| Commit History - (may be incomplete: for full details, see links to repositories near top of page) |
| Commit | Credits | Log message |
1.1_1 05 Mar 2009 00:35:08
 |
amdmi3  |
- Document pngcrush -- libpng Uninitialised Pointer Arrays Vulnerability
Reviewed by: tabthorpe |
1.1_1 04 Mar 2009 15:30:27
 |
roam  |
Document the cURL redirection security bypass - CVE-2009-0037.
I'll update the ftp/curl port itself ASAP.
PR: 132299
Reported by: Mark Foster <mark@foster.cc> (the PR),
Daniel Bond <db@danielbond.org> (e-mail) |
1.1_1 23 Feb 2009 20:48:17
 |
marcus  |
Bump the modified date for the previous Firefox change.
Requested by: miwi |
1.1_1 23 Feb 2009 20:41:48
 |
marcus  |
Correct the Firefox 2.0 version for the recent Firefox vulnerabilities. |
1.1_1 23 Feb 2009 00:53:23
 |
mnag  |
- Add CVE entries for last lighttpd security issue.
Reported by: Eygene Ryabinkin <rea-fbsd___codelabs.ru> |
1.1_1 18 Feb 2009 18:06:37
 |
glarkin  |
- Update to 1.7.5
- Added UPDATING entry about incompatibility between 1.7.4 and 1.7.5
- Added vuln.xml entry for local file inclusion vulnerability in <1.7.5
- Added maintainer mode target in ZF Makefile to speed up fixups of
pkg-plist output from genplist
Security: cf495fd4-fdcd-11dd-9a86-0050568452ac
Security: http://framework.zend.com/issues/browse/ZF-5748
Security:
http://weierophinney.net/matthew/archives/206-Zend-Framework-1.7.5-Released-Important-Note-Regarding-Zend_View.html |
1.1_1 17 Feb 2009 21:11:06
 |
jadawin  |
- Document dia -- remote command execution vulnerability
Reviewed by: miwi |
1.1_1 15 Feb 2009 21:45:30
 |
miwi  |
- Document pycrypto -- ARC2 module buffer overflow
PR: based on 131689
Submitted by: Mark Foster <mark@foster.cc> |
1.1_1 15 Feb 2009 18:23:19
 |
marcus  |
Update the latest firefox vulnerability ranges. |
1.1_1 15 Feb 2009 13:29:57
 |
kuriyama  |
Minor whitespace nits. |
1.1_1 15 Feb 2009 13:08:20
 |
miwi  |
- Update previous entry
* remove duplicate bid entry
* add more referens
* fix whitespaces |
1.1_1 15 Feb 2009 11:06:48
 |
des  |
Document Varnish 2.0 DoS.
PR: ports/131690
Submitted by: Mark Foster <mark@foster.cc> |
1.1_1 13 Feb 2009 13:30:03
 |
miwi  |
- Document tor -- multiple vulnerabilites |
1.1_1 11 Feb 2009 19:15:08
 |
miwi  |
- Fix portaudit conflict with www/firefox and www/firefox3
- Mark www/firefox and www/linux-firefox FORBIDDEN
Discussion by: simon/stas
With hat: secteam |
1.1_1 11 Feb 2009 16:52:36
 |
miwi  |
- Fix latest firefox entry |
1.1_1 11 Feb 2009 14:37:26
 |
miwi  |
- Document firefox -- multiple vulnerabilities |
1.1_1 11 Feb 2009 14:15:25
 |
glarkin  |
- document codeigniter -- arbitrary script execution in the new
Form Validationclass |
1.1_1 11 Feb 2009 13:36:14
 |
jadawin  |
- Document pyblosxom -- atom flavor multiple XML injection vulnerabilities
Reviewed by: miwi |
1.1_1 11 Feb 2009 10:15:26
 |
miwi  |
- Document typo3 -- cross-site scripting and information disclosure |
1.1_1 10 Feb 2009 20:53:22
 |
miwi  |
- Update latest squid* entry
Add CVE-2009-0478
Submitted by: jadawin |
1.1_1 09 Feb 2009 17:55:33
 |
stas  |
- Update ruby vuxml entries due to ruby19 version bump. |
1.1_1 09 Feb 2009 15:31:02
 |
miwi  |
- Document amaya -- multiple buffer overflow vulnerabilities
PR: based on 131508
Submitted by: Mark Foster <mark@foster.cc> |
1.1_1 09 Feb 2009 14:52:55
 |
miwi  |
- Document websvn -- multiple vulnerabilities
PR: based on 130934
Submitted by: Mark Foster <mark@foster.cc> |
1.1_1 09 Feb 2009 14:20:16
 |
miwi  |
- Document phplist -- local file inclusion vulnerability
PR: based on 130932 |
1.1_1 09 Feb 2009 14:04:18
 |
miwi  |
- Document squid -- remote denial of service vulnerability
PR: based on 131431 |
1.1_1 09 Feb 2009 13:41:36
 |
miwi  |
- Fix topic s/typo/typo3 |
1.1_1 09 Feb 2009 13:30:09
 |
miwi  |
- Document typo3 -- Multiple Vulnerabilities |
1.1_1 06 Feb 2009 19:59:49
 |
miwi  |
- Fix previous entry |
1.1_1 06 Feb 2009 19:35:47
 |
tmclaugh  |
Security update for sudo to 1.6.9p20 for CVE 2009-0034
Changes:
- Only use the cached supplementory group vector when matching groups
for the invoking user. (security)
- When setting the umask, use the union of the user's umask and the
default value set in sudoers so that we never lower the user's umask
when running a command.
- Sudo now operates in the C locale again when doing a match against
sudoers.
PR: 131446
Submitted by: Eygene Ryabinkin
Security: vid:13d6d997-f455-11dd-8516-001b77d09812 |
1.1_1 04 Feb 2009 14:01:58
 |
miwi  |
- Fix a typo (s/drual/drupal) |
1.1_1 04 Feb 2009 13:53:49
 |
miwi  |
- Cleanup |
1.1_1 04 Feb 2009 13:47:09
 |
miwi  |
- Document drupal -- multible vulnerabilities |
1.1_1 04 Feb 2009 06:47:06
 |
ale  |
Update php5-gd entry. |
1.1_1 03 Feb 2009 21:42:52
 |
miwi  |
- Document perl -- Directory Permissions Race Condition
PR: based on 129317 |
1.1_1 30 Jan 2009 09:55:02
 |
miwi  |
- Rework ganglia entry
* Fix topic
* Fix discovery and entry day |
1.1_1 30 Jan 2009 09:13:58
 |
miwi  |
- Set modified for b9077cc4-6d04-4bcb-a37a-9ceaebfdcc9e entry
- more cleanup |
1.1_1 30 Jan 2009 08:59:45
 |
miwi  |
- Document moinmoin -- multiple cross site scripting vulnerabilities |
1.1_1 30 Jan 2009 08:51:50
 |
miwi  |
- Cleanup previous entry
* remove whitespaces
* sort bid/cvename/url |
1.1_1 30 Jan 2009 03:56:35
 |
brooks  |
Upgrade Ganglia to 3.1.1 plus a fix for CVE-2009-0241.
PR: ports/129822, ports/131067
Submitted by: Mark Foster <mark at foster dot cc> (vuxml)
Security: vid:b9077cc4-6d04-4bcb-a37a-9ceaebfdcc9e |
1.1_1 29 Jan 2009 22:49:10
 |
miwi  |
- Document Tor -- Unspecified Memory Corruption Vulnerability |
1.1_1 28 Jan 2009 13:11:24
 |
miwi  |
- Cleanup
* Fix whitespaces/ Tabs
* Sort <bid>/<cvename>/<url> |
1.1_1 28 Jan 2009 13:05:29
 |
miwi  |
- Rewording 2ffb1b0d-ecf5-11dd-abae-00219b0fc4d (glpi -- SQL Injection)
- Add more reference sites |
1.1_1 28 Jan 2009 05:07:48
 |
pgollucci  |
Document glpi -- SQL Injection vulnerabilty
PR: ports/131011
Submitted by: Mathias Monnerville <mathias@monnerville.com> |
1.1_1 25 Jan 2009 00:56:18
 |
tabthorpe  |
- Document openfire -- multiple vulnerabilities
PR: ports/130606
Submitted by: Mark Foster <mark foster.cc> |
1.1_1 24 Jan 2009 02:31:09
 |
delphij  |
Update information about 9fff8dc8-7aa7-11da-bf72-00123f589060
and 651996e0-fe07-11d9-8329-000e0c2e438a, newer versions of
apache+ipv6 has the problems fixed.
Submitted by: sumikawa |
1.1_1 21 Jan 2009 19:44:15
 |
wxs  |
- Document two old ipsec-tools DoS
PR: ports/129468
Submitted by: Eygene Ryabinkin <rea-fbsd@codelabs.ru> |
1.1_1 20 Jan 2009 15:20:17
 |
wxs  |
- Document directory traversal bug in teamspeak server
PR: ports/130608
Submitted by: Mark Foster <mark@foster.cc> |
1.1_1 19 Jan 2009 20:21:31
 |
wxs  |
- Document graphics/optipng buffer overflow
PR: ports/129072
Submitted by: Eygene Ryabinkin <rea-fbsd@codelabs.ru> |
1.1_1 19 Jan 2009 20:04:50
 |
wxs  |
- Document old gitweb privilege escalation vulnerability.
PR: ports/130600
Submitted by: Eygene Ryabinkin <rea-fbsd@codelabs.ru> |
1.1_1 16 Jan 2009 16:11:04
 |
naddy  |
Document vulnerability in older versions of GNU tar.
PR: 130602
Submitted by: Mark Foster <mark@foster.cc> |
1.1_1 16 Jan 2009 00:02:53
 |
miwi  |
- Mark net-mgmt/nagios2 as secure |
1.1_1 15 Jan 2009 23:00:51
 |
miwi  |
- Document mplayer -- vulnerability in STR files processor
PR: based on 130573 |
1.1_1 13 Jan 2009 12:22:21
 |
miwi  |
- Cleanup previous entry
- Add more references |
1.1_1 13 Jan 2009 03:30:53
 |
wxs  |
- Add missing blockquote and linewrap properly |
1.1_1 13 Jan 2009 03:19:19
 |
wxs  |
- Document cgiwrap XSS vulnerability
PR: ports/130277
Submitted by: Eric W. Bates <ericx@vineyard.net> |
1.1_1 12 Jan 2009 12:27:39
 |
miwi  |
- Document nagios -- web interface privilege escalation vulnerability |
1.1_1 11 Jan 2009 19:58:49
 |
miwi  |
- Document pdfjam -- insecure temporary files
PR: based on 130028 |
1.1_1 11 Jan 2009 19:35:56
 |
miwi  |
- Document verlihub -- insecure temporary file usage and arbitrary command
execution |
1.1_1 11 Jan 2009 18:16:13
 |
miwi  |
- Document mysql -- empty bit-string literal denial of service
PR: based on 129978
Submitted by: Eygene Ryabinkin <rea-fbsd@codelabs.ru> |
1.1_1 11 Jan 2009 15:38:48
 |
miwi  |
- Fix discovery date |
1.1_1 11 Jan 2009 15:27:57
 |
miwi  |
- Document mysql multiple vulnerabilities:
* mysql -- renaming of arbitrary tables by authenticated users
* mysql -- remote Denial of Service via malformed password packet
* mysql -- privilege escalation and overwrite of the system table
information
PR: based on 130025
Submitted by: Eygene Ryabinkin <rea-fbsd@codelabs.ru> |
1.1_1 11 Jan 2009 14:49:32
 |
miwi  |
- Document imap-uw -- imap c-client buffer overflow
PR: 130013
Submitted by: Mark Foster <mark@foster.cc>
Approved by: maintainer timeout |
1.1_1 11 Jan 2009 14:32:43
 |
miwi  |
- Fix a small typo |
1.1_1 11 Jan 2009 14:29:50
 |
miwi  |
- Document imap-uw -- local buffer overflow vulnerabilities
PR: 128923
Submitted by: Mark Foster <mark@foster.cc>
Approved by: maintainer timeout |
1.1_1 11 Jan 2009 13:15:54
 |
miwi  |
- Document libcdaudio -- remote buffer overflow and code execution |
1.1_1 06 Jan 2009 04:31:42
 |
tabthorpe  |
- Mark xterm 238 safe |
1.1_1 05 Jan 2009 10:09:57
 |
remko  |
Import latest FreeBSD-SA's so that we are up to date again. |
1.1_1 05 Jan 2009 09:40:29
 |
stas  |
- Document xterm vulnerability. |
1.1_1 05 Jan 2009 09:06:12
 |
stas  |
- Document PHP gd library vulnerability. |
1.1_1 04 Jan 2009 09:13:16
 |
miwi  |
- Update awstats entry (also affect www/awstats-devel) |
1.1_1 04 Jan 2009 08:01:22
 |
chinsan  |
- Fix the affected version of awstats |
1.1_1 04 Jan 2009 06:21:42
 |
chinsan  |
- Document awstats -- multiple XSS vulnerabilities
PR: ports/129957
Submitted by: Eygene Ryabinkin <rea-fbsd _at\ codelabs.ru>
Approved by: Alex Samorukov (maintainer)
Security: http://secunia.com/advisories/31519 |
1.1_1 03 Jan 2009 12:35:32
 |
miwi  |
- Cleanup (fix whitespaces, typos) |
1.1_1 03 Jan 2009 12:06:45
 |
chinsan  |
- Completely fix CVE-2005-0448
PR: ports/129301
Submitted by: Eygene Ryabinkin <rea-fbsd@codelabs.ru> |
1.1_1 02 Jan 2009 09:56:29
 |
erwin  |
Bump copyright year. |
1.1_1 02 Jan 2009 04:44:10
 |
tabthorpe  |
- Document vim -- multiple vulnerabilities in the netrw module
PR: ports/129137
Submitted by: Eygene Ryabinkin <rea-fbsd codelabs.ru> |
1.1_1 31 Dec 2008 21:23:01
 |
mezz  |
Add vinagre -- format string vulnerability entry.
PR: ports/129959
Submitted by: Eygene Ryabinkin <rea-fbsd@codelabs.ru> |
1.1_1 30 Dec 2008 19:16:15
 |
glarkin  |
Document twiki - multiple vulnerabilities |
1.1_1 30 Dec 2008 17:09:02
 |
ale  |
Add entry for roundcube.
Submitted by: Eygene Ryabinkin <rea-fbsd@codelabs.ru> |
1.1_1 30 Dec 2008 11:12:39
 |
miwi  |
- Document mysql -- MyISAM table privileges security bypass vulnerability for
symlinked paths |
1.1_1 30 Dec 2008 09:29:18
 |
miwi  |
- Document mplayer -- twinvq processing buffer overflow vulnerability
Reported by: Thomas Zander <riggs@rrr.de> (mplayer maintainer) |
1.1_1 26 Dec 2008 09:22:47
 |
jadawin  |
- ampache -- insecure temporary file usage |
1.1_1 25 Dec 2008 16:41:55
 |
miwi  |
- Small cleanup for the last cups-base entry
* CVE-2008-5184 was fixed in 1.3.8.
* CVE-2008-1722 does not related to anything in this entry;
* PNG buffer overflow is really CVE-2008-5286.
Reported by: Eygene Ryabinkin <rea-fbsd@codelabs.ru>
No Cookies for: miwi |
1.1_1 19 Dec 2008 21:07:07
 |
miwi  |
- Document opera -- multiple vulnerabilities |
1.1_1 19 Dec 2008 21:00:00
 |
miwi  |
- Document mediawiki -- multiple vulnerabilities |
1.1_1 19 Dec 2008 20:36:51
 |
miwi  |
- Fix make validate |
1.1_1 19 Dec 2008 20:29:46
 |
miwi  |
- document drupal -- Multiple vulnerabilities |
1.1_1 19 Dec 2008 20:01:32
 |
miwi  |
- Document mozilla -- multiple vulnerabilities |
1.1_1 11 Dec 2008 19:39:06
 |
miwi  |
- Fix a small typo |
1.1_1 11 Dec 2008 19:37:42
 |
miwi  |
- Document phpmyadmin -- cross-site request forgery vulnerability |
1.1_1 08 Dec 2008 14:15:34
 |
tabthorpe  |
- Document php5 -- potential magic_quotes_gpc vulnerability
Reviewed by: miwi |
1.1_1 07 Dec 2008 19:13:45
 |
miwi  |
- Fix a typo
Reported by: Eygene Ryabinkin <rea-fbsd@codelabs.ru> |
1.1_1 07 Dec 2008 18:11:30
 |
miwi  |
- Document wireshark -- SMTP Processing Denial of Service Vulnerability |
1.1_1 07 Dec 2008 12:13:14
 |
miwi  |
- Document php -- multiple vulnerabilities |
1.1_1 07 Dec 2008 11:41:32
 |
miwi  |
- Document mgetty+sendfax -- symlink attack via insecure temporary files
PR: based on 129471
Submitted by: Eygene Ryabinkin <rea-fbsd@codelabs.ru> |
1.1_1 07 Dec 2008 11:32:08
 |
miwi  |
- Document dovecot-managesieve -- Script Name Directory Traversal Vulnerability
PR: based on 129303
Submitted by: Eygene Ryabinkin <rea-fbsd@codelabs.ru> |
1.1_1 07 Dec 2008 11:20:17
 |
miwi  |
Document habari -- Cross-Site Scripting Vulnerability
PR: 129475
Submitted by: Ayumi M <ayu@dahlia.commun.jp> |
1.1_1 07 Dec 2008 09:09:23
 |
miwi  |
- Add 32545 to the latest vlc entry. |
1.1_1 06 Dec 2008 23:47:28
 |
miwi  |
- Document vlc -- arbitrary code execution in the RealMedia processor |
1.1_1 06 Dec 2008 23:18:46
 |
miwi  |
- S/secunia/Secunia |