notbugAs an Amazon Associate I earn from qualifying purchases.
Want a good read? Try FreeBSD Mastery: Jails (IT Mastery Book 15)
Want a good monitor light? See my photosAll times are UTC
Ukraine
NOW FIXED. We had a known problem with lists of packages - they were out of date. The fix has been applied to production. See packages-import/issues/3 & packages-import/issues/4
Port details
vuxml Vulnerability and eXposure Markup Language DTD
1.1_6 security on this many watch lists=33 search for ports that depend on this port Find issues related to this port Report an issue related to this port View this port on Repology. pkg-fallout 1.1_6Version of this port present on the latest quarterly branch.
Maintainer: ports-secteam@FreeBSD.org search for ports maintained by this maintainer
Port Added: 2004-02-12 14:24:23
Last Update: 2025-02-02 08:32:18
Commit Hash: fe2f031
People watching this port, also watch:: gnupg, curl, libxml2, nmap, vim
Also Listed In: textproc
License: BSD2CLAUSE
WWW:
https://vuxml.freebsd.org/
Description:
VuXML (the Vulnerability and eXposure Markup Language) is an XML application for documenting security bugs and corrections within a software package collection such as the FreeBSD Ports Collection. This port installs the DTDs required for validating VuXML documents.
Homepage    cgit ¦ Codeberg ¦ GitHub ¦ GitLab ¦ SVNWeb

Manual pages:
FreshPorts has no man page information for this port.
pkg-plist: as obtained via: make generate-plist
Expand this list (13 items)
Collapse this list.
  1. /usr/local/share/licenses/vuxml-1.1_6/catalog.mk
  2. /usr/local/share/licenses/vuxml-1.1_6/LICENSE
  3. /usr/local/share/licenses/vuxml-1.1_6/BSD2CLAUSE
  4. @xmlcatmgr share/xml/dtd/vuxml/catalog
  5. @xmlcatmgr share/xml/dtd/vuxml/catalog.xml
  6. share/xml/dtd/vuxml/vuxml-10.dtd
  7. share/xml/dtd/vuxml/vuxml-11.dtd
  8. share/xml/dtd/vuxml/vuxml-model-10.mod
  9. share/xml/dtd/vuxml/vuxml-model-11.mod
  10. share/xml/dtd/vuxml/xml1.dcl
  11. @owner
  12. @group
  13. @mode
Collapse this list.
Dependency lines:
  • vuxml>0:security/vuxml
To install the port:
cd /usr/ports/security/vuxml/ && make install clean
To add the package, run one of these commands:
  • pkg install security/vuxml
  • pkg install vuxml
NOTE: If this package has multiple flavors (see below), then use one of them instead of the name specified above.
PKGNAME: vuxml
Flavors: there is no flavor information for this port.
distinfo:
SHA256 (vuxml/vuxml-10.dtd) = 6a635ad2cf45f52361c8c2a29a689157fad4d00519045485bc822d34e04a524e SIZE (vuxml/vuxml-10.dtd) = 2986 SHA256 (vuxml/vuxml-model-10.mod) = 051fed00b52bedde8ee901003fc29f7b95cd904157e31ceef34e6b06f2d1a14a

Expand this list (11 items)

Collapse this list.

SIZE (vuxml/vuxml-model-10.mod) = 10599 SHA256 (vuxml/vuxml-11.dtd) = 12b50061d7bb34cecffede2e08d439e4469324376d55aeb7c73eb6aab0f36af1 SIZE (vuxml/vuxml-11.dtd) = 3063 SHA256 (vuxml/vuxml-model-11.mod) = a40777208625a3029c6f416aeeea733f614802a6a5f26035a4e445a09e61a47c SIZE (vuxml/vuxml-model-11.mod) = 13282 SHA256 (vuxml/xml1.dcl) = 343efa94c4e1302e85e08b2d1791d86e50aac1ecdbc3161daecac100e4726847 SIZE (vuxml/xml1.dcl) = 7372 SHA256 (vuxml/catalog) = 479a69cf02995603443fd1f3b5b33f97811670931f87f53be99a727d664abc66 SIZE (vuxml/catalog) = 549 SHA256 (vuxml/catalog.xml) = 7b2e2850f57264eeba0ccd3d1fc161b9d5ce3071ae0ec51b9da7fa956f2a6509 SIZE (vuxml/catalog.xml) = 2150

Collapse this list.


Packages (timestamps in pop-ups are UTC):
vuxml
ABIaarch64amd64armv6armv7i386powerpcpowerpc64powerpc64le
FreeBSD:13:latest1.1_61.1_61.1_51.1_61.1_6-1.1_5-
FreeBSD:13:quarterly1.1_61.1_61.1_61.1_61.1_61.1_61.1_61.1_6
FreeBSD:14:latest1.1_61.1_61.1_61.1_61.1_61.1_6-1.1_6
FreeBSD:14:quarterly1.1_61.1_6-1.1_61.1_61.1_61.1_61.1_6
FreeBSD:15:latest1.1_61.1_6n/a1.1_6n/a1.1_61.1_61.1_6
Dependencies
NOTE: FreshPorts displays only information on required and default dependencies. Optional dependencies are not covered.
Runtime dependencies:
  1. xmlcatmgr : textproc/xmlcatmgr
  2. xsltproc : textproc/libxslt
  3. VERSION : textproc/xhtml-modularization
  4. xhtml-basic10.dtd : textproc/xhtml-basic
  5. python3.11 : lang/python311
There are no ports dependent upon this port

Configuration Options:
No options to configure
Options name:
security_vuxml
USES:
python:run
FreshPorts was unable to extract/find any pkg message
Master Sites:
Expand this list (1 items)
Collapse this list.
  1. http://www.vuxml.org/dtd/vuxml-1/
Collapse this list.

Number of commits found: 7511 (showing only 100 on this page)

[First Page]  «  39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49  »  [Last Page]

Commit History - (may be incomplete: for full details, see links to repositories near top of page)
CommitCreditsLog message
1.1_1
27 Oct 2013 17:53:20
Revision:331789Original commit files touched by this commit
sunpoet search for other commits by this committer
- Document WordPress XSS vulnerability
1.1_1
25 Oct 2013 16:52:51
Revision:331612Original commit files touched by this commit
jgh search for other commits by this committer
- Add url reference to 9065b930-3d8b-11e3-bd1a-e840f2096bd0

With Hat: ports-secteam
1.1_1
25 Oct 2013 16:07:27
Revision:331605Original commit files touched by this commit
wg search for other commits by this committer
- Remove report url as it is a default CVE

Reported by:	ak
1.1_1
25 Oct 2013 15:55:41
Revision:331604Original commit files touched by this commit
wg search for other commits by this committer
- Document gnutls3 denial of service CVE
1.1_1
24 Oct 2013 13:05:10
Revision:331484Original commit files touched by this commit
kwm search for other commits by this committer
Document xorg-server use after free CVE.

Reviewed by:	zeising@
1.1_1
19 Oct 2013 08:27:56
Revision:330854Original commit files touched by this commit
delphij search for other commits by this committer
Document pycrypto PRNG reseed race condition.
1.1_1
19 Oct 2013 03:54:52
Revision:330844Original commit files touched by this commit
swills search for other commits by this committer
- Add CVE references to WordPress 3.6.1 entry
1.1_1
19 Oct 2013 03:40:48
Revision:330843Original commit files touched by this commit
swills search for other commits by this committer
- Note issues with WordPress before 3.6.1
1.1_1
19 Oct 2013 03:22:32
Revision:330842Original commit files touched by this commit
swills search for other commits by this committer
- node-devel packages is vulnerable too, guessing this is going to be fixed in
  0.11.7, but if not, I'll update further.
1.1_1
19 Oct 2013 02:48:02
Revision:330834Original commit files touched by this commit
swills search for other commits by this committer
- Update to 0.10.21 to address a security issue

PR:		ports/183092
Submitted by:	Kenji Rikitake <kenji.rikitake@acm.org>
Security:	206f9826-a06d-4927-9a85-771c37010b32
17 Oct 2013 19:35:22
Revision:330666Original commit files touched by this commit Sanity Test Failure Refresh
ohauer search for other commits by this committer
- update to latest release [1]
- use PKGNAMESUFFIX instead LATEST_LINK
- whitespace cleanup
- svn mv */bugzilla to */bugzilla40
- add vuxml entry

4.4.1, 4.2.7, and 4.0.11 Security Advisory
Wednesday Oct 16th, 2013

Summary
=======

Bugzilla is a Web-based bug-tracking system used by a large number of
software projects. The following security issues have been discovered
in Bugzilla:
(Only the first 15 lines of the commit message are shown above View all of this commit message)
1.1_1
17 Oct 2013 12:43:19
Revision:330634Original commit files touched by this commit
des search for other commits by this committer
Fix build by commenting out the most recent of the two discovery
dates.
1.1_1
17 Oct 2013 10:56:57
Revision:330627Original commit files touched by this commit
ak search for other commits by this committer
- Fix year, move entry up
1.1_1
17 Oct 2013 10:46:54
Revision:330626Original commit files touched by this commit
ak search for other commits by this committer
- Document new vulnerabilities in security/dropbear
1.1_1
15 Oct 2013 19:04:28
Revision:330429Original commit files touched by this commit
rene search for other commits by this committer
Document new vulnerabilities in www/chromium < 30.0.1599.101

Obtained from:	http://googlechromereleases.blogspot.nl/
1.1_1
10 Oct 2013 20:02:42
Revision:330031Original commit files touched by this commit
ohauer search for other commits by this committer
- update mod_fcgid to version 2.3.9
- add stage support
- add vuxml entry

PR:		ports/182878
Submitted by:	Fabiano Sidler <freebsd.ports@webstyle.ch> (maintainer)
Security:	CVE-2013-4365
1.1_1
05 Oct 2013 09:44:24
Revision:329431Original commit files touched by this commit
kuriyama search for other commits by this committer
Add recent gnupg1/gnupg vuln.
1.1_1
03 Oct 2013 13:05:49
Revision:329177Original commit files touched by this commit
sem search for other commits by this committer
Document the last xinetd vulnerability
1.1_1
01 Oct 2013 23:47:14
Revision:329009Original commit files touched by this commit
jase search for other commits by this committer
- Update to 1.2.9
- Add vuxml entry
- Prevent install target from copying patch backup files

Changes:	https://raw.github.com/polarssl/polarssl/60ad84f43f46b0d3673eaca8b9847d7e01b83c5e/ChangeLog
Security:	ccefac3e-2aed-11e3-af10-000c29789cb5
Security:	CVE-2013-5915
1.1_1
01 Oct 2013 21:30:23
Revision:328998Original commit files touched by this commit
rene search for other commits by this committer
Document new vulnerabilities for www/chromium < 30.0.1599.66

Obtained from:	http://googlechromereleases.blogspot.nl/
1.1_1
30 Sep 2013 20:55:51
Revision:328873Original commit files touched by this commit
delphij search for other commits by this committer
Our "package" can have multiple "name" elements.  Since these packages are
from the same origin, they can be collapased into one entry.
1.1_1
30 Sep 2013 19:40:29
Revision:328853Original commit files touched by this commit
brd (doc committer) search for other commits by this committer
- Add a low version to the graphite-web vuln

Approved by:	swills@
1.1_1
30 Sep 2013 19:31:32
Revision:328851Original commit files touched by this commit
swills search for other commits by this committer
- Document graphite issue
1.1_1
24 Sep 2013 13:55:56
Revision:328135Original commit files touched by this commit
tabthorpe search for other commits by this committer
- ebd877b9-7ef4-4375-b1fd-c67780581898 also applies to our ruby18

Reviewed by:	swills
1.1_1
22 Sep 2013 10:36:32
Revision:327862Original commit files touched by this commit
lwhsu search for other commits by this committer
Document CVE-2013-1443 for www/py-django{,14,-devel}
1.1_1
22 Sep 2013 10:09:42
Revision:327861Original commit files touched by this commit
lwhsu search for other commits by this committer
- Split names for different packages

Notified by:	remko
1.1_1
20 Sep 2013 22:55:26
Revision:327769Original commit files touched by this commit
bapt search for other commits by this committer
Add NO_STAGE all over the place in preparation for the staging support (cat:
security)
1.1_1
19 Sep 2013 08:29:16
Revision:327604Original commit files touched by this commit
rm search for other commits by this committer
- add modification date to mozilla entry, that I forgot about
1.1_1
19 Sep 2013 07:50:30
Revision:327600Original commit files touched by this commit
rm search for other commits by this committer
- correct thunderbird version in recent mozilla entry
1.1_1
19 Sep 2013 05:44:02
Revision:327595Original commit files touched by this commit
remko (src,doc committer) search for other commits by this committer
Add the latest two FreeBSD Security Advisories that have impact
on -RELEASE versions. (RC's are not documented).

Hat:	secteam
1.1_1
18 Sep 2013 22:40:58
Revision:327587Original commit files touched by this commit
flo search for other commits by this committer
- update firefox, thunderbird and libxul to 24.0
- update seamonkey to 2.21
- update firefox-esr to 17.0.9
- enable GSTREAMER by default for html5 with h264/aac/mp3
- WEBRTC is now always built
- add PROFILE and TESTS options

Security:		7dfed67b-20aa-11e3-b8d8-0025905a4771
In collaboration with:	Jan Beich <jbeich@tormail.org>
1.1_1
13 Sep 2013 13:13:36
Revision:327145Original commit files touched by this commit
eadler search for other commits by this committer
Update flash to version 11.2.202.310

PR:		ports/182013
Submitted by:	Tsurutani Naoki <turutani@scphys.kyoto-u.ac.jp>
Security:	http://www.vuxml.org/freebsd/5bd6811f-1c75-11e3-ba72-98fc11cdc4f5
1.1_1
12 Sep 2013 16:03:45
Revision:327080Original commit files touched by this commit
lwhsu search for other commits by this committer
Document CVE-2013-4315 for www/py-django{,14,-devel}
1.1_1
02 Sep 2013 19:04:21
Revision:326057Original commit files touched by this commit
ohauer search for other commits by this committer
- update devel/subversion to 1.8.3	[1]
- update devel/subversion17 to 1.7.13	[1]
- add vuxml entry

Version 1.7.13
(29 Aug 2013, from /branches/1.7.x)
http://svn.apache.org/repos/asf/subversion/tags/1.7.13/CHANGES

User-visible changes:
 - General
   * merge: fix bogus mergeinfo with conflicting file merges (issue #4306)
   * diff: fix duplicated path component in '--summarize' output (issue #4408)
   * ra_serf: ignore case when checking certificate common names (r1514763)

 - Server-side bugfixes:
(Only the first 15 lines of the commit message are shown above View all of this commit message)
1.1_1
29 Aug 2013 10:56:24
Revision:325582Original commit files touched by this commit
sem search for other commits by this committer
- Document the last cacti vulnerabilities

PR:		ports/181606 (based on)
Submitted by:	Rodrigo (ros) OSORIO <rodrigo@bebik.net>
1.1_1
29 Aug 2013 06:15:52
Revision:325565Original commit files touched by this commit
remko (src,doc committer) search for other commits by this committer
Add CVE entries to latest entry for Asterisk.
Add "The" in who reports the issue.
Bump modified date
1.1_1
28 Aug 2013 20:51:32
Revision:325551Original commit files touched by this commit
flo search for other commits by this committer
Update net/asterisk to 1.8.23.1
Update net/asterisk10 to 10.12.3
Update net/asterisk11 to 11.5.1

Security:	fd2bf3b5-1001-11e3-ba94-0025905a4771
1.1_1
21 Aug 2013 09:29:44
Revision:325102Original commit files touched by this commit
rene search for other commits by this committer
Document new vulnerabilities in www/chromium < 29.0.1547.57

Obtained from:	http://googlechromereleases.blogspot.nl/
1.1_1
20 Aug 2013 15:36:43
Revision:325059Original commit files touched by this commit
kwm search for other commits by this committer
Fix multiple security issues in the bundled libav version by replacing it
with a newer version.

Reported by:	Jan Beich <jbeich@tormail.org>
1.1_1
19 Aug 2013 08:07:02
Revision:324952Original commit files touched by this commit
stas (src committer) search for other commits by this committer
- Correct lcms2 VuXML entry: only versions before 2.5 are vulnerable.

PR:		ports/181384
Reported by:	Derek Schrock <dereks@lifeofadishwasher.com>
1.1_1
18 Aug 2013 10:41:11
Revision:324899Original commit files touched by this commit
ashish search for other commits by this committer
- Update modified date of VuXML entry which was missed in r317985

Reported by:	remko
1.1_1
17 Aug 2013 08:36:30
Revision:324834Original commit files touched by this commit
remko (src,doc committer) search for other commits by this committer
Correct latest entry, properly indent the paragraphs
and sort the url list alphabetically.
1.1_1
17 Aug 2013 08:24:35
Revision:324831Original commit files touched by this commit
bf search for other commits by this committer
Amend 689c2bf7-0701-11e3-9a25-002590860428 so that it doesn't overlap with
80771b89-f57b-11e2-bf21-b499baab0cbe, but keep both entries rather than
augmenting the old one, because I've cited the new one in a commit message.
1.1_1
17 Aug 2013 07:56:12
Revision:324830Original commit files touched by this commit
bf search for other commits by this committer
Update security/libgcrypt to 1.5.3 [1], and document the latest gnupg
and libgcrypt vulnerability

PR:		181231
Submitted by:	Hirohisa Yamaguchi (maintainer) [1]
Security:	http://www.vuxml.org/freebsd/689c2bf7-0701-11e3-9a25-002590860428.html
1.1_1
16 Aug 2013 17:54:42
Revision:324808Original commit files touched by this commit
brd (doc committer) search for other commits by this committer
- Update puppet to 3.2.4 which fixes CVE-2013-4761 and CVE-2013-4956

Approved by:	swills@
Security:	2b2f6092-0694-11e3-9e8e-000c29f6ae42
1.1_1
16 Aug 2013 05:35:00
Revision:324791Original commit files touched by this commit
remko (src,doc committer) search for other commits by this committer
Correct polarssl entry, the lines were way to long, indentation was
incorrect, and the topic description does not need too many details
since that is explained in the description itself.

Also correct the url's since c comes before u ;-)

Prodded by:	stas
1.1_1
15 Aug 2013 19:54:23
Revision:324783Original commit files touched by this commit
stas (src committer) search for other commits by this committer
- Fix ordering of references.

Reported by:	remko
1.1_1
15 Aug 2013 19:02:34
Revision:324781Original commit files touched by this commit
stas (src committer) search for other commits by this committer
- Add lcms2 DoS vulnerability entry.

Hat: secteam
1.1_1
13 Aug 2013 06:20:27
Revision:324652Original commit files touched by this commit
mandree search for other commits by this committer
Add CVE Id, which was not in the advisory,
but on <https://polarssl.org/security>.
1.1_1
13 Aug 2013 06:17:33
Revision:324651Original commit files touched by this commit
mandree search for other commits by this committer
Record PolarSSL < 1.2.8 infinite loop denial of service.

Note: the port has not yet been upgraded, and the fix then needs to be merged
to the 9.2 ports branch before release.
1.1_1
09 Aug 2013 20:52:29
Revision:324462Original commit files touched by this commit
delphij search for other commits by this committer
Add a link to the advisory.

Submitted by:	remko
1.1_1
09 Aug 2013 17:22:17
Revision:324452Original commit files touched by this commit
delphij search for other commits by this committer
Document Samba DoS vulnerability.
1.1_1
08 Aug 2013 18:42:03
Revision:324409Original commit files touched by this commit
flo search for other commits by this committer
- update firefox to 23.0
- update firefox-esr, thunderbird and libxul to 17.0.8
- update seamonkey to 2.20
- fix plist for *-i18n

Security:		0998e79d-0055-11e3-905b-0025905a4771
In collaboration with:	Jan Beich <jbeich@tormail.org>
1.1_1
07 Aug 2013 16:26:13
Revision:324359Original commit files touched by this commit
mandree search for other commits by this committer
Add one more reference for PuTTY 0.59-0.61 vuln CVE-2011-4607.
1.1_1
07 Aug 2013 16:22:30
Revision:324358Original commit files touched by this commit
mandree search for other commits by this committer
More references for PuTTY < 0.63 vulnerabilities.
1.1_1
07 Aug 2013 16:11:18
Revision:324357Original commit files touched by this commit
mandree search for other commits by this committer
Upgrade PuTTY to new 0.63 beta upstream release, adding vulnerability info.

Quoting the upstream's change log:

- Security fix: prevent a nefarious SSH server or network attacker from
  crashing PuTTY at startup in three different ways by presenting a maliciously
  constructed public key and signature.
- Security fix: PuTTY no longer retains the private half of users' keys in
  memory by mistake after authenticating with them.
- Revamped the internal configuration storage system to remove all fixed
  arbitrary limits on string lengths. In particular, there should now no longer
  be an unreasonably small limit on the number of port forwardings PuTTY can
  store.
- Port-forwarded TCP connections which close one direction before the other
  should now be reliably supported, with EOF propagated independently in the
(Only the first 15 lines of the commit message are shown above View all of this commit message)
1.1_1
07 Aug 2013 08:41:51
Revision:324336Original commit files touched by this commit
danfe search for other commits by this committer
Adjust NVidia driver version ranges after r304966 to remedy false positives.
1.1_1
05 Aug 2013 21:56:57
Revision:324294Original commit files touched by this commit
ohauer search for other commits by this committer
- secuity update for typo3 ports
- some small Makefile cleanups
- add vuxml entry

Vulnerability Types: Cross-Site Scripting, Remote Code Execution
 Overall Severity: Critical

Vulnerable subcomponent: Third Party Libraries used for audio and video playback
 Affected Versions: All versions from 4.5.0 up to the development branch of 6.2
 Vulnerability Type: Cross-Site Scripting
 Severity: Medium

Vulnerable subcomponent: Backend File Upload / File Abstraction Layer
 Vulnerability Type: Remote Code Execution by arbitrary file creation
 Affected Versions: All versions from 6.0.0 up to the development branch of 6.2
 Severity: Critical

PR:		ports/180951
		ports/180952
		ports/180953
Submitted by:	Helmut Ritter <freebsd-ports@charlieroot.de> (maintainer)
Security:	http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2013-002/
		CVE-2011-3642
		CVE-2013-1464
1.1_1
04 Aug 2013 12:13:51
Revision:324220Original commit files touched by this commit
matthew search for other commits by this committer
- Security update of databases/phpmyadmin to 4.0.5

ChangeLog:
http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/4.0.5/phpMyAdmin-4.0.5-notes.html/download
SecurityAdvisory: http://www.phpmyadmin.net/home_page/security/PMASA-2013-10.php

- Deprecate databases/phpmyadmin35

This version is vulnerable to the 'clickjacking protection bypass'
problem fixed in 4.0.5, but the development team will not be
publishing a fix. "We have no solution for 3.5.x, due to the proposed
solution requiring JavaScript. We don't want to introduce a dependency
to JavaScript in the 3.5.x family."

Therefore deprecate this port and set expiry for one month.  Please
upgrade to 4.0.5 instead.

Security:	17326fd5-fcfb-11e2-9bb9-6805ca0b3d42
1.1_1
03 Aug 2013 14:56:42
Revision:324196Original commit files touched by this commit
rene search for other commits by this committer
Add new vulnerabilities for www/chromium < 28.0.1500.95

Obtained from:	http://googlechromereleases.blogspot.nl/
1.1_1
01 Aug 2013 18:43:49
Revision:324117Original commit files touched by this commit
remko (src,doc committer) search for other commits by this committer
Modify the latest puppet entry. Because the matching of the version everything
below 3.2.2 was a match, including all 2.7.x versions. It also appears that
there is no puppet27 version, just puppet-2.7.x and puppet-3.2.x instead.

Bump modification date.

PR:		180958
Submitted by:	Kan Sasaki <sasaki@fcc.ad.jp>
1.1_1
29 Jul 2013 19:17:27
Revision:323898Original commit files touched by this commit
matthew search for other commits by this committer
Now that PMSA-2013-{9,11-15} have been published, borrow from them to
expand on the original rather sketchy entries.

Sort URL references[1]

Submitted by:	remko [1]
1.1_1
28 Jul 2013 15:38:45
Revision:323835Original commit files touched by this commit
matthew search for other commits by this committer
Security update: multiple vulnerabilities in databases/phpmyadmin and
databases/phpmyadmin35

 - update phpmyadmin to 4.0.4.2

ChangeLog:
http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/4.0.4.2/phpMyAdmin-4.0.4.2-notes.html/view

 - update phpmyadmin35 to 3.5.8.2

ChangeLog:
http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/3.5.8.2/phpMyAdmin-3.5.8.2-notes.html/view

 - vuxml

The PMSA references shown have not been published yet, hence no CVE
numbers and a lack of detail in the descriptions.  Yes, PMSA-2013-10
is missing from the sequence.  According to the security alert e-mail:

   "For more details, see the upcoming PMASA-2013-8 to PMASA-2013-15 (minus
    PMASA-2013-10 which is reserved for a future advisory)."
1.1_1
27 Jul 2013 17:36:20
Revision:323801Original commit files touched by this commit
remko (src,doc committer) search for other commits by this committer
Add entry for wordpress < 3.5.2

Requested by:	Patrick Oonk
1.1_1
27 Jul 2013 13:24:18
Revision:323783Original commit files touched by this commit
remko (src,doc committer) search for other commits by this committer
Add additional reference, bump modified date.
1.1_1
26 Jul 2013 23:22:36
Revision:323760Original commit files touched by this commit
delphij search for other commits by this committer
Document BIND denial of service vulnerability
1.1_1
26 Jul 2013 11:06:45
Revision:323712Original commit files touched by this commit
remko (src,doc committer) search for other commits by this committer
Cleanup last entry. Properly indent the entry and
make sure that after a period on the end of a line
we follow with two spaces.

hat:	    secteam
1.1_1
25 Jul 2013 22:56:06
Revision:323675Original commit files touched by this commit
kuriyama search for other commits by this committer
Add an entry for security/gnupg1.
1.1_1
25 Jul 2013 18:29:27
Revision:323659Original commit files touched by this commit
bjk (doc committer) search for other commits by this committer
Update to 1.6.5

This is a security release by upstream, and requires configuration changes
in addition to the software update.  See UPDATING.

Reviewed by:	ports-security (zi, remko)
Approved by:	hrs (mentor, ports committer)
1.1_1
24 Jul 2013 20:59:28
Revision:323617Original commit files touched by this commit
lev search for other commits by this committer
  Add <url></url> to references.

Submitted by:	Remko Lodder <remko@FreeBSD.org>
1.1_1
24 Jul 2013 17:18:50
Revision:323611Original commit files touched by this commit
lev search for other commits by this committer
 Update:
   devel/subversion to 1.8.1
   devel/subversion16 to 1.7.11

 These releases fix CVE-2013-4131
 http://subversion.apache.org/security/CVE-2013-4131-advisory.txt

Approved by:	Olli Hauer <ohauer@FreeBSD.org> for devel/subversion17
Security:	CVE-2013-4131
1.1_1
23 Jul 2013 10:32:23
Revision:323525Original commit files touched by this commit
bdrewery search for other commits by this committer
- Update whitespace for 2fbfd455-f2d0-11e2-8a46-000d601460a4

Requested by:	remko
1.1_1
22 Jul 2013 13:24:05
Revision:323445Original commit files touched by this commit
bdrewery search for other commits by this committer
- Update suPHP to 0.7.2
- Document possible privilege escalation

Approved by:	maintainer timeout
Security:	2fbfd455-f2d0-11e2-8a46-000d601460a4
1.1_1
21 Jul 2013 18:54:51
Revision:323410Original commit files touched by this commit
ohauer search for other commits by this committer
- change apache24 version from 2.4.5 to 2.4.6 (2.4.5 was not released)
- add http://www.apache.org/dist/httpd/Announcement2.4.html as reference

requested by remko@
1.1_1
20 Jul 2013 17:11:54
Revision:323351Original commit files touched by this commit
ohauer search for other commits by this committer
- update to apache24-2.4.6
 - new modules: mod_cache_socache, mod_macro and mod_proxy_wstunnel

- add enty to vuxml

SECURITY: CVE-2013-1896 (cve.mitre.org)
 mod_dav: Sending a MERGE request against a URI handled by mod_dav_svn with
 the source href (sent as part of the request body as XML) pointing to a
 URI that is not configured for DAV will trigger a segfault.

SECURITY: CVE-2013-2249 (cve.mitre.org)
 mod_session_dbd: Make sure that dirty flag is respected when saving
 sessions, and ensure the session ID is changed each time the session
 changes. This changes the format of the updatesession SQL statement.
 Existing configurations must be changed.

Changelog:
http://www.apache.org/dist/httpd/CHANGES_2.4.6

with hat apache@

Security:	ca4d63fb-f15c-11e2-b183-20cf30e32f6d
1.1_1
17 Jul 2013 22:09:58
Revision:323190Original commit files touched by this commit
delphij search for other commits by this committer
Document gallery3 multiple vulnerabilities.
1.1_1
17 Jul 2013 22:07:22
Revision:323189Original commit files touched by this commit
eadler search for other commits by this committer
Add missing citation

Requested by:	remko
1.1_1
16 Jul 2013 18:10:12
Revision:323118Original commit files touched by this commit
des search for other commits by this committer
Add two more PHP entries for issues which have already been fixed.
1.1_1
15 Jul 2013 21:06:36
Revision:323080Original commit files touched by this commit
eadler search for other commits by this committer
Update to 11.2r202.291

PR:		ports/179502
Submitted by:	Tsurutani Naoki <turutani@scphys.kyoto-u.ac.jp>
1.1_1
15 Jul 2013 18:25:19
Revision:323071Original commit files touched by this commit
delphij search for other commits by this committer
Document squid 3.x denial of service vulnerability.
1.1_1
15 Jul 2013 09:26:37
Revision:323026Original commit files touched by this commit
cs search for other commits by this committer
Adjust version numbers for OTRS vulnerabilities
1.1_1
14 Jul 2013 22:03:55
Revision:323009Original commit files touched by this commit
eadler search for other commits by this committer
Add missing modified dates from r321329.

I had this sitting for a bit, but forgot to test & commit.

Requested by:	remko
1.1_1
11 Jul 2013 21:28:39
Revision:322798Original commit files touched by this commit
delphij search for other commits by this committer
Wrap long lines.  No content change.
1.1_1
11 Jul 2013 20:35:20
Revision:322797Original commit files touched by this commit
cs search for other commits by this committer
Security vulnerabilities in libzrtp

Security:	04320e7d-ea66-11e2-a96e-60a44c524f57
1.1_1
11 Jul 2013 20:17:34
Revision:322795Original commit files touched by this commit
swills search for other commits by this committer
- Document ruby vulnerability
1.1_1
11 Jul 2013 07:50:27
Revision:322757Original commit files touched by this commit
cs search for other commits by this committer
Add vulnerability on otrs

Security:	e3e788aa-e9fd-11e2-a96e-60a44c524f57
1.1_1
10 Jul 2013 19:01:44
Revision:322728Original commit files touched by this commit
ohauer search for other commits by this committer
- update to apache-2.2.25
- update vuxml with additional CVE-2013-1896 entry

Changes with Apache 2.2.25
  http://www.apache.org/dist/httpd/CHANGES_2.2.25

  *) SECURITY: CVE-2013-1896 (cve.mitre.org)
     mod_dav: Sending a MERGE request against a URI handled by mod_dav_svn with
     the source href (sent as part of the request body as XML) pointing to a
     URI that is not configured for DAV will trigger a segfault. [Ben Reser
     <ben reser.org>]

  *) SECURITY: CVE-2013-1862 (cve.mitre.org)
     mod_rewrite: Ensure that client data written to the RewriteLog is
     escaped to prevent terminal escape sequences from entering the
(Only the first 15 lines of the commit message are shown above View all of this commit message)
1.1_1
10 Jul 2013 14:35:58
Revision:322699Original commit files touched by this commit
rene search for other commits by this committer
Add new vulnerabilities for www/chromium < 28.0.1500.71

Obtained from:	http://googlechromereleases.blogspot.nl/
1.1_1
06 Jul 2013 08:46:40
Revision:322368Original commit files touched by this commit
ohauer search for other commits by this committer
- add fix for CVE-2013-1862
- adjust vuxml
1.1_1
05 Jul 2013 21:06:16
Revision:322357Original commit files touched by this commit
ohauer search for other commits by this committer
- document apache22 CVE-2013-1862 (mod_rewrite)

Update to apache22-2.2.25 is ready to commit.
Until now there is no official announcement from apache.org
so we hold the update back until we have official checksums.
1.1_1
02 Jul 2013 07:43:03
Revision:322159Original commit files touched by this commit
delphij search for other commits by this committer
Fix CVE-2013-2174 for ftp/curl with a patch from vendor for
now so that users can build the port, per popular demands
on mailing list.

The upgrade patch found in ports/172325 is currently under
exp-run.  The changes in this commit against ftp/curl can be
safely reverted before applying that patch, as it's shipped
with new curl release.

Approved by:	portmgr (miwi)
1.1_1
30 Jun 2013 20:49:33
Revision:322099Original commit files touched by this commit
matthew search for other commits by this committer
Security update to 4.0.4.1

ChangeLog:
http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/4.0.4.1/phpMyAdmin-4.0.4.1-notes.html/view

Advisory: http://www.phpmyadmin.net/home_page/security/PMASA-2013-7.php

Security:	1b93f6fe-e1c1-11e2-948d-6805ca0b3d42
1.1_1
28 Jun 2013 11:07:49
Revision:321955Original commit files touched by this commit
girgen search for other commits by this committer
Security update for apache-xml-security-c

URL:	http://santuario.apache.org/secadv.data/CVE-2013-2210.txt
Security:	81da673e-dfe1-11e2-9389-08002798f6ff
Security:	CVE-2013-2210
1.1_1
26 Jun 2013 11:01:35
Revision:321792Original commit files touched by this commit
flo search for other commits by this committer
- update firefox to 22.0
- update firefox-esr, thunderbird and libxul to 17.0.7
- update nspr to 4.10
- OSS support was removed upstream, only ALSA and PulseAudio are supported
  from now on.

Security:	b3fcb387-de4b-11e2-b1c6-0025905a4771
In collaboration with:	Jan Beich <jbeich@tormail.org>
1.1_1
23 Jun 2013 20:14:01
Revision:321649Original commit files touched by this commit
rea search for other commits by this committer
VuXML: document CVE-2013-2174, heap corruption in cURL library
1.1_1
22 Jun 2013 12:49:29
Revision:321570Original commit files touched by this commit
swills search for other commits by this committer
- Update puppet to 3.2.2 which fixes CVE-2013-3567 [1]
- Update puppet27 to 2.7.22 which fixes CVE-2013-3567
- Document security issue

PR:		ports/179816 [1]
Submitted by:	mat [1]
Security:	b162b218-c547-4ba2-ae31-6fdcb61bc763
1.1_1
22 Jun 2013 09:36:10
Revision:321558Original commit files touched by this commit
bf search for other commits by this committer
Correct the CVE-2013-0131 entry, so that the most recent revision of
x11/nvidia-driver-304 is not mistakenly flagged as vulnerable
1.1_1
19 Jun 2013 21:56:57
Revision:321338Original commit files touched by this commit
jgh search for other commits by this committer
- fix formating of 8b97d289-d8cf-11e2-a1f5-60a44c524f57

With Hat:	ports-secteam
1.1_1
19 Jun 2013 21:20:50
Revision:321330Original commit files touched by this commit
eadler search for other commits by this committer
Add extra-validation to the validation target.

While here, test with python2 and permit the script to run with either 2 or 3.

Requested by:	delphij
With Hat:	ports-secteam
1.1_1
19 Jun 2013 21:14:51
Revision:321329Original commit files touched by this commit
eadler search for other commits by this committer
- Fix entry dates for some 'insane' dates.  In some cases a best effort was made
to guess what was meant due to either destroyed svn logs (formatting 'fixes') or
lost to time reports.

With Hat:	ports-secteam

Number of commits found: 7511 (showing only 100 on this page)

[First Page]  «  39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49  »  [Last Page]