notbugAs an Amazon Associate I earn from qualifying purchases.
Want a good read? Try FreeBSD Mastery: Jails (IT Mastery Book 15)
Want a good monitor light? See my photosAll times are UTC
Ukraine

Bot filter coming soon

To deter bots pegging the database CPU to 100%, a bot testing filter to be added to the website. This should not affect newsfeeds etc. Anubis seems light-weight - it is already in use within the FreeBSD Project. This notice is just a heads up in case you see something odd. This notice will be updated after Anubis is installed.

non port: security/vuxml/vuln.xml

Number of commits found: 6273 (showing only 100 on this page)

[First Page]  «  35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45  »  [Last Page]

Wednesday, 25 May 2011
16:38 rene search for other commits by this committer
Document latest www/chromium vulnerabilities.

Security:       CVE-2011-1801, -1804, -1806, -1807
Original commit
10:58 miwi search for other commits by this committer
- Cleanup Part 1

PS: wonder when pplz start to ask ports-security for review ...
Original commit
09:44 sem search for other commits by this committer
- Document the last unbound vulnerability
Original commit
Tuesday, 24 May 2011
23:51 ohauer search for other commits by this committer
 - revert last change of apr-* entry

 Broken build reported by wxs@
Original commit
22:59 ohauer search for other commits by this committer
- use apr-* and add <gt></gt> entries for all apr0/apr1 issues
  (<gt> .. is needed else the parser cannot make a difference
   between apr0 and apr1)

- lowercase ViewVC -> viewvc

 Thanks Jun Kuriyama ( kuriyama@ ) for the notice and the patch
 for the apr entries.
Original commit
16:05 brooks search for other commits by this committer
Update the mod_pubcookie entry with an ap20 prefix.  The port has alwasy
has USE_APACHE=2.0 in it so we can avoid enumarating all values of
APACHE_PKGNAMEPREFIX.

Pointy hat:     brooks
Original commit
06:19 simon search for other commits by this committer
Unbreak VuXML web build by changing "ap*-" to "ap-" in package name for
1ca8228f-858d-11e0-a76c-000743057ca2 / mod_pubcookie -- Empty
Authentication Security Advisory.

While the new one is likely not correct, this fixes the build until
somebody can put in the right thing.
Original commit
05:55 delphij search for other commits by this committer
Fix build.
Original commit
Monday, 23 May 2011
23:04 brooks search for other commits by this committer
Partially address several years of neglect of pubcookie.  Indicate the
security issues in two two ports.

I've not use pubcookie in several year and given the lack of complaint
about the deprication of mod_pubcookie, I doubt anyone else uses it from
ports.  The mod_pubcookie port has already expired and I've set a two
week expriation for pubcookie-login-server.  If not maintainer
appears I will send both to the Attic on June 6th.

While I'm here, address the use of CONF_FILES and CONF_DIRS in
pubcookie-login-server to avoid getting in the way of progress. [0]

PR:             ports/157164 [0]
Security:       vuxml:115a1389-858e-11e0-a76c-000743057ca2
                vuxml:1ca8228f-858d-11e0-a76c-000743057ca2
Original commit
22:22 ohauer search for other commits by this committer
- add entry for ViewVC < 1.1.11
- add entry for apr1 (CVE-2011-1928)
- correct version in previous apr1 entry
- run tidy
Original commit
21:17 nox search for other commits by this committer
Update to 10.3r181.14 .

PR:             ports/156996
Submitted by:   Tsurutani Naoki <turutani@scphys.kyoto-u.ac.jp>
Security:      
http://www.freebsd.org/ports/portaudit/d226626c-857f-11e0-95cc-001b2134ef46.html
Original commit
10:58 mandree search for other commits by this committer
Document Opera Frameset unload code injection vulnerability.
Original commit
09:58 delphij search for other commits by this committer
Document pure-ftpd multiple vulnerabilities prior to 1.0.32.
Original commit
Saturday, 14 May 2011
17:48 rea search for other commits by this committer
mail/exim: document CVE-2011-1764 and CVE-2011-1407

Both vulnerabilities are in the DKIM code and were fixed in 4.76.

Approved-by: erwin (mentor)
Feature-safe: yes
Original commit
Friday, 13 May 2011
23:33 ohauer search for other commits by this committer
- document Apache APR DoS vulnerabilities
Original commit
15:06 glarkin search for other commits by this committer
- Document www/zend-framework (potential SQL injection when using PDO_MySQL)

Security:       http://framework.zend.com/security/advisory/ZF2011-02
Original commit
Thursday, 12 May 2011
23:46 wxs search for other commits by this committer
Document mediawiki multiple vulnerabilities.

PR:             ports/156914
Submitted by:   Ryan Steinmetz <rpsfa@rit.edu>
Original commit
20:13 rene search for other commits by this committer
Document CVE-2011-1799 and CVE-2011-1800 for www/chromium
Original commit
18:09 wxs search for other commits by this committer
Incorporate changes recommended by the tidy target. While here, properly
label dc9f8335-2b3b-11e0-a91b-00e0815b8da8.
Original commit
Monday, 9 May 2011
13:11 sahil search for other commits by this committer
Document CVE-2011-1720: Postfix memory corruption error.
Original commit
Saturday, 30 Apr 2011
09:25 rene search for other commits by this committer
Document www/chromium vulnerabilities fixed in version 11.0.696.57

Security:       CVE-2011-[1303-1305, 1434-1452, 1454-1456]
Original commit
Friday, 29 Apr 2011
06:26 flo search for other commits by this committer
Document mozilla -- multiple vulnerabilities
Original commit
Thursday, 21 Apr 2011
22:41 flo search for other commits by this committer
- document recent asterisk vulnerabilities
- fix topic in RT entry
Original commit
Sunday, 17 Apr 2011
20:31 jsa search for other commits by this committer
Document VideoLAN-SA-1103. Heap corruption in MP4 demultiplexer in VLC.
Original commit
18:32 nox search for other commits by this committer
Update to 10.2r159.1 .

Security:      
http://www.freebsd.org/ports/portaudit/32b05547-6913-11e0-bdc4-001b2134ef46.html
Original commit
10:59 flo search for other commits by this committer
Document multiple vulnerabilities in RT www/rt36 and www/rt38
Original commit
Thursday, 14 Apr 2011
22:14 rene search for other commits by this committer
Document www/chromium vulnerabilities

Security:       CVE-2011-1301, CVE-2011-1302
Original commit
21:08 simon search for other commits by this committer
Unbreak file format:
- Place <vuxml> tag at the start of the file.
- Close topic tags.

Pointy hat to:  cy
Original commit
19:51 cy search for other commits by this committer
Add the following for security/krb5:
        MITKRB5-SA-2011-001 - kpropd denial of service
        MITKRB5-SA-2011-002 - KDC denial of service attacks
        MITKRB5-SA-2011-003 - KDC vulnerable to double-free when PKINIT enabled
        MITKRB5-SA-2011-004 - kadmind invalid pointer free()
Original commit
07:43 kwm search for other commits by this committer
Document a root exploit via rogue hostname in xrdb.
Original commit
Wednesday, 13 Apr 2011
11:01 bapt search for other commits by this committer
Limit affected mupdf version to <0.8

Submitted by:   tobez@ (irc)
Original commit
Tuesday, 12 Apr 2011
17:52 skv search for other commits by this committer
Document "otrs" - several XSS attacks possible.
Original commit
15:36 erwin search for other commits by this committer
Fix typo

Submitted by:    Dan Langille <dan@langille.org>
Original commit
Sunday, 10 Apr 2011
21:39 wxs search for other commits by this committer
Document isc-dhcp41-client and isc-dhcp31-client vulnerabilities.

PR:             ports/156246
Submitted by:   Douglas Thrift <douglas@douglasthrift.net>
Original commit
Saturday, 9 Apr 2011
01:41 wxs search for other commits by this committer
Add CVE entry for recent tinyproxy vulnerability.
Original commit
Friday, 8 Apr 2011
07:39 pav search for other commits by this committer
- tinyproxy
Original commit
Friday, 1 Apr 2011
18:03 sem search for other commits by this committer
Document two quagga DoS vulnerabilities
Original commit
Tuesday, 29 Mar 2011
13:50 kwm search for other commits by this committer
Add a missing </p>.

Pointed out by: jadawin@
Original commit
13:38 kwm search for other commits by this committer
Document gdm privilege escalation vulnerability
Original commit
Saturday, 26 Mar 2011
20:13 rene search for other commits by this committer
Document vulnerabilities before Chromium 10.0.648.204

Obtained from: 
http://googlechromereleases.blogspot.com/search/label/Stable%20updates
Original commit
Friday, 25 Mar 2011
11:09 ale search for other commits by this committer
Add entries for php5-exif and php5-zip before 5.3.6 release.

PR:             ports/155922
Submitted by:   Chris Tandiono <christandiono@tbp.berkeley.edu>
Original commit
Thursday, 24 Mar 2011
18:40 nox search for other commits by this committer
Update to 10.2r153.

Security:      
http://www.freebsd.org/ports/portaudit/501ee07a-5640-11e0-985a-001b2134ef46.html
PR:             ports/155874
Submitted by:   Tsurutani Naoki <turutani@scphys.kyoto-u.ac.jp>
Original commit
00:56 beat search for other commits by this committer
- Document mozilla -- update to HTTPS certificate blacklist
Original commit
Saturday, 19 Mar 2011
06:10 sahil search for other commits by this committer
Document CVE-2011-0411: Postfix "STARTTLS" Plaintext
Injection Vulnerability.

Reviewed by:    miwi (secteam)
Original commit
Thursday, 17 Mar 2011
17:42 glarkin search for other commits by this committer
- Documented integer overflow in hiawatha web server

Submitted by:   C-S <c-s@c-s.li>
Original commit
00:03 delphij search for other commits by this committer
Document asterisk multiple vulnerabilities.
Original commit
Monday, 14 Mar 2011
18:34 rene search for other commits by this committer
Mark chromium-9.0.597.107 and chromium-10.0.648.127 as vulnerable.
Original commit
16:46 miwi search for other commits by this committer
- Cleanup a bit
Original commit
16:25 miwi search for other commits by this committer
- Add correct infos to the avahi issus
- Add url to original advisory
Original commit
16:14 kwm search for other commits by this committer
Fix date in avahi entry.
Original commit
16:04 kwm search for other commits by this committer
Add avahi denial of services attack.
Original commit
Thursday, 10 Mar 2011
15:01 wxs search for other commits by this committer
Fix discovery for mailman XSS vulnerabilities.

Noticed by:     erwin@
Pointyhat to:   wxs@
Original commit
14:31 wxs search for other commits by this committer
Document mail/mailman XSS vulnerabilities.
Original commit
Monday, 7 Mar 2011
21:31 decke search for other commits by this committer
- Document redmine -- XSS vulnerability
Original commit
Saturday, 5 Mar 2011
12:21 lev search for other commits by this committer
Document subversion -- remote HTTP DoS vulnerability
Obtained from http://subversion.apache.org/security/CVE-2011-0715-advisory.txt
Original commit
Tuesday, 1 Mar 2011
23:05 beat search for other commits by this committer
- Document mozilla -- multiple vulnerabilities
Original commit
18:15 rene search for other commits by this committer
Document Chromium versions 9.0.597.[84,94,107]

Obtained from: 
http://googlechromereleases.blogspot.com/search/label/Stable%20updates
Original commit
Friday, 25 Feb 2011
18:39 delphij search for other commits by this committer
Add two OpenLDAP security by-pass vulnerabilities.
Original commit
14:01 mandree search for other commits by this committer
Fix broken linux-sun-jdk vulndb entries.

VuXML:          18e5428f-ae7c-11d9-837d-000e0c2e438a
VuXML:          c93e4d41-75c5-11dc-b903-0016179b2dd5
PR:             ports/154918
Original commit
Wednesday, 23 Feb 2011
14:43 miwi search for other commits by this committer
- Cleanup previous entry
Original commit
Tuesday, 22 Feb 2011
21:30 flo search for other commits by this committer
- add asterisk -- Exploitable Stack and Heap Array Overflows
Original commit
Sunday, 20 Feb 2011
05:04 delphij search for other commits by this committer
Document PivotX administrator password reset vulnerability.
Original commit
Tuesday, 15 Feb 2011
08:18 miwi search for other commits by this committer
- Update lastest tomcat entry (tomcat6/7 have the same problem)

Note: Please ask for review at ports-security@  THX!
Original commit
08:00 wen search for other commits by this committer
- Document tomcat vulnerability
Original commit
Friday, 11 Feb 2011
22:23 delphij search for other commits by this committer
Document two phpMyAdmin vulnerabilities.
Original commit
21:39 nox search for other commits by this committer
Update to 10.2r152.

PR:             ports/154630
Submitted by:   Tsurutani Naoki <turutani@scphys.kyoto-u.ac.jp>
Security:      
http://www.freebsd.org/ports/portaudit/4a3482da-3624-11e0-b995-001b2134ef46.html
Feature safe:   yes
Original commit
19:59 delphij search for other commits by this committer
Document mupdf PDF handling remote code execution vulnerability.

Submitted by:   Tim Zingelman <tez netbsd.org>
Original commit
19:51 delphij search for other commits by this committer
Document rubygem-mail Remote Arbitrary Shell Command Injection Vulnerability.

Submitted by:   Tim Zingelman <tez netbsd.org>
Original commit
19:48 delphij search for other commits by this committer
Document plone remote security bypass vulnerability.

Submitted by:   Tim Zingelman <tez netbsd.org>
Original commit
19:40 delphij search for other commits by this committer
Document exim local privilege escalasion vulnerability.

Submitted by:   Tim Zingelman <tez netbsd.org>
Original commit
19:36 delphij search for other commits by this committer
Document OpenOffice multiple vulnerabilities.

Submitted by:   Tim Zingelman <tez netbsd.org>
Original commit
Thursday, 10 Feb 2011
16:44 miwi search for other commits by this committer
- Cleanup previous commit
Original commit
10:41 kwm search for other commits by this committer
Document multiple webkit-gtk2 security vulnabilities, fixed in 1.2.7.
Original commit
00:44 delphij search for other commits by this committer
Document awstat multiple vulnerability.

Notified by:    Tim Zingelman <tez netbsd.org>
Original commit
00:28 delphij search for other commits by this committer
Document Opera multiple vulnerabilities.

Notified by:    Tim Zingelman <tez netbsd.org>
Original commit
Wednesday, 9 Feb 2011
21:37 delphij search for other commits by this committer
Document multiple vulnerabilities in Django.

Notified by:    Jesco Freund <jesco.freund my-universe.com>
Original commit
05:36 miwi search for other commits by this committer
- S/seriuos/serious
Original commit
05:23 miwi search for other commits by this committer
- Document mediawiki - multiple vulnerabilites
Original commit
04:53 miwi search for other commits by this committer
- Add chinese/wordpress-zh_CN and  chinese/wordpress-zh_TW to the previous
wordpress entry
Original commit
Saturday, 5 Feb 2011
04:36 miwi search for other commits by this committer
- Add entry for wordpress - SQL injection vulnerability

PR:             153526
Submitted by:   Mark Foster <mark@foster.cc>
Feature safe:   yes
Original commit
Wednesday, 2 Feb 2011
23:51 miwi search for other commits by this committer
- Cleanup previous commit

Feature safe:   yes
Original commit
15:45 kwm search for other commits by this committer
Add vlc - Insufficient input validation in MKV demuxer vulnability.
Feature safe:   yes
Original commit
Monday, 31 Jan 2011
14:02 miwi search for other commits by this committer
- Cleanup previous Entry

Feature safe:   yes
Original commit
09:47 decke search for other commits by this committer
- Document maradns -- denial of service when resolving a long DNS hostname

Submitted by:   n j <nino80 at gmail dot com>
Feature safe:   yes
Original commit
Saturday, 29 Jan 2011
00:23 wxs search for other commits by this committer
Adjust range for ISC DHCPv6 server crash.

Feature safe:   yes
Original commit
00:15 wxs search for other commits by this committer
Document ISC DHCPv6 server crash.

Feature safe:   yes
Original commit
Tuesday, 25 Jan 2011
15:07 skv search for other commits by this committer
Document "bugzilla" - multiple seriuos vulnerabilities.

Feature safe:   yes
Original commit
Monday, 24 Jan 2011
23:00 delphij search for other commits by this committer
Add dokuwiki multiple ACL escalation vulnerabilities.

Feature safe:   yes
Original commit
Sunday, 23 Jan 2011
23:29 simon search for other commits by this committer
Try to unbreak vuxml portaudit build by removing use of HTML entity.
UTF-8 chars should be used.

This is not a fix, just a hack to get it working for now.

Feature safe:   yes (really)
Original commit
13:41 rene search for other commits by this committer
Describe www/chromium vulnerabilities between 8.0.552.215 and 8.0.552.237

Obtained from:  http://googlechromereleases.blogspot.com/
Feature safe:   yes
Original commit
Friday, 21 Jan 2011
01:23 flo search for other commits by this committer
asterisk-1.8.2.1 is still vulnerable due to a botched merge upstream.

Feature safe:   yes
Original commit
Wednesday, 19 Jan 2011
09:19 flo search for other commits by this committer
- fix asterisk16 version string

Approved by:    fjoe (mentor)
Feature safe:   yes
Original commit
08:46 flo search for other commits by this committer
- Document Exploitable Stack Buffer Overflow in asterisk

Approved by:    fjoe (mentor)
Feature safe:   yes
Original commit
02:26 wxs search for other commits by this committer
Document tarsnap cryptographic nonce reuse vulnerability.

Discussed with: cperciva@
Feature safe:   yes
Original commit
Tuesday, 18 Jan 2011
09:26 delphij search for other commits by this committer
Add entry for moinmoin XSS vulnerabilities.

PR:             ports/153898
Submitted by:   Ruslan Mahmatkhanov <cvs-src yandex ru>
Feature safe:   yes
Original commit
02:14 delphij search for other commits by this committer
Document tor remote code execution and crash vulnerability.

Submitted by:   Janne Snabb <snabb epipe com>
Feature safe:   yes
Original commit
Thursday, 13 Jan 2011
14:09 rea search for other commits by this committer
security/sudo: document privilege escalation, CVE-2011-0010

PR: 153939
Approved by: delphij (secteam), erwin (mentor)
Feature safe: yes
Original commit
12:53 rea search for other commits by this committer
devel/subversion: document security fixes in 1.6.15

Two DoS conditions:
 - CVE-2010-4539, DoS via walking of SVNParentPath
   collections;
 - CVE-2010-4644, DoS via memory leaks triggered
   by the option "-g" of the blame command.

Approved by: delphij (secteam), erwin (mentor)
Feature safe: yes
Original commit
05:44 rea search for other commits by this committer
Split recent PHP entry into multiple ones

Many reasons:
 - some vulnerabilities were present only in the specific
   PHP modules and not in the core PHP;
 - it is better to group vulnerabilities by-topic (DoS, code
   execution, etc);
 - PHAR vulnerability is present only in 5.3.x;
 - extract() vulnerability was fixed both in 5.2 and 5.3:
   http://www.mail-archive.com/php-cvs@lists.php.net/msg47722.html
 - NULL-byte poisoning was fixed only in 5.3, 5.2.x is still
   vulnerable to this design error;
 - DFS-related fixes are not relevant for FreeBSD, since DFS
   is Windows file system that is unsupported by us.

PR: 153433
Approved by: remko (secteam), erwin (mentor)
Feature safe: yes
Original commit
Sunday, 9 Jan 2011
09:12 ale search for other commits by this committer
Add entry for CVE-2010-4645 (php).

PR:             ports/153766
Submitted by:   Tom Judge <tom@tomjudge.com>
Original commit

Number of commits found: 6273 (showing only 100 on this page)

[First Page]  «  35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45  »  [Last Page]