| Commit History - (may be incomplete: for full details, see links to repositories near top of page) |
| Commit | Credits | Log message |
1.1_1 10 Jul 2006 11:48:01
 |
simon  |
- For the latest trac entry include information from the release
announcements about setups which are not affected. To avoid having
to reference two documents simply reference the release notes for
all the information (it's basically the same as the changelog with
slightly different wording).
- Add a modified date tag. |
1.1_1 10 Jul 2006 08:56:13
 |
simon  |
Document twiki -- multiple file extensions file upload vulnerability. |
1.1_1 10 Jul 2006 08:39:43
 |
simon  |
Improve markup for last entry. No content change. |
1.1_1 09 Jul 2006 23:31:15
 |
kuriyama  |
Add trac DoS. |
1.1_1 05 Jul 2006 17:45:15
 |
thierry  |
Add an entry for Horde's latest vulnerabilities. |
1.1_1 05 Jul 2006 17:30:40
 |
simon  |
Document mambo -- SQL injection vulnerabilities. |
1.1_1 03 Jul 2006 12:45:31
 |
miwi  |
Document phpmyadmin -- cross site scripting vulnerability
Approved by: markus (co mentor) |
1.1_1 02 Jul 2006 13:09:45
 |
remko  |
Document webmin, usermin -- arbitrary file disclosure vulnerability.
Details are unknown, all sources talk about an "unspecified" vulnerability. |
1.1_1 01 Jul 2006 12:19:21
 |
shaun  |
Document mutt -- Remote Buffer Overflow Vulnerability.
Approved by: ahze (mentor) |
1.1_1 30 Jun 2006 22:48:34
 |
miwi  |
Document joomla -- multiple vulnerabilities
Approved by: markus (co mentor) |
1.1_1 27 Jun 2006 19:55:05
 |
remko  |
Document hashcash -- heap overflow vulnerability. |
1.1_1 25 Jun 2006 18:39:19
 |
simon  |
Document gnupg -- user id integer overflow vulnerability. |
1.1_1 23 Jun 2006 08:32:02
 |
simon  |
Document opera -- JPEG processing integer overflow vulnerability. |
1.1_1 17 Jun 2006 14:36:33
 |
remko  |
Update the webcalendar entry, use alphabetic sorting, no functional
change of information. |
1.1_1 17 Jun 2006 07:11:10
 |
thierry  |
Add an entry for Horde's latest XSS vulnerabilities. |
1.1_1 16 Jun 2006 22:38:16
 |
simon  |
Add webcalendar -- information disclosure vulnerability.
PR: ports/98993
Submitted by: Gregory C. Larkin <glarkin@sourcehosting.net> |
1.1_1 14 Jun 2006 16:30:58
 |
remko  |
Add FreeBSD-SA-06:17.sendmail to the VuXML database. |
1.1_1 12 Jun 2006 15:41:35
 |
remko  |
Bump modification date in the last entry and earn my own pointyhat.
Forgotten by/pointyhat: remko |
1.1_1 12 Jun 2006 15:26:46
 |
remko  |
Fix the latest entry by using the entity for &, this passes make validate.
Reported by: Michal Kaps <michal at ionic dot co dot uk>
Pointyhat by: aaron, (tobez implicit) |
1.1_1 12 Jun 2006 06:22:59
 |
aaron  |
- Added multiple dokuwiki vulnerabilities
Approved by: tobez |
1.1_1 11 Jun 2006 12:55:21
 |
nobutaka  |
Add an entry for libxine -- buffer overflow vulnerability. |
1.1_1 09 Jun 2006 13:32:10
 |
remko  |
Document FreeBSD-SA-06:15.ypserv and FreeBSD-SA-06:16.smbfs.
Add the proper freebsdsa tag for older entries and bump
their modification date. |
1.1_1 08 Jun 2006 17:10:56
 |
remko  |
Document two freeradius issues, one newer and one older issue:
freeradius -- multiple vulnerabilities
freeradius -- authentication bypass vulnerability |
1.1_1 08 Jun 2006 12:21:36
 |
ehaupt  |
Mark graphics/fractorama 1.6.7_1 "clean". This port now links against libtiff
from ports.
Approved by: simon (secteam) |
1.1_1 07 Jun 2006 18:51:20
 |
simon  |
The awstats port has PORTEPOCH bumped, so update the vuxml entry awstats
-- arbitrary command execution vulnerability to reflect that. |
1.1_1 06 Jun 2006 10:57:44
 |
simon  |
Mumble, back out local changes which should not have been committed. |
1.1_1 06 Jun 2006 10:55:10
 |
simon  |
Mark squirrelmail-1.4.6_1 as fixed for squirrelmail -- plugin.php
local file inclusion vulnerability. |
1.1_1 05 Jun 2006 20:18:51
 |
simon  |
Document squirrelmail -- plugin.php local file inclusion vulnerability. |
1.1_1 05 Jun 2006 19:57:27
 |
simon  |
Document dokuwiki -- spellchecker remote PHP code execution. |
1.1_1 05 Jun 2006 19:48:00
 |
simon  |
Document drupal -- multiple vulnerabilities. |
1.1_1 01 Jun 2006 18:30:07
 |
mnag  |
- Add last two MySQL vulnerabilities
MySQL -- SQL-injection security vulnerability
MySQL -- Information Disclosure and Buffer Overflow Vulnerabilities |
1.1_1 23 May 2006 19:23:48
 |
simon  |
Document frontpage -- cross site scripting vulnerability and point
FORBIDDEN from the frontpage ports at it.
While this is "only" a cross site scripting vulnerability it has some
rather serious implications which can allow an attacker to take over a
web site, so I'm keeping FORBIDDEN. |
1.1_1 23 May 2006 15:20:45
 |
mnag  |
cscope -- buffer overflow vulnerabilities |
1.1_1 22 May 2006 15:25:55
 |
mnag  |
coppermine -- Multiple File Extensions Vulnerability
coppermine -- "file" Local File Inclusion Vulnerability
coppermine -- File Inclusion Vulnerabilities |
1.1_1 21 May 2006 01:02:29
 |
mnag  |
phpmyadmin -- XSRF vulnerabilities |
1.1_1 18 May 2006 21:19:02
 |
pav  |
- Normalize the topic of last entry
Requested by: remko |
1.1_1 18 May 2006 16:12:17
 |
pav  |
- Add VuXML entry for vnc 4.1.1 |
1.1_1 14 May 2006 03:57:14
 |
mnag  |
- Add vulnerabilities in last topic. |
1.1_1 14 May 2006 03:56:08
 |
mnag  |
phpldapadmin -- Cross-Site Scripting and Script Insertion |
1.1_1 11 May 2006 19:17:55
 |
tobez  |
Modify the entry for p5-DBI insecure temporary files creation to reflect
the fact that version 1.37_1 of p5-DBI-137 is OK now.
Reviewed by: simon |
1.1_1 06 May 2006 10:56:39
 |
kuriyama  |
Add www/fswiki vulnerability. |
1.1_1 05 May 2006 22:24:37
 |
simon  |
- Add missing s in latest awstats entry's title.
- Document mysql50-server -- COM_TABLE_DUMP arbitrary code execution. |
1.1_1 05 May 2006 21:39:22
 |
mnag  |
- Cancel last rsync entry. Does not affect FreeBSD port.
Notified by: simon, pav
Discussed with: simon |
1.1_1 05 May 2006 20:45:21
 |
simon  |
Document awstat -- arbitrary command execution vulnerability.
Fix a incorrect use of cvename in the latest firefox entry, which I
missed when reviewing the entry (and which make validate did not / can
not catch). |
1.1_1 03 May 2006 20:14:48
 |
mnag  |
phpwebftp -- "language" Local File Inclusion |
1.1_1 03 May 2006 08:00:56
 |
vd  |
Document firefox -- denial of service vulnerability
Reviewed by: simon |
1.1_1 03 May 2006 01:01:55
 |
mnag  |
trac -- Wiki Macro Script Insertion Vulnerability |
1.1_1 03 May 2006 00:56:33
 |
mnag  |
rsync -- "xattrs.diff" Patch Integer Overflow Vulnerability |
1.1_1 03 May 2006 00:45:52
 |
mnag  |
clamav -- Freshclam HTTP Header Buffer Overflow Vulnerability |
1.1_1 01 May 2006 15:09:47
 |
mnag  |
- Add last jabberd entry:
jabberd -- SASL Negotiation Denial of Service Vulnerability |
1.1_1 27 Apr 2006 11:12:19
 |
simon  |
Also mark linux-seamonkey vulnerable to recent mozilla
vulnerabilities.
Reported by: Andrew Pantyukhin infofarmer at gmail dotty com |
1.1_1 27 Apr 2006 04:30:54
 |
mnag  |
cacti -- ADOdb "server.php" Insecure Test Script Security Issue |
1.1_1 27 Apr 2006 03:48:33
 |
mnag  |
amaya -- Attribute Value Buffer Overflow Vulnerabilities |
1.1_1 27 Apr 2006 03:22:26
 |
mnag  |
lifetype -- ADOdb "server.php" Insecure Test Script Security Issue |
1.1_1 27 Apr 2006 02:46:41
 |
mnag  |
ethereal -- Multiple Protocol Dissector Vulnerabilities |
1.1_1 25 Apr 2006 20:57:47
 |
remko  |
My 100th commit to the vuln.xml file:
- Document Asterisk -- denial of service vulnerability, local system access. |
1.1_1 25 Apr 2006 17:40:50
 |
anholt  |
Change paraview checks to be < 2.4.3 now that paraview uses system libtiff. |
1.1_1 23 Apr 2006 21:46:35
 |
remko  |
Document zgv, xzgv -- heap overflow vulnerability. |
1.1_1 23 Apr 2006 14:14:52
 |
remko  |
Document crossfire-server -- denial of service and remote code execution
vulnerability. |
1.1_1 23 Apr 2006 10:25:28
 |
remko  |
Document p5-DBI -- insecure temporary file creation vulnerability. |
1.1_1 23 Apr 2006 09:58:04
 |
remko  |
Document wordpress -- full path disclosure. |
1.1_1 23 Apr 2006 09:35:38
 |
remko  |
Document xine -- multiple remote string vulnerabilities. |
1.1_1 21 Apr 2006 16:51:13
 |
ume  |
Add an entry for cyrus-sasl -- DIGEST-MD5 Pre-Authentication
Denial of Service. |
1.1_1 19 Apr 2006 17:53:27
 |
remko  |
Also mark all other versions of FreeBSD (That were released) as
vulnerable.
Noticed by: brueffer
Discussed with: brueffer, simon |
1.1_1 19 Apr 2006 17:36:57
 |
remko  |
Add FreeBSD -- FPU information disclosure (SA-06:14) to the
vuxml list. |
1.1_1 18 Apr 2006 19:39:22
 |
simon  |
Add some CERT references to latest Mozilla entry. |
1.1_1 18 Apr 2006 13:48:47
 |
mnag  |
plone -- "member_id" Parameter Portrait Manipulation Vulnerability |
1.1_1 16 Apr 2006 22:02:11
 |
simon  |
Fix copy/paste error in last commit and mark linux-mozilla < 1.7.13 as
vulnerable. |
1.1_1 16 Apr 2006 21:52:31
 |
simon  |
Document mozilla/firefox/thunderbirds's latest attempt at Internet
Explorer compatibility.
Note that I omitted marking some really old mozilla versions as
vulnerable this time, since there is already a bunch of entries
covering these versions (which haven't been in ports for a while). |
1.1_1 16 Apr 2006 13:00:05
 |
ehaupt  |
Update entry for sysutils/heartbeat. The insecure temporary file creation
vulnerability is fixed in 1.2.4.
Approved by: secteam (simon) |
1.1_1 16 Apr 2006 01:52:17
 |
mnag  |
mailman -- Private Archive Script Cross-Site Scripting |
1.1_1 10 Apr 2006 19:11:15
 |
remko  |
Document f2c -- insecure temporary files.
It is not very clear to me to see what version is fixed. The one fixing
this port should import the latest available one which is fixed. |
1.1_1 08 Apr 2006 14:53:01
 |
mnag  |
mplayer -- Multiple integer overflows |
1.1_1 07 Apr 2006 14:15:02
 |
mnag  |
- Add Secunia references for last phpMyAdmin issue. |
1.1_1 07 Apr 2006 11:23:07
 |
remko  |
Document kaffeine -- buffer overflow vulnerability. |
1.1_1 07 Apr 2006 10:38:53
 |
remko  |
Document thunderbird -- javascript execution. |
1.1_1 06 Apr 2006 17:30:16
 |
remko  |
Update the latest zoo entry to match the latest update to the port.
This will mark zoo-2.10.1_2 and later as not vulnerable for this
issue. |
1.1_1 06 Apr 2006 16:44:46
 |
mnag  |
phpmyadmin -- XSS vulnerabilities
phpmyadmin -- 'set_theme' Cross-Site Scripting |
1.1_1 06 Apr 2006 15:30:13
 |
mnag  |
clamav -- Multiple Vulnerabilities |
1.1_1 06 Apr 2006 04:47:47
 |
remko  |
Add cvename to the recent OpenVPN entry.
Submitted by: Matthias Andree <matthias dot andree at gmx dot de> |
1.1_1 05 Apr 2006 20:00:18
 |
remko  |
Document mediawiki -- hardcoded placeholder string security bypass
vulnerability. |
1.1_1 05 Apr 2006 19:50:25
 |
remko  |
Document netpbm -- buffer overflow in pnmtopng. |
1.1_1 05 Apr 2006 19:23:10
 |
remko  |
Document zoo -- stack based buffer overflow. |
1.1_1 05 Apr 2006 19:02:44
 |
remko  |
Document mediawiki -- cross site scripting vulnerability. |
1.1_1 05 Apr 2006 17:37:38
 |
mnag  |
dia -- XFig Import Plugin Buffer Overflow |
1.1_1 05 Apr 2006 14:57:46
 |
mnag  |
openvpn -- LD_PRELOAD code execution on client through malicious or compromised
server
PR: 95343
Submitted by: Matthias Andree <matthias.andree__gmx.de> |
1.1_1 05 Apr 2006 04:33:25
 |
mnag  |
samba -- Exposure of machine account credentials in winbind log files |
1.1_1 05 Apr 2006 03:46:56
 |
brooks  |
Upgrade pubcookie from 3.3.0-beta2 to 3.3.0a fixing serious XSS
vulnerabilities. |
1.1_1 01 Apr 2006 05:01:12
 |
edwin  |
Fill in the version numbers for the vids
6e3b12e2-6ce3-11da-b90c-000e0c2e438a and
82a41084-6ce7-11da-b90c-000e0c2e438a to show which Mantis versions
are vulnerable.
Submitted by: In cooperation with dvl |
1.1_1 30 Mar 2006 06:53:31
 |
simon  |
For horde -- remote code execution vulnerability in the help viewer
entry:
- Add more references.
- Reformat description to follow normal formatting style better.
- Remove a redundant line in the description to make the meaning more
clear. |
1.1_1 29 Mar 2006 19:08:51
 |
mnag  |
freeradius -- EAP-MSCHAPv2 Authentication Bypass |
1.1_1 28 Mar 2006 18:13:15
 |
thierry  |
Add an entry about Horde's remote code execution vulnerability in the
help viewer. |
1.1_1 27 Mar 2006 19:06:54
 |
mnag  |
linux-realplayer -- buffer overrun
linux-realplayer -- heap overflow
Reviewed by: simon |
1.1_1 24 Mar 2006 18:02:29
 |
remko  |
s/8 spaces/tab/ in the sendmail entry.
Noticed by: simon |
1.1_1 24 Mar 2006 17:10:24
 |
remko  |
Record that our sendmail port was also vulnerable.
Bump modification date. |
1.1_1 24 Mar 2006 13:08:54
 |
remko  |
Update the 'Evolution - remote format string vulnerabilities' entry. |
1.1_1 24 Mar 2006 12:25:59
 |
remko  |
Document the latest three FreeBSD Security Advisories:
SA-06:13
SA-06:12
SA-06:11 |
1.1_1 21 Mar 2006 17:05:15
 |
lesi  |
xorg-server -- privilege escalation
Reviewed by: simon |
1.1_1 20 Mar 2006 15:21:49
 |
mnag  |
- heimdal -- Multiple vulnerabilities
Reviewed by: simon |
1.1_1 20 Mar 2006 12:58:16
 |
vd  |
Document ftp/curl's TFTP packet buffer overflow vulnerability
Reworked by: simon
Approved by: security-officer (simon) |