notbugAs an Amazon Associate I earn from qualifying purchases.
Want a good read? Try FreeBSD Mastery: Jails (IT Mastery Book 15)
Want a good monitor light? See my photosAll times are UTC
Ukraine
NOW FIXED. We had a known problem with lists of packages - they were out of date. The fix has been applied to production. See packages-import/issues/3 & packages-import/issues/4
Port details
vuxml Vulnerability and eXposure Markup Language DTD
1.1_6 security on this many watch lists=33 search for ports that depend on this port Find issues related to this port Report an issue related to this port View this port on Repology. pkg-fallout 1.1_6Version of this port present on the latest quarterly branch.
Maintainer: ports-secteam@FreeBSD.org search for ports maintained by this maintainer
Port Added: 2004-02-12 14:24:23
Last Update: 2025-02-02 08:32:18
Commit Hash: fe2f031
People watching this port, also watch:: gnupg, curl, libxml2, nmap, vim
Also Listed In: textproc
License: BSD2CLAUSE
WWW:
https://vuxml.freebsd.org/
Description:
VuXML (the Vulnerability and eXposure Markup Language) is an XML application for documenting security bugs and corrections within a software package collection such as the FreeBSD Ports Collection. This port installs the DTDs required for validating VuXML documents.
Homepage    cgit ¦ Codeberg ¦ GitHub ¦ GitLab ¦ SVNWeb

Manual pages:
FreshPorts has no man page information for this port.
pkg-plist: as obtained via: make generate-plist
Expand this list (13 items)
Collapse this list.
  1. /usr/local/share/licenses/vuxml-1.1_6/catalog.mk
  2. /usr/local/share/licenses/vuxml-1.1_6/LICENSE
  3. /usr/local/share/licenses/vuxml-1.1_6/BSD2CLAUSE
  4. @xmlcatmgr share/xml/dtd/vuxml/catalog
  5. @xmlcatmgr share/xml/dtd/vuxml/catalog.xml
  6. share/xml/dtd/vuxml/vuxml-10.dtd
  7. share/xml/dtd/vuxml/vuxml-11.dtd
  8. share/xml/dtd/vuxml/vuxml-model-10.mod
  9. share/xml/dtd/vuxml/vuxml-model-11.mod
  10. share/xml/dtd/vuxml/xml1.dcl
  11. @owner
  12. @group
  13. @mode
Collapse this list.
Dependency lines:
  • vuxml>0:security/vuxml
To install the port:
cd /usr/ports/security/vuxml/ && make install clean
To add the package, run one of these commands:
  • pkg install security/vuxml
  • pkg install vuxml
NOTE: If this package has multiple flavors (see below), then use one of them instead of the name specified above.
PKGNAME: vuxml
Flavors: there is no flavor information for this port.
distinfo:
SHA256 (vuxml/vuxml-10.dtd) = 6a635ad2cf45f52361c8c2a29a689157fad4d00519045485bc822d34e04a524e SIZE (vuxml/vuxml-10.dtd) = 2986 SHA256 (vuxml/vuxml-model-10.mod) = 051fed00b52bedde8ee901003fc29f7b95cd904157e31ceef34e6b06f2d1a14a

Expand this list (11 items)

Collapse this list.

SIZE (vuxml/vuxml-model-10.mod) = 10599 SHA256 (vuxml/vuxml-11.dtd) = 12b50061d7bb34cecffede2e08d439e4469324376d55aeb7c73eb6aab0f36af1 SIZE (vuxml/vuxml-11.dtd) = 3063 SHA256 (vuxml/vuxml-model-11.mod) = a40777208625a3029c6f416aeeea733f614802a6a5f26035a4e445a09e61a47c SIZE (vuxml/vuxml-model-11.mod) = 13282 SHA256 (vuxml/xml1.dcl) = 343efa94c4e1302e85e08b2d1791d86e50aac1ecdbc3161daecac100e4726847 SIZE (vuxml/xml1.dcl) = 7372 SHA256 (vuxml/catalog) = 479a69cf02995603443fd1f3b5b33f97811670931f87f53be99a727d664abc66 SIZE (vuxml/catalog) = 549 SHA256 (vuxml/catalog.xml) = 7b2e2850f57264eeba0ccd3d1fc161b9d5ce3071ae0ec51b9da7fa956f2a6509 SIZE (vuxml/catalog.xml) = 2150

Collapse this list.


Packages (timestamps in pop-ups are UTC):
vuxml
ABIaarch64amd64armv6armv7i386powerpcpowerpc64powerpc64le
FreeBSD:13:latest1.1_61.1_61.1_51.1_61.1_6-1.1_5-
FreeBSD:13:quarterly1.1_61.1_61.1_61.1_61.1_61.1_61.1_61.1_6
FreeBSD:14:latest1.1_61.1_61.1_61.1_61.1_61.1_6-1.1_6
FreeBSD:14:quarterly1.1_61.1_6-1.1_61.1_61.1_61.1_61.1_6
FreeBSD:15:latest1.1_61.1_6n/a1.1_6n/a1.1_61.1_61.1_6
Dependencies
NOTE: FreshPorts displays only information on required and default dependencies. Optional dependencies are not covered.
Runtime dependencies:
  1. xmlcatmgr : textproc/xmlcatmgr
  2. xsltproc : textproc/libxslt
  3. VERSION : textproc/xhtml-modularization
  4. xhtml-basic10.dtd : textproc/xhtml-basic
  5. python3.11 : lang/python311
There are no ports dependent upon this port

Configuration Options:
No options to configure
Options name:
security_vuxml
USES:
python:run
FreshPorts was unable to extract/find any pkg message
Master Sites:
Expand this list (1 items)
Collapse this list.
  1. http://www.vuxml.org/dtd/vuxml-1/
Collapse this list.

Number of commits found: 7511 (showing only 100 on this page)

[First Page]  «  40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50  »  [Last Page]

Commit History - (may be incomplete: for full details, see links to repositories near top of page)
CommitCreditsLog message
1.1_1
19 Jun 2013 20:46:23
Revision:321322Original commit files touched by this commit
eadler search for other commits by this committer
Add an additional validation script to the vuxml port.
At this point it is not tied to the validate: target because validation fails.

Reviewed by:	simon, delphij
With Hat:	ports-secteam
1.1_1
19 Jun 2013 11:08:02
Revision:321237Original commit files touched by this commit
cs search for other commits by this committer
Fix typo soccat -> socat
1.1_1
19 Jun 2013 11:07:36
Revision:321236Original commit files touched by this commit
cs search for other commits by this committer
Add vulnerability on OTRS
1.1_1
18 Jun 2013 15:50:05
Revision:321198Original commit files touched by this commit
delphij search for other commits by this committer
Fix date for flashpluginwrapper.
1.1_1
18 Jun 2013 15:45:03
Revision:321196Original commit files touched by this commit
delphij search for other commits by this committer
Add entry for SA-13:06.mmap.
1.1_1
18 Jun 2013 15:15:48
Revision:321194Original commit files touched by this commit
girgen search for other commits by this committer
Security update for apache-xml-security-c.
Dependant ports, especially shibboleth2-sp, opensaml2, xmltooling
and log4shib should all be updated.

Security: CVE-2013-2156
1.1_1
17 Jun 2013 03:23:53
Revision:321084Original commit files touched by this commit
bf search for other commits by this committer
Document Tor bug 9072
1.1_1
14 Jun 2013 06:21:14
Revision:320884Original commit files touched by this commit
ak search for other commits by this committer
- Fix typo in dbus entry

Reported by:	Christoph Mallon <christoph.mallon@gmx.de>
1.1_1
13 Jun 2013 19:54:25
Revision:320834Original commit files touched by this commit
kwm search for other commits by this committer
Update to 1.6.12.

I'm not completly sure this affects us, but beter safe then sorry.
While here wordsmith Options description to try to make it clearer.

Security:	CVE-2013-2168
1.1_1
11 Jun 2013 22:44:39
Revision:320654Original commit files touched by this commit
eadler search for other commits by this committer
Update to 11.2r202.291

PR:		ports/179502
Submitted by:	Tsurutani Naoki <turutani@scphys.kyoto-u.ac.jp>
1.1_1
11 Jun 2013 21:03:38
Revision:320642Original commit files touched by this commit
culot search for other commits by this committer
- Document vulnerabilities in www/owncloud

Security:	d7a43ee6-d2d5-11e2-9894-002590082ac6
Obtained from:	http://owncloud.org/about/security/advisories/
1.1_1
07 Jun 2013 15:19:27
Revision:320210Original commit files touched by this commit
flo search for other commits by this committer
Update to 5.3.26

Security:	59e7163c-cf84-11e2-907b-0025905a4770
1.1_1
07 Jun 2013 06:30:39
Revision:320151Original commit files touched by this commit
erwin search for other commits by this committer
Match only the most recent Bind9* version in the latest vulnerability,
older versions are not affected.
1.1_1
06 Jun 2013 10:59:35
Revision:320080Original commit files touched by this commit
erwin search for other commits by this committer
Fix typo in previous revision.
1.1_1
06 Jun 2013 08:36:34
Revision:320060Original commit files touched by this commit
erwin search for other commits by this committer
Add entry for the latest Bind vulnerabilities in CVE-2013-3919.
1.1_1
05 Jun 2013 22:02:14
Revision:320032Original commit files touched by this commit
matthew search for other commits by this committer
Security upgrade to 4.0.3

Advisory: http://www.phpmyadmin.net/home_page/security/PMASA-2013-6.php

ChangeLog:
http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/4.0.3/phpMyAdmin-4.0.3-notes.html/view

Security:	6b97436c-ce1e-11e2-9cb2-6805ca0b3d42
1.1_1
05 Jun 2013 09:02:47
Revision:319965Original commit files touched by this commit
kwm search for other commits by this committer
Update to 0.16.6.

Obtained from:	GNOME dev repo
Security:	CVE-2013-1431
1.1_1
04 Jun 2013 22:30:28
Revision:319933Original commit files touched by this commit
rene search for other commits by this committer
Document vulnerabilities in www/chromium < 27.0.1453.110

Obtained from:	http://googlechromereleases.blogspot.nl/
1.1_1
04 Jun 2013 21:52:40
Revision:319919Original commit files touched by this commit
eadler search for other commits by this committer
- Fix build
- Ensure validation
1.1_1
04 Jun 2013 19:31:30
Revision:319899Original commit files touched by this commit
zeising search for other commits by this committer
Fix security issues in xorg client libraries.
Most libraries were updated to newer versions, in some cases patches
were backported instead.

Most notably, x11/libX11 was updated to 1.6.0

Security:	CVE-2013-1981
		CVE-2013-1982
		CVE-2013-1983
		CVE-2013-1984
		CVE-2013-1985
		CVE-2013-1986
		CVE-2013-1987
		CVE-2013-1988
		CVE-2013-1989
(Only the first 15 lines of the commit message are shown above View all of this commit message)
1.1_1
04 Jun 2013 04:45:23
Revision:319823Original commit files touched by this commit
cy search for other commits by this committer
Update krb5 1.11.2 --> 1.11.3.

This is a bugfix release.

* Fix a UDP ping-pong vulnerability in the kpasswd (password changing)
  service.  [CVE-2002-2443]

* Improve interoperability with some Windows native PKINIT clients.

Security:	CVE-2002-2443
1.1_1
03 Jun 2013 18:29:51
Revision:319798Original commit files touched by this commit
crees search for other commits by this committer
Update to 1.6.2

* Fix buffer overflows in fileserver and ptserver.
* Fix rare file corruption during background sync (Gerrit 8796).
* Fix corrupting clients' metadata cache during certain errors (Gerrit 6957).
* Fix cache corruption when reading from a file another client is simultaneously
writing to (Gerrit 7994).
* Fix fileservers to properly report >2 TiB partitions.

and some other less serious changes.

PR:		ports/179259
Submitted by:	Adam Nowacki <nowak@tepeserwery.pl>
Submitted by:	bjk (maintainer)
Security:	CVE-2013-1794
1.1_1
03 Jun 2013 06:51:43
Revision:319757Original commit files touched by this commit
araujo search for other commits by this committer
- Update to 2.7.4.

More info:
https://github.com/SpiderLabs/ModSecurity/blob/master/CHANGES

PR:		ports/179167
Submitted by:	ohauer@
Security:	9dfb63b8-8f36-11e2-b34d-000c2957946c
1.1_1
01 Jun 2013 19:22:39
Revision:319586Original commit files touched by this commit
rakuco search for other commits by this committer
Remove duplicate optipng vulnerability.

It was separately committed in r315254, so remove the version I added
in r318453.

Reported by:	Alexander Milanov <a@amilanov.com>
1.1_1
01 Jun 2013 16:49:14
Revision:319581Original commit files touched by this commit
mandree search for other commits by this committer
Add two more URLs to openvpn's vulnerability from March 2013 (CVE-2013-2061)

Security: 92f30415-9935-11e2-ad4c-080027ef73ec
1.1_1
01 Jun 2013 16:47:41
Revision:319579Original commit files touched by this commit
mandree search for other commits by this committer
- Backport fix for CVE-2013-2061 to openvpn22 and openvpn20;
  while it is unclear whether it affects OpenSSL-builds at all.
  Let's play it safe.
- Reference CVE-2013-2061 name in OpenVPN's VuXML entry
- Mark 2.0.9_4 <= openvpn < 2.1.0 and 2.2.2_2 < openvpn < 2.3.0 not vulnerable
- Mark openvpn22 deprecated and to expire 2013-09-01.
  (openvpn20 is already marked to expire 2013-07-11.)

Security:	CVE-2013-2061
Security:	92f30415-9935-11e2-ad4c-080027ef73ec
1.1_1
01 Jun 2013 08:08:56
Revision:319558Original commit files touched by this commit
osa search for other commits by this committer
Document passenger vulnerability.
1.1_1
31 May 2013 21:41:56
Revision:319544Original commit files touched by this commit
lev search for other commits by this committer
  Update subversion ports to 1.7.10 and 1.6.23.
  It fixes 3 security issues:

    CVE-2013-1968: fsfs repository corruption caused by newline characters in
filenames
    CVE-2013-2088: contrib hook-scripts can allow arbitrary code execution
    CVE-2013-2112: svnserve remotely triggerable DoS.

Security:	CVE-2013-1968
Security:	CVE-2013-2088
Security:	CVE-2013-2112
1.1_1
31 May 2013 11:33:41
Revision:319486Original commit files touched by this commit
crees search for other commits by this committer
Actually remove bitchx-devel and add a VuXML entry.

Security:	CVE-2007-4584
Security:	CVE-2007-5839
Security:	CVE-2007-5922
1.1_1
28 May 2013 14:23:30
Revision:319314Original commit files touched by this commit
jase search for other commits by this committer
- Document znc null pointer dereference vulnerability.
1.1_1
27 May 2013 00:41:56
Revision:319144Original commit files touched by this commit
ehaupt search for other commits by this committer
Adjust range for socat entry.
1.1_1
26 May 2013 22:01:38
Revision:319138Original commit files touched by this commit
ehaupt search for other commits by this committer
Document socat FD leak vulnerability.

Security:	CVE-2013-3571
1.1_1
26 May 2013 20:34:16
Revision:319136Original commit files touched by this commit
swills search for other commits by this committer
- Add entry for ruby 1.9.3p429
1.1_1
26 May 2013 08:38:26
Revision:319098Original commit files touched by this commit
delphij search for other commits by this committer
Document couchdb XSS vulnerability.

PR:		ports/178985
Submitted by:	wollman
1.1_1
23 May 2013 15:30:08
Revision:318877Original commit files touched by this commit
flo search for other commits by this committer
Update to 2.17.1 as the 2.18 release was postponed / cancelled
1.1_1
23 May 2013 08:20:48
Revision:318853Original commit files touched by this commit
cs search for other commits by this committer
Fix entry date, wrongly entered in revision 318453
1.1_1
23 May 2013 08:02:57
Revision:318851Original commit files touched by this commit
cs search for other commits by this committer
fix typo in recent otrs vulnerability
1.1_1
23 May 2013 07:58:58
Revision:318850Original commit files touched by this commit
cs search for other commits by this committer
Add vulnerabilities

Security:	CVE-2013-2637
		CVE-2013-3551
1.1_1
23 May 2013 07:24:40
Revision:318848Original commit files touched by this commit
matthew search for other commits by this committer
Security Updates

   - www/rt40 to 4.0.13
   - www/rt38 to 3.8.17 [1]

This is a security fix addressing a number of CVEs:

    CVE-2012-4733
    CVE-2013-3368
    CVE-2013-3369
    CVE-2013-3370
    CVE-2013-3371
    CVE-2013-3372
    CVE-2013-3373
    CVE-2013-3374

Users will need to update their database schemas as described in
pkg-message

Approved by:	flo [1]
Security:	3a429192-c36a-11e2-97a9-6805ca0b3d42
1.1_1
22 May 2013 09:14:17
Revision:318751Original commit files touched by this commit
rene search for other commits by this committer
Fix vuxml by using the correct format for CVE names.

Prodded by:	bz on IRC
1.1_1
22 May 2013 08:45:11
Revision:318748Original commit files touched by this commit
rene search for other commits by this committer
List vulnerabilities fixed in www/chromium 27.0.1453.93 (which is the
current version in the Ports Collection).
1.1_1
19 May 2013 14:06:36
Revision:318524Original commit files touched by this commit
rakuco search for other commits by this committer
Patch multiple vulnerabilities in x11-toolkits/plib.

PR:		ports/178710
Submitted by:	Denny Lin <dennylin93@hs.ntnu.edu.tw>
1.1_1
18 May 2013 20:35:07
Revision:318453Original commit files touched by this commit
rakuco search for other commits by this committer
- Update to 0.7.4
- Add VuXML entry
- Trim Makefile header
- Add LICENSE

PR:		ports/177206
Submitted by:	Alexander Milanov <a@amilanov.com>
Approved by:	Thomas Hurst <tom@hur.st> (maintainer)
Security:	a8818f7f-9182-11e2-9bdf-d48564727302
1.1_1
16 May 2013 22:46:39
Revision:318342Original commit files touched by this commit
delphij search for other commits by this committer
Update the recent nginx entry to cover the exact version range and include
information for CVE-2013-2070.
1.1_1
16 May 2013 04:14:31
Revision:318273Original commit files touched by this commit
eadler search for other commits by this committer
Update to the latest version of Adobe Flash
1.1_1
16 May 2013 02:00:38
Revision:318268Original commit files touched by this commit
flo search for other commits by this committer
- update firefox to 21.0
- update firefox-esr and thunderbird to 17.0.6
- WEBRTC now supports PULSEAUDIO
- make linux-firefox work with plugins again (e.g. quakelive)

Security:		4a1ca8a4-bd82-11e2-b7a0-d43d7e0c7c02
In collaboration with:	Jan Beich <jbeich@tormail.org>
1.1_1
14 May 2013 07:15:24
Revision:318140Original commit files touched by this commit
osa search for other commits by this committer
Update ranges according latest available information.

Source:	http://mailman.nginx.org/pipermail/nginx-announce/2013/000114.html
1.1_1
13 May 2013 00:08:14
Revision:317985Original commit files touched by this commit
ashish search for other commits by this committer
- Update emacs entry to correct the version ranges for CVE-2012-3479
1.1_1
07 May 2013 18:58:55
Revision:317627Original commit files touched by this commit
delphij search for other commits by this committer
Update nginx entry to reflect the right version ranges for CVE-2013-2028.

Note that we don't really have nginx 1.3.9 in the ports collection, due
to the recent ports freeze.  The version 1.3.9 is used here just to
better match the original advisory.
1.1_1
07 May 2013 13:32:03
Revision:317606Original commit files touched by this commit
osa search for other commits by this committer
Fix typo.

Found by:	ru
1.1_1
07 May 2013 11:35:19
Revision:317599Original commit files touched by this commit
osa search for other commits by this committer
Document nginx -- a stack-base buffer overflow.
1.1_1
03 May 2013 18:20:43
Revision:317230Original commit files touched by this commit
ohauer search for other commits by this committer
- fix strongSwan discovery date /2013-05-03/2013-04-30/
1.1_1
03 May 2013 18:16:36
Revision:317229Original commit files touched by this commit
ohauer search for other commits by this committer
- update to version 5.0.4 which fixes CVE-2013-2944.
- add entry to vuxml
- add CVE references to jankins vuxml entry

while I'm here remove .sh from rc script

PR:		ports/178266
Submitted by:	David Shane Holden <dpejesh@yahoo.com>
Approved by:	strongswan@nanoteq.com (maintainer)
1.1_1
03 May 2013 16:26:20
Revision:317217Original commit files touched by this commit
lwhsu search for other commits by this committer
Document Jenkins Security Advisory 2013-05-02
1.1_1
02 May 2013 19:41:07
Revision:317143Original commit files touched by this commit
tmseck search for other commits by this committer
- Add the vendor patch for SQUID-2012:1 (CVE-2012-5643) and update VuXML
  information accordingly
- Bump PORTREVISION

PR:		ports/177773
Submitted by:	Kan Sasaki
Approved by:	flo (mentor)
Security:	c37de843-488e-11e2-a5c9-0019996bc1f7
1.1_1
29 Apr 2013 22:41:58
Revision:316854Original commit files touched by this commit
des search for other commits by this committer
Add entry for SA-13:05.nfsserver
1.1_1
27 Apr 2013 20:58:01
Revision:316694Original commit files touched by this commit
nivit search for other commits by this committer
- Document multiple XSS and DDoS vulnerabilities for Joomla!
(2.5.0 <= version < 2.5.10)
1.1_1
24 Apr 2013 20:23:16
Revision:316477Original commit files touched by this commit
matthew search for other commits by this committer
Security updae to 3.5.8.1

Four new serious security alerts were issued today by the phpMyAdmin
them: PMASA-2013-2 and PMASA-2013-3 are documented in this commit to
vuln.xml.

 - Remote code execution via preg_replace().

 - Locally Saved SQL Dump File Multiple File Extension Remote Code
   Execution.

The other two: PMASA-2013-4 and PMASA-2013-5 only affect PMA 4.0.0
pre-releases earlier than 4.0.0-rc3, which are not available through
the ports.
1.1_1
22 Apr 2013 20:57:03
Revision:316276Original commit files touched by this commit
dinoex search for other commits by this committer
- Security update to 1.0.21
Security: CVE-2013-1428
1.1_1
20 Apr 2013 16:01:56
Revision:316157Original commit files touched by this commit
dinoex search for other commits by this committer
- Security fix
Security: CVE-2011-4517 execute arbitrary code on decodes images
Submitted by:   naddy (Christian Weisgerber)
Obtained from:  Fedora
Feature safe: yes
1.1_1
20 Apr 2013 09:24:30
Revision:316134Original commit files touched by this commit
matthew search for other commits by this committer
Document PMASA-2013-1

It turns out that release 3.5.8 (recently updated in ports) was the
cure to an XSS vulnerability.

Feature safe:  yes
1.1_1
19 Apr 2013 18:03:18
Revision:316114Original commit files touched by this commit
delphij search for other commits by this committer
Document roundcube arbitrary file disclosure vulnerability.

Reported by:	Marcelo Gondim <gondim bsdinfo com br>
Feature safe:	yes
1.1_1
18 Apr 2013 04:03:08
Revision:316016Original commit files touched by this commit
dinoex search for other commits by this committer
- add jasper
Feature safe: yes
1.1_1
16 Apr 2013 10:58:16
Revision:315811Original commit files touched by this commit
araujo search for other commits by this committer
- Update to 2.7.3 due a vulnerability that affect all versions 2.x. [1]
- Update MASTER_SITES.
- Convert to optionsNG.
- Trim header.

More info:
https://github.com/SpiderLabs/ModSecurity/blob/master/CHANGES

Reported by:    olli hauer <ohauer@gmx.de> [1]
Approved by:    portmgr (bdrewery)
Security:       2070c79a-8e1e-11e2-b34d-000c2957946c
1.1_1
15 Apr 2013 12:28:58
Revision:315802Original commit files touched by this commit
bdrewery search for other commits by this committer
- Update to 0.85
- Convert to new options framework

sieve-connect was not actually verifying TLS certificate identities matched
the expected hostname. Changes with new version:

Fix TLS verification; find server by own hostname & SRV.

* TLS hostname verification was not actually happening.

* IO::Socket::SSL requirement bumped to 1.14 (was 0.97).

* By default, if no server specified, before falling back to localhost try to
use the current hostname and SRV records in DNS to figure out if Sieve is
available. Checks for sieve, imaps & imap protocol SRV records and honours
(Only the first 15 lines of the commit message are shown above View all of this commit message)
1.1_1
13 Apr 2013 15:44:09
Revision:315796Original commit files touched by this commit
eadler search for other commits by this committer
Replace duplicate vids with a newly generated GUID.
Older duplicates kept their own number.

Approved by:	portmgr (implicit)
With Hat:	ports-secteam
1.1_1
12 Apr 2013 16:19:38
Revision:315791Original commit files touched by this commit
des search for other commits by this committer
Oops, fix the cite URL.

Approved by:	portmgr (tabthorpe)
1.1_1
12 Apr 2013 16:14:22
Revision:315790Original commit files touched by this commit
des search for other commits by this committer
Edit OpenVPN 2.3.1 entry:

 - Replace links to changelog and commit with a link to the official
   announcement (which also links to the commit)

 - Replace the description with a sentence lifted from the
   announcement.

Approved by:	portmgr (tabthorpe)
1.1_1
11 Apr 2013 22:19:50
Revision:315788Original commit files touched by this commit
eadler search for other commits by this committer
Update flash to 11.2r202.280

Security:	15236023-a21b-11e2-a460-208984377b34
Reviewed by:	delphij
Approved by:	portmgr (bdrewery)
1.1_1
11 Apr 2013 11:41:29
Revision:315784Original commit files touched by this commit
bdrewery search for other commits by this committer
- Add url reference to 1431f2d6-a06e-11e2-b9e0-001636d274f3

Approved by:	portmgr (implicit)
Requested by:	jgh
1.1_1
11 Apr 2013 11:30:01
Revision:315783Original commit files touched by this commit
bdrewery search for other commits by this committer
- Update to 3.2.13 to fix security vulnerabilities
- Update rubygem-mail to 2.5.3 as rubygem-actionmailer-3.2.13 requires it

PR:		ports/177709
Submitted by:	Geoffroy Desvernay <dgeo@centrale-marseille.fr>
With hat:	ruby
Approved by:	portmgr (implicit)
Reviewed by:	miwi
Security:	db0c4b00-a24c-11e2-9601-000d601460a4
1.1_1
09 Apr 2013 01:18:58
Revision:315767Original commit files touched by this commit
bdrewery search for other commits by this committer
- Document CVE-2013-0131 for nvidia-driver

Submitted by:	danfe
Approved by:	portmgr (implicit)
1.1_1
08 Apr 2013 20:57:22
Revision:315765Original commit files touched by this commit
flo search for other commits by this committer
Typo fix for the typo fix. Validated with make validate this time.

Reported by:	bz
Approved by:	portmgr (implicit)
1.1_1
08 Apr 2013 20:33:11
Revision:315764Original commit files touched by this commit
flo search for other commits by this committer
Fix a typo in the recent mozilla entry

Reported by:	pluknet
Approved by:	portmgr (tabthorpe)
1.1_1
06 Apr 2013 16:51:41
Revision:315746Original commit files touched by this commit
dinoex search for other commits by this committer
- Security udpate to 12.15
Security: http://www.opera.com/docs/changelogs/unified/1215/
Security: http://www.opera.com/security/advisory/1046
Security: http://www.opera.com/security/advisory/1047
PR:		177654
Approved by:	portmgr
1.1_1
06 Apr 2013 16:43:28
Revision:315745Original commit files touched by this commit
ohauer search for other commits by this committer
- fix subversion range

Approved by:	portmgr (implizit)
1.1_1
06 Apr 2013 10:00:28
Revision:315739Original commit files touched by this commit
ohauer search for other commits by this committer
- Subversion 1.7.9 security update [1]
- Subversion 1.6.21 security update [2]

This release addesses the following issues security issues:
[1][2]  CVE-2013-1845: mod_dav_svn excessive memory usage from property changes
[1][2]  CVE-2013-1846: mod_dav_svn crashes on LOCK requests against activity
URLs
[1][2]  CVE-2013-1847: mod_dav_svn crashes on LOCK requests against non-existant
URLs
[1][2]  CVE-2013-1849: mod_dav_svn crashes on PROPFIND requests against activity
URLs
[1]     CVE-2013-1884: mod_dav_svn crashes on out of range limit in log REPORT
request

More information on these vulnerabilities, including the relevent advisories
and potential attack vectors and workarounds, can be found on the Subversion
security website:
    http://subversion.apache.org/security/

PR:		177646
Submitted by:	ohauer
Approved by:	portmgr (tabthorpe, erwin), lev
Security:	b6beb137-9dc0-11e2-882f-20cf30e32f6d
1.1_1
05 Apr 2013 21:16:54
Revision:315737Original commit files touched by this commit
cs search for other commits by this committer
Vulnerability in OTRS

Approved by:	portmgr
Security:	eae8e3cf-9dfe-11e2-ac7f-001fd056c417
1.1_1
04 Apr 2013 13:21:23
Revision:315718Original commit files touched by this commit
girgen search for other commits by this committer
The PostgreSQL Global Development Group has released a security
update to all current versions of the PostgreSQL database system,
including versions 9.2.4, 9.1.9, 9.0.13, and 8.4.17. This update
fixes a high-exposure security vulnerability in versions 9.0 and
later. All users of the affected versions are strongly urged to apply
the update *immediately*.

A major security issue (for versions 9.x only) fixed in this release,
[CVE-2013-1899](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1899),
makes it possible for a connection request containing a database name
that begins with "-" to be crafted that can damage or destroy files
within a server's data directory. Anyone with access to the port the
PostgreSQL server listens on can initiate this request. This issue was
discovered by Mitsumasa Kondo and Kyotaro Horiguchi of NTT Open Source
Software Center.
(Only the first 15 lines of the commit message are shown above View all of this commit message)
1.1_1
03 Apr 2013 20:27:48
Revision:315713Original commit files touched by this commit
flo search for other commits by this committer
- update thunderbird, firefox-esr, linux-thunderbird and linux-firefox to
  17.0.5
- update firefox to 20.0
- update seamonkey and linux-seamonkey to 2.17
- update nspr to 4.9.6
- remove mail/thunderbird-esr, Mozilla stopped providing 2 versions of
  thunderbird
- prune support for old FreeBSD versions; users of 8.2, 7.4 or earlier
  are advised to upgrade - http://www.freebsd.org/security/
- add vuln.xml entry

Security:	94976433-9c74-11e2-a9fc-d43d7e0c7c02
Approved by:	portmgr (miwi)
In collaboration with:	Jan Beich <jbeich@tormail.org>
1.1_1
02 Apr 2013 20:21:28
Revision:315687Original commit files touched by this commit
delphij search for other commits by this committer
Document two latest FreeBSD security advisories.

Approved by:	portmgr (bdrewery)
1.1_1
31 Mar 2013 17:36:30
Revision:315642Original commit files touched by this commit
ohauer search for other commits by this committer
- update japanes/bugzilla templates
- update vuxml to reflect bugzilla templates
- fix typo in vuxml

Approved by:	portmgr (miwi)
Sponsored by:
1.1_1
31 Mar 2013 16:00:02
Revision:315640Original commit files touched by this commit
mandree search for other commits by this committer
security upgrade to OpenVPN 2.3.1; upstream release notes are

  "This release adds supports for PolarSSL 1.2. It also adds a fix to
  prevent potential side-channel attacks by switching to a constant-time
  memcmp when comparing HMACs in the openvpn_decrypt function. In
  addition, it contains several bugfixes and documentation updates, as
  well as some minor enhancements."

Full ChangeLog:
<https://community.openvpn.net/openvpn/wiki/ChangesInOpenvpn23>

The port upgrade also offers an option to use the GPLv2+-licensed
PolarSSL instead of OpenSSL (which brings in a license mix).

PR:		ports/177517
Reviewed by:	miwi
Approved by:	portmgr (miwi)
Security:	92f30415-9935-11e2-ad4c-080027ef73ec
1.1_1
29 Mar 2013 14:08:47
Revision:315540Original commit files touched by this commit
kwm search for other commits by this committer
Update to 2.8.0. [1]
Add patch to fix CVE-2013-0338 and CVE-2013-0339. [2]
Convert to OptionsNG, rename patches to standard form. [1]

Notified by:	swills@ [2]
Obtained from:	gnome team repo [1]
Security:	843a4641-9816-11e2-9c51-080027019be0
1.1_1
29 Mar 2013 10:04:43
Revision:315534Original commit files touched by this commit
flo search for other commits by this committer
Update asterisk ports to:

net/asterisk 1.8.20.2
net/asterisk10 10.12.2
net/asterisk11 11.2.2

Security:	daf0a339-9850-11e2-879e-d43d7e0c7c02
1.1_1
27 Mar 2013 20:44:51
Revision:315412Original commit files touched by this commit
delphij search for other commits by this committer
Explicitly use -E for sed(1).

Submitted by:	des
Reviewed by:	eadler
1.1_1
27 Mar 2013 10:29:25
Revision:315370Original commit files touched by this commit
erwin search for other commits by this committer
Add entry for latest Bind advisory CVE-2013-2266
1.1_1
26 Mar 2013 23:25:20
Revision:315339Original commit files touched by this commit
delphij search for other commits by this committer
In validate target, use unexpand and sed to make sure that we are using
consistent space style.

Reviewed by:	stas, simon
1.1_1
26 Mar 2013 20:58:23
Revision:315329Original commit files touched by this commit
rene search for other commits by this committer
Document vulnerabilities in www/chromium < 26.0.1410.43

Obtained from:	http://googlechromereleases.blogspot.nl/search/Stable%20Updates
1.1_1
26 Mar 2013 18:16:33
Revision:315319Original commit files touched by this commit
delphij search for other commits by this committer
Remove trailing space, no content change.
1.1_1
26 Mar 2013 18:09:07
Revision:315318Original commit files touched by this commit
delphij search for other commits by this committer
unexpand vuln.xml.
1.1_1
26 Mar 2013 05:31:07
Revision:315257Original commit files touched by this commit
acm search for other commits by this committer
firebird vulnerability entry (CVE-2013-2492)

Security:	6adca5e9-95d2-11e2-8549-68b599b52a02
1.1_1
26 Mar 2013 01:13:34
Revision:315254Original commit files touched by this commit
zi search for other commits by this committer
- Document vulnerability in graphics/optipng (CVE-2012-4432)

PR:		ports/177206
Submitted by:	Alexander Milanov <a@amilanov.com>
Security:	8818f7f-9182-11e2-9bdf-d48564727302
1.1_1
18 Mar 2013 20:46:52
Revision:314596Original commit files touched by this commit
flo search for other commits by this committer
Update to 5.3.23

Security:	1d23109a-9005-11e2-9602-d43d7e0c7c02
1.1_1
18 Mar 2013 12:12:59
Revision:314559Original commit files touched by this commit
zi search for other commits by this committer
- Document recent vulnerabilities in www/piwigo: CVE-2013-1468, CVE-2013-1469
Reported by:	Ruslan Makhmatkhanov <cvs-src@yandex.ru>
Security:	edd201a5-8fc3-11e2-b131-000c299b62e1
1.1_1
16 Mar 2013 22:12:54
Revision:314388Original commit files touched by this commit
remko (src,doc committer) search for other commits by this committer
Fix typo in the libpurple entry.

Submitted by:	Derek Schrock <dereks@lifeofadishwasher.com>
1.1_1
15 Mar 2013 13:52:09
Revision:314303Original commit files touched by this commit
zi search for other commits by this committer
- Perl vulnerability (CVE-2013-1667) also applies to perl-threaded

Reported by:	Alexandre Krasnov <freebsd@tern.ru>
Security:	68c1f75b-8824-11e2-9996-c4850808617
1.1_1
14 Mar 2013 08:17:40
Revision:314141Original commit files touched by this commit
pclin search for other commits by this committer
- graphics/libexif:
  * Update to 0.6.21
  * Add LICENSE
  * Switch to OptionsNG and PORTDOCS
- Document libexif 2012-07-12 vulnerabilty
- Bump PORTREVISION for libexif related ports
- Trim headers while here

PR:		ports/175910
Approved by:	swills (mentor)
Security:	d881d254-70c6-11e2-862d-080027a5ec9a
1.1_1
13 Mar 2013 04:04:48
Revision:314021Original commit files touched by this commit
eadler search for other commits by this committer
Update flash the latest (hopefully) secure version.

PR:		ports/176904
Submitted by:	Tsurutani Naoki <turutani@scphys.kyoto-u.ac.jp>
Security:	http://www.vuxml.org/freebsd/5ff40cb4-8b92-11e2-bdb6-001060e06fd4.html
1.1_1
13 Mar 2013 03:35:54
Revision:314019Original commit files touched by this commit
swills search for other commits by this committer
- Update puppet to 3.1.1 resolving multiple security issues
- Update puppet27 to 2.7.21 resolving multiple security issues
- Document multiple puppet security issues

Security:	cda566a0-2df0-4eb0-b70e-ed7a6fb0ab3c

Number of commits found: 7511 (showing only 100 on this page)

[First Page]  «  40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50  »  [Last Page]