
- Mark squid 3.1.0.12 as safe |
1.1_1 04 Aug 2009 22:57:02
 |
miwi  |
- Document mozilla -- multiple vulnerabilities |
1.1_1 04 Aug 2009 18:20:18
 |
wxs  |
- Add bind9-sdb-ldap and bind9-sdb-postgresql to recent BIND DoS.
Reviewed by: miwi |
1.1_1 04 Aug 2009 18:06:59
 |
wxs  |
- Document silc-client and silc-irssi-plugin format string vulnerability.
Reviewed by: miwi |
1.1_1 02 Aug 2009 14:11:24
 |
thierry  |
Mark mail/squirrelmail-multilogin-plugin as FORBIDDEN and add the
corresponding entry in VuXML.
Security: VuXML: 0d0237d0-7f68-11de-984d-0011098ad87f |
1.1_1 01 Aug 2009 14:25:45
 |
wxs  |
- White space fixes and correct the entry date in
vid 83725c91-7c7e-11de-9672-00e0815b8da8 |
1.1_1 01 Aug 2009 14:17:30
 |
wxs  |
s/package/system/ for vid fbc8413f-2f7a-11de-9a3f-001b77d09812.
Reviewed by: remko
Approved by: secteam (remko) |
1.1_1 01 Aug 2009 14:13:24
 |
wxs  |
- Document BIND DoS in base and ports.
Reviewed by: remko
Approved by: secteam (remko) |
1.1_1 29 Jul 2009 16:17:18
 |
miwi  |
- Close tag |
1.1_1 29 Jul 2009 16:00:53
 |
miwi  |
- Document Mono XML Signature HMAC Truncation Spoofing |
1.1_1 27 Jul 2009 19:39:34
 |
delphij  |
Document squid remote denial of service vulnerabilities.
Submitted by: Thomas-Martin Seck <tmseck@web.de>
PR: ports/137184 |
1.1_1 22 Jul 2009 00:11:48
 |
jpaetzel  |
Fix security advsory with patches from Ubuntu project.
http://vuxml.FreeBSD.org/c444c8b7-7169-11de-9ab7-000c29a67389.html
PR: ports/136891
Submitted by: wxs@
Reviewed by: simon@
Approved by: itetcu@ (mentor) |
1.1_1 17 Jul 2009 10:18:30
 |
miwi  |
- Fix a typo |
1.1_1 17 Jul 2009 07:58:06
 |
miwi  |
- Document firefox35 -- corrupt JIT state after deep return from native function |
1.1_1 15 Jul 2009 18:34:19
 |
wxs  |
- Document isc-dhcp*-client stack overflow. |
1.1_1 14 Jul 2009 03:17:17
 |
wxs  |
- Tweak nagios version information a bit for the command injection
vulnerability. Patches for net-mgmt/nagios and net-mgmt/nagios2 coming
shortly. |
1.1_1 13 Jul 2009 19:01:17
 |
miwi  |
- Document drupal -- multiple vulnerabilities
Submitted by: Nick Hilliard (based on) |
1.1_1 12 Jul 2009 13:51:05
 |
beat  |
- Mark linux-firefox 3.0.11 and higher as safe
Approved by: secteam (miwi) |
1.1_1 03 Jul 2009 01:35:18
 |
wxs  |
- Document remote command execution in net-mgmt/nfsen
PR: ports/136070
Submitted by: Bjoern Engels <engels@openit.de> |
1.1_1 02 Jul 2009 20:38:11
 |
wxs  |
- Add syslog-ng package to the list of vulnerable versions for the chroot
vulnerability. |
1.1_1 01 Jul 2009 13:01:54
 |
wxs  |
- Add newly created CVE for nagios command injection vulnerability.
- Add the other two nagios packages to the list.
- Add modified entry accordingly. |
1.1_1 30 Jun 2009 19:10:50
 |
delphij  |
Document phpMyAdmin XSS vulnerability |
1.1_1 30 Jun 2009 14:13:03
 |
wxs  |
- Document nagios command injection vulnerability. |
1.1_1 24 Jun 2009 16:54:17
 |
wxs  |
- s/secunia reports/Secnuia reports/
- Fix whitespace
Approved by: secteam (miwi) |
1.1_1 23 Jun 2009 13:03:52
 |
wxs  |
- Document tor-devel DNS resolution issue.
PR: ports/135925
Submitted by: bf <bf1783@gmail.com> |
1.1_1 16 Jun 2009 20:59:01
 |
miwi  |
- Document cscope -- multiple buffer overflows
PR: 135097
Submitted by: Eygene Ryabinkin <rea-fbsd@codelabs.ru> |
1.1_1 16 Jun 2009 20:52:44
 |
miwi  |
- Document cscope -- buffer overflow
PR: based on 135097
Submitted by: Eygene Ryabinkin <rea-fbsd@codelabs.ru> |
1.1_1 16 Jun 2009 20:45:46
 |
miwi  |
- Fix a typo from previous commit |
1.1_1 16 Jun 2009 20:10:47
 |
skreuzer  |
Document joomla -- multiple vulnerabilities
Approved by: wxs (mentor) |
1.1_1 16 Jun 2009 20:04:13
 |
miwi  |
- Document pidgin -- multiple vulnerabilities
PR: 135239 (based on)
Submitted by: Eygene Ryabinkin <rea-fbsd@codelabs.ru> |
1.1_1 15 Jun 2009 13:57:19
 |
wxs  |
- Document git-daemon DoS. |
1.1_1 12 Jun 2009 22:46:49
 |
stas  |
- Fix the latest ruby entry: 1.9 branch is not vulnerable. |
1.1_1 12 Jun 2009 22:07:41
 |
stas  |
- Document ruby denial of sevice vulnerability in BigDecimal. |
1.1_1 12 Jun 2009 15:40:58
 |
beat  |
- Fix firefox3 version in da185955-5738-11de-b857-000f20797ede
Approved by: miwi (secteam) |
1.1_1 12 Jun 2009 14:55:51
 |
beat  |
- Document mozilla -- multiple vulnerabilities
Approved by: miwi (secteam) |
1.1_1 08 Jun 2009 06:19:48
 |
miwi  |
- Add some more cve to the previous entry |
1.1_1 08 Jun 2009 06:17:53
 |
miwi  |
- Fix previous entry |
1.1_1 08 Jun 2009 02:21:53
 |
pgollucci  |
Document DOS in apr-util xml(expat) processing
Submitted by: Eygene Ryabinkin <rea-fbsd@codelabs.ru> |
1.1_1 04 Jun 2009 21:52:26
 |
delphij  |
Document dokuwiki local File Inclusion with register_globals on vulnerability. |
1.1_1 30 May 2009 20:53:22
 |
miwi  |
- Document openssl -- denial of service in DTLS implementation
PR: based on 134653
Submitted by: Eygene Ryabinkin <rea-fbsd@codelabs.ru> |
1.1_1 30 May 2009 20:39:39
 |
miwi  |
- Document eggdrop -- denial of service vulnerability |
1.1_1 30 May 2009 20:07:42
 |
miwi  |
- Document wireshark -- Denial of Service in the PCNFSD dissector
PR: 135061 (based on)
Submitted by: Eygene Ryabinkin <rea-fbsd@codelabs.ru> |
1.1_1 30 May 2009 19:23:41
 |
miwi  |
- Add more infos for libsndfile entry |
1.1_1 30 May 2009 19:16:35
 |
miwi  |
- Document libsndfile -- multiple vulnerabilities |
1.1_1 30 May 2009 19:07:01
 |
miwi  |
- Document slim -- local disclosure of X authority magic cookie |
1.1_1 23 May 2009 10:50:54
 |
miwi  |
- Cleanup previous entry |
1.1_1 23 May 2009 09:15:36
 |
simon  |
Unbreak file by removing double <vuxml> tag. |
1.1_1 23 May 2009 04:37:11
 |
cy  |
Add CVE information for NTP stack overflow.
PR: 134755
Submitted by: Mark Foster <mark@foster.cc>
Security: CVE-2009-0159 and CVE-2009-1252 |
1.1_1 22 May 2009 16:34:03
 |
miwi  |
- Fix 5ed2f96b-33b7-4863-8c6b-540d22344424
* Remove duplicte url
* Fix safe version
* Bump modified date |
1.1_1 22 May 2009 16:08:21
 |
miwi  |
- Bump modified date for previous commit. |
1.1_1 22 May 2009 13:15:34
 |
wxs  |
- Add CVE information for nsd overflow.
- s/over flow/overflow/ for the same entry.
Submitted by: Eygene Ryabinkin <rea-fbsd@codelabs.ru> (private mail) |
1.1_1 21 May 2009 15:30:42
 |
pav  |
- Document imap-uw -- University of Washington IMAP c-client Remote Format
String Vulnerability (submitted back in Feb 2009)
PR: ports/131939
Submitted by: Mark Foster <mark@foster.cc> |
1.1_1 19 May 2009 17:20:27
 |
wxs  |
- Document dns/nsd and dns/nsd2 one-byte overflow (both are already fixed
in ports). Still need a CVE entry but there is not one assigned yet. |
1.1_1 17 May 2009 15:05:20
 |
nobutaka  |
Add entries of libxine vulnerabilities fixed in version 1.1.16.2 and 1.1.16.3.
PR: ports/132593
Submitted by: Eygene Ryabinkin <rea-fbsd@codelabs.ru> |
1.1_1 16 May 2009 20:36:19
 |
miwi  |
- Document php -- ini database truncation inside dba_replace() function
PR: 129459 (based on)
Submitted by: Eygene Ryabinkin <rea-fbsd@codelabs.ru> |
1.1_1 16 May 2009 20:09:00
 |
miwi  |
- Document libwmf -- embedded GD library Use-After-Free vulnerability
PR: based on 134246 |
1.1_1 16 May 2009 19:59:44
 |
miwi  |
- Document libwmf -- Integer Overflow Vulnerability
PR: based on 134246 |
1.1_1 16 May 2009 13:01:26
 |
miwi  |
- Document moinmoin -- cross-site scripting vulnerabilities |
1.1_1 16 May 2009 12:51:24
 |
miwi  |
- Rework previus entry |
1.1_1 16 May 2009 01:32:37
 |
pgollucci  |
- Document mod_perl -- cross site scripting in Apache::Status |
1.1_1 16 May 2009 00:44:25
 |
miwi  |
- Small cleanup
* fix spelling
* fix tabs/whitespaces
* add more references to the latest drual entry |
1.1_1 16 May 2009 00:36:02
 |
miwi  |
- Fix formating |
1.1_1 15 May 2009 22:26:01
 |
delphij  |
Document drupal -- cross-site scripting vulnerability.
Submitted by: Nick Hilliard <nick foobar org> |
1.1_1 15 May 2009 01:49:18
 |
ume  |
- Document cyrus-sasl -- buffer overflow vulnerability |
1.1_1 13 May 2009 10:07:30
 |
miwi  |
- Document moinmoin -- multiple cross site scripting vulnerabilities
PR: based on 134467 |
1.1_1 13 May 2009 08:23:57
 |
miwi  |
- Document ghostscript8 -- Buffer Overflow Vulnerability
PR: 133331 (baesed on) |
1.1_1 13 May 2009 08:10:48
 |
miwi  |
- Cleanup |
1.1_1 13 May 2009 07:55:07
 |
miwi  |
- Added a referece to the latest pango entry
(4b172278-3f46-11de-becb-001cc0377035) |
1.1_1 12 May 2009 23:03:02
 |
stas  |
- Document pango buffer overflow vulnerability. |
1.1_1 09 May 2009 20:13:24
 |
marcus  |
Document the recent Wireshark vulnerabilities.
PR: 134245
Submitted by: Eygene Ryabinkin <rea-fbsd@codelabs.ru> |
1.1_1 07 May 2009 14:46:03
 |
wxs  |
- Add CVE entry for quagga vulnerability.
Submitted by: Eygene Ryabinkin <rea-fbsd@codelabs.ru> (private mail) |
1.1_1 07 May 2009 07:57:05
 |
dinoex  |
- add CUPS 1.3.10
PR: 134247 |
1.1_1 07 May 2009 07:40:39
 |
dinoex  |
- add SA-09:08.openssl
PR: 133156 |