notbugAs an Amazon Associate I earn from qualifying purchases.
Want a good read? Try FreeBSD Mastery: Jails (IT Mastery Book 15)
Want a good monitor light? See my photosAll times are UTC
Ukraine
NOW FIXED. We had a known problem with lists of packages - they were out of date. The fix has been applied to production. See packages-import/issues/3 & packages-import/issues/4
Port details
vuxml Vulnerability and eXposure Markup Language DTD
1.1_6 security on this many watch lists=33 search for ports that depend on this port Find issues related to this port Report an issue related to this port View this port on Repology. pkg-fallout 1.1_6Version of this port present on the latest quarterly branch.
Maintainer: ports-secteam@FreeBSD.org search for ports maintained by this maintainer
Port Added: 2004-02-12 14:24:23
Last Update: 2025-02-02 08:32:18
Commit Hash: fe2f031
People watching this port, also watch:: gnupg, curl, libxml2, nmap, vim
Also Listed In: textproc
License: BSD2CLAUSE
WWW:
https://vuxml.freebsd.org/
Description:
VuXML (the Vulnerability and eXposure Markup Language) is an XML application for documenting security bugs and corrections within a software package collection such as the FreeBSD Ports Collection. This port installs the DTDs required for validating VuXML documents.
Homepage    cgit ¦ Codeberg ¦ GitHub ¦ GitLab ¦ SVNWeb

Manual pages:
FreshPorts has no man page information for this port.
pkg-plist: as obtained via: make generate-plist
Expand this list (13 items)
Collapse this list.
  1. /usr/local/share/licenses/vuxml-1.1_6/catalog.mk
  2. /usr/local/share/licenses/vuxml-1.1_6/LICENSE
  3. /usr/local/share/licenses/vuxml-1.1_6/BSD2CLAUSE
  4. @xmlcatmgr share/xml/dtd/vuxml/catalog
  5. @xmlcatmgr share/xml/dtd/vuxml/catalog.xml
  6. share/xml/dtd/vuxml/vuxml-10.dtd
  7. share/xml/dtd/vuxml/vuxml-11.dtd
  8. share/xml/dtd/vuxml/vuxml-model-10.mod
  9. share/xml/dtd/vuxml/vuxml-model-11.mod
  10. share/xml/dtd/vuxml/xml1.dcl
  11. @owner
  12. @group
  13. @mode
Collapse this list.
Dependency lines:
  • vuxml>0:security/vuxml
To install the port:
cd /usr/ports/security/vuxml/ && make install clean
To add the package, run one of these commands:
  • pkg install security/vuxml
  • pkg install vuxml
NOTE: If this package has multiple flavors (see below), then use one of them instead of the name specified above.
PKGNAME: vuxml
Flavors: there is no flavor information for this port.
distinfo:
SHA256 (vuxml/vuxml-10.dtd) = 6a635ad2cf45f52361c8c2a29a689157fad4d00519045485bc822d34e04a524e SIZE (vuxml/vuxml-10.dtd) = 2986 SHA256 (vuxml/vuxml-model-10.mod) = 051fed00b52bedde8ee901003fc29f7b95cd904157e31ceef34e6b06f2d1a14a

Expand this list (11 items)

Collapse this list.

SIZE (vuxml/vuxml-model-10.mod) = 10599 SHA256 (vuxml/vuxml-11.dtd) = 12b50061d7bb34cecffede2e08d439e4469324376d55aeb7c73eb6aab0f36af1 SIZE (vuxml/vuxml-11.dtd) = 3063 SHA256 (vuxml/vuxml-model-11.mod) = a40777208625a3029c6f416aeeea733f614802a6a5f26035a4e445a09e61a47c SIZE (vuxml/vuxml-model-11.mod) = 13282 SHA256 (vuxml/xml1.dcl) = 343efa94c4e1302e85e08b2d1791d86e50aac1ecdbc3161daecac100e4726847 SIZE (vuxml/xml1.dcl) = 7372 SHA256 (vuxml/catalog) = 479a69cf02995603443fd1f3b5b33f97811670931f87f53be99a727d664abc66 SIZE (vuxml/catalog) = 549 SHA256 (vuxml/catalog.xml) = 7b2e2850f57264eeba0ccd3d1fc161b9d5ce3071ae0ec51b9da7fa956f2a6509 SIZE (vuxml/catalog.xml) = 2150

Collapse this list.


Packages (timestamps in pop-ups are UTC):
vuxml
ABIaarch64amd64armv6armv7i386powerpcpowerpc64powerpc64le
FreeBSD:13:latest1.1_61.1_61.1_51.1_61.1_6-1.1_5-
FreeBSD:13:quarterly1.1_61.1_61.1_61.1_61.1_61.1_61.1_61.1_6
FreeBSD:14:latest1.1_61.1_61.1_61.1_61.1_61.1_6-1.1_6
FreeBSD:14:quarterly1.1_61.1_6-1.1_61.1_61.1_61.1_61.1_6
FreeBSD:15:latest1.1_61.1_6n/a1.1_6n/a1.1_61.1_61.1_6
Dependencies
NOTE: FreshPorts displays only information on required and default dependencies. Optional dependencies are not covered.
Runtime dependencies:
  1. xmlcatmgr : textproc/xmlcatmgr
  2. xsltproc : textproc/libxslt
  3. VERSION : textproc/xhtml-modularization
  4. xhtml-basic10.dtd : textproc/xhtml-basic
  5. python3.11 : lang/python311
There are no ports dependent upon this port

Configuration Options:
No options to configure
Options name:
security_vuxml
USES:
python:run
FreshPorts was unable to extract/find any pkg message
Master Sites:
Expand this list (1 items)
Collapse this list.
  1. http://www.vuxml.org/dtd/vuxml-1/
Collapse this list.

Number of commits found: 7511 (showing only 100 on this page)

[First Page]  «  41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51  »  [Last Page]

Commit History - (may be incomplete: for full details, see links to repositories near top of page)
CommitCreditsLog message
1.1_1
10 Mar 2013 19:04:01
Revision:313838Original commit files touched by this commit
rea search for other commits by this committer
Perl 5.x: fix CVE-2013-1667

Feature safe:	wholeheartedly hope so
1.1_1
10 Mar 2013 04:03:12
Revision:313798Original commit files touched by this commit
miwi search for other commits by this committer
- Fix previous entry
1.1_1
10 Mar 2013 00:13:00
Revision:313784Original commit files touched by this commit
marcus search for other commits by this committer
Belatedly add an entry for libpurple's recent vulnerabilities.
1.1_1
08 Mar 2013 22:27:39
Revision:313676Original commit files touched by this commit
flo search for other commits by this committer
- update thunderbird, firefox-esr, linux-thunderbird and linux-firefox to
  17.0.4
- update firefox to 19.0.2
- add vuln.xml entry

Security:	630c8c08-880f-11e2-807f-d43d7e0c7c02
1.1_1
08 Mar 2013 09:06:27
Revision:313628Original commit files touched by this commit
rene search for other commits by this committer
Document a vulnerability in chromium < 25.0.1364.160

Obtained from:	http://googlechromereleases.blogspot.nl/search/Stable%20Updates
1.1_1
06 Mar 2013 15:57:00
Revision:313525Original commit files touched by this commit
culot search for other commits by this committer
- Document vulnerabilities in typo3.

Security:       b9a347ac-8671-11e2-b73c-0019d18c446a
Obtained from: 
http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2013-001/
1.1_1
06 Mar 2013 00:19:09
Revision:313485Original commit files touched by this commit
rene search for other commits by this committer
Document vulnerabilities in www/chromium < 25.0.1364.152

Obtained from:	http://googlechromereleases.blogspot.nl/search/Stable%20Updates
1.1_1
03 Mar 2013 20:17:59
Revision:313375Original commit files touched by this commit
zi search for other commits by this committer
- Document recent vulerability in security/stunnel (CVE-2013-1762)
Security:	c97219b6-843d-11e2-b131-000c299b62e1
1.1_1
02 Mar 2013 20:07:42
Revision:313292Original commit files touched by this commit
ohauer search for other commits by this committer
- document apache22 issues
- tim trailing tabs
1.1_1
01 Mar 2013 02:08:31
Revision:313132Original commit files touched by this commit
wxs search for other commits by this committer
Document two sudo problems.
1.1_1
28 Feb 2013 01:46:41
Revision:313076Original commit files touched by this commit
swills search for other commits by this committer
- Update to 0.9.14 to fix CVE-2013-1756

Security:	aa7764af-0b5e-4ddc-bc65-38ad697a484f
1.1_1
27 Feb 2013 13:40:47
Revision:313052Original commit files touched by this commit
eadler search for other commits by this committer
Update to 11.2r202.273

Security:	http://www.vuxml.org/freebsd/dbdac023-80e1-11e2-9a29-001060e06fd4.html
1.1_1
26 Feb 2013 17:27:07
Revision:313001Original commit files touched by this commit
sunpoet search for other commits by this committer
- Update affected ettercap versions: CVE-2012-0722 was fixed in
0.7.5.2-Assimilation
1.1_1
26 Feb 2013 01:38:58
Revision:312948Original commit files touched by this commit
bdrewery search for other commits by this committer
- Document 3 OTRS vulnerabilities from 2012
 - CVE-2012-4751
 - CVE-2012-4600
 - CVE-2012-2582
1.1_1
24 Feb 2013 18:21:03
Revision:312887Original commit files touched by this commit
swills search for other commits by this committer
- Document Ruby REXML DoS
1.1_1
24 Feb 2013 17:51:49
Revision:312886Original commit files touched by this commit
swills search for other commits by this committer
- Document rubygem-ruby_parser issue
1.1_1
24 Feb 2013 14:23:46
Revision:312867Original commit files touched by this commit
pclin search for other commits by this committer
- Document Django 2013-02-21 vulnerabilty

Approved by:	araujo (mentor)
1.1_1
22 Feb 2013 23:49:45
Revision:312793Original commit files touched by this commit
rene search for other commits by this committer
Document vulnerabilities in www/chromium < 25.0.1364.97

Obtained from:	http://googlechromereleases.blogspot.nl/search/Stable%20Updates
1.1_1
22 Feb 2013 20:28:22
Revision:312789Original commit files touched by this commit
cy search for other commits by this committer
Document security/krb5 1.11 and prior null pointer dereference in the
KDC PKINIT code [CVE-2013-1415].

Security:	CVE-2013-1415
1.1_1
22 Feb 2013 08:07:27
Revision:312753Original commit files touched by this commit
remko (src,doc committer) search for other commits by this committer
Convert the ! back into a 1.

Noticed by:	crees
1.1_1
21 Feb 2013 21:38:16
Revision:312742Original commit files touched by this commit
remko (src,doc committer) search for other commits by this committer
Add the latest two FreeBSD Security Advisories.
1.1_1
21 Feb 2013 07:11:50
Revision:312707Original commit files touched by this commit
flo search for other commits by this committer
Document drupal7 Denial of service
1.1_1
20 Feb 2013 13:58:20
Revision:312626Original commit files touched by this commit
rm search for other commits by this committer
- add an entry for net/nss-pam-ldapd stack-based buffer overflow

According to advisory, vulnerability exists in nss-pam-ldapd < 0.8.11,
but since we never had this version in the ports tree, mark everything
< 0.8.12 as vulnerable.

PR:		176293
Submitted by:	pluknet
1.1_1
20 Feb 2013 07:16:31
Revision:312612Original commit files touched by this commit
flo search for other commits by this committer
Fix up the latest gecko update by:
- reapplying the workaround for svn:eol-style and svn:keywords
- fixing version matching in vuln.xml, 17.0.3 is NOT vulnerable
1.1_1
20 Feb 2013 06:16:01
Revision:312611Original commit files touched by this commit
ohauer search for other commits by this committer
- update bugzilla ports to latest version

  Bugzilla 4.0.10 and 3.6.13 are security updates for the 4.0
  branch and the 3.6 branch, respectively. 4.0.10 contains several
  useful bug fixes and 3.6.13 contains only security fixes.

Security:	CVE-2013-0785
		CVE-2013-0786
1.1_1
19 Feb 2013 23:53:08
Revision:312608Original commit files touched by this commit
flo search for other commits by this committer
- update firefox to 19.0
- update firefox-esr, thunderbird, linux-firefox, linux-thunderbird to 17.0.3
- update linux-seamonkey to 2.16
- update nspr to 4.9.5
- update nss to 3.14.3
- add DuckDuckGo search plugin to firefox [1]
- mark kompozer deprecated
- clang fixes for www/libxul19 [2]

Security:	http://www.vuxml.org/freebsd/e3f0374a-7ad6-11e2-84cd-d43d7e0c7c02.html
Submitted by:	DuckDuckGo [1], dim [2]
In collaboration with:	Jan Beich <jbeich@tormail.org>
1.1_1
19 Feb 2013 00:19:14
Revision:312537Original commit files touched by this commit
zi search for other commits by this committer
- Fix version range for recent ruby vulnerabilities
(d3e96508-056b-4259-88ad-50dc8d1978a6 and c79eb109-a754-45d7-b552-a42099eb2265)
due to missing port epoch in package range

Submitted by:	Matthias Andree <mandree@FreeBSD.org>
1.1_1
17 Feb 2013 19:58:29
Revision:312441Original commit files touched by this commit
eadler search for other commits by this committer
Combine ranges into one entry to prevent false positives
1.1_1
17 Feb 2013 16:47:06
Revision:312428Original commit files touched by this commit
swills search for other commits by this committer
- Document rubygem-rack issue
1.1_1
17 Feb 2013 16:33:19
Revision:312426Original commit files touched by this commit
swills search for other commits by this committer
- Document activemodel issue
1.1_1
17 Feb 2013 10:28:54
Revision:312408Original commit files touched by this commit
lwhsu search for other commits by this committer
Document Jenkins Security Advisory 2013-02-16
1.1_1
16 Feb 2013 17:03:28
Revision:312377Original commit files touched by this commit
rm search for other commits by this committer
- add entry for dns/poweradmin

PR:		175704
Submitted by:	Edmondas Girkantas <eg@fbsd.lt> (maintainer of dns/poweradmin)
1.1_1
16 Feb 2013 14:41:44
Revision:312355Original commit files touched by this commit
swills search for other commits by this committer
- Document ruby json issue
1.1_1
16 Feb 2013 04:29:14
Revision:312323Original commit files touched by this commit
swills search for other commits by this committer
- Document vulnerability in rdoc
1.1_1
08 Feb 2013 19:18:41
Revision:311950Original commit files touched by this commit
eadler search for other commits by this committer
Update flash to the latest version

PR:		ports/175159
Submitted by:	Tsurutani Naoki <turutani@scphys.kyoto-u.ac.jp>
1.1_1
08 Feb 2013 08:44:15
Revision:311921Original commit files touched by this commit
miwi search for other commits by this committer
- Fix whitespaces
1.1_1
07 Feb 2013 02:10:29
Revision:311808Original commit files touched by this commit
eadler search for other commits by this committer
Fix vuxml build
1.1_1
06 Feb 2013 20:06:18
Revision:311791Original commit files touched by this commit
dinoex search for other commits by this committer
- report openssl vulnerabilities
1.1_1
01 Feb 2013 22:42:55
Revision:311404Original commit files touched by this commit
flo search for other commits by this committer
- update databases/mariadb-server to 5.3.12 [1]
- update databases/mariadb55-server 5.5.29 [2]

PR:		ports/175764 [1]
PR:		ports/175767 [2]
Submitted by:	Geoffroy Desvernay <dgeo@centrale-marseille.fr> (maintainer) [1]
Submitted by:	Alexandr Kovalenko <never@nevermind.kiev.ua> (maintainer) [2]
Security:	8c773d7f-6cbb-11e2-b242-c8600054b392
1.1_1
01 Feb 2013 08:50:40
Revision:311359Original commit files touched by this commit
dinoex search for other commits by this committer
- report opera 12.12 vulnerabilities
1.1_1
30 Jan 2013 18:34:03
Revision:311253Original commit files touched by this commit
pawel search for other commits by this committer
Document devel/upnp vulnerabilities
1.1_1
29 Jan 2013 20:02:38
Revision:311185Original commit files touched by this commit
delphij search for other commits by this committer
Document wordpress multiple vulnerabilities.
1.1_1
25 Jan 2013 09:37:56
Revision:310972Original commit files touched by this commit
cs search for other commits by this committer
Fix last entry: version 2.3.4 is also affected
1.1_1
25 Jan 2013 02:08:57
Revision:310957Original commit files touched by this commit
wxs search for other commits by this committer
Fix whitespace in previous commit.
1.1_1
25 Jan 2013 01:26:37
Revision:310956Original commit files touched by this commit
cs search for other commits by this committer
XSS vulnerability in py-django-cms
1.1_1
23 Jan 2013 12:52:49
Revision:310862Original commit files touched by this commit
rene search for other commits by this committer
Document vulnerabilities in www/chromium < 24.0.1312.56

Obtained
from:	http://googlechromereleases.blogspot.nl/search/label/Stable%20updates
1.1_1
20 Jan 2013 20:58:13
Revision:310718Original commit files touched by this commit
flo search for other commits by this committer
- update www/drupal6 to 6.28
- update www/drupal7 to 7.19

Security:	http://www.vuxml.org/freebsd/1827f213-633e-11e2-8d93-c8600054b392.html
Approved by:	portmgr (beat)
1.1_1
16 Jan 2013 19:16:10
Revision:310514Original commit files touched by this commit
rea search for other commits by this committer
VuXML: add newly-allocated CVE for SQUID-2012:1

New CVE was allocated for the underfixed DoS and added possible
infinite loop in Squid 3.2 and 3.1.
1.1_1
16 Jan 2013 19:13:32
Revision:310513Original commit files touched by this commit
rea search for other commits by this committer
VuXML: document buffer overflow in ettercap (CVE-2013-0722)
Reviewed by:	simon@
1.1_1
16 Jan 2013 19:11:43
Revision:310512Original commit files touched by this commit
rea search for other commits by this committer
VuXML: document recent security manager bypass in Java 7.x
Reviewed by:	glewis@, simon@
1.1_1
16 Jan 2013 07:39:28
Revision:310476Original commit files touched by this commit
delphij search for other commits by this committer
Properly limit the match for PHP 5.3.x and 5.2.x versions.

Noticed by:	remko
1.1_1
15 Jan 2013 22:06:19
Revision:310468Original commit files touched by this commit
delphij search for other commits by this committer
Apply version ranges of php53 and php52 to php5 as well.
1.1_1
11 Jan 2013 14:11:28
Revision:310235Original commit files touched by this commit
zi search for other commits by this committer
- Fix discovery date on nagios vulnerability  	(CVE-2012-6096)
1.1_1
11 Jan 2013 09:53:42
Revision:310225Original commit files touched by this commit
rea search for other commits by this committer
www/squid3x: upgrade to 3.1.23 and 3.2.6

Squid 3.1.23 is effectively Squid 3.1.22_2 with the final fix for
CVE-2012-5643 applied.

Squid 3.2.6 also received that abovementioned fix, but in comparison
with 3.2.5 from ports it has another change that fixes handling the
"tcp_outgoing_tos" directive for BSD-like systems, including FreeBSD,
  http://bugs.squid-cache.org/show_bug.cgi?id=3731

VuXML entry for SQUID:2012-1 (aka CVE-2012-5643) was also updated to
reflect the proper version specifications from the updated advisory,
  http://www.squid-cache.org/Advisories/SQUID-2012_1.txt

Approved by:	Thomas-Martin Seck <tmseck@web.de>
Security:	http://portaudit.freebsd.org/c37de843-488e-11e2-a5c9-0019996bc1f7.html
QA page:	http://codelabs.ru/fbsd/ports/qa/www/squid31/3.1.23
QA page:	http://codelabs.ru/fbsd/ports/qa/www/squid32/3.2.6
1.1_1
11 Jan 2013 01:16:14
Revision:310216Original commit files touched by this commit
zi search for other commits by this committer
- Document vulnerability in net-mgmt/nagios (CVE-2012-6096)
1.1_1
11 Jan 2013 00:32:48
Revision:310212Original commit files touched by this commit
rene search for other commits by this committer
Document vulnerabilities in www/chromium < 24.0.1312.52

Obtained
from:	http://googlechromereleases.blogspot.nl/search/label/Stable%20updates
1.1_1
09 Jan 2013 23:28:20
Revision:310165Original commit files touched by this commit
flo search for other commits by this committer
- update firefox, thunderbird, linux-firefox and linux-thunderbird to 17.0.2
- update firefox-esr, thunderbird-esr and libxul to 10.0.12
- update linux-seamonkey to 2.15

Security:	http://www.vuxml.org/freebsd/a4ed6632-5aa9-11e2-8fcb-c8600054b392.html
1.1_1
09 Jan 2013 15:03:02
Revision:310149Original commit files touched by this commit
sem search for other commits by this committer
Fix <topic> style: common dash style, remove softvare versions
1.1_1
09 Jan 2013 03:53:16
Revision:310121Original commit files touched by this commit
swills search for other commits by this committer
- Update rubygem-rails to 3.2.11
- Update ports require by rubygem-rails
- Add vuxml entry for rails security issues

Security:	ca5d3272-59e3-11e2-853b-00262d5ed8ee
Security:	b4051b52-58fa-11e2-853b-00262d5ed8ee
1.1_1
08 Jan 2013 23:46:02
Revision:310114Original commit files touched by this commit
zi search for other commits by this committer
- Properly copy namespace attributes/resolve make validate issues

Reviewed by:	simon@, eadler@
Approved by:	zi (with ports-secteam hat)
1.1_1
08 Jan 2013 05:18:15
Revision:310068Original commit files touched by this commit
lwhsu search for other commits by this committer
Document Jenkins 2013-01-04 Security Advisory
1.1_1
06 Jan 2013 20:37:24
Revision:310013Original commit files touched by this commit
rea search for other commits by this committer
VuXML: extend entry for MoinMoin vulnerabilities fixed in 1.9.6

Use more verbose descriptions from CVE entries and trim citation
from CHANGES to the relevant parts.
1.1_1
06 Jan 2013 18:14:24
Revision:310004Original commit files touched by this commit
lwhsu search for other commits by this committer
Document Django 2012-12-10 vulnerabilty
1.1_1
06 Jan 2013 13:24:39
Revision:309984Original commit files touched by this commit
rea search for other commits by this committer
VuXML: fix r309982

Use proper tags for CVE identifiers.  I should run 'make validate'
_every_ time before committing.
Pointyhat to:	rea
1.1_1
06 Jan 2013 13:10:10
Revision:309982Original commit files touched by this commit
rea search for other commits by this committer
VuXML for MoinMoin issues: add CVE references
1.1_1
05 Jan 2013 12:54:28
Revision:309958Original commit files touched by this commit
crees search for other commits by this committer
Freetype 2.4.8 vulnerabilities were already documented.

While here, correct pkgname

Noticed by:	kwm
1.1_1
05 Jan 2013 11:29:01
Revision:309954Original commit files touched by this commit
crees search for other commits by this committer
Mark moinmoin vulnerable

Security:	http://www.debian.org/security/2012/dsa-2593

document freetype vulnerabilities

Security:	CVE-2012-(1126-1144)
1.1_1
04 Jan 2013 07:30:10
Revision:309917Original commit files touched by this commit
erwin search for other commits by this committer
Bump copyright to 2013.
1.1_1
03 Jan 2013 19:46:51
Revision:309904Original commit files touched by this commit
flo search for other commits by this committer
Add correct version numbers to the recent asterisk entry

Pointy hat to:	flo
1.1_1
03 Jan 2013 19:41:31
Revision:309903Original commit files touched by this commit
flo search for other commits by this committer
- update net/asterisk to 1.8.19.1
- update net/asterisk10 to 10.11.1
- update net/asterisk11 to 10.1.2
- add vuln.xml entry

Security:	f7c87a8a-55d5-11e2-a255-c8600054b392
1.1_1
02 Jan 2013 12:28:47
Revision:309813Original commit files touched by this commit
crees search for other commits by this committer
Note charybdis and ircd-ratbox vulnerabilities

PR:		ports/174878
Security:	http://www.ratbox.org/ASA-2012-12-31.txt
1.1_1
30 Dec 2012 23:13:04
Revision:309700Original commit files touched by this commit
anders search for other commits by this committer
Separate entries for Puppet 2.6 and 2.7.
1.1_1
30 Dec 2012 20:10:42
Revision:309688Original commit files touched by this commit
cs search for other commits by this committer
Add OTRS vulnerabilities
1.1_1
29 Dec 2012 19:53:47
Revision:309629Original commit files touched by this commit
rea search for other commits by this committer
VuXML entries for Tomcat: split into three distinct ones

They affect different Tomcat versions from 7.x branch, so don't let
users of VuXML be fooled on the affected software for each vulnerability.

Feature safe:	yes
1.1_1
28 Dec 2012 18:17:22
Revision:309576Original commit files touched by this commit
rea search for other commits by this committer
VuXML: add entry for DoS in Squid's cachemgr.cgi

Feature safe:	yes
Submitted by:	Thomas-Martin Seck <tmseck@web.de>
1.1_1
18 Dec 2012 16:34:14
Revision:309196Original commit files touched by this commit
bdrewery search for other commits by this committer
Remove invalid entry
1.1_1
18 Dec 2012 16:28:57
Revision:309195Original commit files touched by this commit
dinoex search for other commits by this committer
- add entry for opera 12.11
1.1_1
14 Dec 2012 09:09:16
Revision:308891Original commit files touched by this commit
delphij search for other commits by this committer
Fix typo.

Noticed by:	mandree
1.1_1
14 Dec 2012 03:51:08
Revision:308880Original commit files touched by this commit
jgh search for other commits by this committer
- add url block in references for 1657a3e6-4585-11e2-a396-10bf48230856
1.1_1
14 Dec 2012 00:41:42
Revision:308874Original commit files touched by this commit
delphij search for other commits by this committer
Update linux-f10-flashpulgin11 to 11.2r202.258 to address multiple
vulnerabilities that could cause a crash and potentially allow an
attacker to take control of the affected system.

Submitted by:	Tsurutani Naoki <turutani scphys kyoto-u ac jp>
1.1_1
12 Dec 2012 11:33:17
Revision:308757Original commit files touched by this commit
rene search for other commits by this committer
Document vulnerabilities in www/chromium < 23.0.1271.97

Obtained
from:	http://googlechromereleases.blogspot.nl/search/label/Stable%20updates
1.1_1
05 Dec 2012 23:52:36
Revision:308355Original commit files touched by this commit
zi search for other commits by this committer
- Fix recent vulnerability entry for www/tomcat[67]

Reported by:	Victor Balada Diaz <victor@bsdes.net>
Feature safe:	yes
1.1_1
05 Dec 2012 18:47:24
Revision:308343Original commit files touched by this commit
zi search for other commits by this committer
- Document recent vulnerabilities in www/tomcat6 and www/tomcat7

Requested by:	Victor Balada Diaz <victor@bsdes.net>
Feature safe:	yes
1.1_1
05 Dec 2012 07:46:03
Revision:308317Original commit files touched by this commit
erwin search for other commits by this committer
Update to the latest patch level from ISC:

  BIND 9 nameservers using the DNS64 IPv6 transition mechanism are
  vulnerable to a software defect that allows a crafted query to
  crash the server with a REQUIRE assertion failure.  Remote
  exploitation of this defect can be achieved without extensive
  effort, resulting in a denial-of-service (DoS) vector against
  affected servers.

Security:	2892a8e2-3d68-11e2-8e01-0800273fe665
		CVE-2012-5688
Feature safe:	yes
1.1_1
03 Dec 2012 22:49:43
Revision:308178Original commit files touched by this commit
mandree search for other commits by this committer
Add URL for recent bogofilter heap vuln', CVE-2012-5468, aka. vuln vid=
f524d8e0-3d83-11e2-807a-080027ef73ec

Feature safe: yes
1.1_1
03 Dec 2012 20:16:21
Revision:308171Original commit files touched by this commit
mandree search for other commits by this committer
Update bogofilter to new upstream release 1.2.3.
Security update to fix a heap corruption bug with invalid base64 input,
reported and fixed by Julius Plenz, FU Berlin, Germany.

Feature safe:   yes
Security:       CVE-2012-5468
Security:       f524d8e0-3d83-11e2-807a-080027ef73ec
1.1_1
30 Nov 2012 09:13:32
Revision:308000Original commit files touched by this commit
rene search for other commits by this committer
Document vulnerabilities in www/chromium < 23.0.1271.95

Obtained
from:	http://googlechromereleases.blogspot.nl/search/label/Stable%20updates
Feature safe:	yes
1.1_1
29 Nov 2012 20:33:20
Revision:307978Original commit files touched by this commit
ohauer search for other commits by this committer
www/yahoo-ui
 - fix CVE-2012-5881

security/vuxml
 - adjust version (we have only 2.8.2 in the tree)

Feature safe: yes

Approved by:	glarkin (maintainer) explicit
1.1_1
28 Nov 2012 14:37:24
Revision:307907Original commit files touched by this commit
wxs search for other commits by this committer
Fix date in yahoo-ui entry.

Noticed by:	dvl@
Feature safe:	yes
1.1_1
27 Nov 2012 20:09:35
Revision:307861Original commit files touched by this commit
ohauer search for other commits by this committer
- document www/yahoo-ui security issue and mark port forbidden [1]
  pet portlint (maintainer is already notified)

- adjust CVE entries for bugzilla (CVE-2012-5475 was rejected) [2]

Feature safe: yes

Security:	CVE-2012-5881 [1][2]
		CVE-2012-5882 [1][2]
		CVE-2012-5883 [2]

Approved by:	glarkin (implicit) [1]
1.1_1
27 Nov 2012 10:02:25
Revision:307828Original commit files touched by this commit
rene search for other commits by this committer
Describe new vulnerabilities in www/chromium < 23.0.1271.91

Obtained
from:	http://googlechromereleases.blogspot.nl/search/label/Stable%20updates
Feature safe:	yes
1.1_1
25 Nov 2012 15:42:23
Revision:307747Original commit files touched by this commit
flo search for other commits by this committer
- Update backports patch to 20121114
- Bump PORTREVISION

Changes:
- CVE-2006-7243
PHP before 5.3.4 accepts the \0 character in a pathname, which might allow
context-dependent attackers to bypass intended access restrictions by placing a
safe file extension after this character, as demonstrated by .php\0.jpg at the
end of the argument to the file_exists function

Secuity 3761df02-0f9c-11e0-becc-0022156e8794 fixed by check in fopen functions
for strlen(filename) != filename_len

- CVE-2012-4388
The sapi_header_op function in main/SAPI.c does not properly determine a pointer
(Only the first 15 lines of the commit message are shown above View all of this commit message)
1.1_1
25 Nov 2012 04:02:29
Revision:307733Original commit files touched by this commit
wxs search for other commits by this committer
Add entries for the following advisories:

FreeBSD-SA-12:08.linux
FreeBSD-SA-12:07.hostapd
FreeBSD-SA-12:06.bind

Feature safe:	yes
1.1_1
22 Nov 2012 20:27:45
Revision:307666Original commit files touched by this commit
dinoex search for other commits by this committer
- opera -- execution of arbitrary code
Feature safe: yes
1.1_1
21 Nov 2012 14:35:31
Revision:307616Original commit files touched by this commit
mm search for other commits by this committer
Document new vulnerability in www/lighttpd 1.4.31

Feature safe:	yes
1.1_1
20 Nov 2012 23:01:15
Revision:307606Original commit files touched by this commit
flo search for other commits by this committer
- Update firefox and thunderbird to 17.0
- Update seamonkey to 2.14
- Update ESR ports and libxul to 10.0.11
- support more h264 codecs when using GSTREAMER with YouTube
- Unbreak firefox-esr, thunderbird-esr and libxul on head >= 1000024 [1]
- Buildsystem is not python 3 aware, use python up to 2.7 [2]

PR:		ports/173679 [1]
Submitted by:	swills [1], demon [2]
In collaboration with:	Jan Beich <jbeich@tormail.org>
Security:	d23119df-335d-11e2-b64c-c8600054b392
Approved by:	portmgr (beat)
Feature safe:	yes
1.1_1
18 Nov 2012 12:51:26
Revision:307535Original commit files touched by this commit
jase search for other commits by this committer
- Fix copy and paste error in latest weechat entry
  (81826d12-317a-11e2-9186-406186f3d89d)

Feature safe:	yes
1.1_1
18 Nov 2012 12:46:40
Revision:307534Original commit files touched by this commit
jase search for other commits by this committer
- Document new vulnerability in irc/weechat and irc/weechat-devel

Feature safe:	yes
1.1_1
14 Nov 2012 19:29:42
Revision:307425Original commit files touched by this commit
ohauer search for other commits by this committer
- bugzilla security updates to version(s)
  3.6.11, 4.0.8, 4.2.4

Summary
=======

The following security issues have been discovered in Bugzilla:

* Confidential product and component names can be disclosed to
  unauthorized users if they are used to control the visibility of
  a custom field.

* When calling the 'User.get' WebService method with a 'groups'
  argument, it is possible to check if the given group names exist
  or not.
(Only the first 15 lines of the commit message are shown above View all of this commit message)
1.1_1
13 Nov 2012 18:17:13
Revision:307387Original commit files touched by this commit
jase search for other commits by this committer
- Update recent weechat entry (e02c572f-2af0-11e2-bb44-003067b2972c)

- Document assigned CVE Identifier
- Document workaround for vulnerable versions

Feature safe:	yes

Number of commits found: 7511 (showing only 100 on this page)

[First Page]  «  41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51  »  [Last Page]