| Commit History - (may be incomplete: for full details, see links to repositories near top of page) |
| Commit | Credits | Log message |
1.1_1 29 Nov 2008 16:24:42
 |
miwi  |
- Fix discovery from previous entry |
1.1_1 29 Nov 2008 16:16:02
 |
miwi  |
- Document openoffice -- arbitrary code execution vulnerabilities
PR: based on 129192
Submitted by: Eygene Ryabinkin <rea-fbsd@codelabs.ru> |
1.1_1 29 Nov 2008 15:15:33
 |
miwi  |
- Document wordpress -- Header RSS Feed Script Insertion Vulnerability |
1.1_1 29 Nov 2008 14:31:33
 |
miwi  |
- Document samba -- potential leakage of arbitrary memory contents
- Fix my previous entry |
1.1_1 29 Nov 2008 13:48:44
 |
miwi  |
- Document hplip -- hpssd Denial of Service
PR: based on 129097
Submitted by: Eygene Ryabinkin |
1.1_1 29 Nov 2008 13:04:55
 |
miwi  |
- Document cups -- multiple vulnerabilities |
1.1_1 24 Nov 2008 17:47:53
 |
stas  |
- Document a buffer overflow vulnerability in imlib2.
PR: ports/129037
Submitted by: Eygene Ryabinkin <rea-fbsd@codelabs.ru> |
1.1_1 23 Nov 2008 16:04:36
 |
miwi  |
- Fix latest mozilla entry
Note:
mail/thunderbird and mail/linux-thunderbird versions are wrong.
All problems are fixed in 2.0.0.18 and not in 2.0.0.17.
Pointy hat to: tabthorpe |
1.1_1 23 Nov 2008 08:38:54
 |
miwi  |
- Document streamripper -- multiple buffer overflows
PR: based on 128999 |
1.1_1 22 Nov 2008 22:01:10
 |
miwi  |
- Dokument -- Mantis: Session hijacking vulnerability |
1.1_1 22 Nov 2008 21:46:05
 |
miwi  |
- Cleanup
- Fix a lot whitespaces |
1.1_1 19 Nov 2008 22:37:18
 |
delphij  |
Document two ACL bypassing vulnerabilities of dovecot.
Submitted by: Eygene Ryabinkin <rea-fbsd codelabs.ru> (with changes)
PR: ports/129000 |
1.1_1 19 Nov 2008 21:07:47
 |
tabthorpe  |
- Document libxml2 -- multiple vulnerabilities |
1.1_1 19 Nov 2008 15:24:44
 |
tabthorpe  |
- Document openfire -- multiple vulnerabilities |
1.1_1 18 Nov 2008 23:07:15
 |
wxs  |
Document syslog-ng2 chroot vulnerability.
PR: ports/128960
Submitted by: Eygene Ryabinkin <rea-fbsd@codelabs.ru>
Reviewed by: tabthorpe |
1.1_1 18 Nov 2008 15:34:11
 |
rafan  |
- Add a missing new line between entries |
1.1_1 18 Nov 2008 15:33:34
 |
rafan  |
- Add an entry for print/enscript and its slave ports
PR: ports/128958
Submitted by: Eygene Ryabinkin <rea-fbsd at codelabs.ru> (based on)
Reviewed by: stas@ |
1.1_1 17 Nov 2008 19:02:06
 |
wxs  |
Add CVE identifier for clamav off-by-one error.
PR: ports/128924
Submitted by: Mark Foster <mark@foster.cc> |
1.1_1 16 Nov 2008 10:01:28
 |
stas  |
- Fix an indentation in the latest net-snmp entry. |
1.1_1 16 Nov 2008 09:59:35
 |
stas  |
- Document the recent chain validation vulnerability in gnutls.
PR: ports/128868
Submitted by: Eygene Ryabinkin <rea-fbsd@codelabs.ru> (based on) |
1.1_1 15 Nov 2008 17:04:30
 |
miwi  |
- Fix formating |
1.1_1 14 Nov 2008 06:16:44
 |
kuriyama  |
Add entry for net-snmp (fix will be followed).
PR: ports128772, ports/128837
Submitted by: "Mark D. Foster" <mark@foster.cc>,
Eygene Ryabinkin <rea-fbsd@codelabs.ru> |
1.1_1 13 Nov 2008 20:43:58
 |
miwi  |
- Cleanup
* Add some more references to the faad2 entry
* Fix formating for the last emacs and trac entry |
1.1_1 13 Nov 2008 18:24:31
 |
tabthorpe  |
- Document mozilla -- multiple vulnerabilities
Reviewed by: simon |
1.1_1 12 Nov 2008 17:06:56
 |
tabthorpe  |
- Document faad2 -- heap overflow vulnerability |
1.1_1 11 Nov 2008 22:22:15
 |
miwi  |
- Fix multimedia/vlc entry |
1.1_1 10 Nov 2008 22:50:28
 |
bsam  |
Document vulnerability in Emacs python integration.
PR: 127168
Submitted by: keramida |
1.1_1 10 Nov 2008 11:53:00
 |
garga  |
- Document clamav get_unicode_name() off-by-one buffer overflow, 0.94.1 have
fixed the problem [1]
- Since i'm here, document clamav-devel either
PR: ports/128749 [1]
Submitted by: Eygene Ryabinkin <rea-fbsd@codelabs.ru> [1] |
1.1_1 09 Nov 2008 03:46:45
 |
delphij  |
Document trac wiki markup DoS issue |
1.1_1 08 Nov 2008 21:30:14
 |
miwi  |
- Document vlc -- cue processing stack overflow |
1.1_1 03 Nov 2008 19:17:53
 |
remko  |
Document opera -- multiple vulnerabilities
With hat: secteam
Requested by: simon |
1.1_1 02 Nov 2008 22:47:41
 |
nox  |
Document qemu -- Heap overflow in Cirrus emulation |
1.1_1 01 Nov 2008 00:21:34
 |
delphij  |
Fix BugTraq ID :(
Pointy hat to: delphij |
1.1_1 31 Oct 2008 23:58:02
 |
delphij  |
Add more reference with last commit |
1.1_1 31 Oct 2008 23:52:28
 |
delphij  |
Document phpmyadmin XSS issue |
1.1_1 29 Oct 2008 06:16:26
 |
mezz  |
Add linux-opera with opera entries. Remove the YYYYMMDD in the version (ie:
9.61.YYYYMMDD -> 9.61) as linux-opera does not do it anymore. It should not
affect anything on opera. |
1.1_1 28 Oct 2008 21:04:29
 |
miwi  |
- Fix formating |
1.1_1 28 Oct 2008 20:05:44
 |
tabthorpe  |
- Document opera -- multiple vulnerabilities
PR: ports/128264
Submitted by: Arjan van Leeuwen <freebsd-maintainer opera.com> |
1.1_1 27 Oct 2008 18:47:05
 |
tabthorpe  |
- Document libspf2 -- Buffer overflow |
1.1_1 25 Oct 2008 20:13:08
 |
miwi  |
- Document openx -- sql injection vulnerability |
1.1_1 25 Oct 2008 19:09:24
 |
miwi  |
- Fix duplicate wording |
1.1_1 25 Oct 2008 18:51:13
 |
miwi  |
- Document flyspray -- multiple vulnerabilities
Submitted by: Nick Hilliard (nick@foobar.org) (based on) |
1.1_1 24 Oct 2008 19:13:15
 |
delphij  |
Document wordpress snoopy shell command execution vulnerability |
1.1_1 24 Oct 2008 16:56:30
 |
miwi  |
- Fix libxine entry |
1.1_1 22 Oct 2008 21:02:51
 |
stas  |
- Whitespace fix in last entry. |
1.1_1 22 Oct 2008 20:55:59
 |
delphij  |
Document drupal multiple vulnerabilities.
Submitted by: Nick Hilliard <nick foobar org> |
1.1_1 22 Oct 2008 20:02:12
 |
delphij  |
Newer version of wordpress-mu has resolved the security vulnerability,
I have verified the code with respect to older release and to wordpress
changeset.
Reviewed by: stas |
1.1_1 20 Oct 2008 16:19:08
 |
mezz  |
The libxml2-2.6.32_1 now have two security fixed. If I edit it incorrect,
please fix it for me. |
1.1_1 19 Oct 2008 13:21:12
 |
nobutaka  |
Document libxine denial of service vulnerability. |
1.1_1 18 Oct 2008 12:52:11
 |
miwi  |
- Fix formating from previous entry |
1.1_1 18 Oct 2008 02:15:23
 |
tabthorpe  |
- Fix previous commit |
1.1_1 17 Oct 2008 22:31:17
 |
tabthorpe  |
- Document linux-flashplugin -- multiple vulnerabilities
Reviewed by: stas |
1.1_1 15 Oct 2008 09:19:59
 |
delphij  |
Document libxml2 vulnerabilities. |
1.1_1 12 Oct 2008 16:49:39
 |
miwi  |
- Fix a small typo |
1.1_1 12 Oct 2008 16:37:10
 |
miwi  |
- Document drupal -- multiple vulnerabilities |
1.1_1 10 Oct 2008 22:40:01
 |
delphij  |
Document cups multiple vulnerabilities. |
1.1_1 10 Oct 2008 18:58:32
 |
ale  |
Update mysql entries. |
1.1_1 10 Oct 2008 10:00:19
 |
miwi  |
- Fix formating and remove whitespaces from previous commit. |
1.1_1 10 Oct 2008 09:41:09
 |
itetcu  |
Add two www/opera vulnarabilities which affect versions <9.60.20081004
PR: ports/127941
Submitted by: Arjan van Leeuwen (opera maintainer) |
1.1_1 02 Oct 2008 22:37:27
 |
stas  |
- Capitalize "Secunia" word in all entries.
Reviewed by: tabthorpe |
1.1_1 01 Oct 2008 21:31:33
 |
stas  |
- Mplayer vulnerability has been fixed in 0.99.11_7. |
1.1_1 30 Sep 2008 20:46:02
 |
stas  |
- Document mysql-client input validation vulnerability. |
1.1_1 30 Sep 2008 20:13:08
 |
stas  |
- Document mplayer integer overflows. |
1.1_1 29 Sep 2008 22:56:48
 |
simon  |
Bump copyright year. |
1.1_1 29 Sep 2008 22:45:46
 |
simon  |
Really fix firefox 3 part of the latest mozilla entry. Now it doesn't
match fixed firefox 2 versions.
Cluebat: Eygene Ryabinkin <rea-fbsd@codelabs.ru>
Pointyhat: simon (for too quick review of last update) |
1.1_1 29 Sep 2008 11:46:06
 |
miwi  |
- Fix bad firefox3 specification
PR: 127712
Reported by: Eygene Ryabinkin <rea-fbsd@codelabs.ru>
Reviewed by: simon |
1.1_1 27 Sep 2008 23:48:48
 |
mnag  |
lighttpd -- multiple vulnerabilities |
1.1_1 26 Sep 2008 23:07:17
 |
miwi  |
- Fix last thunderbird entrys
- Bump modified date |
1.1_1 26 Sep 2008 21:43:26
 |
miwi  |
- Cleanup previous entry. |
1.1_1 26 Sep 2008 21:38:31
 |
brix  |
Add irc/bitlbee entry. |
1.1_1 26 Sep 2008 21:10:18
 |
simon  |
- Update samba entries so they don't match upcomming Samba 3.2 which
doesn't have PORTEPOCH in the version number.
- Bump modified date for all updated entries.
Requested by: timur |
1.1_1 24 Sep 2008 14:59:54
 |
miwi  |
- Fix firefox version
Reported by: bsam@ |
1.1_1 24 Sep 2008 12:39:42
 |
miwi  |
- Fix a typo (s/reportss/reports)
Submitted by: tabthorpe/remko |
1.1_1 24 Sep 2008 12:09:44
 |
miwi  |
- Document mozilla -- multiple vulnerabilities |
1.1_1 23 Sep 2008 21:51:39
 |
miwi  |
- Mark ftp/proftpd as safe
- Add more references to the last phpMyAdmin entry |
1.1_1 23 Sep 2008 19:13:12
 |
tabthorpe  |
- Document squirrelmail -- Session hijacking vulnerability |
1.1_1 23 Sep 2008 10:07:44
 |
miwi  |
- Fix discovery from my previous commit |
1.1_1 23 Sep 2008 10:06:00
 |
miwi  |
- Document proftpd -- Long Command Processing Vulnerability |
1.1_1 23 Sep 2008 09:21:19
 |
miwi  |
- Document phpmyadmin -- cross-site scripting vulnerability |
1.1_1 19 Sep 2008 20:44:08
 |
miwi  |
- Document gallery -- multiple vulnerabilities
Approved by: portmgr (secteam blanked) |
1.1_1 17 Sep 2008 17:10:49
 |
miwi  |
- Replace phpmyadmin with phpMyAdmin to fix portaudit
Note:
portaudit does not flag phpmyadmin as vulnerable,
so we need to change it to the pkgname (phpMyAdmin).
Reported by: glarkin@
Reviewed by: simon
Discussion on: ports-security@
Approved by: portmgr (secteam blanked) |
1.1_1 17 Sep 2008 08:41:27
 |
miwi  |
- Document phpmyadmin -- Code execution vulnerability
Approved by: portmgr (secteam blanked) |
1.1_1 15 Sep 2008 09:07:31
 |
miwi  |
- Fix previous commit
Approved by: portmgr (secteam blanked) |
1.1_1 15 Sep 2008 02:03:18
 |
glarkin  |
- Mark www/twiki FORBIDDEN due to security exploit
Approved by: beech (mentor, implicit)
Approved by: portmgr (pav)
Security: http://twiki.org/cgi-bin/view/Codev/SecurityAlert-CVE-2008-3195 |
1.1_1 12 Sep 2008 09:41:16
 |
miwi  |
- corrects the bid number from me previous commit
Approved by: portmgr (secteam blanked) |
1.1_1 12 Sep 2008 09:12:18
 |
miwi  |
- Document neon -- NULL pointer dereference in Digest domain support
Approved by: portmgr (secteam blanked) |
1.1_1 12 Sep 2008 04:31:17
 |
delphij  |
Document clamav CHM parser DoS issue.
Approved by: portmgr (vuxml blanket) |
1.1_1 11 Sep 2008 11:45:37
 |
miwi  |
- Document horde -- multiple vulnerabilities
Approved by: portmgr (secteam blanked) |
1.1_1 11 Sep 2008 07:52:32
 |
miwi  |
- Document python -- multiple vulnerabilities
Reviewed by: remko/tabthorpe
Approved by: portmgr (secteam blanked) |
1.1_1 10 Sep 2008 12:09:27
 |
miwi  |
- Mark www/wordpress and german/wordpress as safe
Approved by: portmgr (secteam approved: remko, blanket vuxml) |
1.1_1 10 Sep 2008 10:53:03
 |
stas  |
- Document wordpress, rails and mysql vulnerabilties.
Reviewed by: remko
Approved by: portmgr (secteam approved: remko, blanket vuxml) |
1.1_1 08 Sep 2008 22:33:54
 |
brd  |
Extend the Nagios entry to cover Nagios 3.x < 3.0.2. This covers the edge case
of `portupgrade -o net-mgmt/nagios-devel nagios'.
Approved by: portmgr (simon@ using secteam blanket) |
1.1_1 05 Sep 2008 16:44:26
 |
remko  |
Add FreeBSD-SA-08:09.icmp6 |
1.1_1 05 Sep 2008 16:39:02
 |
remko  |
Add FreeBSD-SA-08:08.nmount |
1.1_1 05 Sep 2008 16:34:12
 |
remko  |
Add FreeBSD-SA-08:07.amd64.
Hat: secteam |
1.1_1 04 Sep 2008 14:00:12
 |
ale  |
Update for php5 safe_mode fix. |
1.1_1 26 Aug 2008 19:34:35
 |
simon  |
Fix XML in openvpn-devel entry: – was used but as vuln.xml does
not import HTML named entities this is not allowed - use –
instead which produces the same end result. |
1.1_1 25 Aug 2008 22:12:34
 |
miwi  |
- Document opera -- multiple vulnerabilities |
1.1_1 21 Aug 2008 02:32:39
 |
mnag  |
gnutls -- "gnutls_handshake()" Denial of Service |
1.1_1 20 Aug 2008 23:37:41
 |
delphij  |
Use joomla15 as name for the vulnerability |