| Commit History - (may be incomplete: for full details, see links to repositories near top of page) |
| Commit | Credits | Log message |
1.1_1 20 Oct 2011 11:01:41
 |
flo  |
add an entry for the recent piwik vulnerability, with the little information
that's available.
The only known fact is that Piwik rates this update critical. |
1.1_1 18 Oct 2011 18:53:16
 |
delphij  |
Fix discovery date. |
1.1_1 18 Oct 2011 18:24:29
 |
kwm  |
Document a File disclosure vulnerability and File permission change
vulnerability
in xorg-server.
Obtained from:
http://lists.freedesktop.org/archives/xorg-announce/2011-October/001744.html
upstream xorg-server
Security: CVE-2011-4028, CVE-2011-4029 |
1.1_1 17 Oct 2011 19:49:23
 |
amdmi3  |
- Fix entry dates for recently added OpenTTD vulns
Submitted by: "Ilya A. Arkhipov" <micro@heavennet.ru> |
1.1_1 17 Oct 2011 19:02:23
 |
delphij  |
Document asterisk -- remote crash vulnerability in SIP channel driver. |
1.1_1 17 Oct 2011 18:54:31
 |
delphij  |
Commit result of manually merged make tidy output. |
1.1_1 17 Oct 2011 18:52:16
 |
delphij  |
Document PivotX remote file inclusion vulnerability.
PR: ports/161734
Submitted by: Fumiyuki Shimizu <fumifumi abacustech jp> |
1.1_1 17 Oct 2011 03:50:23
 |
amdmi3  |
- Fix quotation links
Reported by: danfe |
1.1_1 16 Oct 2011 18:39:44
 |
amdmi3  |
Document openttd multiple vulnerabilities
PR: 161488
Submitted by: "Ilya A. Arkhipov" <micro@heavennet.ru> |
1.1_1 08 Oct 2011 10:56:33
 |
mandree  |
ca_root_nss - fix capitalization of topics
Security: 1b27af46-d6f6-11e0-89a6-080027ef73ec
Security: aa5bc971-d635-11e0-b3cf-080027ef73ec |
1.1_1 08 Oct 2011 10:54:58
 |
mandree  |
ca_root_nss - reword topic for clarity
Security: 1b27af46-d6f6-11e0-89a6-080027ef73ec |
1.1_1 07 Oct 2011 07:32:11
 |
novel  |
Be less grubby in specifying vulnerable gnutls-devel versions. |
1.1_1 06 Oct 2011 00:25:58
 |
jlaffaye  |
Latest pyblosxom version is not vulnerable |
1.1_1 05 Oct 2011 20:44:30
 |
delphij  |
Document quagga multiple vulnerabilities |
1.1_1 04 Oct 2011 18:24:47
 |
rene  |
Document latest vulnerabilities for www/chromium
Obtained from: http://googlechromereleases.blogspot.com/
Security: CVE-2011-[2876-2881, 3873] |
1.1_1 30 Sep 2011 18:06:53
 |
delphij  |
Correct tomcat version represetations.
Pointed out by: Tim Zingelman <tez netbsd.org> |
1.1_1 28 Sep 2011 15:58:02
 |
beat  |
- Document mozilla -- multiple vulnerabilities |
1.1_1 23 Sep 2011 20:02:19
 |
delphij  |
Properly mark version range for horde-imp. |
1.1_1 22 Sep 2011 20:47:10
 |
nox  |
- Update linux-f10-flashplugin to 10.3r183.10 . [1]
- Make gnome desktopfileutils dependency optional. [2]
PR: ports/160894 [1]
Submitted by: Garrett Cooper <yanegomi@gmail.com> [1]
Suggested by: Peter Jeremy <peterjeremy@acm.org> [2]
Security:
http://www.freebsd.org/ports/portaudit/53e531a7-e559-11e0-b481-001b2134ef46.html |
1.1_1 21 Sep 2011 11:35:28
 |
zi  |
Improve accuracy of krb5 vulnerability entries for upcoming port addition of
krb5-17.
(one entry was missed from the previous commit) |
1.1_1 21 Sep 2011 02:21:25
 |
zi  |
Improve accuracy of krb5 vulnerability entries for upcoming port addition
of krb5-17. |
1.1_1 20 Sep 2011 18:24:20
 |
rene  |
Document vulnerabilities in Chromium 13.0.x.y
Obtained from: http://googlechromereleases.blogspot.com/
Security: CVE-2011-[2834-2838, 2840-2844, 2846-2862, 2864, 2874-2875,
3234] |
1.1_1 14 Sep 2011 23:26:28
 |
delphij  |
Document phpMyAdmin multiple XSS vulnerability.
Update phpMyAdminn to 3.4.5 release. [1]
PR: ports/160589 [1]
Submitted by: maitainer [1] |
1.1_1 13 Sep 2011 17:50:29
 |
delphij  |
Document Django multiple vulnerabilities. |
1.1_1 13 Sep 2011 01:11:03
 |
delphij  |
Document roundcube XSS vulnerability. |
1.1_1 12 Sep 2011 18:38:31
 |
olgeni  |
Document libsndfile -- PAF file processing integer overflow.
Security: CVE-2011-2696 |
1.1_1 10 Sep 2011 07:41:22
 |
ashish  |
Re-revise emacs vulnerability to limit with >= 22 and < 22.2_1 instead of
>21.* and <22.2_1 which didn't work as expected |
1.1_1 08 Sep 2011 22:30:43
 |
ashish  |
- Limit emacs vulnerability to > 21.* and <= 22.2 instead of just <= 22.2 |
1.1_1 07 Sep 2011 18:30:42
 |
delphij  |
Document two OpenSSL vulnerabilities.
(There is no OpenSSL 0.9.8s in the ports so mark <1.0.0 as vulnerable). |
1.1_1 06 Sep 2011 21:12:04
 |
flo  |
fix last thunderbird entry |
1.1_1 06 Sep 2011 20:12:45
 |
flo  |
add firefox, thunderbird and seamonkey to the DigiNotar.nl entry
Security:
http://www.vuxml.org/freebsd/aa5bc971-d635-11e0-b3cf-080027ef73ec.html |
1.1_1 05 Sep 2011 16:24:22
 |
bapt  |
Fix vuln.xml, while here fix indentation |
1.1_1 05 Sep 2011 15:55:38
 |
eadler  |
- Update to 1.2.7
PR: ports/160368
Submitted by: gjb
Approved by: dvl (maintainer), bapt (mentor)
Security: CVE-2011-2938 |
1.1_1 04 Sep 2011 20:15:52
 |
crees  |
- Document cfs buffer overflow vulnerability.
- While here, unbreak packaudit -- it doesn't like newlines in the
middle of tags. Perhaps a comment should say something? |
1.1_1 04 Sep 2011 13:14:22
 |
mandree  |
Revise nss/ca_root_nss working around Mozilla,
limit ca_root_nss vuln to < 3.12.11 from <= 3.12.11.
Add a new entry for the ca_root_nss bug that caused extraction of untrusted
certificates to the trust bundle.
PR: ports/160455 |
1.1_1 04 Sep 2011 11:46:47
 |
sunpoet  |
- Correct affected plone versions |
1.1_1 04 Sep 2011 04:09:43
 |
dinoex  |
- bump modifiled for CVE-2007-5137 |
1.1_1 03 Sep 2011 16:28:49
 |
dinoex  |
- update CVE-2007-5137 |
1.1_1 03 Sep 2011 16:18:19
 |
mandree  |
Update range to exclude nss 3.12.11 from vuln, as kwm@'s commit
to upgrade nss to 3.12.11 included the newer CKBI 1.87 that explicitly
distrusts DigiNotar. |
1.1_1 03 Sep 2011 15:43:39
 |
mandree  |
Add a security notice for the DigiNotar incident, listing nss/ca_root/nss. |
1.1_1 03 Sep 2011 12:49:13
 |
flo  |
- only match vulnerable versions in the hlstats entry
- add additional CVEs |
1.1_1 02 Sep 2011 17:15:58
 |
crees  |
Final modification for apache22 vulnerability; include slave ports as well
Pointed out by: flo
Reviewed by: eadler |
1.1_1 01 Sep 2011 19:06:27
 |
crees  |
Correct range for apache22, 2.2.20 is fixed and 1.3 wasn't affected.
Submitted by: Aleksandr Stankevic (sysmonk on IRC/Freenode##FreeBSD)
Security: CVE-2011-3192 |
1.1_1 30 Aug 2011 22:29:14
 |
shaun  |
Put a lower bound on the last php entry, as the bug was introduced in
5.3.7-RC5.
Submitted by: "jaset" via #bsdports |
1.1_1 30 Aug 2011 13:21:27
 |
sbz  |
- Fix entry date and use two ranges
Reviewed by: gahr@
Approved by: jadawin@ (mentor) |
1.1_1 30 Aug 2011 12:01:13
 |
sbz  |
- Document CVE-2011-3192 for recent apache DoS vulnerability
Approved by: jadawin@ (mentor)
Security:
http://vuxml.org/freebsd/7f6108d2-cea8-11e0-9d58-0800279895ea.html |
1.1_1 26 Aug 2011 18:12:00
 |
delphij  |
Upstream indicates that this only affects 4.40 and 4.41 so add a <ge> tag
to indicate that. |
1.1_1 26 Aug 2011 18:10:39
 |
delphij  |
Document stunnel heap corruption vulnerability. |
1.1_1 24 Aug 2011 22:43:04
 |
bapt  |
Fix discovery date |
1.1_1 24 Aug 2011 22:20:14
 |
delphij  |
DOcument phpMyAdmin CVE-2011-3181 (multiple XSS). |
1.1_1 23 Aug 2011 17:02:34
 |
rene  |
Document new Chromium vulnerabilities.
Obtained from: http://google-chrome-browser.com/releases
Security: CVE-2011-[2821, 2823-2829, 2839] |
1.1_1 23 Aug 2011 00:58:34
 |
delphij  |
Mark PHP5 < 5.3.7_2 as vulnerable to PHP bug #55439: crypt() returns only
the salt for MD5. |
1.1_1 20 Aug 2011 00:43:49
 |
delphij  |
Document multiple PHP vulnerabilities. |
1.1_1 19 Aug 2011 18:42:12
 |
delphij  |
Document Rails multiple vulnerabilities. |
1.1_1 19 Aug 2011 17:46:10
 |
delphij  |
Document dovecot DoS vulnerability. |
1.1_1 18 Aug 2011 19:06:26
 |
skv  |
Document "otrs" - vulnerabilities in OTRS-Core allows read access
to any file on local file system. |
1.1_1 16 Aug 2011 18:12:50
 |
flo  |
document recent mozilla vulnerabilities |
1.1_1 16 Aug 2011 17:36:06
 |
delphij  |
Document samba vulnerabilities of SWAT web interface. |
1.1_1 15 Aug 2011 20:00:37
 |
wxs  |
Adjust dates in 510b630e-c43b-11e0-916c-00e0815b8da8.
Noticed by: kwm@ |
1.1_1 14 Aug 2011 01:41:10
 |
wxs  |
- Document ISC DHCP server DoS. |
1.1_1 13 Aug 2011 18:19:06
 |
skv  |
Document "bugzilla" - multiple vulnerabilities. |
1.1_1 13 Aug 2011 15:02:29
 |
crees  |
Document dtc security issues
PR: ports/159736
Submitted by: Ansgar Burchardt <ansgar@debian.org> |
1.1_1 11 Aug 2011 08:37:56
 |
kwm  |
Document freetype2 and libXfont vulnabilities. |
1.1_1 10 Aug 2011 20:27:26
 |
nox  |
Update linux-f10-flashplugin to 10.3r183.5 .
Submitted by: pointyhat via erwin
Security:
http://www.freebsd.org/ports/portaudit/2c12ae0c-c38d-11e0-8eb7-001b2134ef46.html |
1.1_1 02 Aug 2011 17:57:05
 |
rene  |
Document new vulnerabilities for www/chromium ( < 13.0.782.107)
Obtained from: http://googlechromereleases.blogspot.com/
Security: CVE-2011-{2358-2361, 2782-2805, 2818-2819} |
1.1_1 28 Jul 2011 19:18:37
 |
kwm  |
Document libsoup security hole. |
1.1_1 28 Jul 2011 07:10:38
 |
delphij  |
Fix match of phpmyadmin in recent revisions. |
1.1_1 26 Jul 2011 02:12:47
 |
swills  |
- Add CVE reference for OpenSAML2 issue
- Use official citation |
1.1_1 26 Jul 2011 01:12:25
 |
zi  |
Document phpmyadmin vulnerabilities
Approved by: wxs (mentor) |
1.1_1 25 Jul 2011 23:47:57
 |
swills  |
Document OpenSAML2 issue |
1.1_1 20 Jul 2011 20:50:19
 |
delphij  |
Document rsync DoS issue (CVE-2011-1097). |
1.1_1 05 Jul 2011 23:39:46
 |
dougb  |
Document BIND vulnerabilities for ports. This was inspired by the PR,
but re-formatted and edited by me, so responsibility for errors is mine.
PR: ports/158672
Submitted by: Ryan Steinmetz <rpsfa@rit.edu> |
1.1_1 03 Jul 2011 13:32:49
 |
jlaffaye  |
Document phpMyAdmin multiple vulnerabilities
Reviewed by: flo
Approved by: rene (mentor vacation) |
1.1_1 29 Jun 2011 10:15:18
 |
flo  |
document one more vulnerability in the recent asterisk entry |
1.1_1 28 Jun 2011 22:50:51
 |
rene  |
Document new vulnerabilities for www/chromium ( < 12.0.742.112)
Security: CVE-2011-[2345-2351] |
1.1_1 28 Jun 2011 00:57:09
 |
wxs  |
Add modified tag to 8a5770b4-54b5-11db-a5ae-00508d6a62df.
Noticed by: sahil@ |
1.1_1 27 Jun 2011 14:39:37
 |
wxs  |
Now that www/mambo is updated, fix the range in
8a5770b4-54b5-11db-a5ae-00508d6a62df. |
1.1_1 25 Jun 2011 22:48:01
 |
flo  |
document recent asterisk vulnerabilities |
1.1_1 24 Jun 2011 13:46:51
 |
ashish  |
- Document ejabberd vulnerability fixed in 2.1.8
PR: ports/158137
Submitted by: Ruslan Mahamatkhanov <cvs-src@yandex.ru>
Security:
http://vuxml.org/freebsd/01d3ab7d-9c43-11e0-bc0f-0014a5e3cda6.html |
1.1_1 23 Jun 2011 12:36:04
 |
flo  |
- also mark firefox35 vulnerable |
1.1_1 21 Jun 2011 20:26:57
 |
flo  |
- document recent mozilla vulnerabilities [1]
- while here also document an older samba Denial of service vulnerability [2]
Security:
http://www.vuxml.org/freebsd/dfe40cff-9c3f-11e0-9bec-6c626dd55a41.html [1]
http://www.vuxml.org/freebsd/bfdbc7ec-9c3f-11e0-9bec-6c626dd55a41.html [2]
Requested by: timur [2] |
1.1_1 21 Jun 2011 17:50:00
 |
culot  |
Document piwik remote command execution vulnerability. |
1.1_1 20 Jun 2011 22:59:44
 |
delphij  |
Document dokuwiki XSS vulnerability. |
1.1_1 15 Jun 2011 19:53:02
 |
nox  |
Update linux-f10-flashplugin to 10.3r181.26 .
PR: ports/157900
Submitted by: Tsurutani Naoki <turutani@scphys.kyoto-u.ac.jp>
Security:
http://www.freebsd.org/ports/portaudit/55a528e8-9787-11e0-b24a-001b2134ef46.html |
1.1_1 15 Jun 2011 12:43:37
 |
brix  |
- Document CVE-2011-1408 in www/ikiwiki |
1.1_1 12 Jun 2011 05:15:32
 |
miwi  |
- Cleanup |
1.1_1 08 Jun 2011 20:49:57
 |
nox  |
Update to 10.3r181.22 .
PR: ports/157696
Submitted by: Tsurutani Naoki <turutani@scphys.kyoto-u.ac.jp>
Security:
http://www.freebsd.org/ports/portaudit/57573136-920e-11e0-bdc9-001b2134ef46.html |
1.1_1 07 Jun 2011 17:30:30
 |
rene  |
Document www/chromium vulnerabilities fixed in version 12.0.742.91
Security: CVE-2011-{1808-1819,2332,2342} |
1.1_1 07 Jun 2011 00:24:35
 |
wxs  |
- Document CVE-2011-1910
PR: ports/157548
Submitted by: Ryan Steinmetz <rpsfa@rit.edu> |
1.1_1 06 Jun 2011 12:45:20
 |
mandree  |
Add CVE-2011-1947: fetchmail STARTTLS denial of service. |
1.1_1 03 Jun 2011 03:36:15
 |
miwi  |
- Cleanup |
1.1_1 02 Jun 2011 20:39:54
 |
flo  |
- document asterisk remote crash vulnerability
Security:
http://www.vuxml.org/freebsd/34ce5817-8d56-11e0-b5a2-6c626dd55a41.html |
1.1_1 02 Jun 2011 14:19:28
 |
lev  |
Document CVE-2011-1752, CVE-2011-1783 and CVE-2011-1921 in devel/subversion |
1.1_1 26 May 2011 13:54:08
 |
wxs  |
Document drupal6 multiple vulnerabilities.
Submitted by: Nick Hilliard <nick@foobar.org> |
1.1_1 25 May 2011 21:14:43
 |
olgeni  |
Document Erlang R14B02 ssh library vulnerability (cryptographically
weak RNG).
Security: CVE-2011-0766 |
1.1_1 25 May 2011 16:38:56
 |
rene  |
Document latest www/chromium vulnerabilities.
Security: CVE-2011-1801, -1804, -1806, -1807 |
1.1_1 25 May 2011 10:58:15
 |
miwi  |
- Cleanup Part 1
PS: wonder when pplz start to ask ports-security for review ... |
1.1_1 25 May 2011 09:44:01
 |
sem  |
- Document the last unbound vulnerability |
1.1_1 24 May 2011 23:51:21
 |
ohauer  |
- revert last change of apr-* entry
Broken build reported by wxs@ |
1.1_1 24 May 2011 22:59:52
 |
ohauer  |
- use apr-* and add <gt></gt> entries for all apr0/apr1 issues
(<gt> .. is needed else the parser cannot make a difference
between apr0 and apr1)
- lowercase ViewVC -> viewvc
Thanks Jun Kuriyama ( kuriyama@ ) for the notice and the patch
for the apr entries. |