Commit History - (may be incomplete: for full details, see links to repositories near top of page) |
Commit | Credits | Log message |
1.1 25 Jun 2004 17:18:57
 |
trhodes  |
Move giFT-FastTrack to VuXML. |
1.1 25 Jun 2004 02:04:08
 |
trhodes  |
Fix an older entry which ends with "buffer overflows vuxml".
Fill in a date on my previous entry. |
1.1 25 Jun 2004 01:35:18
 |
trhodes  |
Move the Gallery entry to VuXML. |
1.1 25 Jun 2004 00:36:12
 |
eik  |
www/sitecopy uses the included libneon version 0.24.0 |
1.1 21 Jun 2004 22:03:48
 |
eik  |
I believe that linux-png-1.2.2 still contains the vulnerability.
Add some references that support this opinion. |
1.1 21 Jun 2004 20:04:18
 |
pav  |
- Extend png entry to cover it's linux-png variant
Requested by: eik |
1.1 14 Jun 2004 21:05:16
 |
fjoe  |
Midnight Commander security vulnerabilities
CAN-2004-0226, CAN-2004-0231, CAN-2004-0232
fixed in mc-4.6.0_10. |
1.1 12 Jun 2004 12:22:23
 |
eik  |
add a $FreeBSD$ tag |
1.1 09 Jun 2004 20:38:33
 |
des  |
Add CAN-2004-0541 (buffer overflow in Squid NTLM authentication helper) |
1.1 08 Jun 2004 12:42:09
 |
eik  |
Fix for CAN-2004-0097
Forgotten by: sobomax |
1.1 07 Jun 2004 21:21:06
 |
des  |
Correction: FreeBSD-SA-04:12.jailroute does not apply to 4.7 and older. |
1.1 07 Jun 2004 21:17:33
 |
des  |
Whitespace cleanup |
1.1 07 Jun 2004 21:17:02
 |
des  |
Add FreeBSD-SA-04:12.jailroute. |
1.1 26 May 2004 11:32:29
 |
des  |
FreeBSD-SA-04:11 |
1.1 24 May 2004 11:49:54
 |
ale  |
Update modified date for mysql bug after fixing typo.
Requested by: nectar |
1.1 21 May 2004 12:42:01
 |
nectar  |
Add CVE name for one of the leafnode issues. |
1.1 21 May 2004 12:39:46
 |
nectar  |
Edit the topics to distinguish a bit better between the different
leafnode DoS issues. |
1.1 21 May 2004 12:13:52
 |
nectar  |
Document several issues in leafnode.
Submitted by: Matthias Andree <matthias.andree@gmx.de> |
1.1 21 May 2004 07:57:39
 |
ale  |
Fix typo.
Spotted by: eik |
1.1 19 May 2004 21:06:20
 |
nectar  |
Correct a typo (s/Jon/Joe/) |
1.1 19 May 2004 20:21:32
 |
nectar  |
Add subversion and neon date parsing vulnerabilities. |
1.1 19 May 2004 12:57:14
 |
des  |
make tidy |
1.1 19 May 2004 12:55:35
 |
des  |
Add an entry for the cvs pserver heap overflow. |
1.1 18 May 2004 14:53:33
 |
nectar  |
Add CVE name and CERT Vulnerability Note references for old Cyrus bug. |
1.1 18 May 2004 14:43:04
 |
nectar  |
make tidy |
1.1 18 May 2004 14:40:22
 |
nectar  |
Forced commit to note that the content of the previous revision was
Reported by: Ion-Mihai Tetcu <itetcu@apropo.ro> |
1.1 18 May 2004 14:39:03
 |
nectar  |
Add URI handling issue that affects Opera and KDE, at least. |
1.1 18 May 2004 11:50:58
 |
ale  |
Note that the mysqlbug has been fixed. |
1.1 17 May 2004 13:20:30
 |
nectar  |
Update version number for fspd, now that it has been corrected.
Reported by: Radim Kolar <hsn@netmag.cz> |
1.1 15 May 2004 13:20:04
 |
eik  |
&, not | |
1.1 15 May 2004 13:13:50
 |
eik  |
ProFTPD vulnerability is fixed in
<http://www.proftpd.org/docs/NEWS-1.2.10rc1>
Submitted by: Koop Mast <kwm@rainbow-runner.nl> |
1.1 12 May 2004 16:01:25
 |
nectar  |
Add Cyrus IMSPd security release.
Reported by: eik |
1.1 12 May 2004 15:28:50
 |
nectar  |
Add old Cyrus IMAP server heap buffer overflow.
Reported by: eik |
1.1 09 May 2004 22:26:05
 |
nobutaka  |
The security issue of multimedia/xine (insecure temporary file creation in
xine-check, xine-bugreport) has been fixed in 0.9.23_3. |
1.1 06 May 2004 21:11:00
 |
nectar  |
Only one <modified> is allowed per entry. |
1.1 06 May 2004 20:40:19
 |
des  |
Correct the discovery date for the proftpd issue. |
1.1 06 May 2004 16:26:28
 |
nectar  |
Oops. s/2005-05-05/2004-05-05/ :-) |
1.1 06 May 2004 16:12:55
 |
nectar  |
Second-guess Oliver and correct the affected entry for exim
in order to unbreak this file. |
1.1 06 May 2004 15:43:53
 |
eik  |
exim buffer overflow when verify = header_syntax is used |
1.1 06 May 2004 15:33:57
 |
nectar  |
Add phpBB session table exhaustion issue.
Submitted by: Xin LI <delphij@frontfree.net> |
1.1 05 May 2004 21:49:49
 |
nectar  |
Add the issues covered in FreeBSD-SA-04:08.heimdal and
FreeBSD-SA-04:09.kadmind. |
1.1 05 May 2004 14:57:33
 |
nectar  |
make tidy |
1.1 05 May 2004 14:57:02
 |
nectar  |
Use PORTVERSION conventions for FreeBSD version numbers, so that
5.2.1-RELEASE-p5 becomes 5.2.1_5 (not 5.2.1p5, as it would have been
previously).
This is necessary because e.g. 5.2p1 > 5.2.1p5 using existing version
comparison tools. |
1.1 03 May 2004 20:15:32
 |
nectar  |
Correct package name for xchat Socks5 vulnerability (xchat -> xchat2).
Note that the issue is fixed in version 2.0.8_2 (thanks marcus!). |
1.1 03 May 2004 18:23:43
 |
nectar  |
Correct the fixed version for lha. |
1.1 03 May 2004 14:42:39
 |
nectar  |
png issue was fixed in png-1.2.5_4 |
1.1 02 May 2004 16:55:28
 |
nectar  |
Add a vulnerability in www/pound.
Submitted by: clement
Add a security-related regression in ftp/proftpd.
Add several security issues in misc/mc.
Add a DoS issue in graphics/png.
Add a security issues in archivers/lha.
Add recent advisories for xine.
Add rsync path traversal issue. |
1.1 30 Apr 2004 16:04:55
 |
nectar  |
tla is also affected by libneon issue.
PR: ports/65754
Submitted by: Frank Ruell <stoerte@dreamwarrior.net>
Additional reference for mysql issue.
Submitted by: Daniel Harris <dannyboy@FreeBSD.org> |
1.1 23 Apr 2004 23:07:28
 |
nectar  |
Added CVE name for ident2 issue.
Added the ``new'' TCP DoS issue.
Added phpBB issue. (1)
Added XChat Socks5 issue.
Submitted by: (1) Frankye - ML <listsucker@ipv5.net> |
1.1 16 Apr 2004 16:29:01
 |
nectar  |
Add mysqlbug temporary file handling vulnerability.
Add ident2 vulnerability.
make tidy (sorry, I meant to do this in a separate commit) |
1.1 16 Apr 2004 14:44:09
 |
nectar  |
Additional CVE name for recent CVS vulnerability. |
1.1 16 Apr 2004 00:49:15
 |
nectar  |
Add kdepim vulnerability |
1.1 16 Apr 2004 00:26:36
 |
nectar  |
Add neon vulnerability
Correct the version range for openh323 |
1.1 14 Apr 2004 17:18:52
 |
nectar  |
Add CVS vulnerabilities. |
1.1 14 Apr 2004 15:10:12
 |
nectar  |
Document another racoon DoS vulnerability.
Note that racoon was also affected by the tcpdump ISAKMP vulnerability. |
1.1 13 Apr 2004 20:39:27
 |
nectar  |
make tidy |
1.1 13 Apr 2004 20:38:39
 |
nectar  |
Add CVE name for racoon DoS vulnerability. |
1.1 13 Apr 2004 17:56:43
 |
nectar  |
Correct modified date in previous commit: format is YYYY-MM-DD and
timezone is UTC. |
1.1 13 Apr 2004 17:31:13
 |
fjoe  |
Midnight Commander vulnerability CAN-2003-1023 was fixed in version 4.6.0_9. |
1.1 07 Apr 2004 17:13:05
 |
nectar  |
make tidy |
1.1 07 Apr 2004 16:27:57
 |
nectar  |
Add new affected version of gaim.
Add year 2004 FreeBSD security advisories. |
1.1 07 Apr 2004 13:06:25
 |
nectar  |
Add two racoon issues, one particularly serious. |
1.1 05 Apr 2004 17:05:25
 |
nectar  |
Add CVE name for oftpd issue. |
1.1 03 Apr 2004 23:19:29
 |
nectar  |
Add Midnight Commander buffer overflow. |
1.1 03 Apr 2004 23:18:05
 |
nectar  |
Oops, tidy.xsl should now produce VuXML 1.1 documents on output. |
1.1 02 Apr 2004 23:31:04
 |
nectar  |
Add VuXML 1.1 DTD
Update document type declaration to VuXML 1.1 |
1.0 02 Apr 2004 23:27:51
 |
nectar  |
make tidy |
1.0 02 Apr 2004 23:24:50
 |
nectar  |
Add Heimdal cross-realm validation issue. |
1.0 01 Apr 2004 22:41:02
 |
nectar  |
Correct usage message for tidy.sh.
Submitted by: Frankye Fattarelli <frankye@ipv5.net> |
1.0 31 Mar 2004 20:33:24
 |
nectar  |
Add security issue affecting the Courier mail services. |
1.0 31 Mar 2004 19:42:11
 |
nectar  |
Add isakmpd denial-of-service vulnerability. |
1.0 31 Mar 2004 19:03:40
 |
nectar  |
Add apache 2 DoS vulnerability that doesn't affect us. I keep coming
across the CVE name (CAN-2004-0174) and re-researching it. |
1.0 31 Mar 2004 16:52:24
 |
nectar  |
Add mplayer and tcpdump issues.
Submitted by: Frankye Fattarelli <frankye@ipv5.net>
Reported by: Many |
1.0 31 Mar 2004 16:28:34
 |
nectar  |
Correct a mispelled CVE name. |
1.0 30 Mar 2004 06:18:27
 |
nectar  |
make tidy |
1.0 30 Mar 2004 06:16:21
 |
nectar  |
Add a `make tidy' target that will clean up and sort a VuXML
document. Requires xsltproc. |
1.0 30 Mar 2004 06:14:34
 |
nectar  |
Fix dates for SA-04:06.ipv6 and phpbb issues (typos).
Add Bugtraq ID and other references for many entries.
Delete duplicate copula.
Submitted by: Frankye Fattarelli <frankye@ipv5.net> |
1.0 29 Mar 2004 17:25:50
 |
nectar  |
Add zebra/quagga denial of service vulnerability.
Submitted by: sumikawa |
1.0 29 Mar 2004 15:26:51
 |
nectar  |
Correct advisory name for old bind issue. |
1.0 29 Mar 2004 15:26:14
 |
nectar  |
Add old ecartis issue.
Add FreeBSD-SA-04:06.ipv6.
Correct advisory name for old pine issue. |
1.0 28 Mar 2004 20:13:32
 |
nectar  |
Add Emil issue. |
1.0 28 Mar 2004 19:59:46
 |
nectar  |
Fix a botched version number (the package name was erroneously included).
Add another phpbb vulnerability. [1]
Add oftpd denial-of-services. [2]
Submitted by: Frankye Fattarelli <frankye@ipv5.net> [1]
Reported by: Shane Kerr <shane@time-travellers.org> (oftpd author) [2] |
1.0 26 Mar 2004 17:40:56
 |
nectar  |
Add ethereal vulnerabilities.
PR: ports/64777 |
1.0 26 Mar 2004 17:26:51
 |
nectar  |
Oops, empty <topic> tag. Fill in for squid ACL bypass issue. |
1.0 26 Mar 2004 15:29:13
 |
nectar  |
Add squid ACL bypass.
Add xine temporary file handling issue. [1]
Submitted by: Frankye Fattarelli <frankye@ipv5.net> [1] |
1.0 26 Mar 2004 08:58:41
 |
eik  |
Add ezbounce (old) and phpBB (new) |
1.0 25 Mar 2004 18:13:59
 |
nectar  |
Add xdeview to existing UUDecode issue
Add racoon SA deletion issue. |
1.0 18 Mar 2004 19:48:56
 |
nectar  |
Add uulib, uudeview issue. |
1.0 18 Mar 2004 14:46:23
 |
nectar  |
Add SIZE.
Submitted by: trevor |
1.0 17 Mar 2004 14:19:37
 |
nectar  |
Add OpenSSL denial-of-service vulnerability. |
1.0 17 Mar 2004 00:49:52
 |
eik  |
ModSecurity < 1.7.5 |
1.0 15 Mar 2004 13:24:08
 |
nectar  |
Remove linux-XFree86-libs.
Reminded by: eik |
1.0 12 Mar 2004 03:01:46
 |
eik  |
add russian/apache13* |
1.0 11 Mar 2004 18:38:00
 |
eik  |
- restore the healthy mix of marc and securityfocus
- unicodeify Ulf again
Requested by: nectar |
1.0 11 Mar 2004 17:56:35
 |
eik  |
remove vid 3ca8dd7a-6fb3-11d8-873f-0020ed76ef5a, since the unsafe call
to sprintf is made in preparation for outputting a debug message using
OutputDebugString, which is a function from a different operating system.
While I'm here, transform U+C3A4 into ä (or 쎤), since CVS is
bad in handling binary data. |
1.0 11 Mar 2004 17:22:33
 |
eik  |
add a modified tag to vid 09d418db-70fd-11d8-873f-0020ed76ef5a |
1.0 11 Mar 2004 17:19:42
 |
eik  |
The apache ports have fixes from CVS |
1.0 11 Mar 2004 16:34:30
 |
eik  |
canonicalize list urls (mostly bugtraq) |
1.0 11 Mar 2004 13:07:06
 |
eik  |
correct typo
correct entry/modification date |
1.0 11 Mar 2004 12:41:06
 |
nectar  |
Delete duplicated mod_python entry, merging additional information into
previous entry. |