notbugAs an Amazon Associate I earn from qualifying purchases.
Want a good read? Try FreeBSD Mastery: Jails (IT Mastery Book 15)
Want a good monitor light? See my photosAll times are UTC
Ukraine
non port: security/vuxml/vuln.xml

Number of commits found: 6274 (showing only 100 on this page)

[First Page]  «  46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56  »  [Last Page]

Wednesday, 21 Feb 2007
22:17 simon search for other commits by this committer
Document snort -- DCE/RPC preprocessor vulnerability.
Original commit
Saturday, 17 Feb 2007
13:55 simon search for other commits by this committer
Document rar -- password prompt buffer overflow vulnerability.

Reminded by:    Nate Eldredge
Original commit
12:34 simon search for other commits by this committer
Mark 5.2.1_2 as the first safe version for the recent "php -- multiple
vulnerabilities" entry since there was a bug in one of the fixes in
upstream 5.2.1 which port revision 5.2.1_2 fixed.
Original commit
11:51 simon search for other commits by this committer
Document php -- multiple vulnerabilities.
Original commit
Wednesday, 17 Jan 2007
22:17 gabor search for other commits by this committer
joomla -- multiple remote vulnerabilities

Reviewed by:    secteam (remko)
Approved by:    erwin (mentor, implicit)
Original commit
Monday, 15 Jan 2007
10:58 gabor search for other commits by this committer
Document two sircd vulnerabilities:

  sircd -- remote reverse DNS buffer overflow
  sircd -- remote operator privilege escalation vulnerability

Reviewed by:    secteam (remko)
Approved by:    erwin (mentor)
Original commit
Friday, 12 Jan 2007
15:11 sem search for other commits by this committer
- Document multple net/cacti vulnerabilities.
Original commit
Monday, 8 Jan 2007
16:06 itetcu search for other commits by this committer
Add mplayer RealMedia RTSP streams buffer overflow entry.

PR:             ports/107217
Submitted by:   Thomas E. Zander (multimedia/mplayer maintainer)
Reviewed by:    simon@
Original commit
Saturday, 6 Jan 2007
14:15 barner search for other commits by this committer
Document two fetchmail vulnerabilities.

See also:       http://fetchmail.berlios.de/fetchmail-SA-2006-02.txt
                http://fetchmail.berlios.de/fetchmail-SA-2006-03.txt

Reported by:    Matthias Andree (upstream author)
Original commit
Friday, 5 Jan 2007
22:45 simon search for other commits by this committer
Document opera -- multiple vulnerabilities.
Original commit
21:32 brooks search for other commits by this committer
Upgrade drupal to 4.7.5 fixing a couple security issues.
Upgrade drupal-pubcookie and drupal-textile to the 4.7 versions.

Submitted by:   Nick Hilliard <nick at foobar dot org> (upgrade to 4.7.4)
Security:       vid:3d8d3548-9d02-11db-a541-000ae42e9b93
Original commit
Wednesday, 3 Jan 2007
17:21 simon search for other commits by this committer
Unbreak file by using &amp; in w3m entry.

Pointy hat to:  nobutaka
Reported by:    Philipp Wuensche
Original commit
Tuesday, 2 Jan 2007
14:12 nobutaka search for other commits by this committer
Document a format string vulnerability of w3m.
Original commit
Wednesday, 27 Dec 2006
16:37 gabor search for other commits by this committer
- Document www/plone vulnerability

Reviewed by:    simon
Approved by:    erwin (mentor)
Original commit
16:31 gabor search for other commits by this committer
- Update the www/zope entry to indicate it is fixed now

PR:             ports/106505
Submitted by:   HAYASHI Yasushi <yasi@yasi.to>
Reviewed by:    simon
Approved by:    erwin (mentor)
Original commit
Sunday, 24 Dec 2006
13:57 delphij search for other commits by this committer
phpbb -- NULL byte injection vulnerability has been fixed in
their 2.0.22, so mark it as safe.  Update to the port is pending.
Original commit
Thursday, 21 Dec 2006
06:52 delphij search for other commits by this committer
Add an entry for recently fixed proftpd remote code execution
vulnerabilities.

Reviewed by:    remoko
Original commit
Tuesday, 19 Dec 2006
20:33 remko search for other commits by this committer
Document gzip -- multiple vulnerabilities, this is FreeBSD-SA06:21.gzip
Original commit
20:16 remko search for other commits by this committer
Document bind9 -- Denial of Service in named(8) which is also known
as FreeBSD-SA-06:20.bind

Notice: The previous commit was FreeBSD-SA-06:19.openssl
Original commit
20:02 remko search for other commits by this committer
Document openssl -- Incorrect PKCS#1 v1.5 padding validation in crypto(3)
Original commit
14:46 lth search for other commits by this committer
sql-ledger -- multiple vulnerabilities

Reviewed by:    remko
Original commit
Friday, 15 Dec 2006
19:47 remko search for other commits by this committer
Update several entries, making them a bit clearer (Were possible),
adjusting some package names, and collapsing some ruby entries that
can be combined. Also properly sort the <bid> and <cvename> tags.
b comes before c.
Original commit
Thursday, 14 Dec 2006
20:35 marcus search for other commits by this committer
Document the recent D-BUS vulnerability as described by CVE-2006-6107.

Submitted by:   mnag
Original commit
19:27 mnag search for other commits by this committer
- evince -- Buffer Overflow Vulnerability
Original commit
13:44 mnag search for other commits by this committer
- Change spaces to tabs in <name> and <range>
- Remove some empty lines
- Respect 2 spaces between <body> and <p>
- Respect empty line between <vuln vid=""> entry.
Original commit
Wednesday, 13 Dec 2006
22:56 miwi search for other commits by this committer
tDiary - Injection Vulnerability
Original commit
12:44 mnag search for other commits by this committer
- wv -- Multiple Integer Overflow Vulnerabilities
Original commit
12:37 mnag search for other commits by this committer
- wv2 -- Integer Overflow Vulnerability
Original commit
07:04 miwi search for other commits by this committer
- Fix tnftpd entry (made validate happy)
Original commit
06:42 miwi search for other commits by this committer
tnftpd - remote root exploit

Reviewed by:    simon
Approved by:    secteam
Original commit
Tuesday, 12 Dec 2006
20:51 mnag search for other commits by this committer
- clamav -- Multipart Nestings Denial of Service
Original commit
Saturday, 9 Dec 2006
09:36 remko search for other commits by this committer
Rewrite the libxine entry:

o Use the FDP style to fill in the entry.
o Remove the secunia references and use the libxine information.
o Properly sort the references section
o Add the modified tag (since I changed it).
Original commit
Thursday, 7 Dec 2006
17:50 nobutaka search for other commits by this committer
Add an entry for libxine multiple buffer overflow vulnerabilities.
Original commit
12:37 mnag search for other commits by this committer
- Ok. gnupg-devel are not affected.
Original commit
12:24 mnag search for other commits by this committer
- Add gnupg-devel package in last entry
- Add secunia reference in las entry
Original commit
09:00 vd search for other commits by this committer
Forced commit to note that my last commit is:

Approved by:    secteam (remko)
Original commit
08:54 vd search for other commits by this committer
* Fix typo in the latest GnuPG entry, inherited from the original message
* Fix the URL in references, the former one gives 404 Not found.
  Kuriyama, where did you get it from?
Original commit
00:35 kuriyama search for other commits by this committer
Add CVE-2006-6235 entry for GnuPG.
Original commit
Monday, 4 Dec 2006
21:25 stas search for other commits by this committer
- Add a modified field for the entry, touched by the previous commit
Original commit
21:16 stas search for other commits by this committer
- List all affected packages for the Novermber ruby cgi DOS vulnerability
- This vulnerability was not fixed in ruby_static
Original commit
21:10 stas search for other commits by this committer
- Documenet ruby cgi library vulnerability
Original commit
Sunday, 3 Dec 2006
07:59 stas search for other commits by this committer
- Document buffer overflow vulnerabilities in the libmusicbrainz.
Original commit
Saturday, 2 Dec 2006
16:06 simon search for other commits by this committer
Fix markup in last entry so the file is valid XML again.

Pointy hat to:  simon
Original commit
15:09 miwi search for other commits by this committer
- Add a entry for www/tDiary, www/tDiary-devel

Reviewed by:    simon
Original commit
11:41 stas search for other commits by this committer
- Document the SGI Image File heap overflow vulnerability in ImageMagick
Original commit
Thursday, 30 Nov 2006
20:33 naddy search for other commits by this committer
Document "gtar -- GNUTYPE_NAMES directory traversal vulnerability".
Original commit
00:32 shaun search for other commits by this committer
Document 'kronolith -- arbitrary local file inclusion vulnerability'
Original commit
Tuesday, 28 Nov 2006
13:45 simon search for other commits by this committer
In latest gnupg entry:
- Use "Werner Koch reports" instead of "Author reports" to follow
  normal style in vuln.xml.
- Fix some indentation and markup in body.
Original commit
05:57 kuriyama search for other commits by this committer
Add recent gnupg one.
Original commit
Tuesday, 21 Nov 2006
00:27 shaun search for other commits by this committer
Add <modified> tag to previous proftpd entry.

Requested by:   remko
Original commit
Wednesday, 15 Nov 2006
14:40 shaun search for other commits by this committer
Add proftpd-mysql to the previous entry.
Original commit
Tuesday, 14 Nov 2006
23:25 shaun search for other commits by this committer
Document "proftpd -- Remote Code Execution Vulnerability".
Original commit
16:57 delphij search for other commits by this committer
The Command Injection Vulnerability was corrected by awstats 6.5_2,1.

Submitted by:   Alex Samorukov
PR:             ports/105233
Original commit
08:35 ehaupt search for other commits by this committer
Add archivers/unzoo Directory Traversal Vulnerability.

Reviewed by:    simon
Original commit
Saturday, 11 Nov 2006
15:56 simon search for other commits by this committer
Add bugzilla -- multiple vulnerabilities entry.

Update earleir bugzilla entry with better topic, add ja-bugzilla as
also potentially vulnerable (thought the version currently in
ja-bugzilla isn't), and add more references.
Original commit
Wednesday, 8 Nov 2006
19:32 remko search for other commits by this committer
Add cvs+ipv6 to the cvsbug to the vulnerability.

PR:                     ports/104638
Submitted by:           KIMURA Yasuhiro <yasu at utahime dot org>
Original commit
17:13 stas search for other commits by this committer
- Document recent vulerabilties in the imlib2.
Original commit
Saturday, 4 Nov 2006
21:09 stas search for other commits by this committer
- Document recent vulnerability in the ruby CGI library.

Reviewed by:    simon
Original commit
Friday, 3 Nov 2006
05:27 dinoex search for other commits by this committer
- pgp < 3.0 and pgpin does not support OpenPGP format
no user given symetric key encryption
Submitted by:   dinoex
Original commit
Thursday, 2 Nov 2006
06:33 simon search for other commits by this committer
The latest couple of firefox vulnerabilities should be fixed in the
2.0 release, so mark 2.0 as fixed.

Prodded by:     ahze
Original commit
Wednesday, 1 Nov 2006
13:15 lev search for other commits by this committer
 ru-apache and ru-apacvhe+mod_ssl were fixed.
Original commit
Monday, 30 Oct 2006
07:34 vd search for other commits by this committer
Add a <modified> tag with the current date to reflect my previous change.
I knew I should ask someone before committing, however trivial was the change.

Spotted by:     remko
Approved by:    portmgr (implicit)
Original commit
07:04 vd search for other commits by this committer
Fix typo: "Dmitri Lenev reports reports a privilege ..."

Approved by:    portmgr (implicit)
Original commit
Sunday, 29 Oct 2006
19:07 simon search for other commits by this committer
Document screen -- combined UTF-8 characters vulnerability.

Approved by:    portmgr (secteam blanket)
Original commit
13:50 simon search for other commits by this committer
Document two MySQL privilege escalations.

PR:             ports/104890
Submitted by:   Henrik Brix Andersen <henrik@brixandersen.dk>
Approved by:    portmgr (secteam blanket)
Original commit
Monday, 23 Oct 2006
13:15 miwi search for other commits by this committer
- Add entry for www/serendipity and www/serendipity-devel

Reviewed by:    markus@
Approved by:    portmgr (implicit VuXML), secteam (Remko (not reviewed yet))
Original commit
11:15 markus search for other commits by this committer
Document an integer overflow vulnerability in Qt and kdelibs, based on an
entry by sat

Approved by:    portmgr (erwin)
Original commit
Friday, 20 Oct 2006
22:59 simon search for other commits by this committer
Add reference, which I missed the first time around, from Opera
Software to opera -- URL parsing heap overflow vulnerability entry,

Approved by:    portmgr (secteam blanket)
Original commit
22:56 simon search for other commits by this committer
Document opera -- URL parsing heap overflow vulnerability.

Approved by:    portmgr (secteam blanket)
Original commit
22:45 simon search for other commits by this committer
Minor correction to last commit; the NVIDIA driver version 1.0.8762
was also affected, so mark it as such.

Approved by:            portmgr (secteam blanket)
Original commit
22:32 simon search for other commits by this committer
Update entry for nvidia-driver -- arbitrary root code execution
vulnerability:

- Add new info about vulnerable versions from NVIDIA.
- Add workaround.
- Add more references.
- Remove suggestion to move to "nv" driver now that we have a simpler
  workaround.

Approved by:            portmgr (secteam blanket)
Parts submitted by:     mnag
Original commit
08:13 remko search for other commits by this committer
Document asterisk -- remote heap overwrite vulnerability

Approved by:            portmgr (VuXML blanket)
Submitted by:           Thomas Sandford
Facilitated by:         Snow B.V.
Original commit
07:44 remko search for other commits by this committer
Some style changes to the plone entry.

Previous commit was also reviewed by myself.

Approved by:            portmgr (Blanket VuXML)
Facilitated by:         Snow B.V.
Original commit
Thursday, 19 Oct 2006
22:47 miwi search for other commits by this committer
- Add a entry for www/plone

Approved by:    portmgr (erwin)
Original commit
13:48 shaun search for other commits by this committer
Document:
  drupal -- HTML attribute injection
  drupal -- cross site request forgeries
  drupal -- multiple XSS vulnerabilities

Submitted by:   brooks
Reviewed by:    remko
Approved by:    portmgr (erwin)
Original commit
13:19 shaun search for other commits by this committer
Document "ingo -- local arbitrary shell command execution"

Submitted by:   thierry
Reviewed by:    remko
Approved by:    portmgr (erwin)
Original commit
Tuesday, 17 Oct 2006
20:45 simon search for other commits by this committer
Update php -- _ecalloc Integer Overflow Vulnerability entry with
details from Steffan Essers advisory about the implications of this
issue.  The advisory was not public when this issue was initially
fixed.

Approved by:    portmgr (secteam blanket)
Original commit
09:21 erwin search for other commits by this committer
Mark multimedia/win32-codecs as not-vulnerable after the quicktime codecs
were optional. The quicktime codecs are still vulnerable though, but we
rely on the conditional FORBIDDEN statement in the ports Makefile for this.

Approved by:    portmgr (self), secteam (simon)
Original commit
Monday, 16 Oct 2006
21:54 simon search for other commits by this committer
Document "nvidia-driver -- arbitrary root code execution vulnerability".

Note that I haven't actually had time to make a test system to reproduce
this on FreeBSD, but due to the nature of this issue and that there is a
PoC exploit in the advisory, I'm adding this entry due to "better safe
than sorry"...

Approved by:    portmgr (secteam blanket)
Original commit
17:44 sat search for other commits by this committer
- Mark php open_basedir fixed

Reviewed by:    secteam (simon)
Approved by:    portmgr (secteam blanket)
Original commit
14:32 mnag search for other commits by this committer
- clamav -- CHM unpacker and PE rebuilding vulnerabilities

Approved by:    portmgr (mnag with secteam hat)
Original commit
Sunday, 15 Oct 2006
19:43 sat search for other commits by this committer
- Add some references

Reviewed by:    secteam (simon)
Approved by:    portmgr (secteam blanket)
Original commit
16:04 sat search for other commits by this committer
- Document temporary file symlink privilege escalation in tkdiff
- Correct Javier's name spelling in an old advisory

Reviewed by:    secteam (simon)
Approved by:    portmgr (secteam blanket)
Original commit
11:31 sat search for other commits by this committer
- Document multiple remote file inclusion vulnerabilities in vtiger

Reviewed by:    secteam (simon)
Approved by:    portmgr (secteam blanket)
Original commit
Saturday, 14 Oct 2006
12:32 sat search for other commits by this committer
- Document heap overflow in the KML engine in google-earth

Reviewed by:    secteam (simon)
Approved by:    portmgr (implicit)
Original commit
Wednesday, 11 Oct 2006
08:32 erwin search for other commits by this committer
devel/cscope was fixed in version 15.6 so use lt instead of le.

Submitted by:   joerg
Pointyhat to:   erwin
Approved by:    portmgr (self)
Original commit
Monday, 9 Oct 2006
15:45 simon search for other commits by this committer
Mark zgv as fixed wrt. "zgv, xzgv -- heap overflow vulnerability".
Original commit
Sunday, 8 Oct 2006
16:41 sat search for other commits by this committer
- Add php-suhosin to edabe438-542f-11db-a5ae-00508d6a62df
  as per original advisory

Discussed with: ale
Original commit
07:44 sat search for other commits by this committer
- Fix python package naming in 6afa87d3-764b-11d9-b0e7-0000e249a0a2

Reported by:    simon
Original commit
07:17 simon search for other commits by this committer
Update versions affected by python -- buffer overrun in repr() for
unicode strings:

- Python 2.5.c2 was already fixed (verified in upstream SVN).
- Python 2.4 port just got the fix.
- I can't find any trace of python23, python22, and python-devel ever
  having existed as package names, so I removed them.
- Add python+ipv6.  I don't really know if it contained the
  problematic unicode code, but better safe than sorry.
Original commit
06:51 simon search for other commits by this committer
Fix whitespace in openssh -- multiple vulnerabilities entry, which I
originally missed.
Original commit
Saturday, 7 Oct 2006
23:01 tmclaugh search for other commits by this committer
Update vuxml id 5a39a22e-5478-11db-8f1a-000a48049292
- Fixed in version 1.1.13.8.1
Original commit
22:16 tmclaugh search for other commits by this committer
Remove mono-devel and mono-svn from 5a39a22e-5478-11db-8f1a-000a48049292
- These are packages from BSD#'s (my project) development repo.  Don't even
  give the impression that FreeBSD is supporting security updates for an
  outside project.
Original commit
15:22 sat search for other commits by this committer
- Remove an empty url (a typo)
Original commit
09:24 sat search for other commits by this committer
- Document User-Agent XSS Vulnerability in torrentflux
Original commit
09:13 sat search for other commits by this committer
- Document buffer overrun in repr() for unicode strings in python
Original commit
Friday, 6 Oct 2006
20:57 erwin search for other commits by this committer
devel/cscope was fixed in version 15.6

Glanced at by:  remko
Original commit
05:12 sat search for other commits by this committer
- Document _ecalloc Integer Overflow Vulnerability in php5
Original commit
Thursday, 5 Oct 2006
21:34 sat search for other commits by this committer
- Update an old mambo advisory and document its new vulnerabilities
Original commit
16:46 sat search for other commits by this committer
- Add linux-curl to a curl advisory and tweak versions a bit
Original commit

Number of commits found: 6274 (showing only 100 on this page)

[First Page]  «  46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56  »  [Last Page]