notbugAs an Amazon Associate I earn from qualifying purchases.
Want a good read? Try FreeBSD Mastery: Jails (IT Mastery Book 15)
Want a good monitor light? See my photosAll times are UTC
Ukraine
NOW FIXED. We had a known problem with lists of packages - they were out of date. The fix has been applied to production. See packages-import/issues/3 & packages-import/issues/4
Port details
vuxml Vulnerability and eXposure Markup Language DTD
1.1_6 security on this many watch lists=33 search for ports that depend on this port Find issues related to this port Report an issue related to this port View this port on Repology. pkg-fallout 1.1_6Version of this port present on the latest quarterly branch.
Maintainer: ports-secteam@FreeBSD.org search for ports maintained by this maintainer
Port Added: 2004-02-12 14:24:23
Last Update: 2025-02-02 08:32:18
Commit Hash: fe2f031
People watching this port, also watch:: gnupg, curl, libxml2, nmap, vim
Also Listed In: textproc
License: BSD2CLAUSE
WWW:
https://vuxml.freebsd.org/
Description:
VuXML (the Vulnerability and eXposure Markup Language) is an XML application for documenting security bugs and corrections within a software package collection such as the FreeBSD Ports Collection. This port installs the DTDs required for validating VuXML documents.
Homepage    cgit ¦ Codeberg ¦ GitHub ¦ GitLab ¦ SVNWeb

Manual pages:
FreshPorts has no man page information for this port.
pkg-plist: as obtained via: make generate-plist
Expand this list (13 items)
Collapse this list.
  1. /usr/local/share/licenses/vuxml-1.1_6/catalog.mk
  2. /usr/local/share/licenses/vuxml-1.1_6/LICENSE
  3. /usr/local/share/licenses/vuxml-1.1_6/BSD2CLAUSE
  4. @xmlcatmgr share/xml/dtd/vuxml/catalog
  5. @xmlcatmgr share/xml/dtd/vuxml/catalog.xml
  6. share/xml/dtd/vuxml/vuxml-10.dtd
  7. share/xml/dtd/vuxml/vuxml-11.dtd
  8. share/xml/dtd/vuxml/vuxml-model-10.mod
  9. share/xml/dtd/vuxml/vuxml-model-11.mod
  10. share/xml/dtd/vuxml/xml1.dcl
  11. @owner
  12. @group
  13. @mode
Collapse this list.
Dependency lines:
  • vuxml>0:security/vuxml
To install the port:
cd /usr/ports/security/vuxml/ && make install clean
To add the package, run one of these commands:
  • pkg install security/vuxml
  • pkg install vuxml
NOTE: If this package has multiple flavors (see below), then use one of them instead of the name specified above.
PKGNAME: vuxml
Flavors: there is no flavor information for this port.
distinfo:
SHA256 (vuxml/vuxml-10.dtd) = 6a635ad2cf45f52361c8c2a29a689157fad4d00519045485bc822d34e04a524e SIZE (vuxml/vuxml-10.dtd) = 2986 SHA256 (vuxml/vuxml-model-10.mod) = 051fed00b52bedde8ee901003fc29f7b95cd904157e31ceef34e6b06f2d1a14a

Expand this list (11 items)

Collapse this list.

SIZE (vuxml/vuxml-model-10.mod) = 10599 SHA256 (vuxml/vuxml-11.dtd) = 12b50061d7bb34cecffede2e08d439e4469324376d55aeb7c73eb6aab0f36af1 SIZE (vuxml/vuxml-11.dtd) = 3063 SHA256 (vuxml/vuxml-model-11.mod) = a40777208625a3029c6f416aeeea733f614802a6a5f26035a4e445a09e61a47c SIZE (vuxml/vuxml-model-11.mod) = 13282 SHA256 (vuxml/xml1.dcl) = 343efa94c4e1302e85e08b2d1791d86e50aac1ecdbc3161daecac100e4726847 SIZE (vuxml/xml1.dcl) = 7372 SHA256 (vuxml/catalog) = 479a69cf02995603443fd1f3b5b33f97811670931f87f53be99a727d664abc66 SIZE (vuxml/catalog) = 549 SHA256 (vuxml/catalog.xml) = 7b2e2850f57264eeba0ccd3d1fc161b9d5ce3071ae0ec51b9da7fa956f2a6509 SIZE (vuxml/catalog.xml) = 2150

Collapse this list.


Packages (timestamps in pop-ups are UTC):
vuxml
ABIaarch64amd64armv6armv7i386powerpcpowerpc64powerpc64le
FreeBSD:13:latest1.1_61.1_61.1_51.1_61.1_6-1.1_5-
FreeBSD:13:quarterly1.1_61.1_61.1_61.1_61.1_61.1_61.1_61.1_6
FreeBSD:14:latest1.1_61.1_61.1_61.1_61.1_61.1_6-1.1_6
FreeBSD:14:quarterly1.1_61.1_6-1.1_61.1_61.1_61.1_61.1_6
FreeBSD:15:latest1.1_61.1_6n/a1.1_6n/a1.1_61.1_61.1_6
Dependencies
NOTE: FreshPorts displays only information on required and default dependencies. Optional dependencies are not covered.
Runtime dependencies:
  1. xmlcatmgr : textproc/xmlcatmgr
  2. xsltproc : textproc/libxslt
  3. VERSION : textproc/xhtml-modularization
  4. xhtml-basic10.dtd : textproc/xhtml-basic
  5. python3.11 : lang/python311
There are no ports dependent upon this port

Configuration Options:
No options to configure
Options name:
security_vuxml
USES:
python:run
FreshPorts was unable to extract/find any pkg message
Master Sites:
Expand this list (1 items)
Collapse this list.
  1. http://www.vuxml.org/dtd/vuxml-1/
Collapse this list.

Number of commits found: 7511 (showing only 100 on this page)

[First Page]  «  38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48  »  [Last Page]

Commit History - (may be incomplete: for full details, see links to repositories near top of page)
CommitCreditsLog message
1.1_1
13 Mar 2014 22:58:56
Revision:348138Original commit files touched by this commit
cs search for other commits by this committer
Vulnerability in sysutils/wemux
1.1_1
11 Mar 2014 22:39:08
Revision:347941Original commit files touched by this commit
delphij search for other commits by this committer
Document samba multiple vulnerabilities announced today.
1.1_1
11 Mar 2014 20:14:38
Revision:347911Original commit files touched by this commit
flo search for other commits by this committer
Document asterisk vulnerabilities

MFH:	2014Q1
1.1_1
11 Mar 2014 17:16:55
Revision:347892Original commit files touched by this commit
rene search for other commits by this committer
Document new vulnerabilities in www/chromium < 33.0.1750.149

Obtained from:	http://googlechromereleases.blogspot.nl/
MFH:		2014Q1
1.1_1
09 Mar 2014 18:59:15
Revision:347684Original commit files touched by this commit
remko search for other commits by this committer
Properly indent the last entry.

Discussed with:	kwm
1.1_1
09 Mar 2014 08:43:48
Revision:347557Original commit files touched by this commit
kwm search for other commits by this committer
Unbreak vuxml.

Submitted by:	battlez
MFH:		2014Q1
1.1_1
09 Mar 2014 08:18:18
Revision:347554Original commit files touched by this commit
kwm search for other commits by this committer
Document freetype2 vuln.

MFH:	2014Q1
1.1_1
06 Mar 2014 13:09:20
Revision:347193Original commit files touched by this commit
bapt search for other commits by this committer
Reference xmms vulnerabilities: CVE-2007-0653 and CVE-2007-0654
1.1_1
06 Mar 2014 00:21:06
Revision:347158Original commit files touched by this commit
osa search for other commits by this committer
Add security advisory for nginx-1.5.10.
1.1_1
05 Mar 2014 23:14:02
Revision:347154Original commit files touched by this commit
rene search for other commits by this committer
Document new vulnerabilities in www/chromium < 33.0.1750.146

Obtained from:	http://googlechromereleases.blogspot.nl/
1.1_1
04 Mar 2014 22:50:05
Revision:347080Original commit files touched by this commit
bdrewery search for other commits by this committer
security/gnutls is fixed for CVE-2014-0092 and CVE-2014-1959
1.1_1
04 Mar 2014 22:17:32
Revision:347076Original commit files touched by this commit
delphij search for other commits by this committer
Document GnuTLS multiple certification verification issues.
1.1_1
03 Mar 2014 14:38:31
Revision:346908Original commit files touched by this commit
bf search for other commits by this committer
Add an entry for the file DOS vulnerability, CVE-2014-1943
1.1_1
02 Mar 2014 15:26:53
Revision:346772Original commit files touched by this commit
demon search for other commits by this committer
Use correct PORTREVISION for python33's CVE.
1.1_1
01 Mar 2014 12:51:06
Revision:346618Original commit files touched by this commit
koobs search for other commits by this committer
security/vuxml: Sort Python entry references alphabetically

MFH:		2014Q1
Reported by:	remko
1.1_1
01 Mar 2014 10:51:35
Revision:346613Original commit files touched by this commit
koobs search for other commits by this committer
security/vuxml: Document CVE-2014-1912 for Python 2.7 - 3.3

Python: buffer overflow in socket.recvfrom_into()

MFH:		2014Q1
Security:	CVE-2014-1912
1.1_1
26 Feb 2014 21:27:47
Revision:346229Original commit files touched by this commit
ohauer search for other commits by this committer
- add entry for subversion CVE-2014-0032
1.1_1
25 Feb 2014 19:45:18
Revision:346065Original commit files touched by this commit
cs search for other commits by this committer
Report new vulnerability in otrs to vuxml
Security:	CVE-2014-1695
1.1_1
24 Feb 2014 13:13:55
Revision:345835Original commit files touched by this commit
rene search for other commits by this committer
Document new vulnerabilities in www/chromium < 33.0.1750.117

Obtained from:	http://googlechromereleases.blogspot.nl/
MFH:		2014Q1
1.1_1
20 Feb 2014 18:11:25
Revision:345256Original commit files touched by this commit
girgen search for other commits by this committer
The PostgreSQL Global Development Group has released an important
update to all supported versions of the PostgreSQL database system,
which includes minor versions 9.3.3, 9.2.7, 9.1.12, 9.0.16, and
8.4.20. This update contains fixes for multiple security issues, as
well as several fixes for replication and data integrity issues.  All
users are urged to update their installations at the earliest
opportunity, especially those using binary replication or running a
high-security application.

This update fixes CVE-2014-0060, in which PostgreSQL did not properly
enforce the WITH ADMIN OPTION permission for ROLE management. Before
this fix, any member of a ROLE was able to grant others access to the
same ROLE regardless if the member was given the WITH ADMIN OPTION
permission. It also fixes multiple privilege escalation issues,
including: CVE-2014-0061, CVE-2014-0062, CVE-2014-0063, CVE-2014-0064,
CVE-2014-0065, and CVE-2014-0066. More information on these issues can
be found on our security page and the security issue detail wiki page.

Security:	CVE-2014-0060,CVE-2014-0061,CVE-2014-0062,CVE-2014-0063
		CVE-2014-0064,CVE-2014-0065,CVE-2014-0066,CVE-2014-0067
1.1_1
15 Feb 2014 17:05:12
Revision:344452Original commit files touched by this commit
lwhsu search for other commits by this committer
- Last whitespace change
- Sort CVE entries

Notified by:	remko
1.1_1
15 Feb 2014 12:10:20
Revision:344371Original commit files touched by this commit
matthew search for other commits by this committer
Document the latest PMA security advisory: PMSA-2014-1

The version of PMA currently in ports (since 2014-02-09) is not
affected.
1.1_1
15 Feb 2014 09:09:57
Revision:344335Original commit files touched by this commit
lwhsu search for other commits by this committer
Add CVE entry to references

Notified by:	remko
1.1_1
15 Feb 2014 09:07:34
Revision:344334Original commit files touched by this commit
lwhsu search for other commits by this committer
whitespace

Notified by:	remko
1.1_1
15 Feb 2014 08:04:51
Revision:344327Original commit files touched by this commit
lwhsu search for other commits by this committer
Document Jenkins Security Advisory 2014-02-14
1.1_1
14 Feb 2014 04:36:50
Revision:344160Original commit files touched by this commit
zi search for other commits by this committer
- Document recent vulnerabilities in www/lighttpd
1.1_1
06 Feb 2014 23:05:06
Revision:343170Original commit files touched by this commit
flo search for other commits by this committer
Document phpmyfaq vulnerabilities
1.1_1
06 Feb 2014 20:39:31
Revision:343150Original commit files touched by this commit
cs search for other commits by this committer
Update VUXML entry on recent otrs vulnerabilities

Suggested by:	remko@
1.1_1
05 Feb 2014 15:57:58
Revision:342743Original commit files touched by this commit
eadler search for other commits by this committer
Update the latest flash security advisory
1.1_1
05 Feb 2014 02:15:47
Revision:342624Original commit files touched by this commit
eadler search for other commits by this committer
Report the latest flash security issue
1.1_1
04 Feb 2014 21:19:14
Revision:342609Original commit files touched by this commit
beat search for other commits by this committer
Document mozilla vulnerabilities

Reviewed by:	flo
1.1_1
02 Feb 2014 13:52:18
Revision:342294Original commit files touched by this commit
zi search for other commits by this committer
- Add modified date to libyaml entry
1.1_1
02 Feb 2014 03:51:39
Revision:342244Original commit files touched by this commit
zi search for other commits by this committer
- Add libyaml to the libyaml vulnerability entry
1.1_1
01 Feb 2014 20:53:20
Revision:342211Original commit files touched by this commit
bdrewery search for other commits by this committer
- Document libyaml vulnerability in pkg

Security:	CVE-2013-6393
1.1_1
29 Jan 2014 08:42:34
Revision:341697Original commit files touched by this commit
ehaupt search for other commits by this committer
Use the same URL as in blockquote.

Submitted by:	remko
1.1_1
29 Jan 2014 08:22:56
Revision:341695Original commit files touched by this commit
miwi search for other commits by this committer
- Fix format
1.1_1
29 Jan 2014 07:53:48
Revision:341685Original commit files touched by this commit
ehaupt search for other commits by this committer
Document socat vulnerability.

Security:	CVE-2014-0019
1.1_1
28 Jan 2014 22:29:12
Revision:341666Original commit files touched by this commit
cs search for other commits by this committer
2 new OTRS vulnerabilities

Security:	CVE-2014-1471
1.1_1
27 Jan 2014 23:10:11
Revision:341472Original commit files touched by this commit
matthew search for other commits by this committer
rt42-4.2.1_3, which appears only on the 2014Q1 branch, should also be
counted as not vulnerable.
1.1_1
27 Jan 2014 23:01:12
Revision:341469Original commit files touched by this commit
rene search for other commits by this committer
Document vulnerabilities in www/chromium < 32.0.1700.102

Obtained from:	http://googlechromereleases.blogspot.nl/
1.1_1
27 Jan 2014 22:46:38
Revision:341466Original commit files touched by this commit
matthew search for other commits by this committer
Formatting fixes

Submitted by:	remko
1.1_1
27 Jan 2014 21:08:46
Revision:341451Original commit files touched by this commit
decke search for other commits by this committer
- Fix style for strongswan entry

Reported by:	remko
1.1_1
27 Jan 2014 20:44:52
Revision:341446Original commit files touched by this commit
matthew search for other commits by this committer
vuxml entry concerning	the recent security advisory about www/rt42
from 4.2.0 to 4.2.2 inclusive.  This is slightly unusual in the the
fix is applied to a completely different port
mail/p5-Email-Address-List which www/rt42 depends on..

Security:	d1dfc4c7-8791-11e3-a371-6805ca0b3d42
1.1_1
27 Jan 2014 13:52:18
Revision:341408Original commit files touched by this commit
decke search for other commits by this committer
- Fix typo in last entry

Reported by:	bz
1.1_1
27 Jan 2014 13:31:46
Revision:341403Original commit files touched by this commit
decke search for other commits by this committer
- Document multiple DoS vulnerabilities in strongswan

Security:	CVE-2013-5018
Security:	CVE-2013-6075
Security:	CVE-2013-6076
1.1_1
25 Jan 2014 09:24:38
Revision:340998Original commit files touched by this commit
koobs search for other commits by this committer
Document Varnish HTTP Cache < 3.0.5 DoS Vulnerability

Reviewed by:	remko
1.1_1
24 Jan 2014 05:05:37
Revision:340877Original commit files touched by this commit
eadler search for other commits by this committer
Update flash to 11.2r202.335
Report security issues

PR:		ports/185790
Reported by:	Tsurutani Naoki <turutani@scphys.kyoto-u.ac.jp>
1.1_1
23 Jan 2014 10:03:33
Revision:340819Original commit files touched by this commit
remko (src,doc committer) search for other commits by this committer
Cleanup the HTMLDOC entry, long lines and remove the ...
entries because I think it's not needed.  Also adjust
the previous entry by indenting correctly.

Hat:		secteam
Facilicated by:	Snow B.V.
1.1_1
22 Jan 2014 23:51:10
Revision:340750Original commit files touched by this commit
mandree search for other commits by this committer
Document HTMLDOC < 1.8.28 vulnerability.
1.1_1
16 Jan 2014 16:15:48
Revision:339929Original commit files touched by this commit
decke search for other commits by this committer
Document virtualbox-ose vulnerabilities

Security:	CVE-2013-5892
1.1_1
15 Jan 2014 21:41:16
Revision:339825Original commit files touched by this commit
rene search for other commits by this committer
Document new vulnerabilities in www/chromium < 32.0.1700.77

Obtained from:	http://googlechromereleases.blogspot.nl/
MFH:		2014Q1
1.1_1
15 Jan 2014 08:48:46
Revision:339767Original commit files touched by this commit
erwin search for other commits by this committer
Sort references

Submitted by:	remko
1.1_1
15 Jan 2014 08:36:23
Revision:339766Original commit files touched by this commit
erwin search for other commits by this committer
Document SA-13:07.bind
1.1_1
14 Jan 2014 21:15:11
Revision:339721Original commit files touched by this commit
remko (src,doc committer) search for other commits by this committer
Fix the latest entry, it has many issues, make validate
told us exactly what was wrong. I redid the entry and
just took out the ul/li structure and replaced it with
regular paragraphs. It might be worth investigating
to use the FreeBSD SA that got released because of this
as the main text, which is best suited imo.

Hat:	    secteam
1.1_1
14 Jan 2014 20:54:57
Revision:339717Original commit files touched by this commit
cy search for other commits by this committer
Mark net/ntp forbidden.

Security:	CVE-2013-5211 / VU#348126
1.1_1
14 Jan 2014 14:16:13
Revision:339686Original commit files touched by this commit
mat search for other commits by this committer
Document the latest nagios vulnerability.
1.1_1
13 Jan 2014 17:38:28
Revision:339612Original commit files touched by this commit
mat search for other commits by this committer
Security update to fix CVE-2014-0591 as reported at
https://kb.isc.org/article/AA-01078/74/

9.9.4 -> 9.9.4-P2
9.8.6 -> 9.8.6-P2
9.6-ESV-R10 -> 9.6-ESV-R10-P2

Security:	CVE-2014-0591 Remote DOS
1.1_1
08 Jan 2014 10:42:05
Revision:339086Original commit files touched by this commit
zeising search for other commits by this committer
Update libXfont to 1.4.7

This is a security fix and it is important to update, since it might lead to
a privilege escalation if the X server is run as root (which is the default)

Security:	CVE-2013-6462
1.1_1
06 Jan 2014 23:55:39
Revision:338961Original commit files touched by this commit
delphij search for other commits by this committer
Document OpenSSL 1.0.1e multiple vulnerabilities.
1.1_1
28 Dec 2013 23:52:50
Revision:337930Original commit files touched by this commit
remko (src,doc committer) search for other commits by this committer
Correct ident for most recent entries.  No functional changes.

People, please be aware that we use the FreeBSD Documentation Primer
and that there are style rules we have to follow.  If you are in
doubt please consult me and I am more then willing to help.

Hat:	secteam
1.1_1
22 Dec 2013 17:49:47
Revision:337204Original commit files touched by this commit
ohauer search for other commits by this committer
- mark as FORBIDDEN (zero day SQL vuln)

Security:	CVE-2013-7149
1.1_1
19 Dec 2013 07:45:42
Revision:336878Original commit files touched by this commit
delphij search for other commits by this committer
Cover gnupg1 ports/packages as well.
1.1_1
18 Dec 2013 23:04:24
Revision:336860Original commit files touched by this commit
delphij search for other commits by this committer
Apply vendor fix for CVE-2013-6422, cURL libcurl cert name check ignore
with GnuTLS.  Document the vulnerability fix in vuxml while I'm here.
1.1_1
18 Dec 2013 15:22:59
Revision:336840Original commit files touched by this commit
kuriyama search for other commits by this committer
Add about gnupg-1.4.16.
1.1_1
17 Dec 2013 23:26:27
Revision:336790Original commit files touched by this commit
flo search for other commits by this committer
- document asterisk vulnerabilities
- correctly order references [1]

Reported by:	remko [1]
1.1_1
16 Dec 2013 23:37:24
Revision:336678Original commit files touched by this commit
flo search for other commits by this committer
- update to 2.8.4
- add stage support

Security:	3b86583a-66a7-11e3-868f-0025905a4771
1.1_1
16 Dec 2013 04:11:00
Revision:336606Original commit files touched by this commit
delphij search for other commits by this committer
Document Zabbix agent remote command execution vulnerability.
1.1_1
14 Dec 2013 23:30:37
Revision:336500Original commit files touched by this commit
flo search for other commits by this committer
Update to 5.3.28

Security:	47b4e713-6513-11e3-868f-0025905a4771
1.1_1
14 Dec 2013 13:42:06
Revision:336446Original commit files touched by this commit
flo search for other commits by this committer
Update to nspr 4.10.2
Update to nss 3.15.3.1
Update firefox-esr and thunderbird to 24.2.0
Update firefox to 26.0
Update seamonkey to 2.23

- catch up with directory renames since USES=webplugins was introduced;
  fixes plugins not being automatically enabled after install
- linux-firefox and linux-seamonkey can play HTML5 audio [2][3] and
  measure about:memory usage, again
- dom.ipc.plugins.enabled->true no longer crash linux-firefox which makes
  some flash sites work again; as there's no nspluginwrapper in-between
  the infamous "youtube issue" never occurs
- install DEBUG with symbols [3] and describe the option better [4]
- enable dumping about:memory upon kill -65, kill -66 and GC/CC log
  upon kill -67 to a file under /tmp directory; linux-firefox uses
  kill -34, kill -35 and kill -36 respectively

PR:		ports/183861 [1]
PR:		ports/184006 [2]
PR:		ports/169896 [3]
PR:		ports/184285 [3]
PR:		ports/184286 [4]
Security:	dd116b19-64b3-11e3-868f-0025905a4771
In collaboration with: Jan Beich <jbeich@tormail.org>
1.1_1
10 Dec 2013 19:45:12
Revision:336101Original commit files touched by this commit
sunpoet search for other commits by this committer
- Group affected packages
- Sort CVE
- Fix indent

Notified by:	remko
1.1_1
10 Dec 2013 04:57:36
Revision:336047Original commit files touched by this commit
timur search for other commits by this committer
Add entry for net/samba* CVE-2012-6150 and CVE-2013-4408
1.1_1
08 Dec 2013 14:19:02
Revision:335897Original commit files touched by this commit
sunpoet search for other commits by this committer
- Document Rails vulnerability
1.1_1
06 Dec 2013 00:38:50
Revision:335721Original commit files touched by this commit
delphij search for other commits by this committer
Document drupal multiple vulnerabilities.
1.1_1
05 Dec 2013 12:07:00
Revision:335662Original commit files touched by this commit
rene search for other commits by this committer
Document new vulnerabilities in www/chromium < 31.0.1650.63

Obtained from:	http://googlechromereleases.blogspot.nl/
1.1_1
05 Dec 2013 00:00:11
Revision:335649Original commit files touched by this commit
nivit search for other commits by this committer
- Document multiple XSS core vulnerabilities for Joomla!
  (2.5.0 <= version <= 2.5.14, 3.0.0 <= version <= 3.1.5)
1.1_1
03 Dec 2013 06:28:04
Revision:335546Original commit files touched by this commit
danfe search for other commits by this committer
Update to version 1.3.3, which fixes an important crashy bug: denial of
service (server) using forcefully crashed aircrafts.

While here, reduce the diffs between other OpenTTD's VuXML entries; and
limit build logs verbosity to bulk package builders (or batch builds).

PR:		ports/184434, ports/184435
Submitted by:	Ilya A. Arkhipov
Security:	CVE-2013-6411
1.1_1
01 Dec 2013 15:10:19
Revision:335393Original commit files touched by this commit
ohauer search for other commits by this committer
- security update to 3.3.1

This is a maintenance release that fixes a serious bug in the built-in HTTP
server. It was discovered that the handle_request() routine did not properly
perform input sanitization which led into a number of security
vulnerabilities.

An unauthenticated, remote attacker could exploit this flaw to execute
arbitrary commands on the remote host.

All users still using older versions are advised to upgrade to this version,
which resolves this issue.

Approved by:	crees (maintainer, per PM)
Security:	620cf713-5a99-11e3-878d-20cf30e32f6d
1.1_1
25 Nov 2013 19:52:24
Revision:334888Original commit files touched by this commit
ohauer search for other commits by this committer
- security update subversion-1.8.5 / 1.7.14 [1]
- add vuxml entry
- let bindings ports load options file [2]

[1]
Version 1.8.5
(25 November 2013, from /branches/1.8.x)
http://svn.apache.org/repos/asf/subversion/tags/1.8.5

 User-visible changes:
  - Client-side bugfixes:
    * fix externals that point at redirected locations (issues #4428, #4429)
    * diff: fix assertion with move inside a copy (issue #4444)

  - Server-side bugfixes:
(Only the first 15 lines of the commit message are shown above View all of this commit message)
1.1_1
25 Nov 2013 06:56:08
Revision:334815Original commit files touched by this commit
remko (src,doc committer) search for other commits by this committer
Make it more clear that "SAME URL" is actually the blockquote
url.

hat:	secteam
1.1_1
24 Nov 2013 05:36:29
Revision:334705Original commit files touched by this commit
swills search for other commits by this committer
- Update devel/ruby-gems to 1.8.28
- Document security issues with 1.8.26 and 1.8.27 (CVE-2013-4287 and
CVE-2013-4363)

Security:	742eb9e4-e3cb-4f5a-b94e-0e9a39420600
Security:	54237182-9635-4a8b-92d7-33bfaeed84cd
1.1_1
23 Nov 2013 03:10:04
Revision:334630Original commit files touched by this commit
swills search for other commits by this committer
- Fix and report heap overflow in floating point parsing issue in ruby

Security:	cc9043cf-7f7a-426e-b2cc-8d1980618113
1.1_1
19 Nov 2013 23:11:40
Revision:334362Original commit files touched by this commit
timur search for other commits by this committer
Add entries about CVE-2013-4475 and CVE-2013-4476 for net/samba* ports.
1.1_1
19 Nov 2013 17:54:54
Revision:334335Original commit files touched by this commit
osa search for other commits by this committer
Document new vulnerability in www/nginx (< 1.4.4) and www/nginx-devel (< 1.5.7).
1.1_1
17 Nov 2013 02:25:24
Revision:334047Original commit files touched by this commit
eadler search for other commits by this committer
Add back NO_STAGE which snuck away during testing.
1.1_1
17 Nov 2013 02:12:32
Revision:334046Original commit files touched by this commit
eadler search for other commits by this committer
Minor tweak to standard template in order to fit with convention
1.1_1
15 Nov 2013 12:57:27
Revision:333862Original commit files touched by this commit
rene search for other commits by this committer
Document new vulnerability in www/chromium < 31.0.1650.57

Obtained from:	http://googlechromereleases.blogspot.nl/
1.1_1
13 Nov 2013 14:07:04
Revision:333686Original commit files touched by this commit
remko (src,doc committer) search for other commits by this committer
Fix the OpenSSH entry, a version entry should be marked
on a per rule basis, and not on it's own lines, because
that would bogusly match other versions then intended.

When in doubt, please let me review your changes!!

hat:	secteam
1.1_1
13 Nov 2013 05:55:57
Revision:333651Original commit files touched by this commit
eadler search for other commits by this committer
Update to latest flash and mark the old one as vulnerable.

PR:		ports/183911
Submitted by:	Tsurutani Naoki <turutani@scphys.kyoto-u.ac.jp>
1.1_1
12 Nov 2013 19:08:37
Revision:333601Original commit files touched by this commit
rene search for other commits by this committer
Document new vulnerabilities in www/chromium < 31.0.1650.48

Obtained from:	http://googlechromereleases.blogspot.nl/
1.1_1
12 Nov 2013 13:09:18
Revision:333567Original commit files touched by this commit
zi search for other commits by this committer
- Set MAINTAINER to ports-secteam

Requested by:	des@
With hat:	ports-secteam@
1.1_1
11 Nov 2013 12:34:18
Revision:333489Original commit files touched by this commit
bdrewery search for other commits by this committer
- Fix versions for entry 5709d244-4873-11e3-8a46-000d601460a4
1.1_1
08 Nov 2013 12:50:29
Revision:333217Original commit files touched by this commit
bdrewery search for other commits by this committer
- Document memory corruption in security/openssh-portable
1.1_1
06 Nov 2013 16:24:34
Revision:333011Original commit files touched by this commit
makc search for other commits by this committer
Document vulnerability in irc/quassel
1.1_1
01 Nov 2013 12:37:11
Revision:332362Original commit files touched by this commit
wg search for other commits by this committer
security/vuxml: add modified date for gnutls

Reported by:	kwm
1.1_1
01 Nov 2013 11:16:16
Revision:332356Original commit files touched by this commit
wg search for other commits by this committer
gnutls3 3.1.15 is affected by the same vulnerability
1.1_1
31 Oct 2013 15:42:13
Revision:332257Original commit files touched by this commit
flo search for other commits by this committer
Thunderbird is only at version 24.1.0, not 25.0
1.1_1
30 Oct 2013 20:59:23
Revision:332173Original commit files touched by this commit
flo search for other commits by this committer
Add an entry for the recent mozilla vulnerabilities
1.1_1
28 Oct 2013 18:48:22
Revision:331887Original commit files touched by this commit
swills search for other commits by this committer
- Update www/mod_pagespeed to 1.2.24.2,1
- Document security issue in mod_pagespeed
1.1_1
28 Oct 2013 07:04:10
Revision:331834Original commit files touched by this commit
sunpoet search for other commits by this committer
- Cancel the vuxml entry correctly

Notified by:	remko
1.1_1
27 Oct 2013 18:19:16
Revision:331796Original commit files touched by this commit
sunpoet search for other commits by this committer
- Revert previous commit

Number of commits found: 7511 (showing only 100 on this page)

[First Page]  «  38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48  »  [Last Page]