| Commit History - (may be incomplete: for full details, see links to repositories near top of page) |
| Commit | Credits | Log message |
1.1 06 May 2004 15:43:53
 |
eik  |
exim buffer overflow when verify = header_syntax is used |
1.1 06 May 2004 15:33:57
 |
nectar  |
Add phpBB session table exhaustion issue.
Submitted by: Xin LI <delphij@frontfree.net> |
1.1 05 May 2004 21:49:49
 |
nectar  |
Add the issues covered in FreeBSD-SA-04:08.heimdal and
FreeBSD-SA-04:09.kadmind. |
1.1 05 May 2004 14:57:33
 |
nectar  |
make tidy |
1.1 05 May 2004 14:57:02
 |
nectar  |
Use PORTVERSION conventions for FreeBSD version numbers, so that
5.2.1-RELEASE-p5 becomes 5.2.1_5 (not 5.2.1p5, as it would have been
previously).
This is necessary because e.g. 5.2p1 > 5.2.1p5 using existing version
comparison tools. |
1.1 03 May 2004 20:15:32
 |
nectar  |
Correct package name for xchat Socks5 vulnerability (xchat -> xchat2).
Note that the issue is fixed in version 2.0.8_2 (thanks marcus!). |
1.1 03 May 2004 18:23:43
 |
nectar  |
Correct the fixed version for lha. |
1.1 03 May 2004 14:42:39
 |
nectar  |
png issue was fixed in png-1.2.5_4 |
1.1 02 May 2004 16:55:28
 |
nectar  |
Add a vulnerability in www/pound.
Submitted by: clement
Add a security-related regression in ftp/proftpd.
Add several security issues in misc/mc.
Add a DoS issue in graphics/png.
Add a security issues in archivers/lha.
Add recent advisories for xine.
Add rsync path traversal issue. |
1.1 30 Apr 2004 16:04:55
 |
nectar  |
tla is also affected by libneon issue.
PR: ports/65754
Submitted by: Frank Ruell <stoerte@dreamwarrior.net>
Additional reference for mysql issue.
Submitted by: Daniel Harris <dannyboy@FreeBSD.org> |
1.1 23 Apr 2004 23:07:28
 |
nectar  |
Added CVE name for ident2 issue.
Added the ``new'' TCP DoS issue.
Added phpBB issue. (1)
Added XChat Socks5 issue.
Submitted by: (1) Frankye - ML <listsucker@ipv5.net> |
1.1 16 Apr 2004 16:29:01
 |
nectar  |
Add mysqlbug temporary file handling vulnerability.
Add ident2 vulnerability.
make tidy (sorry, I meant to do this in a separate commit) |
1.1 16 Apr 2004 14:44:09
 |
nectar  |
Additional CVE name for recent CVS vulnerability. |
1.1 16 Apr 2004 00:49:15
 |
nectar  |
Add kdepim vulnerability |
1.1 16 Apr 2004 00:26:36
 |
nectar  |
Add neon vulnerability
Correct the version range for openh323 |
1.1 14 Apr 2004 17:18:52
 |
nectar  |
Add CVS vulnerabilities. |
1.1 14 Apr 2004 15:10:12
 |
nectar  |
Document another racoon DoS vulnerability.
Note that racoon was also affected by the tcpdump ISAKMP vulnerability. |
1.1 13 Apr 2004 20:39:27
 |
nectar  |
make tidy |
1.1 13 Apr 2004 20:38:39
 |
nectar  |
Add CVE name for racoon DoS vulnerability. |
1.1 13 Apr 2004 17:56:43
 |
nectar  |
Correct modified date in previous commit: format is YYYY-MM-DD and
timezone is UTC. |
1.1 13 Apr 2004 17:31:13
 |
fjoe  |
Midnight Commander vulnerability CAN-2003-1023 was fixed in version 4.6.0_9. |
1.1 07 Apr 2004 17:13:05
 |
nectar  |
make tidy |
1.1 07 Apr 2004 16:27:57
 |
nectar  |
Add new affected version of gaim.
Add year 2004 FreeBSD security advisories. |
1.1 07 Apr 2004 13:06:25
 |
nectar  |
Add two racoon issues, one particularly serious. |
1.1 05 Apr 2004 17:05:25
 |
nectar  |
Add CVE name for oftpd issue. |
1.1 03 Apr 2004 23:19:29
 |
nectar  |
Add Midnight Commander buffer overflow. |
1.1 03 Apr 2004 23:18:05
 |
nectar  |
Oops, tidy.xsl should now produce VuXML 1.1 documents on output. |
1.1 02 Apr 2004 23:31:04
 |
nectar  |
Add VuXML 1.1 DTD
Update document type declaration to VuXML 1.1 |
1.0 02 Apr 2004 23:27:51
 |
nectar  |
make tidy |
1.0 02 Apr 2004 23:24:50
 |
nectar  |
Add Heimdal cross-realm validation issue. |
1.0 01 Apr 2004 22:41:02
 |
nectar  |
Correct usage message for tidy.sh.
Submitted by: Frankye Fattarelli <frankye@ipv5.net> |
1.0 31 Mar 2004 20:33:24
 |
nectar  |
Add security issue affecting the Courier mail services. |
1.0 31 Mar 2004 19:42:11
 |
nectar  |
Add isakmpd denial-of-service vulnerability. |
1.0 31 Mar 2004 19:03:40
 |
nectar  |
Add apache 2 DoS vulnerability that doesn't affect us. I keep coming
across the CVE name (CAN-2004-0174) and re-researching it. |
1.0 31 Mar 2004 16:52:24
 |
nectar  |
Add mplayer and tcpdump issues.
Submitted by: Frankye Fattarelli <frankye@ipv5.net>
Reported by: Many |
1.0 31 Mar 2004 16:28:34
 |
nectar  |
Correct a mispelled CVE name. |
1.0 30 Mar 2004 06:18:27
 |
nectar  |
make tidy |
1.0 30 Mar 2004 06:16:21
 |
nectar  |
Add a `make tidy' target that will clean up and sort a VuXML
document. Requires xsltproc. |
1.0 30 Mar 2004 06:14:34
 |
nectar  |
Fix dates for SA-04:06.ipv6 and phpbb issues (typos).
Add Bugtraq ID and other references for many entries.
Delete duplicate copula.
Submitted by: Frankye Fattarelli <frankye@ipv5.net> |
1.0 29 Mar 2004 17:25:50
 |
nectar  |
Add zebra/quagga denial of service vulnerability.
Submitted by: sumikawa |
1.0 29 Mar 2004 15:26:51
 |
nectar  |
Correct advisory name for old bind issue. |
1.0 29 Mar 2004 15:26:14
 |
nectar  |
Add old ecartis issue.
Add FreeBSD-SA-04:06.ipv6.
Correct advisory name for old pine issue. |
1.0 28 Mar 2004 20:13:32
 |
nectar  |
Add Emil issue. |
1.0 28 Mar 2004 19:59:46
 |
nectar  |
Fix a botched version number (the package name was erroneously included).
Add another phpbb vulnerability. [1]
Add oftpd denial-of-services. [2]
Submitted by: Frankye Fattarelli <frankye@ipv5.net> [1]
Reported by: Shane Kerr <shane@time-travellers.org> (oftpd author) [2] |
1.0 26 Mar 2004 17:40:56
 |
nectar  |
Add ethereal vulnerabilities.
PR: ports/64777 |
1.0 26 Mar 2004 17:26:51
 |
nectar  |
Oops, empty <topic> tag. Fill in for squid ACL bypass issue. |
1.0 26 Mar 2004 15:29:13
 |
nectar  |
Add squid ACL bypass.
Add xine temporary file handling issue. [1]
Submitted by: Frankye Fattarelli <frankye@ipv5.net> [1] |
1.0 26 Mar 2004 08:58:41
 |
eik  |
Add ezbounce (old) and phpBB (new) |
1.0 25 Mar 2004 18:13:59
 |
nectar  |
Add xdeview to existing UUDecode issue
Add racoon SA deletion issue. |
1.0 18 Mar 2004 19:48:56
 |
nectar  |
Add uulib, uudeview issue. |
1.0 18 Mar 2004 14:46:23
 |
nectar  |
Add SIZE.
Submitted by: trevor |
1.0 17 Mar 2004 14:19:37
 |
nectar  |
Add OpenSSL denial-of-service vulnerability. |
1.0 17 Mar 2004 00:49:52
 |
eik  |
ModSecurity < 1.7.5 |
1.0 15 Mar 2004 13:24:08
 |
nectar  |
Remove linux-XFree86-libs.
Reminded by: eik |
1.0 12 Mar 2004 03:01:46
 |
eik  |
add russian/apache13* |
1.0 11 Mar 2004 18:38:00
 |
eik  |
- restore the healthy mix of marc and securityfocus
- unicodeify Ulf again
Requested by: nectar |
1.0 11 Mar 2004 17:56:35
 |
eik  |
remove vid 3ca8dd7a-6fb3-11d8-873f-0020ed76ef5a, since the unsafe call
to sprintf is made in preparation for outputting a debug message using
OutputDebugString, which is a function from a different operating system.
While I'm here, transform U+C3A4 into ä (or 쎤), since CVS is
bad in handling binary data. |
1.0 11 Mar 2004 17:22:33
 |
eik  |
add a modified tag to vid 09d418db-70fd-11d8-873f-0020ed76ef5a |
1.0 11 Mar 2004 17:19:42
 |
eik  |
The apache ports have fixes from CVS |
1.0 11 Mar 2004 16:34:30
 |
eik  |
canonicalize list urls (mostly bugtraq) |
1.0 11 Mar 2004 13:07:06
 |
eik  |
correct typo
correct entry/modification date |
1.0 11 Mar 2004 12:41:06
 |
nectar  |
Delete duplicated mod_python entry, merging additional information into
previous entry. |
1.0 11 Mar 2004 11:42:14
 |
eik  |
le -> lt |
1.0 11 Mar 2004 11:37:29
 |
eik  |
add mod_python |
1.0 08 Mar 2004 13:53:50
 |
nectar  |
The previous commit was in error. Re-add wu-ftpd+ipv6.
The actual port which was corrected due to IPv6 modifications is
apache+ipv6: remove it.
Reported by: ache
Doofus: nectar |
1.0 08 Mar 2004 13:44:42
 |
nectar  |
Remove wu-ftpd+ipv6. Due to IPv6 modifications, the bug had been
already corrected.
Submitted by: sumikawa |
1.0 08 Mar 2004 13:30:22
 |
nectar  |
Add wu-ftpd `restricted-[ug]id' issue. |
1.0 08 Mar 2004 12:56:20
 |
nectar  |
Add recent Apache 1.3 and 2.0 issues. |
1.0 08 Mar 2004 12:14:04
 |
nectar  |
Add mpg123. |
1.0 06 Mar 2004 21:54:59
 |
nectar  |
Add Adobe Acrobat Reader and GNU Anubis issues. |
1.0 06 Mar 2004 19:06:20
 |
nectar  |
chronological sort |
1.0 06 Mar 2004 19:04:23
 |
nectar  |
Add linux-XFree86-libs |
1.0 06 Mar 2004 00:49:31
 |
nectar  |
Expand tabs.
Add xboing issue. |
1.0 03 Mar 2004 13:58:53
 |
nectar  |
Christian Weisgerber <naddy@FreeBSD.org> fixed the metamail fix.
Add mod_python DoS issue. |
1.0 25 Feb 2004 17:03:18
 |
nectar  |
Allow validation without the need to specify which processor to use.
Now just invoke `make validate', and a shell script will be run and try
to use xmllint or nsgmls.
Requested by: des |
1.0 25 Feb 2004 16:24:40
 |
nectar  |
Add entries for: hsftp, DarwinStreamingServer, libxml2, lbreakout2,
phpnuke, mailman, and fetchmail. |
1.0 22 Feb 2004 16:15:48
 |
nectar  |
Note vulnerabilities in phpmyadmin, pwlib, openh323, asterisk. |
1.0 19 Feb 2004 16:21:38
 |
nectar  |
Add a <modified> tag to the XFree86 issue, and move it up to
it's chronological spot within the file. |
1.0 19 Feb 2004 16:15:34
 |
nectar  |
I forgot the topic for the metamail issue. |
1.0 19 Feb 2004 02:11:01
 |
eik  |
XFree86-Server-4.3.0_14 is the fixed version |
1.0 18 Feb 2004 21:47:46
 |
nectar  |
Note metamail vulnerabilities. |
1.0 15 Feb 2004 18:11:34
 |
nectar  |
Correct version for previous entry (mnoGoSearch >= 3.2). |
1.0 15 Feb 2004 17:50:53
 |
nectar  |
Normalize dates: YYYY-MM-DD, not YYYY/MM/DD. |
1.0 15 Feb 2004 17:45:06
 |
nectar  |
Note buffer overflow in mnoGoSearch. |
1.0 13 Feb 2004 21:07:05
 |
nectar  |
Note insecure temporary file/directory handling in libtool.
Reported by: eik |
1.0 12 Feb 2004 19:20:51
 |
nectar  |
Update with information garnered from FORBIDDEN tags used in ports
in the accessibility, arabic, archives, astro, audio, benchmarks,
biology, cad, and chinese categories. |
1.0 12 Feb 2004 16:13:51
 |
nectar  |
Note rsync buffer overflow from December. |
1.0 12 Feb 2004 15:54:43
 |
nectar  |
Remove `vulnerability-test-port'--- it wasn't supposed to get committed
:-) |
1.0 12 Feb 2004 15:49:09
 |
nectar  |
Forgot PORTEPOCH for samba 3.x. While I'm at it, note that our port is
patched. |
1.0 12 Feb 2004 15:46:17
 |
nectar  |
Note gaim's bumper crop of vulnerabilities. |
1.0 12 Feb 2004 15:19:03
 |
nectar  |
Note Samba 3.0.x password initialization bug |
1.0 12 Feb 2004 15:09:26
 |
nectar  |
Note clamav remote denial-of-service. |
1.0 12 Feb 2004 15:01:48
 |
nectar  |
Note XFree86 server buffer overflows. |
1.0 12 Feb 2004 14:43:45
 |
nectar  |
Add missing `<p>'s in Apache-SSL entry. |
1.0 12 Feb 2004 14:23:48
 |
nectar  |
Add VuXML DTDs and the VuXML document for FreeBSD. |