| Commit History - (may be incomplete: for full details, see links to repositories near top of page) |
| Commit | Credits | Log message |
1.1 17 Aug 2004 06:40:37
 |
knu  |
Add an entry for:
Ruby insecure file permissions in the CGI session management |
1.1 16 Aug 2004 22:38:28
 |
nectar  |
Document a setgid "games" security issue in xonix. Based on a VuXML
entry that was
Submitted by: robert@OpenBSD.org |
1.1 15 Aug 2004 15:51:15
 |
nectar  |
Correct the version number range affected for ja-samba.
Correct the version number range affected for Mozilla 1.8 alphas.
Problem hinted at by: eik |
1.1 15 Aug 2004 14:31:56
 |
nectar  |
Correct the version number range affected for Mozilla 1.8 alphas.
Problem hinted at by: eik
While I'm here, add a CVE name reference and a couple of other relevant
Bugzilla links. It is interesting that this security issue was reported
as early as 1999. Also, replace the text plagiarized from the Secunia
advisory without attribution with a more helpful (maybe?) description of
the issue. |
1.1 13 Aug 2004 21:31:53
 |
trhodes  |
Format string vulnerability in jftpgw.
Informed by: Robert Nagy <robert@openbsd.org> |
1.1 12 Aug 2004 22:06:17
 |
nectar  |
Repair broken URL.
Noticed by: simon |
1.1 12 Aug 2004 21:07:06
 |
nectar  |
Add two issues covering three KDE advisories: two temporary file
handling issues, and a KHTML issue. |
1.1 12 Aug 2004 20:54:13
 |
marcus  |
The last commit should have changed the comparison tag from <le> to <lt>. |
1.1 12 Aug 2004 20:44:41
 |
marcus  |
Update Gaim vulnerability (5b8f9a02-ec93-11d8-b913-000c41e2cdad) to indicate
that gaim-0.81_1 has a fix for this. |
1.1 12 Aug 2004 19:23:23
 |
nectar  |
The MSN component of Gaim contains remotely exploitable buffer
overflows. |
1.1 12 Aug 2004 19:05:51
 |
nectar  |
The Adobe Acrobat Reader can be coerced into executing arbitrary
commands on UNIX systems. |
1.1 12 Aug 2004 18:56:10
 |
nectar  |
Under certain configurations of POPfile may allow an attacker to
retrieve files from the victim's machine.
Reported by: Daniel Grund <mail@dgrund.de> |
1.1 12 Aug 2004 18:43:01
 |
nectar  |
Correct version information syntax in a number of entries. VuXML-using
tools are expected only to understand actual package names and version
numbers, not globs such as `foo-{bar,baz}' or `1.*'. |
1.1 12 Aug 2004 11:58:18
 |
eik  |
give the ImageMagick png vulnerability an own entry |
1.1 11 Aug 2004 22:57:51
 |
eik  |
f72ccf7c-e607-11d8-9b0a-000347a4fa7d is a duplicate of
6f955451-ba54-11d8-b88c-000d610a3b12, move references |
1.1 10 Aug 2004 11:00:48
 |
eik  |
add a reference for linux-png-1.0.x to 3a408f6f-9c52-11d8-9366-0020ed76ef5a |
1.1 09 Aug 2004 15:10:03
 |
eik  |
add ImageMagick to the list of png-vulnerable ports |
1.1 07 Aug 2004 08:33:00
 |
eik  |
correct typo |
1.1 06 Aug 2004 21:51:24
 |
marcus  |
Add an entry for Thunderbird to the libpng vulnerability. |
1.1 05 Aug 2004 23:35:33
 |
eik  |
move abe47a5a-e23c-11d8-9b0a-000347a4fa7d to vuxml, add mozilla to the list of
vulnerable ports |
1.1 05 Aug 2004 14:27:36
 |
eik  |
move f9e3e60b-e650-11d8-9b0a-000347a4fa7d to vuxml, add mozilla to the list of
vulnerable ports |
1.1 30 Jul 2004 11:19:37
 |
eik  |
Mozilla / Firefox user interface spoofing vulnerability |
1.1 27 Jul 2004 11:46:15
 |
des  |
Use & instead of naked &. |
1.1 27 Jul 2004 11:45:05
 |
des  |
Add CVE name and correct URL to iDEFENSE advisory for the SSLtelnet issue. |
1.1 22 Jul 2004 23:30:11
 |
eik  |
- add some references
- correctly match samba 3.0
- add ja-samba |
1.1 22 Jul 2004 15:45:05
 |
trhodes  |
Fix an XML tag. |
1.1 22 Jul 2004 15:22:43
 |
trhodes  |
Mark the 2.2.x series of Samba as vulnerable. |
1.1 22 Jul 2004 14:43:13
 |
trhodes  |
Recently announced Samba issue. |
1.1 16 Jul 2004 07:31:22
 |
eik  |
fix courier-imap version number |
1.1 15 Jul 2004 08:01:25
 |
eik  |
PHP memory_limit and strip_tags() vulnerabilities. |
1.1 11 Jul 2004 00:59:46
 |
eik  |
ethereal |
1.1 08 Jul 2004 14:24:07
 |
eik  |
move e5e2883d-ceb9-11d8-8898-000d6111a684 to vuln.xml |
1.1 05 Jul 2004 21:27:12
 |
eik  |
XSS vulnerability affecting other webmail systems |
1.1 05 Jul 2004 17:24:44
 |
nectar  |
Add missing mandatory <body> element for SSLtelnet issue. |
1.1 05 Jul 2004 12:03:53
 |
des  |
Add an entry for the SSLtelnet format string vulnerability. |
1.1 03 Jul 2004 15:27:22
 |
naddy  |
Pavuk HTTP Location header overflow |
1.1 03 Jul 2004 06:48:34
 |
trhodes  |
Move phpnuke vulnerabilities to VuXML. |
1.1 02 Jul 2004 14:24:04
 |
eik  |
GNATS local privilege elevation (corrected PORTREVISION) |
1.1 02 Jul 2004 13:31:45
 |
eik  |
GNATS local privilege elevation |
1.1 02 Jul 2004 09:13:07
 |
des  |
Whitespace cleanup. |
1.1 02 Jul 2004 09:12:52
 |
des  |
Add SA-04:13.linux |
1.1 02 Jul 2004 00:48:56
 |
eik  |
move "phpMyAdmin code injection" to vuxml |
1.1 01 Jul 2004 23:55:39
 |
pav  |
- Add phpMyAdmin 2.5.7 vulnerability.
I hope I got XML right. |
1.1 28 Jun 2004 22:49:17
 |
trhodes  |
Use the equal '=' sign as only the current version was affected. |
1.1 28 Jun 2004 21:27:16
 |
eik  |
add a reference to ISC DHCP overflows |
1.1 28 Jun 2004 21:20:00
 |
trhodes  |
Add xorg-clients due to xdm socket vuln. |
1.1 28 Jun 2004 03:58:47
 |
trhodes  |
Move MoinMoin entry to VuXML. |
1.1 27 Jun 2004 19:26:14
 |
eik  |
reference cleanup |
1.1 26 Jun 2004 00:45:08
 |
trhodes  |
Fix the previous entry; it had an incorrect port range. |
1.1 25 Jun 2004 20:01:28
 |
trhodes  |
Add an entry for recent isc-dhcp3-server buffer overflows.
Remove the one in portaudit.txt. |
1.1 25 Jun 2004 17:18:57
 |
trhodes  |
Move giFT-FastTrack to VuXML. |
1.1 25 Jun 2004 02:04:08
 |
trhodes  |
Fix an older entry which ends with "buffer overflows vuxml".
Fill in a date on my previous entry. |
1.1 25 Jun 2004 01:35:18
 |
trhodes  |
Move the Gallery entry to VuXML. |
1.1 25 Jun 2004 00:36:12
 |
eik  |
www/sitecopy uses the included libneon version 0.24.0 |
1.1 21 Jun 2004 22:03:48
 |
eik  |
I believe that linux-png-1.2.2 still contains the vulnerability.
Add some references that support this opinion. |
1.1 21 Jun 2004 20:04:18
 |
pav  |
- Extend png entry to cover it's linux-png variant
Requested by: eik |
1.1 14 Jun 2004 21:05:16
 |
fjoe  |
Midnight Commander security vulnerabilities
CAN-2004-0226, CAN-2004-0231, CAN-2004-0232
fixed in mc-4.6.0_10. |
1.1 12 Jun 2004 12:22:23
 |
eik  |
add a $FreeBSD$ tag |
1.1 09 Jun 2004 20:38:33
 |
des  |
Add CAN-2004-0541 (buffer overflow in Squid NTLM authentication helper) |
1.1 08 Jun 2004 12:42:09
 |
eik  |
Fix for CAN-2004-0097
Forgotten by: sobomax |
1.1 07 Jun 2004 21:21:06
 |
des  |
Correction: FreeBSD-SA-04:12.jailroute does not apply to 4.7 and older. |
1.1 07 Jun 2004 21:17:33
 |
des  |
Whitespace cleanup |
1.1 07 Jun 2004 21:17:02
 |
des  |
Add FreeBSD-SA-04:12.jailroute. |
1.1 26 May 2004 11:32:29
 |
des  |
FreeBSD-SA-04:11 |
1.1 24 May 2004 11:49:54
 |
ale  |
Update modified date for mysql bug after fixing typo.
Requested by: nectar |
1.1 21 May 2004 12:42:01
 |
nectar  |
Add CVE name for one of the leafnode issues. |
1.1 21 May 2004 12:39:46
 |
nectar  |
Edit the topics to distinguish a bit better between the different
leafnode DoS issues. |
1.1 21 May 2004 12:13:52
 |
nectar  |
Document several issues in leafnode.
Submitted by: Matthias Andree <matthias.andree@gmx.de> |
1.1 21 May 2004 07:57:39
 |
ale  |
Fix typo.
Spotted by: eik |
1.1 19 May 2004 21:06:20
 |
nectar  |
Correct a typo (s/Jon/Joe/) |
1.1 19 May 2004 20:21:32
 |
nectar  |
Add subversion and neon date parsing vulnerabilities. |
1.1 19 May 2004 12:57:14
 |
des  |
make tidy |
1.1 19 May 2004 12:55:35
 |
des  |
Add an entry for the cvs pserver heap overflow. |
1.1 18 May 2004 14:53:33
 |
nectar  |
Add CVE name and CERT Vulnerability Note references for old Cyrus bug. |
1.1 18 May 2004 14:43:04
 |
nectar  |
make tidy |
1.1 18 May 2004 14:40:22
 |
nectar  |
Forced commit to note that the content of the previous revision was
Reported by: Ion-Mihai Tetcu <itetcu@apropo.ro> |
1.1 18 May 2004 14:39:03
 |
nectar  |
Add URI handling issue that affects Opera and KDE, at least. |
1.1 18 May 2004 11:50:58
 |
ale  |
Note that the mysqlbug has been fixed. |
1.1 17 May 2004 13:20:30
 |
nectar  |
Update version number for fspd, now that it has been corrected.
Reported by: Radim Kolar <hsn@netmag.cz> |
1.1 15 May 2004 13:20:04
 |
eik  |
&, not | |
1.1 15 May 2004 13:13:50
 |
eik  |
ProFTPD vulnerability is fixed in
<http://www.proftpd.org/docs/NEWS-1.2.10rc1>
Submitted by: Koop Mast <kwm@rainbow-runner.nl> |
1.1 12 May 2004 16:01:25
 |
nectar  |
Add Cyrus IMSPd security release.
Reported by: eik |
1.1 12 May 2004 15:28:50
 |
nectar  |
Add old Cyrus IMAP server heap buffer overflow.
Reported by: eik |
1.1 09 May 2004 22:26:05
 |
nobutaka  |
The security issue of multimedia/xine (insecure temporary file creation in
xine-check, xine-bugreport) has been fixed in 0.9.23_3. |
1.1 06 May 2004 21:11:00
 |
nectar  |
Only one <modified> is allowed per entry. |
1.1 06 May 2004 20:40:19
 |
des  |
Correct the discovery date for the proftpd issue. |
1.1 06 May 2004 16:26:28
 |
nectar  |
Oops. s/2005-05-05/2004-05-05/ :-) |
1.1 06 May 2004 16:12:55
 |
nectar  |
Second-guess Oliver and correct the affected entry for exim
in order to unbreak this file. |
1.1 06 May 2004 15:43:53
 |
eik  |
exim buffer overflow when verify = header_syntax is used |
1.1 06 May 2004 15:33:57
 |
nectar  |
Add phpBB session table exhaustion issue.
Submitted by: Xin LI <delphij@frontfree.net> |
1.1 05 May 2004 21:49:49
 |
nectar  |
Add the issues covered in FreeBSD-SA-04:08.heimdal and
FreeBSD-SA-04:09.kadmind. |
1.1 05 May 2004 14:57:33
 |
nectar  |
make tidy |
1.1 05 May 2004 14:57:02
 |
nectar  |
Use PORTVERSION conventions for FreeBSD version numbers, so that
5.2.1-RELEASE-p5 becomes 5.2.1_5 (not 5.2.1p5, as it would have been
previously).
This is necessary because e.g. 5.2p1 > 5.2.1p5 using existing version
comparison tools. |
1.1 03 May 2004 20:15:32
 |
nectar  |
Correct package name for xchat Socks5 vulnerability (xchat -> xchat2).
Note that the issue is fixed in version 2.0.8_2 (thanks marcus!). |
1.1 03 May 2004 18:23:43
 |
nectar  |
Correct the fixed version for lha. |
1.1 03 May 2004 14:42:39
 |
nectar  |
png issue was fixed in png-1.2.5_4 |
1.1 02 May 2004 16:55:28
 |
nectar  |
Add a vulnerability in www/pound.
Submitted by: clement
Add a security-related regression in ftp/proftpd.
Add several security issues in misc/mc.
Add a DoS issue in graphics/png.
Add a security issues in archivers/lha.
Add recent advisories for xine.
Add rsync path traversal issue. |
1.1 30 Apr 2004 16:04:55
 |
nectar  |
tla is also affected by libneon issue.
PR: ports/65754
Submitted by: Frank Ruell <stoerte@dreamwarrior.net>
Additional reference for mysql issue.
Submitted by: Daniel Harris <dannyboy@FreeBSD.org> |
1.1 23 Apr 2004 23:07:28
 |
nectar  |
Added CVE name for ident2 issue.
Added the ``new'' TCP DoS issue.
Added phpBB issue. (1)
Added XChat Socks5 issue.
Submitted by: (1) Frankye - ML <listsucker@ipv5.net> |
1.1 16 Apr 2004 16:29:01
 |
nectar  |
Add mysqlbug temporary file handling vulnerability.
Add ident2 vulnerability.
make tidy (sorry, I meant to do this in a separate commit) |