Commit History - (may be incomplete: for full details, see links to repositories near top of page) |
Commit | Credits | Log message |
0.2.3 05 Feb 2007 01:08:46
 |
pav  |
Populate a new ports-mgmt category. List of moved ports:
devel/portcheckout -> ports-mgmt/portcheckout
devel/portlint -> ports-mgmt/portlint
devel/portmk -> ports-mgmt/portmk
devel/porttools -> ports-mgmt/porttools
misc/instant-tinderbox -> ports-mgmt/instant-tinderbox
misc/porteasy -> ports-mgmt/porteasy
misc/portell -> ports-mgmt/portell
misc/portless -> ports-mgmt/portless
misc/tinderbox -> ports-mgmt/tinderbox
security/jailaudit -> ports-mgmt/jailaudit
security/portaudit -> ports-mgmt/portaudit
security/portaudit-db -> ports-mgmt/portaudit-db
security/vulnerability-test-port -> ports-mgmt/vulnerability-test-port (Only the first 15 lines of the commit message are shown above ) |
0.2.3 30 Jul 2005 19:13:10
 |
simon  |
Change MAINTAINER address for ports maintained by the Security Team to
secteam@ instead of security@ to make it more clear that the ports are
not maintained by the freebsd-security@ mailing list. Both addresses
go to the same people. |
0.2.3 03 Jul 2005 20:46:48
 |
simon  |
- Set maintainership to security@.
Suggested by: nectar, remko |
0.2.3 14 Jun 2005 22:04:55
 |
simon  |
Grab maintainer-ship of portaudit. While I do not currently have any
plans for improvements (though I have ideas) I feel that portaudit is
too important to not have an active maintainer.
Approved by: portmgr (linimon) |
0.2.3 05 Jan 2005 10:51:21
 |
thierry  |
Document Horde's XSS vulnerabilities.
Approved by: portmgr (krion). |
0.2.3 27 Oct 2004 12:25:06
 |
nectar  |
Create a VuXML entry for Horde XSS help window vulnerability to replace
the portaudit-db entry. |
0.2.3 26 Oct 2004 19:37:44
 |
thierry  |
Add an entry for a vulnerability fixed in horde-2.2.7. |
0.2.3 24 Oct 2004 14:46:52
 |
lofi  |
Add entries for vulnerabilites in imported xpdf code in kdegraphics
and koffice. |
0.2.3 12 Oct 2004 05:25:06
 |
thierry  |
Add an entry for a XSS vulnerability fixed in IMP-3.2.6. |
0.2.3 08 Sep 2004 21:57:10
 |
eik  |
- star-devel: privilege escalation
- multi-gnome-terminal: information leak
- usermin: remote shell command injection and insecure installation
- mpg123: layer 2 decoder buffer overflow
Approved by: portmgr (implicit) |
0.2.3 07 Sep 2004 10:44:11
 |
eik  |
- XSS vulnerability in phpGroupWare wiki module
- add some references
Approved by: portmgr (implicit) |
0.2.3 03 Sep 2004 22:30:35
 |
eik  |
multiple vulnerabilities in LHA |
0.2.3 03 Sep 2004 21:36:18
 |
eik  |
grrrr... left the test case intact |
0.2.3 03 Sep 2004 20:27:26
 |
eik  |
- add some references
- extend ImageMagick entry
- squid ntlm authentication helper DoS
- multiple vpopmail vulnerabilities
- first attempts to check the base system for vulnerabilities:
+ cvs server code
+ zlib DoS
- BSD license portaudit.xml |
0.2.3 30 Aug 2004 23:43:44
 |
eik  |
samba printer change notification request DoS |
0.2.3 30 Aug 2004 10:58:48
 |
eik  |
add some references, add ru-gaim |
0.2.3 30 Aug 2004 10:57:42
 |
eik  |
multiple vulnerabilities in gaim |
0.2.3 30 Aug 2004 10:07:22
 |
eik  |
security bug in rscsi client code
Submitted by: marius |
0.2.3 27 Aug 2004 15:29:58
 |
nectar  |
Document NSS SSLv2 server buffer overflow (already referenced in
portaudit.txt). |
0.2.3 27 Aug 2004 14:43:07
 |
nectar  |
Document ripMIME decoding bug (already referenced in portaudit.txt). |
0.2.3 27 Aug 2004 10:34:05
 |
eik  |
Argh. Duplicate entry for "Scorched 3D server chat box format string
vulnerabilty" |
0.2.3 27 Aug 2004 10:31:21
 |
eik  |
Mozilla / NSS S/MIME DoS vulnerability & Scorched 3D server chat box format
string vulnerability |
0.2.3 26 Aug 2004 22:10:50
 |
nectar  |
Note sanitize_path bug in rsync (already referenced in portaudit.txt). |
0.2.3 26 Aug 2004 20:34:41
 |
nectar  |
Document buffer overflows in SoX (already referenced in portaudit.txt). |
0.2.3 26 Aug 2004 20:15:22
 |
nectar  |
Document cookie bug in Konqueror (already referenced in portaudit.txt). |
0.2.3 25 Aug 2004 13:58:01
 |
nectar  |
Remove libxine issue which is now documented in the FreeBSD VuXML
document.
Reminded by: eik |
0.2.3 25 Aug 2004 13:10:30
 |
eik  |
nss library SSL remote buffer overflow |
0.2.3 25 Aug 2004 11:07:08
 |
eik  |
multiple buffer overflows in xv |
0.2.3 23 Aug 2004 23:28:36
 |
eik  |
Konqueror cross-domain cookie injection |
0.2.3 23 Aug 2004 23:12:02
 |
eik  |
handle some duplicates |
0.2.3 21 Aug 2004 10:45:26
 |
eik  |
a2ps: Possible execution of shell commands as local user. |
0.2.3 20 Aug 2004 08:31:09
 |
eik  |
correct topic of eda0ade6-f281-11d8-81b0-000347a4fa7d |
0.2.3 20 Aug 2004 08:28:33
 |
eik  |
QT 3.x BMP (and possibly other graphics formats) heap-based overflow |
0.2.3 18 Aug 2004 20:01:44
 |
eik  |
potential security flaws in mod_ssl |
0.2.3 17 Aug 2004 07:56:37
 |
eik  |
move a800386e-ef7e-11d8-81b0-000347a4fa7d to xml |
0.2.3 16 Aug 2004 12:23:39
 |
eik  |
ruby CGI::Session insecure file creation |
0.2.3 15 Aug 2004 23:44:59
 |
eik  |
multiple phpGroupWare vulnerabilities |
0.2.3 15 Aug 2004 17:22:09
 |
eik  |
phpGedView, jftpgw |
0.2.3 13 Aug 2004 17:51:46
 |
eik  |
apply xlist not to the own files |
0.2.2 13 Aug 2004 16:48:12
 |
eik  |
fix some vuxml duplicates, add sympa unauthorized list creation |
0.2.2 12 Aug 2004 21:32:15
 |
lofi  |
Add another entry for kdelibs3 due to another missed patch. |
0.2.2 12 Aug 2004 21:17:31
 |
lofi  |
Correct entries for recent kde vuln's and add new entry for kdelibs
(3.2.3_3 didn't have all patches). |
0.2.2 12 Aug 2004 10:45:27
 |
eik  |
fix security hole in non-chroot rsync daemon.
<http://www.freebsd.org/ports/portaudit/2689f4cb-ec4c-11d8-9440-000347a4fa7d.html> |
0.2.2 12 Aug 2004 00:08:06
 |
eik  |
9fb5bb32-d6fa-11d8-b479-02e0185c0b53 is a duplicate of
40800696-c3b0-11d8-864c-02e0185c0b53 |
0.2.2 11 Aug 2004 22:57:51
 |
eik  |
f72ccf7c-e607-11d8-9b0a-000347a4fa7d is a duplicate of
6f955451-ba54-11d8-b88c-000d610a3b12, move references |
0.2.2 11 Aug 2004 01:27:37
 |
lofi  |
Factor out all but one of the build switches of the KDE main module ports
into separate ports. The OPTIONS will remain as of yet and trigger dependencies
now, for easy transition.
Update KOffice to version 1.3.2.
Add patches to fix a number of issues, including:
- fix kxkb on Xorg
- fix kdemultimedia WITH_MPEGLIB (now mpeglib_artsplug) compilation on gcc 3.4.2
with optimizations greater than -O
Add security related patches and entries to portaudit.txt. |
0.2.2 10 Aug 2004 08:50:27
 |
eik  |
libine "vcd:" input source buffer overflow |
0.2.2 10 Aug 2004 00:56:37
 |
eik  |
SpamAssassin DoS & cfengine authentication heap corruption |
0.2.2 07 Aug 2004 09:09:26
 |
eik  |
CVStrac arbitrary remote code execution |
0.2.2 06 Aug 2004 12:37:01
 |
eik  |
fold entry 7eded4b8-e6fe-11d8-b12f-0a001f31891a into
2de14f7a-dad9-11d8-b59a-00061bc2ad93 |
0.2.2 06 Aug 2004 05:41:01
 |
dinoex  |
putty local command execution |
0.2.2 05 Aug 2004 23:35:33
 |
eik  |
move abe47a5a-e23c-11d8-9b0a-000347a4fa7d to vuxml, add mozilla to the list of
vulnerable ports |
0.2.2 05 Aug 2004 16:45:52
 |
nork  |
o Security Update to 2.2.10-ja-1.0.
o rcNG-ify obtained from net/samba3.
PR: ports/70034
Submitted by: NAKAJI Hiroyuki <nakaji@jp.freebsd.org> (maintainer) |
0.2.2 05 Aug 2004 15:36:32
 |
eik  |
add Opera "location" object write access vulnerability |
0.2.2 05 Aug 2004 14:27:36
 |
eik  |
move f9e3e60b-e650-11d8-9b0a-000347a4fa7d to vuxml, add mozilla to the list of
vulnerable ports |
0.2.2 05 Aug 2004 04:33:46
 |
dinoex  |
back out last commit |
0.2.2 05 Aug 2004 04:31:41
 |
dinoex  |
putty local command execution |
0.2.2 04 Aug 2004 20:14:28
 |
eik  |
libPNG stack-based buffer overflow and other code concerns |
0.2.2 04 Aug 2004 11:43:15
 |
eik  |
Acrobat Reader handling of malformed uuencoded pdf files |
0.2.2 04 Aug 2004 11:18:53
 |
eik  |
Squid NTLM authentication helper overflow |
0.2.2 04 Aug 2004 11:10:43
 |
eik  |
ripMIME attachment extraction bypass |
0.2.2 02 Aug 2004 17:54:10
 |
eik  |
GnuTLS certificate chain verification DoS |
0.2.2 31 Jul 2004 15:00:41
 |
eik  |
phpMyAdmin configuration manipulation and code injection |
0.2.2 30 Jul 2004 17:28:06
 |
thierry  |
Register a vulnerability in mail/imp3.
This vulnerability only exists when using the Internet Explorer to
access IMP and only when using the inline MIME viewer for HTML messages. |
0.2.2 30 Jul 2004 15:28:22
 |
eik  |
Mozilla Firefox certificate spoofing |
0.2.2 30 Jul 2004 10:00:44
 |
eik  |
DansGuardian banned extension filter bypass vulnerability |
0.2.2 29 Jul 2004 08:15:20
 |
eik  |
add a reference to the SoX buffer overflow entry |
0.2.2 28 Jul 2004 20:33:38
 |
eik  |
SoX buffer overflows when handling .WAV files |
0.2.2 28 Jul 2004 09:34:18
 |
eik  |
LCDProc buffer overflow/format string vulnerabilities |
0.2.2 27 Jul 2004 10:40:29
 |
eik  |
pavuk digest auth buffer overflow |
0.2.2 27 Jul 2004 10:30:43
 |
eik  |
add Nessus "adduser" race condition and Dropbear DSS verification bug |
0.2.2 22 Jul 2004 19:08:09
 |
eik  |
l2tpd BSS-based buffer overflow |
0.2.2 22 Jul 2004 13:29:21
 |
eik  |
phpBB cross site scripting vulnerabilities |
0.2.2 20 Jul 2004 15:48:58
 |
eik  |
add subversion-perl, subversion-python |
0.2.2 20 Jul 2004 10:30:55
 |
eik  |
subversion access control bypass |
0.2.2 18 Jul 2004 10:49:58
 |
eik  |
mod_ssl format string vulnerability |
0.2.2 16 Jul 2004 07:39:25
 |
eik  |
Roundup directory traversal |
0.2.2 14 Jul 2004 06:56:16
 |
eik  |
wv library datetime field buffer overflow |
0.2.2 13 Jul 2004 23:47:33
 |
eik  |
multiple vulnerabilities in Bugzilla |
0.2.2 11 Jul 2004 12:09:03
 |
eik  |
correct vulnerable version of linux-png and add a reference |
0.2.2 11 Jul 2004 11:18:58
 |
eik  |
libpng row buffer overflow |
0.2.2 09 Jul 2004 14:51:16
 |
eik  |
add some references |
0.2.2 08 Jul 2004 14:24:07
 |
eik  |
move e5e2883d-ceb9-11d8-8898-000d6111a684 to vuln.xml |
0.2.2 06 Jul 2004 14:52:44
 |
eik  |
add some references |
0.2.2 06 Jul 2004 07:17:53
 |
eik  |
MySQL versions < 4.1 seem to be unaffected
Reported by: Alexander Vasenin <blacksir@number.ru> |
0.2.2 05 Jul 2004 19:45:32
 |
eik  |
add MySQL server authentication bypass / buffer overflow |
0.2.2 05 Jul 2004 15:30:35
 |
eik  |
Mark 4aec9d58-ce7b-11d8-858d-000d610a3b12 as a duplicate of the
already existing c63936c1-caed-11d8-8898-000d6111a684. |
0.2.2 03 Jul 2004 06:48:34
 |
trhodes  |
Move phpnuke vulnerabilities to VuXML. |
0.2.2 02 Jul 2004 00:48:56
 |
eik  |
move "phpMyAdmin code injection" to vuxml |
0.2.2 01 Jul 2004 19:03:36
 |
eik  |
phpMyAdmin code injection |
0.2.2 30 Jun 2004 23:39:00
 |
eik  |
- SSLtelnet remote format string vulnerability
(guys, this is a public list)
- add some references |
0.2.2 29 Jun 2004 10:33:03
 |
eik  |
add MIT Kerberos 5 krb5_aname_to_localname() buffer overflow |
0.2.2 29 Jun 2004 10:21:53
 |
eik  |
add isakmpd security association deletion vulnerability |
0.2.2 28 Jun 2004 22:09:24
 |
eik  |
add Apache input header folding DoS vulnerability |
0.2.2 28 Jun 2004 09:55:46
 |
eik  |
xine-lib RTSP handling vulnerabilities |
0.2.2 28 Jun 2004 03:58:47
 |
trhodes  |
Move MoinMoin entry to VuXML. |
0.2.2 28 Jun 2004 01:16:35
 |
eik  |
diversify url conversion |
0.2.2 26 Jun 2004 00:40:17
 |
eik  |
add portaudit2vuxml.pl to easy the migration of entries to VuXML |
0.2.2 25 Jun 2004 20:01:28
 |
trhodes  |
Add an entry for recent isc-dhcp3-server buffer overflows.
Remove the one in portaudit.txt. |
0.2.2 25 Jun 2004 17:18:57
 |
trhodes  |
Move giFT-FastTrack to VuXML. |