| Commit History - (may be incomplete: for full details, see links to repositories near top of page) |
| Commit | Credits | Log message |
1.1_1 23 Feb 2005 15:11:02
 |
nectar  |
De-confuse latest AWStats entry: rewrite description, and add relevant
references. There were so many bugs, it was hard to keep them straight
(^_^). |
1.1_1 23 Feb 2005 14:37:05
 |
nectar  |
Format the <topic> of the most recent entry so that it is more
consistent with other entries. |
1.1_1 23 Feb 2005 13:13:44
 |
delphij  |
Document latest phpbb vulnerabilities.
Discussed with: phpbb maintainer |
1.1_1 23 Feb 2005 05:15:32
 |
simon  |
Add more references to recent putty vulnerability. |
1.1_1 22 Feb 2005 21:58:36
 |
nectar  |
The mod_dosevasive port was upgraded. |
1.1_1 22 Feb 2005 19:27:32
 |
nectar  |
Nit:
- In most recent `unace' entry, replace HTML entity with the Unicode
character. We do not use HTML entities so that a VuXML document may
be processed without using the DTD. (We also avoid character entity
references for more natural grep'ing, sed'ing, and editor searching.)
Corrections:
- An invalid UUID was assigned to a FreeRADIUS vulnerability, and went
undetected since last October. (>_<) Correct it.
- A bnc vulnerability was duplicated. Cancel the older, less informative
entry and update the newer entry. |
1.1_1 22 Feb 2005 15:37:51
 |
naddy  |
Document unace-1.2b vulnerabilities: buffer overflows, directory traversal. |
1.1_1 20 Feb 2005 20:51:37
 |
simon  |
For the the recent kdelibs entry; note that dcopidlng is only used at
build time.
Reported by: lofi |
1.1_1 20 Feb 2005 18:53:25
 |
simon  |
Document heap corruption vulnerabilities in putty. |
1.1_1 19 Feb 2005 12:49:39
 |
simon  |
Update affected versions of latest postgresql entry now that the ports
have been fixed. |
1.1_1 18 Feb 2005 22:37:35
 |
simon  |
Document insecure temporary file creation in kdelibs. |
1.1_1 18 Feb 2005 21:55:08
 |
simon  |
Document format string vulnerability in bidwatcher. |
1.1_1 18 Feb 2005 20:37:19
 |
simon  |
Document a directory traversal vulnerability in gftp. |
1.1_1 18 Feb 2005 20:14:00
 |
simon  |
- Document two Opera vulnerabilities.
- Update information about fixed version for Opera with regard to
"Window Injection" issues (based on release notes for Opera 7.54u2). |
1.1_1 17 Feb 2005 21:45:40
 |
simon  |
Document multiple buffer overflows in postgresql. |
1.1_1 16 Feb 2005 23:39:20
 |
simon  |
Fix entry date for last commit. |
1.1_1 16 Feb 2005 23:25:23
 |
simon  |
Document vulnerabilities in awstats. Note that this entry will most
likely be updated soon when more information becomes available. |
1.1_1 15 Feb 2005 20:55:47
 |
simon  |
Add a few more references to the awstats entry. |
1.1_1 14 Feb 2005 15:44:07
 |
nobutaka  |
Change affected packages version for the emacs movemail format string
vulnerability since I fixed editors/emacs port by adding a patch
instead of upgrading it to 21.4. |
1.1_1 14 Feb 2005 00:10:36
 |
simon  |
Document DoS in powerdns. |
1.1_1 13 Feb 2005 23:19:00
 |
simon  |
Document format string vulnerability in the Emacs movemail utility. |
1.1_1 13 Feb 2005 11:28:52
 |
danfe  |
- Reflect fixing vulnerability in `net/opendchub'
- Print project's name correctly |
1.1_1 13 Feb 2005 09:59:02
 |
simon  |
- Fix a cvename that should have been a certvu.
- Delete trailing white space.
- Fix some nearby formatting while I'm here anyway. |
1.1_1 13 Feb 2005 09:21:00
 |
simon  |
Document two vulnerabilities in ngircd. |
1.1_1 12 Feb 2005 23:53:09
 |
simon  |
Document mod_python information leakage vulnerability. |
1.1_1 12 Feb 2005 20:40:51
 |
simon  |
Document mailman directory traversal vulnerability. |
1.1_1 11 Feb 2005 23:29:31
 |
nectar  |
Expand HTML entity reference in latest VuXML entry. |
1.1_1 11 Feb 2005 21:59:05
 |
naddy  |
Document enscript-{a4,letter,letterdj} vulnerabilities. |
1.1_1 11 Feb 2005 13:37:26
 |
danfe  |
Vulnerability in unrtf is fixed now. |
1.1_1 08 Feb 2005 21:33:54
 |
simon  |
Document privilege escalation vulnerability in postgresql. |
1.1_1 08 Feb 2005 18:14:45
 |
simon  |
Document multiple protocol dissectors vulnerabilities in ethereal. |
1.1_1 08 Feb 2005 14:49:58
 |
nectar  |
Add another squid issue.
PR: ports/76967
Submitted by: Thomas-Martin Seck <tmseck@netcologne.de> |
1.1_1 08 Feb 2005 14:43:51
 |
nectar  |
Add CERT Vulnerability Note reference for one squid issue,
and correct the reference for another one [1].
Reported by: Thomas-Martin Seck <tmseck@netcologne.de> [1] |
1.1_1 08 Feb 2005 13:48:12
 |
nectar  |
Add CVE name for squid confusing empty ACL issue. |
1.1_1 07 Feb 2005 20:02:30
 |
nectar  |
Add US-CERT Vulnerability Note references for recent squid issues. |
1.1_1 04 Feb 2005 04:26:10
 |
perky  |
Add missing <code> markups in a citation from PSF-2005-001. |
1.1_1 04 Feb 2005 04:09:11
 |
perky  |
Add an entry for PSF-2005-001,
"SimpleXMLRPCServer.py allows unrestricted traversal" |
1.1_1 03 Feb 2005 22:30:59
 |
marcus  |
Update the entry for CAN-2005-0064 to indicate that gpdf 2.8.3 has a fix
for this vulnerability. |
1.1_1 02 Feb 2005 18:59:10
 |
nectar  |
Note that perl does not have a suidperl by default. |
1.1_1 02 Feb 2005 17:38:45
 |
nectar  |
Note vulnerabilities in perl. |
1.1_1 02 Feb 2005 15:46:17
 |
nectar  |
Add Bugtraq ID for evolution issue. |
1.1_1 01 Feb 2005 17:03:31
 |
nectar  |
Add CVE name for squid WCCP issue. |
1.1_1 01 Feb 2005 14:14:55
 |
nectar  |
Add a <modified> tag to the perl File::Path issue since the affected
versions were changed.
Forgotten by: tobez |
1.1_1 01 Feb 2005 13:38:16
 |
tobez  |
Narrow perl File::Path vulnerability version range a bit. |
1.1_1 01 Feb 2005 09:03:52
 |
niels  |
Documented vulnerabilities found in the newspost, newsfetch and newsgrab ports.
http://people.freebsd.org/~niels/issues/newspost-20050114.txt
http://people.freebsd.org/~niels/issues/newsgrab-20050114.txt
http://people.freebsd.org/~niels/issues/newsfetch-20050119.txt
Approved by: nectar (mentor) |
1.1_1 31 Jan 2005 21:44:32
 |
nectar  |
The latest xpdf buffer overflow has been repaired in an update
to pdftohtml.
Submitted by: erwin |
1.1_1 31 Jan 2005 21:40:10
 |
nectar  |
Add CVE names for recent squid vulnerabilities. |
1.1_1 29 Jan 2005 21:43:36
 |
sem  |
squid -- buffer overflow in WCCP recvfrom() call
PR: ports/76827
Submitted by: squid maintainer |
1.1_1 27 Jan 2005 16:38:35
 |
simon  |
Mark cups-base as fixed wrt. to "makeFileKey2() buffer overflow
vulnerability". |
1.1_1 26 Jan 2005 20:25:47
 |
simon  |
Document "makeFileKey2()" buffer overflow vulnerability in xpdf (and
programs embedding xpdf). |
1.1_1 26 Jan 2005 16:20:43
 |
nectar  |
pdflib has been corrected.
Noticed by: Hilko Meyer <Hilko.Meyer@gmx.de> |
1.1_1 25 Jan 2005 13:50:43
 |
nectar  |
Document a vulnerability in zhcon. |
1.1_1 25 Jan 2005 10:51:10
 |
simon  |
Fix last YAMT entry update to actually make sense... Greater than and
less than are not the same...
Pointy hat to: simon |
1.1_1 25 Jan 2005 10:46:29
 |
simon  |
Mark latest YAMT port version as fixed. |
1.1_1 25 Jan 2005 00:50:02
 |
simon  |
Document arbitrary code execution vulnerability in evolution. |
1.1_1 24 Jan 2005 22:25:58
 |
nectar  |
The previous commit was
Submitted by: Thomas-Martin Seck <tmseck@netcologne.de> |
1.1_1 24 Jan 2005 22:24:02
 |
nectar  |
Correct the entry date for 4e4bd2c2-6bd5-11d9-9e1e-c296ac722cb3
``squid -- HTTP response splitting cache pollution attack''. |
1.1_1 24 Jan 2005 20:12:25
 |
nectar  |
Document a local vulnerability in mod_dosevasive. |
1.1_1 24 Jan 2005 19:39:20
 |
nectar  |
Document a possible cache-poisoning issue affecting squid.
Submitted by: Thomas-Martin Seck <tmseck@netcologne.de> |
1.1_1 24 Jan 2005 18:45:43
 |
nectar  |
Document Bugzilla XSS issue. |
1.1_1 24 Jan 2005 18:38:47
 |
nectar  |
Oops, forgot to set <discovery> date. |
1.1_1 24 Jan 2005 17:35:45
 |
nectar  |
Document window injection vulnerabilities affecting several web browsers. |
1.1_1 24 Jan 2005 15:29:18
 |
nectar  |
Cancel duplicate phpbb entry e8c6ade2-6bcc-11d9-8e6f-000a95bc6fae. It
was already documented as e3cf89f0-53da-11d9-92b7-ceadd4ac2edd.
Useful references and descriptions were merged.
Noticed by: simon |
1.1_1 23 Jan 2005 23:52:34
 |
simon  |
Document a vulnerability in YAMT. |
1.1_1 22 Jan 2005 14:37:47
 |
simon  |
Add squid security advisories for two recent squid entries.
Submitted by: Thomas-Martin Seck <tmseck@netcologne.de> |
1.1_1 22 Jan 2005 09:35:07
 |
edwin  |
squid bug #1200:
squid -- HTTP response splitting cache pollution attack
PR: ports/76550
Submitted by: Thomas-Martin Seck <tmseck@netcologne.de> |
1.1_1 22 Jan 2005 01:13:36
 |
simon  |
Fix typo in last commit. |
1.1_1 22 Jan 2005 00:55:05
 |
simon  |
Document XSS in Horde. |
1.1_1 21 Jan 2005 18:30:14
 |
nectar  |
Oops, I accidently changed an <entry> date when I should have
added a <modified> date. |
1.1_1 21 Jan 2005 17:48:02
 |
nectar  |
Document vulnerabilities in older versions of Midnight Commander. |
1.1_1 21 Jan 2005 17:34:08
 |
nectar  |
Document a race condition in Perl's File::Path module. |
1.1_1 21 Jan 2005 17:01:03
 |
nectar  |
Document phpBB vulnerabilities. |
1.1_1 21 Jan 2005 16:50:40
 |
nectar  |
Document vulnerabilities in the Opera web browser's Java implementation. |
1.1_1 21 Jan 2005 16:38:02
 |
nectar  |
Document that older versions of sudo lack CDPATH environmental variable
handling. |
1.1_1 21 Jan 2005 16:30:46
 |
nectar  |
Document vulnerabilities in fcron. |
1.1_1 21 Jan 2005 16:07:31
 |
nectar  |
Document vulnerabilities in RealPlayer. |
1.1_1 21 Jan 2005 15:54:15
 |
nectar  |
Add CVE name and iDEFENSE advisory references to xzgv issue. |
1.1_1 21 Jan 2005 15:37:24
 |
nectar  |
Grr, get the imlib version number right! |
1.1_1 21 Jan 2005 15:31:52
 |
nectar  |
Oops, imlib 1.9.15 is still affected. Adjust version number to reflect
upcoming fix. |
1.1_1 21 Jan 2005 15:16:01
 |
nectar  |
Document xpm heap overflows and integer overflows affecting imlib and imlib2. |
1.1_1 21 Jan 2005 14:53:15
 |
nectar  |
Document a vulnerability in eGroupWare. |
1.1_1 21 Jan 2005 14:42:29
 |
nectar  |
Document Quake II vulnerabilities reported by Richard Stanway. |
1.1_1 21 Jan 2005 13:53:46
 |
nectar  |
Add CVE names for konversation bugs. |
1.1_1 19 Jan 2005 20:47:31
 |
josef  |
Document security issue in irc/konversation.
Pointed out by: markus |
1.1_1 19 Jan 2005 16:39:29
 |
nectar  |
Correct several instances where the "msgid" attribute content had an
extraneous trailing greater-than character ">", e.g.
<mlist msgid="some-message@id>">some-url</mlist>
These were probably the result of off-by-one errors during
cut-and-paste. |
1.1_1 19 Jan 2005 16:19:14
 |
nectar  |
Eliminate character entity references. They are technically fine of
course, but I prefer to use the UTF-8 character directly: it makes
grep'ing and the like easier. |
1.1_1 19 Jan 2005 14:13:09
 |
nectar  |
Update entries with 12 new CVE name references. |
1.1_1 19 Jan 2005 11:52:27
 |
edwin  |
Fix date (was YYYY-MM-DD, now 2005-01-19)
Thanks for Chimera@#bsdports |
1.1_1 19 Jan 2005 11:05:02
 |
edwin  |
squid -- no sanity check of usernames in squid_ldap_auth
(My first attempt to update this thing. Hope all goes fine!)
PR: ports/76364
Submitted by: Thomas-Martin Seck <tmseck@netcologne.de> |
1.1_1 18 Jan 2005 20:25:53
 |
simon  |
Document remote DoS in CUPS.
Heads-ups by: Hilko Meyer <hilko.meyer@gmx.de>
Description by: nectar |
1.1_1 18 Jan 2005 17:47:15
 |
nectar  |
During last year's bumpercrop of vulnerabilities in libtiff, a 2004 CVE
name was assigned to what was actually a much older (circa March 2002)
denial-of-service issue. Document it, since occassionally the CVE name
crops up and then I wonder why we missed it. |
1.1_1 18 Jan 2005 17:23:23
 |
nectar  |
Document exploitable vulnerabilities in zgv and xzgv. |
1.1_1 18 Jan 2005 16:59:56
 |
nectar  |
Document bug in Mozilla-based software that may leave downloaded files
or attachments world-readable. |
1.1_1 18 Jan 2005 16:02:38
 |
simon  |
Add more references to exim entry. |
1.1_1 18 Jan 2005 15:23:49
 |
nectar  |
pdflib contains libtiff, and thus is affected by several vulnerabilities
that affected libtiff. |
1.1_1 18 Jan 2005 12:29:58
 |
simon  |
Document remote command execution vulnerability in awstats. |
1.1_1 18 Jan 2005 01:02:45
 |
simon  |
Document security vulnerability in ImageMagick. |
1.1_1 17 Jan 2005 17:44:13
 |
simon  |
Update "cups-base -- HPGL buffer overflow vulnerability" entry to
reflect the fix in the latest port version. |
1.1_1 17 Jan 2005 17:20:57
 |
nectar  |
Spelling corrections. |
1.1_1 17 Jan 2005 13:42:10
 |
nectar  |
Regarding CUPS lppasswd entry: Add the CVE names for each issue inline
with the excerpt from Bernstein's message. Note that the third issue
does not effect users of FreeBSD 4.6 or later. |