notbugAs an Amazon Associate I earn from qualifying purchases.
Want a good read? Try FreeBSD Mastery: Jails (IT Mastery Book 15)
Want a good monitor light? See my photosAll times are UTC
Ukraine

Bot filter coming soon

To deter bots pegging the database CPU to 100%, a bot testing filter to be added to the website. This should not affect newsfeeds etc. Anubis seems light-weight - it is already in use within the FreeBSD Project. This notice is just a heads up in case you see something odd. This notice will be updated after Anubis is installed.

non port: security/vuxml/vuln.xml

Number of commits found: 6273 (showing only 100 on this page)

[First Page]  «  30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40  »  [Last Page]

Friday, 2 Nov 2012
18:08 olgeni search for other commits by this committer
Add entry for webmin < 1.600_1 (potential XSS attack).

Feature safe:	yes
Original commitRevision:306877 
03:17 bdrewery search for other commits by this committer
- Document ruby vulnerabilities:
 * CVE-2012-4464 + CVE-2012-4466
   $SAFE escaping vulnerability about Exception#to_s / NameError#to_s
 * CVE-2012-4522
   Unintentional file creation caused by inserting an illegal NUL character

Reviewed by:	eadler
Feature safe:	yes
Original commitRevision:306834 
Thursday, 1 Nov 2012
14:10 flo search for other commits by this committer
Update to 3.8.15

Security:	4b738d54-2427-11e2-9817-c8600054b392
Feature safe:	yes
Original commitRevision:306803 
Tuesday, 30 Oct 2012
21:01 rm search for other commits by this committer
- update to 7.16 [1]

while here:
- trim Makefile header
- remove indefinite article in COMMENT
- remove IGNORE_WITH_PHP and IGNORE_WITH_PGSQL since
  we have not this versions in the tree anymore
- fix pkg-plist
- add vuxml entry

PR:		173211
Submitted by:	Rick van der Zwet <info at rickvanderzwet dot nl> [1]
Approved by:	Nick Hilliard <nick at foobar dot org> (maintainer)
Security:	2adc3e78-22d1-11e2-b9f0-d0df9acfd7e5
Feature safe:   yes
Original commitRevision:306716 
Sunday, 28 Oct 2012
17:03 flo search for other commits by this committer
- Update www/firefox{,-i18n} to 16.0.2
- Update seamonkey to 2.13.2
- Update ESR ports and libxul to 10.0.10
- Update nspr to 4.9.3
- Update nss to 3.14
- with GNOMEVFS2 option build its extension, too [1]
- make heap-committed and heap-dirty reporters work in about:memory
- properly mark QT4 as experimental (needs love upstream)
- *miscellaneous cleanups and fixups*

mail/thunderbird will be updated once the tarballs are available.

PR:		ports/173052 [1]
Security:	6b3b1b97-207c-11e2-a03f-c8600054b392
Feature safe:	yes
In collaboration with:	Jan Beich <jbeich@tormail.org>
Original commitRevision:306558 
Friday, 26 Oct 2012
08:46 rea search for other commits by this committer
mail/exim: upgrade to 4.80.1

This is bugfix-only release, it eliminates remote code execution
in the DKIM code.

Security: http://www.vuxml.org/freebsd/b0f3ab1f-1f3b-11e2-8fe9-0022156e8794.html
QA page: http://codelabs.ru/fbsd/ports/qa/mail/exim/4.80.1
Feature safe: yes
Original commitRevision:306428 
Thursday, 25 Oct 2012
19:31 rm search for other commits by this committer
- add CVE reference (still in reserved state) for recent django vulnerabilty

Feature safe:	yes
Original commitRevision:306393 
10:12 rm search for other commits by this committer
- update django ports to 1.3.4 and 1.4.2, that fixing couple of security issues.
  All users are encouraged to upgrade immediately.
- add vuxml entry

changes common for both ports:
- trim Makefile header
- strict python version to 2.x only
- utilize options framework multiple choice feature to let user to choose
  database backends needed. Make SQLITE option default
- shorten description of HTMLDOCS_DESC to make it fit into dialog screen
- SITELIBDIR -> PKGNAMEPREFIX change in dependencies
- convert NOPORTDOCS condition to optionsng
- tab -> space change in pkg-descr

PR:		173017
Submitted by:	rm (myself)
Approved by:	lwhsu (maintainer, by mail)
Security:	5f326d75-1db9-11e2-bc8f-d0df9acfd7e5
Feature safe:   yes
Original commitRevision:306376 
Monday, 22 Oct 2012
02:37 wxs search for other commits by this committer
Document multiple wireshark vulnerabilities.

Feature safe:	yes
Original commitRevision:306252 
Thursday, 18 Oct 2012
04:13 jgh search for other commits by this committer
- clarify end-user impact for 57652765-18aa-11e2-8382-00a0d181e71d
Suggested by:	simon@
Feature safe:	yes
Original commitRevision:306051 
Wednesday, 17 Oct 2012
23:47 jgh search for other commits by this committer
- document xlockmore issue, 57652765-18aa-11e2-8382-00a0d181e71d, CVE-2012-4524
Feature safe:	yes
Original commitRevision:306041 
17:22 sem search for other commits by this committer
- xinetd vulnerability

Feature safe:	yes
Original commitRevision:306024 
Tuesday, 16 Oct 2012
14:37 glarkin search for other commits by this committer
- Updated ZF advisory to include similar XEE vulnerability

Feature safe:	yes
Original commitRevision:305978 
14:26 glarkin search for other commits by this committer
- Document Zend Framework XXE injection vulnerability

Feature safe:	yes
Original commitRevision:305974 
Monday, 15 Oct 2012
16:31 eadler search for other commits by this committer
Add the CVE for the gitolite vuln.

Feature safe:	yes
Original commitRevision:305922 
16:02 swills search for other commits by this committer
- Actually commit the VuXML entry

PR:		ports/172565
Feature safe:	yes
Pointyhat to:	swills
Original commitRevision:305918 
Sunday, 14 Oct 2012
21:05 matthew search for other commits by this committer
Document the latest security vulnerabilities for phpMyAdmin.
Fix was already committed to the port 6 days ago.

Feature safe:	yes
Original commitRevision:305894 
15:30 zi search for other commits by this committer
- Add in additional package names for recent bind vulnerability

Feature safe:	yes
Original commitRevision:305882 
Thursday, 11 Oct 2012
19:15 flo search for other commits by this committer
- update to 16.0.1
- update vuln.xml entry

Feature safe:   yes
Original commitRevision:305736 
Wednesday, 10 Oct 2012
22:07 rene search for other commits by this committer
Document a new vulnerability in www/chromium < 22.0.1229.94

Obtained
from:	http://googlechromereleases.blogspot.nl/search/label/Stable%20updates
Feature safe:	yes
Original commitRevision:305692 
21:13 flo search for other commits by this committer
- Update firefox-esr, thunderbird-esr, linux-firefox and linux-thunderbird to
10.0.8
- Update firefox and thunderbird to 16.0
- Update seamonkey to 2.13
- Update all -i18n ports respectively
- switch firefox 16.0 and seamonkey 2.13 to ALSA by default for better
  latency during pause and seeking with HTML5 video
- remove fedisableexcept() hacks, obsolete since FreeBSD 4.0
- support system hunspell dictionaries [1]
- unbreak -esr ports with clang3.2 [2]
- unbreak nss build when CC contains full path [3]
- remove GNOME option grouping [4]
- integrate enigmail into thunderbird/seamonkey as an option [5]
- remove mail/enigmail* [6]
- enable ENIGMAIL, LIGHTNING and GIO options by default
- add more reporters in about:memory: page-faults-hard, page-faults-soft,
  resident, vsize
- use bundled jemalloc 3.0.0 on FreeBSD < 10.0 for gecko 16.0,
  only heap-allocated reporter works in about:memory (see bug 762445)
- use lrintf() instead of slow C cast in bundled libopus
- use libjpeg-turbo's faster color conversion if available during build
- record startup time for telemetry
- use -z origin instead of hardcoding path to gecko runtime
- fail early if incompatible libxul version is installed (in USE_GECKO)
- *miscellaneous cleanups and fixups*

PR:		ports/171534 [1]
PR:		ports/171566 [2]
PR:		ports/172164 [3]
PR:		ports/172201 [4]
Discussed with:	ale, beat, Jan Beich [5]
Approved by:	ale [6]
In collaboration with:	Jan Beich <jbeich@tormail.org>
Security:	6e5a9afd-12d3-11e2-b47d-c8600054b392
Feature safe:	yes
Approved by:	portmgr (beat)
Original commitRevision:305684 
11:54 erwin search for other commits by this committer
Upgrade to the latest BIND patch level:

A deliberately constructed combination of records could cause named
to hang while populating the additional section of a response.

Security:	 
http://www.vuxml.org/freebsd/57a700f9-12c0-11e2-9f86-001d923933b6.html
Original commitRevision:305645 
Wednesday, 3 Oct 2012
12:51 rm search for other commits by this committer
- correct the range in last entry (le/lt typo)
Original commitRevision:305201 
12:33 rm search for other commits by this committer
- update to 2.8.10
- add vuxml entry

This release fixes SQL injection vulnerability.

PR:		172114
Submitted by:	rm (myself)
Approved by:	ports-secteam (eadler)
Security:	dee44ba9-08ab-11e2-a044-d0df9acfd7e5
Original commitRevision:305200 
Thursday, 27 Sep 2012
17:01 danfe search for other commits by this committer
Mark nvidia-driver-173.14.35_1 as not vulnerable.
Original commitRevision:304967 
Wednesday, 26 Sep 2012
21:49 rene search for other commits by this committer
Document vulnerabilities in www/chromium < 22.0.1229.79

Obtained
from:	http://googlechromereleases.blogspot.nl/search/label/Stable%20updates
Original commitRevision:304933 
15:37 glarkin search for other commits by this committer
- Document remote code execution in ePerl (all versions)
- Deprecate and schedule removal in month - no upstream fix available and
  no active development since 1998

Security:	73efb1b7-07ec-11e2-a391-000c29033c32
Security:	CVE-2001-0733
Security:	http://www.shmoo.com/mail/bugtraq/jun01/msg00286.shtml
Original commitRevision:304919 
Tuesday, 25 Sep 2012
21:41 glarkin search for other commits by this committer
- Documented PNG file DoS vulnerability in ImageMagick and GraphicsMagick
- Added -nox11 suffixes to various ImageMagick entries
Original commitRevision:304862 
Sunday, 23 Sep 2012
12:27 eadler search for other commits by this committer
Update vuxml to indicate which versions are vulnerable.
Original commitRevision:304735 
Thursday, 20 Sep 2012
03:02 bdrewery search for other commits by this committer
- Update php52 backports patch to 20120911
- Add and update relevant vuxml entries

Changes:
  - CVE-2011-1398 - The sapi_header_op function in main/SAPI.c in PHP
    before 5.3.11 does not properly handle %0D sequences
  - CVE-2012-0789 - Memory leak in the timezone functionality in PHP
    before 5.3.9 allows remote attackers to cause a denial of service
    (memory consumption) by triggering many strtotime function calls,
    which are not properly handled by the php_date_parse_tzfile cache.
  - CVE-2012-3365 - The SQLite functionality in PHP before 5.3.15 allows
    remote attackers to bypass the open_basedir protection mechanism via
     unspecified vectors
  - Timezone database updated to version 2012.5 (2012e) (from 2011.13 (2011m))
  - Minor improvements (CVE-2012-2688, compilation issues with old GCC)

PR:		ports/171583
Submitted by:	Svyatoslav Lempert <svyatoslav.lempert@gmail.com>
Approved by:	Alex Keda <admin@lissyara.su> (maintainer)
Original commitRevision:304559 
01:09 bdrewery search for other commits by this committer
- CVE-2012-2688 was addressed by php52-5.2.17_10

PR:		ports/170063
PR:		ports/171583
Reported by:	Svyatoslav Lempert <svyatoslav.lempert@gmail.com>
Security:	bdab0acd-d4cd-11e1-8a1c-14dae9ebcf89
Original commitRevision:304558 
Wednesday, 19 Sep 2012
03:46 dougb search for other commits by this committer
Upgrade to the latest BIND patch level:

Prevents a crash when queried for a record whose RDATA exceeds
65535 bytes.

Prevents a crash when validating caused by using "Bad cache" data
before it has been initialized.

ISC_QUEUE handling for recursive clients was updated to address
a race condition that could cause a memory leak. This rarely
occurred with UDP clients, but could be a significant problem
for a server handling a steady rate of TCP queries.

A condition has been corrected where improper handling of
zero-length RDATA could cause undesirable behavior, including
termination of the named process.

For more information: https://kb.isc.org/article/AA-00788
Original commitRevision:304476 
Monday, 17 Sep 2012
18:46 lwhsu search for other commits by this committer
Document Jenkins Security Advisory 2012-09-17
Original commitRevision:304415 
Saturday, 15 Sep 2012
21:25 eadler search for other commits by this committer
include newly 'awarded' CVE
Original commitRevision:304327 
17:22 nox search for other commits by this committer
Add vuxml for older versions of multimedia/vlc .

PR:		ports/169985
Submitted by:	"Anders N." <wicked@baot.se>
Original commitRevision:304320 
02:19 eadler search for other commits by this committer
Tell the world about the recent bacula vuln
Original commitRevision:304305 
Thursday, 13 Sep 2012
03:35 swills search for other commits by this committer
- Update to 0.10.22.6 which fixes two security issues
- Document security issues in vuxml [1]

Reviewed by:	bdrewery [1]
Security:	178ba4ea-fd40-11e1-b2ae-001fd0af1a4c
Original commitRevision:304170 
Wednesday, 12 Sep 2012
07:31 danfe search for other commits by this committer
Update NVIDIA arbitrary memory access vulnerability with CVE-2012-4225.
Original commitRevision:304136 
Tuesday, 11 Sep 2012
11:38 zi search for other commits by this committer
- Update entry for net/freeradius2 to reflect local patch to address
cve-2012-3547
Original commitRevision:304088 
08:46 rea search for other commits by this committer
VuXML: document remote code execution in freeRADIUS
Original commitRevision:304085 
07:51 rea search for other commits by this committer
www/moinmoin: fix CVE-2012-4404, wrong processing of group ACLs

Using upstream patch from
  http://hg.moinmo.in/moin/1.9/raw-rev/7b9f39289e16

PR:		171346
QA page:	http://codelabs.ru/fbsd/ports/qa/www/moinmoin/1.9.4_1
Approved by:	khsing.cn@gmail.com (maintainer)
Security:	http://www.vuxml.org/freebsd/4f99e2ef-f725-11e1-8bd8-0022156e8794.html
Original commitRevision:304084 
Saturday, 8 Sep 2012
02:37 eadler search for other commits by this committer
Add vim specific modeline to help users write correct vuxml

Submitted by:	bdrewery
Original commitRevision:303851 
Friday, 7 Sep 2012
23:07 rakuco search for other commits by this committer
Document the vulnerability that led to emacs 24.2
Original commitRevision:303835 
20:25 swills search for other commits by this committer
- Update to 3.4.2 [1] [2] [3]
- Document security issue [4]

PR:		ports/171397 [1]
PR:		ports/171404 [2]
PR:		ports/171405 [3]
Submitted by:	Yuan-Chung Hsiao <ychsiao@ychsiao.org> (maintainer) [1]
Submitted by:	Joe Horn <joehorn@gmail.com> (maintainer) [2] [3]
Reviewed by:	eadler [4]
Security:	30149157-f926-11e1-95cd-001fd0af1a4c
Original commitRevision:303824 
Thursday, 6 Sep 2012
06:10 rea search for other commits by this committer
VuXML: add <modified> tag for Wireshark's entry for CVE-2012-3548
Original commitRevision:303744 
Wednesday, 5 Sep 2012
16:02 marcus search for other commits by this committer
Change the wireshark version for the DRDA fix.
Original commitRevision:303712 
10:42 rea search for other commits by this committer
VuXML: document XSS in MoinMoin before 1.9.4 via RST parser
Original commitRevision:303700 
09:47 rea search for other commits by this committer
VuXML: document wrong group ACL processing in MoinMoin
Original commitRevision:303695 
06:29 rea search for other commits by this committer
PHP 5.x: document header splitting vulnerability

There is a related CVE number (CVE-2012-4388), but there is no current
consensus about it:
  http://article.gmane.org/gmane.comp.security.oss.general/8303
Original commitRevision:303685 
Tuesday, 4 Sep 2012
21:05 mandree search for other commits by this committer
Modify fetchmail vuln' URLs to established site.
While at it, adjust the two oldest topics to current format, for uniformity,
on, for instance, http://www.vuxml.org/freebsd/pkg-fetchmail.html.
Original commitRevision:303672 
13:45 rea search for other commits by this committer
security/squidclamav: fix DoS and XSS vulnerabilities

Apply upstream patches for CVE-2012-3501 and CVE-2012-4667.

Security:	http://www.vuxml.org/freebsd/ce680f0a-eea6-11e1-8bd8-0022156e8794.html
Security:	http://www.vuxml.org/freebsd/8defa0f9-ee8a-11e1-8bd8-0022156e8794.html
PR:		171022
QA page:	http://codelabs.ru/fbsd/ports/qa/security/squidclamav/5.7_1
Approved by:	maintainer timeout (1 week)
Original commitRevision:303652 
Sunday, 2 Sep 2012
02:57 eadler search for other commits by this committer
Inform the community about a recent bitcoin DoS vuln.

Reviewed by:	swills
Original commitRevision:303527 
Saturday, 1 Sep 2012
20:16 ohauer search for other commits by this committer
- update bugzilla bugzilla3 and bugzilla42
- use new bugzilla@ address (members skv@, tota@, ohauer@)
- patch russian/japanese/german bugzilla and bugzilla templates
  so the reflect the security updates in the original templates
- patch german/bugzilla42 templates
- adopt new Makefile header

	vuxml: 6ad18fe5-f469-11e1-920d-20cf30e32f6d
	CVE: CVE-2012-3981
	https://bugzilla.mozilla.org/show_bug.cgi?id=785470
	https://bugzilla.mozilla.org/show_bug.cgi?id=785522
	https://bugzilla.mozilla.org/show_bug.cgi?id=785511
Original commitRevision:303519 
18:50 rea search for other commits by this committer
VuXML: document CVE-2012-3534, DoS via large number of connections
Original commitRevision:303508 
17:40 eadler search for other commits by this committer
vuxml matches on PKGNAME, not on the port directory.
mediawiki118 has PKGNAME mediawiki-1.18.4
Original commitRevision:303503 
17:16 rea search for other commits by this committer
Add "modified" tag to the Java 7 entry

Forgot to do it at r303435.

Spotted by:	wxs
Pointyhat to:	rea
Original commitRevision:303499 
12:44 wen search for other commits by this committer
- Update www/mediawiki to 1.19.2
- Update www/mediawiki118 to 1.18.5
- Document the security bugs
Original commitRevision:303471 
Friday, 31 Aug 2012
16:58 rea search for other commits by this committer
VuXML: update Java 7 entry with Oracle-provided details

Oracle's Java 7 update 7 fixes CVE-2012-4681.
Original commitRevision:303435 
15:17 mandree search for other commits by this committer
Tidy up paragraph formatting (it passed "make validate" before).

Suggested by:	wxs
Original commitRevision:303428 
10:59 rea search for other commits by this committer
VuXML: document CVE-2012-3548, DoS in Wireshark
Original commitRevision:303414 
Thursday, 30 Aug 2012
23:08 rene search for other commits by this committer
Document vulnerabilities in www/chromium < 21.0.1180.89

Obtained
from:	http://googlechromereleases.blogspot.nl/search/label/Stable%20updates
Original commitRevision:303394 
22:14 flo search for other commits by this committer
- Update net/asterisk to 1.8.15.1
- Update net/asterisk10 to 10.7.1
- Document vulnerabilities in vuln.xml
- Fix URLs in the pervious asterisk vuln.xml entry

Security:	http://www.vuxml.org/freebsd/4c53f007-f2ed-11e1-a215-14dae9ebcf89.html
Original commitRevision:303393 
11:40 jase search for other commits by this committer
- Update to 1.5.20
- Update MASTER_SITES
- Convert to optionsNG and add DOCS option
- Document security vulnerabilities [1]

PR:		ports/169558
Requested by:	Alexey <alexey@kouznetsov.com> (submitter)
Security:	6dd5e45c-f084-11e1-8d0f-406186f3d89d [1]
Approved by:	flo (mentor)
Original commitRevision:303369 
09:03 rea search for other commits by this committer
VuXML: document CVE-2012-4681, security manager bypass in Java 7.x
Original commitRevision:303364 
06:23 mandree search for other commits by this committer
Add a vuln' entry for fetchmail's CVE-2011-3389 vulnerability.
Original commitRevision:303361 
Monday, 27 Aug 2012
17:44 mandree search for other commits by this committer
Update fetchmail to 6.3.21_1, fixing CVE-2012-3482.
Adjust VuXML database entry from < 6.3.22 to < 6.3.21_1.

PR:		ports/170613
Approved by:	maintainer timeout (14 days)
Security:	http://www.vuxml.org/freebsd/83f9e943-e664-11e1-a66d-080027ef73ec.html
Security:	CVE-2012-3482
Original commit
Sunday, 26 Aug 2012
21:31 rea search for other commits by this committer
VuXML entry c906e0a4-efa6-11e1-8fbf-001b77d09812: fix port epoch

Pointyhat to: rea
Original commit
21:26 rea search for other commits by this committer
VuXML: document XSS in RoundCube Web-mail application

Branch 0.8.x before 0.8.1 is prone to XSS attack via incoming
HTML messages.
Original commit
17:33 rea search for other commits by this committer
news/inn: fix plaintext command injection, CVE-2012-3523

Relevant only for INN installations that are using encryption.

PR:		171013
Approved by:	fluffy@FreeBSD.org (maintainer)
Security:	http://www.vuxml.org/freebsd/a7975581-ee26-11e1-8bd8-0022156e8794.html
Original commit
01:44 avilla search for other commits by this committer
- Document Calligra input validation failure.
Original commit
Saturday, 25 Aug 2012
22:17 bdrewery search for other commits by this committer
- Document that CVE-2012-3386 only affects automake >= 1.5.0

Verified this by inspecting the automake14 source, as well as
official release tarballs and git history.

Approved by:	bapt (mentor)
Original commit
11:38 rea search for other commits by this committer
VuXML: document cross-site scripting in SquidClamav
Original commit
10:07 rea search for other commits by this committer
VuXML: document DoS in SquidGuard

SquidGuard can be crashed via the specially-crafted URL
when external URL checker is used.
Original commit
Friday, 24 Aug 2012
20:13 rea search for other commits by this committer
VuXML: document INN plaintext command injection vulnerability
Original commit
Wednesday, 22 Aug 2012
21:10 rea search for other commits by this committer
VuXML: document CVE-2012-3525 in jabberd 2.x
Original commit
20:01 rea search for other commits by this committer
VuXML: fix whitespace in my previous rssh entry
Original commit
20:00 rea search for other commits by this committer
VuXML: document rssh vulnerabilities fixed in version 2.3.3
Original commit
Tuesday, 21 Aug 2012
20:56 rea search for other commits by this committer
rssh: document arbitrary code execution, CVE-2012-3478
Original commit
Monday, 20 Aug 2012
01:40 wxs search for other commits by this committer
Put libotr entry back. I added the cited URL to the references.
Original commit
Sunday, 19 Aug 2012
21:47 dougb search for other commits by this committer
Remove the improperly formatted libotr entry. Someone with more knowledge
and experience needs to take care of this, I'm clearly not competent.
Original commit
Saturday, 18 Aug 2012
08:39 dougb search for other commits by this committer
14 August 2012 libotr version 3.2.1 released

Versions 3.2.0 and earlier of libotr contain a small heap write overrun
(thanks to Justin Ferguson for the report), and a large heap read overrun
(thanks to Ben Hawkes for the report).

Add a vuxml entry, and tune up the notes about adding a new entry.
Original commit
03:07 wxs search for other commits by this committer
Document OpenTTD DoS.
Original commit
02:30 wxs search for other commits by this committer
Document multiple wireshark vulnerabilities.

Two are from 1.8.1 (CVE-2012-4048 and CVE-2012-4049). The remaining are
from 1.8.2 which is not in ports yet.
Original commit
Friday, 17 Aug 2012
19:39 jgh search for other commits by this committer
The PostgreSQL Global Development Group today released security updates for all
active branches
of the PostgreSQL database system, including versions 9.1.5, 9.0.9, 8.4.13 and
8.3.20. This
update patches security holes associated with libxml2 and libxslt, similar to
those affecting
other open source projects. All users are urged to update their installations at
the first
available opportunity.

This security release fixes a vulnerability in the built-in XML functionality,
and a vulnerability
in the XSLT functionality supplied by the optional XML2 extension. Both
vulnerabilities allow
reading of arbitrary files by any authenticated database user, and the XSLT
vulnerability
allows writing files as well. The fixes cause limited backwards compatibility
issues.
These issues correspond to the following two vulnerabilities:

CVE-2012-3488: PostgreSQL insecure use of libxslt
CVE-2012-3489: PostgreSQL insecure use of libxml2
This release also contains several fixes to version 9.1, and a smaller number of
fixes to older versions, including:

Updates and corrections to time zone data
Multiple documentation updates and corrections
Add limit on max_wal_senders
Fix dependencies generated during ALTER TABLE ADD CONSTRAINT USING INDEX.
Correct behavior of unicode conversions for PL/Python
Fix WITH attached to a nested set operation (UNION/INTERSECT/EXCEPT).
Fix syslogger so that log_truncate_on_rotation works in the first rotation.
Only allow autovacuum to be auto-canceled by a directly blocked process.
Improve fsync request queue operation
Prevent corner-case core dump in rfree().
Fix Walsender so that it responds correctly to timeouts and deadlocks
Several PL/Perl fixes for encoding-related issues
Make selectivity operators use the correct collation
Prevent unsuitable slaves from being selected for synchronous replication
Make REASSIGN OWNED work on extensions as well
Fix race condition with ENUM comparisons
Make NOTIFY cope with out-of-disk-space
Fix memory leak in ARRAY subselect queries
Reduce data loss at replication failover
Fix behavior of subtransactions with Hot Standby
Original commit
07:27 matthew search for other commits by this committer
Document the latest phpMyAdmin vulnerability PMSA-2012-4
Original commit
Wednesday, 15 Aug 2012
19:45 bdrewery search for other commits by this committer
- Update www/typo3 to 4.7.4 [1]
- Convert to new options framework [1]
- Update www/typo345 to 4.5.19 [2]
- Update www/typo346 to 4.6.12 [3]
- Changes: https://typo3.org/news/article/typo3-4519-4612-and-474-released/
- Document security vulnerabilities [4]
 
https://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2012-004/

PR:		ports/170650 [1]
PR:		ports/170647 [2]
PR:		ports/170649 [3]
Submitted by:	Helmut Schneider <jumper99@gmx.de> (maintainer)
Security:	48bcb4b2-e708-11e1-a59d-000d601460a4 [4]
Approved by:	eadler (mentor)
Original commit
Tuesday, 14 Aug 2012
23:17 mandree search for other commits by this committer
Document CVE-2012-3482 for fetchmail, one DoS and one information disclosure
vulnerability in non-default NTLM code.

Also see ports/170613 which is pending maintainer feedback.
Original commit
Monday, 13 Aug 2012
17:57 jkim search for other commits by this committer
Belatedly add an entry for the recent IcedTea-Web updates.
Original commit
Saturday, 11 Aug 2012
17:41 novel search for other commits by this committer
Document libcloud MITM vuln.

Security:	CVE-2012-3446
Original commit
08:11 matthew search for other commits by this committer
Document the latest phpmyadmin security problem.
Original commit
Friday, 10 Aug 2012
14:38 rene search for other commits by this committer
- Document vulnerabilities in www/chromium 20.0.1132.57 and 21.0.1180.60.
- Keep the latest chromium vulnerabilies on top.
Original commit
08:08 rene search for other commits by this committer
Document two vulnerabilities in www/chromium < 21.0.1180.75 related to the
builtin PDF viewer.

Obtained
from:	http://googlechromereleases.blogspot.com/search/label/Stable%20updates
Original commit
02:50 swills search for other commits by this committer
- Update rails and friends to 3.2.8
- Document security issue in 3.2.7 [1]

Submitted by:	bdrewery [1]
Reviewed by:	swills [1]
Security:	31db9a18-e289-11e1-a57d-080027a27dbf
Original commit
Thursday, 9 Aug 2012
15:43 wxs search for other commits by this committer
Document old sudosh buffer overflow.

Noticed by:	Diego Linke
Original commit
Tuesday, 7 Aug 2012
15:57 wxs search for other commits by this committer
Fix up whitespace in 10f38033-e006-11e1-9304-000000000000.
Replace broken vid in 10f38033-e006-11e1-9304-000000000000 with one that is
correct.
Original commit
02:02 zi search for other commits by this committer
- Document FreeBSD-SA-12:05.bind
Original commit
Monday, 6 Aug 2012
22:44 bdrewery search for other commits by this committer
Document CVE-2012-3386 for devel/automake

Approved by:	eadler (mentor)
Original commit
Thursday, 2 Aug 2012
21:24 flo search for other commits by this committer
Belatedly add an entry for the recent Mozilla updates

Security:	http://www.freebsd.org/ports/portaudit/dbf338d0-dce5-11e1-b655-14dae9ebcf89.html
Original commit
12:59 zi search for other commits by this committer
- Cleanup whitespace
Original commit
12:48 wxs search for other commits by this committer
Whitespace fixes.
Original commit

Number of commits found: 6273 (showing only 100 on this page)

[First Page]  «  30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40  »  [Last Page]