Commit History - (may be incomplete: for full details, see links to repositories near top of page) |
Commit | Credits | Log message |
1.1_1 18 Apr 2006 19:39:22
 |
simon  |
Add some CERT references to latest Mozilla entry. |
1.1_1 18 Apr 2006 13:48:47
 |
mnag  |
plone -- "member_id" Parameter Portrait Manipulation Vulnerability |
1.1_1 16 Apr 2006 22:02:11
 |
simon  |
Fix copy/paste error in last commit and mark linux-mozilla < 1.7.13 as
vulnerable. |
1.1_1 16 Apr 2006 21:52:31
 |
simon  |
Document mozilla/firefox/thunderbirds's latest attempt at Internet
Explorer compatibility.
Note that I omitted marking some really old mozilla versions as
vulnerable this time, since there is already a bunch of entries
covering these versions (which haven't been in ports for a while). |
1.1_1 16 Apr 2006 13:00:05
 |
ehaupt  |
Update entry for sysutils/heartbeat. The insecure temporary file creation
vulnerability is fixed in 1.2.4.
Approved by: secteam (simon) |
1.1_1 16 Apr 2006 01:52:17
 |
mnag  |
mailman -- Private Archive Script Cross-Site Scripting |
1.1_1 10 Apr 2006 19:11:15
 |
remko  |
Document f2c -- insecure temporary files.
It is not very clear to me to see what version is fixed. The one fixing
this port should import the latest available one which is fixed. |
1.1_1 08 Apr 2006 14:53:01
 |
mnag  |
mplayer -- Multiple integer overflows |
1.1_1 07 Apr 2006 14:15:02
 |
mnag  |
- Add Secunia references for last phpMyAdmin issue. |
1.1_1 07 Apr 2006 11:23:07
 |
remko  |
Document kaffeine -- buffer overflow vulnerability. |
1.1_1 07 Apr 2006 10:38:53
 |
remko  |
Document thunderbird -- javascript execution. |
1.1_1 06 Apr 2006 17:30:16
 |
remko  |
Update the latest zoo entry to match the latest update to the port.
This will mark zoo-2.10.1_2 and later as not vulnerable for this
issue. |
1.1_1 06 Apr 2006 16:44:46
 |
mnag  |
phpmyadmin -- XSS vulnerabilities
phpmyadmin -- 'set_theme' Cross-Site Scripting |
1.1_1 06 Apr 2006 15:30:13
 |
mnag  |
clamav -- Multiple Vulnerabilities |
1.1_1 06 Apr 2006 04:47:47
 |
remko  |
Add cvename to the recent OpenVPN entry.
Submitted by: Matthias Andree <matthias dot andree at gmx dot de> |
1.1_1 05 Apr 2006 20:00:18
 |
remko  |
Document mediawiki -- hardcoded placeholder string security bypass
vulnerability. |
1.1_1 05 Apr 2006 19:50:25
 |
remko  |
Document netpbm -- buffer overflow in pnmtopng. |
1.1_1 05 Apr 2006 19:23:10
 |
remko  |
Document zoo -- stack based buffer overflow. |
1.1_1 05 Apr 2006 19:02:44
 |
remko  |
Document mediawiki -- cross site scripting vulnerability. |
1.1_1 05 Apr 2006 17:37:38
 |
mnag  |
dia -- XFig Import Plugin Buffer Overflow |
1.1_1 05 Apr 2006 14:57:46
 |
mnag  |
openvpn -- LD_PRELOAD code execution on client through malicious or compromised
server
PR: 95343
Submitted by: Matthias Andree <matthias.andree__gmx.de> |
1.1_1 05 Apr 2006 04:33:25
 |
mnag  |
samba -- Exposure of machine account credentials in winbind log files |
1.1_1 05 Apr 2006 03:46:56
 |
brooks  |
Upgrade pubcookie from 3.3.0-beta2 to 3.3.0a fixing serious XSS
vulnerabilities. |
1.1_1 01 Apr 2006 05:01:12
 |
edwin  |
Fill in the version numbers for the vids
6e3b12e2-6ce3-11da-b90c-000e0c2e438a and
82a41084-6ce7-11da-b90c-000e0c2e438a to show which Mantis versions
are vulnerable.
Submitted by: In cooperation with dvl |
1.1_1 30 Mar 2006 06:53:31
 |
simon  |
For horde -- remote code execution vulnerability in the help viewer
entry:
- Add more references.
- Reformat description to follow normal formatting style better.
- Remove a redundant line in the description to make the meaning more
clear. |
1.1_1 29 Mar 2006 19:08:51
 |
mnag  |
freeradius -- EAP-MSCHAPv2 Authentication Bypass |
1.1_1 28 Mar 2006 18:13:15
 |
thierry  |
Add an entry about Horde's remote code execution vulnerability in the
help viewer. |
1.1_1 27 Mar 2006 19:06:54
 |
mnag  |
linux-realplayer -- buffer overrun
linux-realplayer -- heap overflow
Reviewed by: simon |
1.1_1 24 Mar 2006 18:02:29
 |
remko  |
s/8 spaces/tab/ in the sendmail entry.
Noticed by: simon |
1.1_1 24 Mar 2006 17:10:24
 |
remko  |
Record that our sendmail port was also vulnerable.
Bump modification date. |
1.1_1 24 Mar 2006 13:08:54
 |
remko  |
Update the 'Evolution - remote format string vulnerabilities' entry. |
1.1_1 24 Mar 2006 12:25:59
 |
remko  |
Document the latest three FreeBSD Security Advisories:
SA-06:13
SA-06:12
SA-06:11 |
1.1_1 21 Mar 2006 17:05:15
 |
lesi  |
xorg-server -- privilege escalation
Reviewed by: simon |
1.1_1 20 Mar 2006 15:21:49
 |
mnag  |
- heimdal -- Multiple vulnerabilities
Reviewed by: simon |
1.1_1 20 Mar 2006 12:58:16
 |
vd  |
Document ftp/curl's TFTP packet buffer overflow vulnerability
Reworked by: simon
Approved by: security-officer (simon) |
1.1_1 17 Mar 2006 23:24:43
 |
brooks  |
Add drupal <= 4.6.5 vulns. |
1.1_1 15 Mar 2006 21:27:34
 |
thierry  |
Add an entry for Horde < 3.1 (SA19246).
Noticed by: mnag |
1.1_1 15 Mar 2006 07:10:35
 |
simon  |
Document linux-flashplugin -- arbitrary code execution vulnerability. |
1.1_1 12 Mar 2006 21:25:13
 |
remko  |
Document nfs -- remote denial of service (FreeBSD: SA-06:10)
Approved by: portmgr (blanket VuXML) |
1.1_1 12 Mar 2006 19:57:53
 |
remko  |
Add OpenSSH Remote Denial of Service (FreeBSD SA-06:09.openssh) to the
vuxml list.
Approved by: portmgr (Blanket VuXML) |
1.1_1 11 Mar 2006 10:38:11
 |
remko  |
Correct the gpg entry wrt. style.
Approved by: portmgr (Blanket VuXML) |
1.1_1 09 Mar 2006 22:44:23
 |
kuriyama  |
Update to 1.4.2.2.
Security: GnuPG does not detect injection of unsigned data
References:
http://lists.gnupg.org/pipermail/gnupg-announce/2006q1/000216.html
Probbed by: simon
Approved by: portmgr (erwin) |
1.1_1 09 Mar 2006 10:53:15
 |
vd  |
Document multimedia/mplayer's heap overflow in the ASF demuxer
Reviewed by: simon
Approved by: portmgr (implicit), security-officer (simon) |
1.1_1 06 Mar 2006 12:15:26
 |
marius  |
Add the ssh2-nox11 slave port to the list of ports affected by
VID 594ad3c5-a39b-11da-926c-0800209adf0e.
Prodded by: Dmitry Pryanishnikov <dmitry@atlantis.dp.ua>
Approved by: portmgr (erwin) |
1.1_1 04 Mar 2006 17:31:07
 |
marius  |
Document a SSH.COM SFTP server format string vulnerability affecting
the security/ssh2 port.
Approved by: portmgr (erwin) |
1.1_1 04 Mar 2006 15:03:46
 |
naddy  |
Document GNU tar invalid headers buffer overflow.
Approved by: portmgr (erwin) |
1.1_1 27 Feb 2006 20:16:34
 |
remko  |
Remove the pinentry entry. It was gentoo specific and I overlooked
that.
Noticed by: Dejan Lesjak <dejan dot lesjak at ijs dot si>
Pointyhat: remko
Approved by: portmgr (implicit VuXML) |
1.1_1 27 Feb 2006 14:36:53
 |
skv  |
Document Bugzilla [2.*, 2.20.1) vulnerabilities.
Approved by: security-officer (simon)
Approved by: portmgr (implicit) |
1.1_1 24 Feb 2006 19:56:28
 |
delphij  |
Document squirrelmail (< 1.4.6) vulnerabilities:
CVE-2006-0377 (IMAP injection)
CVE-2006-0195 (XSS)
CVE-2006-0188 (XSS)
Approved by: security-officer (simon)
Approved by: portmgr (implicit) |
1.1_1 20 Feb 2006 19:15:17
 |
remko  |
Remove the latest squid entry, it already existed.
Noticed by: Thomas-Martin Seck <tmseck at netcologne dot de> |
1.1_1 20 Feb 2006 16:03:37
 |
remko  |
Document gedit -- format string vulnerability. |
1.1_1 20 Feb 2006 15:43:53
 |
remko  |
Add koffice to the RTF import issue. |
1.1_1 20 Feb 2006 15:17:49
 |
remko  |
Documenet WebCalendar -- unauthorized access vulnerability. |
1.1_1 20 Feb 2006 14:29:51
 |
remko  |
Document abiword -- stack based buffer overflow vulnerabilities. |
1.1_1 20 Feb 2006 12:26:23
 |
remko  |
Document pinentry -- local privilege escalation.
Correct previous entry (the entry time was invalid). |
1.1_1 20 Feb 2006 12:02:10
 |
remko  |
Document squid -- dns lookup spoofing. |
1.1_1 18 Feb 2006 14:22:42
 |
simon  |
Document postgresql81-server -- SET ROLE privilege escalation. |
1.1_1 17 Feb 2006 09:53:59
 |
simon  |
Document gnupg -- false positive signature verification. |
1.1_1 16 Feb 2006 15:05:14
 |
remko  |
Document rssh -- privilege escalation vulnerability.
The port will be marked forbidden due to possible
root access. |
1.1_1 16 Feb 2006 14:33:21
 |
remko  |
Document tor -- malicious tor server can locate a hidden service. |
1.1_1 16 Feb 2006 14:20:23
 |
remko  |
Document sudo -- arbitrary command execution. |
1.1_1 16 Feb 2006 14:08:27
 |
remko  |
Document libtomcrypt -- weak signature scheme with ECC keys. |
1.1_1 16 Feb 2006 13:19:08
 |
remko  |
Document mantis -- "view_filters_page.php" cross site scripting vulnerability. |
1.1_1 16 Feb 2006 12:59:21
 |
remko  |
Document phpbb -- multiple vulnerabilities.
Reviewed by: simon |
1.1_1 16 Feb 2006 12:50:36
 |
remko  |
Document postgresql -- character conversion and tsearch2 vulnerabilities. |
1.1_1 16 Feb 2006 09:08:04
 |
remko  |
Document heartbeat -- insecure temporary file creation vulnerability. |
1.1_1 15 Feb 2006 13:25:56
 |
remko  |
Document kpdf -- heap based buffer overflow |
1.1_1 15 Feb 2006 12:53:21
 |
remko  |
Document perl, webmin, usermin -- perl format string integer wrap vulnerability
PR: ports/91202
Submitted by: KOMATSU Shinichiro <koma2 at lovepeers dot org>
(slightly modified). |
1.1_1 15 Feb 2006 12:33:37
 |
remko  |
Document phpicalendar -- cross site scripting vulnerability and
document phpicalendar -- file disclosure vulnerability [1].
Reviewed by: simon [1]
Spotted on: cvs-ports@ [1] |
1.1_1 14 Feb 2006 10:35:41
 |
remko  |
Document FreeBSD -- Infinite loop in SACK handling (FreeBSD SA 06.08) |
1.1_1 14 Feb 2006 10:28:54
 |
remko  |
Document pf -- IP fragment handling panic, FreeBSD SA 06.07 |
1.1_1 14 Feb 2006 10:09:23
 |
remko  |
Document FreeBSD -- Local kernel memory disclosure
(FreeBSD SA 06.07). |
1.1_1 14 Feb 2006 09:57:32
 |
remko  |
Document IEEE 802.11 -- buffer overflow (FreeBSD SA 06.05). |
1.1_1 14 Feb 2006 08:13:54
 |
remko  |
Add FreeBSD SA 06.04.ipfw to the vuln.xml list. |
1.1_1 07 Feb 2006 20:43:51
 |
simon  |
Mark ivtools 1.2.3 as fixed for jpeg vulnerabilities. Note that this
version is not yet in ports, but marking the new version fixed now
make porting a bit simpler. |
1.1_1 07 Feb 2006 20:09:16
 |
simon  |
Document kpopup -- local root exploit and local denial of service.
PR: ports/92359
Submitted by: Ion-Mihai "IOnut" Tetcu <itetcu@people.tecnik93.com> |
1.1_1 27 Jan 2006 19:07:32
 |
remko  |
Oops. Forgot to modify the discovery date.
Spotted by: simon (again) |
1.1_1 27 Jan 2006 12:20:06
 |
remko  |
Add 4 FreeBSD advisories to the VuXML database.
The other recently released advisories will be
added later today.
o SA-06:03.cpio
o SA-06:02.ee
o SA-06:01.texindex
o SA-05:20.cvsbug |
1.1_1 24 Jan 2006 06:38:31
 |
edwin  |
SHA256ify
Approved by: krion@ |
1.1_1 23 Jan 2006 21:29:47
 |
brooks  |
Document local root exploit in SGE. |
1.1_1 23 Jan 2006 15:35:22
 |
barner  |
Document "fetchmail -- crash when bouncing a message" DOS vulnerability.
Reviewed by: secteam (simon) |
1.1_1 14 Jan 2006 23:36:11
 |
simon  |
- Update description and references for "clamav -- possible heap
overflow in the UPX code" now that more information is available.
- Remove some EOL whitespace. |
1.1_1 10 Jan 2006 14:02:52
 |
ehaupt  |
Add an entry for clamav/clamav-devel
Reviewed by: simon (secteam) |
1.1_1 09 Jan 2006 21:47:30
 |
simon  |
Document milter-bogom -- headerless message crash.
Reported by: Victor Balada Diaz <victor@bsdes.net> |
1.1_1 09 Jan 2006 20:49:54
 |
simon  |
Mark latest bnc version as fixed wrt. to "fd_set -- bitmap index
overflow in multiple applications".
Reported by: Christian Elmerot <Chreo At chreo , net> |
1.1_1 07 Jan 2006 14:56:01
 |
simon  |
Document two bogofilter vulnerabilities.
Submitted by: Matthias Andree <matthias.andree@gmx.de> |
1.1_1 04 Jan 2006 23:00:39
 |
thierry  |
Add an entry for rxvt-unicode < 6.3: root privileges were not restored
before the call to openpty(), so the permissions on the pty device node
remain root:wheel 666 after opening a new terminal.
Discovered by: Ryan Beasley <ryanb (at) rainbowdevilsland.co.uk> |
1.1_1 03 Jan 2006 18:40:54
 |
lev  |
`ru-apache' and `ru-apache+mod_ssl' was patchet against CAN-2005-3352
(http://www.FreeBSD.org/ports/portaudit/9fff8dc8-7aa7-11da-bf72-00123f589060.html)
Yes, changes are validated with xmllint at this time. |
1.1_1 02 Jan 2006 18:32:20
 |
remko  |
Correct a little typo. |
1.1_1 01 Jan 2006 21:40:15
 |
remko  |
Document apache -- mod_imap cross-site scripting flaw.
I expanded the diff from the PR a bit to denote other
affected apache ports as well. Therefor mistakes in
that should be redirected to me.
Also bump the copyright year for the vuxml file.
PR: ports/91157 (based on)
Submitted by: KOMATSU Shinichiro <koma2 at lovepeers dot org> |
1.1_1 01 Jan 2006 09:03:32
 |
hrs  |
Fix the affected versions of 9b4facec-6761-11da-99f6-00123ffe8333.
PR: ports/91156
Submitted by: KOMATSU Shinichiro (koma2 at lovepeers dot org) |
1.1_1 25 Dec 2005 22:23:52
 |
simon  |
Add missing "</package>" tag from rev. 1.917, which caused the file to
be invalid XML and in turn caused the portaudit database to be only
partially built.
Bump modification date of all entries which had modification date on
the 23'rd to make sure VuXML consumers catch the updates.
Portaudit problem reported by: Peter Vohmann
Pointy hat to: lev |
1.1_1 23 Dec 2005 13:33:27
 |
lev  |
russian/apache13 and russian/apache13-modssl were updated and new version
doesn't
contain any known vulnerabilities. |
1.1_1 23 Dec 2005 12:10:22
 |
simon  |
Bump modification date for entries touched by last commit. |
1.1_1 23 Dec 2005 11:47:24
 |
remko  |
Update the phpSysInfo entries, PR ports/90849 will solve the documented
issues.
Requested by: Babak Farrokhi <babak at farrokhi dot net> |
1.1_1 23 Dec 2005 10:29:50
 |
remko  |
Fix another typo in my nbd entry.
Spotted by: Linus Nordberg <linus at nordberg dot se> |
1.1_1 22 Dec 2005 21:25:07
 |
remko  |
Correct a typo.
Submitted by: Linus Nordberg <linus at nordberg dot se> |
1.1_1 22 Dec 2005 21:08:08
 |
remko  |
Update the affected range.
Prodded by: erwin |
1.1_1 22 Dec 2005 21:07:15
 |
remko  |
The previous entry should have read:
Document ndb-server -- buffer overflow vulnerability |
1.1_1 22 Dec 2005 21:05:32
 |
remko  |
: |