Commit History - (may be incomplete: for full details, see links to repositories near top of page) |
Commit | Credits | Log message |
1.1_1 16 Oct 2006 21:54:38 |
simon |
Document "nvidia-driver -- arbitrary root code execution vulnerability".
Note that I haven't actually had time to make a test system to reproduce
this on FreeBSD, but due to the nature of this issue and that there is a
PoC exploit in the advisory, I'm adding this entry due to "better safe
than sorry"...
Approved by: portmgr (secteam blanket) |
1.1_1 16 Oct 2006 17:44:32 |
sat |
- Mark php open_basedir fixed
Reviewed by: secteam (simon)
Approved by: portmgr (secteam blanket) |
1.1_1 16 Oct 2006 14:32:54 |
mnag |
- clamav -- CHM unpacker and PE rebuilding vulnerabilities
Approved by: portmgr (mnag with secteam hat) |
1.1_1 15 Oct 2006 19:43:01 |
sat |
- Add some references
Reviewed by: secteam (simon)
Approved by: portmgr (secteam blanket) |
1.1_1 15 Oct 2006 16:04:57 |
sat |
- Document temporary file symlink privilege escalation in tkdiff
- Correct Javier's name spelling in an old advisory
Reviewed by: secteam (simon)
Approved by: portmgr (secteam blanket) |
1.1_1 15 Oct 2006 11:31:33 |
sat |
- Document multiple remote file inclusion vulnerabilities in vtiger
Reviewed by: secteam (simon)
Approved by: portmgr (secteam blanket) |
1.1_1 14 Oct 2006 12:32:43 |
sat |
- Document heap overflow in the KML engine in google-earth
Reviewed by: secteam (simon)
Approved by: portmgr (implicit) |
1.1_1 11 Oct 2006 08:32:05 |
erwin |
devel/cscope was fixed in version 15.6 so use lt instead of le.
Submitted by: joerg
Pointyhat to: erwin
Approved by: portmgr (self) |
1.1_1 09 Oct 2006 15:45:02 |
simon |
Mark zgv as fixed wrt. "zgv, xzgv -- heap overflow vulnerability". |
1.1_1 08 Oct 2006 16:41:50 |
sat |
- Add php-suhosin to edabe438-542f-11db-a5ae-00508d6a62df
as per original advisory
Discussed with: ale |
1.1_1 08 Oct 2006 07:44:16 |
sat |
- Fix python package naming in 6afa87d3-764b-11d9-b0e7-0000e249a0a2
Reported by: simon |
1.1_1 08 Oct 2006 07:17:50 |
simon |
Update versions affected by python -- buffer overrun in repr() for
unicode strings:
- Python 2.5.c2 was already fixed (verified in upstream SVN).
- Python 2.4 port just got the fix.
- I can't find any trace of python23, python22, and python-devel ever
having existed as package names, so I removed them.
- Add python+ipv6. I don't really know if it contained the
problematic unicode code, but better safe than sorry. |
1.1_1 08 Oct 2006 06:51:43 |
simon |
Fix whitespace in openssh -- multiple vulnerabilities entry, which I
originally missed. |
1.1_1 07 Oct 2006 23:01:05 |
tmclaugh |
Update vuxml id 5a39a22e-5478-11db-8f1a-000a48049292
- Fixed in version 1.1.13.8.1 |
1.1_1 07 Oct 2006 22:16:41 |
tmclaugh |
Remove mono-devel and mono-svn from 5a39a22e-5478-11db-8f1a-000a48049292
- These are packages from BSD#'s (my project) development repo. Don't even
give the impression that FreeBSD is supporting security updates for an
outside project. |
1.1_1 07 Oct 2006 15:22:55 |
sat |
- Remove an empty url (a typo) |
1.1_1 07 Oct 2006 09:24:29 |
sat |
- Document User-Agent XSS Vulnerability in torrentflux |
1.1_1 07 Oct 2006 09:13:36 |
sat |
- Document buffer overrun in repr() for unicode strings in python |
1.1_1 06 Oct 2006 20:57:09 |
erwin |
devel/cscope was fixed in version 15.6
Glanced at by: remko |
1.1_1 06 Oct 2006 05:12:29 |
sat |
- Document _ecalloc Integer Overflow Vulnerability in php5 |
1.1_1 05 Oct 2006 21:34:26 |
sat |
- Update an old mambo advisory and document its new vulnerabilities |
1.1_1 05 Oct 2006 16:46:38 |
sat |
- Add linux-curl to a curl advisory and tweak versions a bit |
1.1_1 05 Oct 2006 16:38:29 |
sat |
- Add ja-lynx* to a lynx advisory |
1.1_1 05 Oct 2006 16:32:15 |
sat |
- chinese/tin was also vulnerable |
1.1_1 05 Oct 2006 16:30:52 |
sat |
- Document buffer overflow vulnerabilities in tin |
1.1_1 05 Oct 2006 14:47:59 |
sat |
- Use >0 for unpatched vulnerabilities
Submitted by: simon |
1.1_1 05 Oct 2006 14:31:50 |
sat |
- Document slapd acl selfwrite Security Issue in openldap |
1.1_1 05 Oct 2006 14:00:57 |
sat |
- Document "System.CodeDom.Compiler" Insecure Temporary Creation in mono |
1.1_1 05 Oct 2006 05:24:37 |
sat |
- Document open_basedir Race Condition Vulnerability in php |
1.1_1 04 Oct 2006 17:10:46 |
sat |
- Document NULL byte injection vulnerability in phpbb |
1.1_1 04 Oct 2006 10:27:16 |
sat |
- Add references and use earlier discovery date in
fffa9257-3c17-11db-86ab-00123ffe8333 |
1.1_1 03 Oct 2006 12:14:22 |
sat |
- Add CVE names to 19b17ab4-51e0-11db-a5ae-00508d6a62df |
1.1_1 03 Oct 2006 12:10:50 |
sat |
- Document admin section SQL injection in postnuke |
1.1_1 02 Oct 2006 12:39:24 |
sat |
- Document LWFN Files Buffer Overflow Vulnerability in freetype |
1.1_1 02 Oct 2006 12:21:55 |
sat |
- Document Buffer Overflow Vulnerabilities in cscope |
1.1_1 02 Oct 2006 12:05:49 |
sat |
- Document RSA Signature Forgery Vulnerability in gnutls |
1.1_1 02 Oct 2006 11:50:49 |
sat |
- Document Search Unspecified XSS in MT |
1.1_1 02 Oct 2006 11:38:14 |
sat |
- Update dokuwiki advisories |
1.1_1 02 Oct 2006 06:59:06 |
sat |
- Document latest XSRF vulnerabilities in phpmyadmin |
1.1_1 01 Oct 2006 07:34:35 |
sat |
- Mark gtetrinet 0.7.10 safe |
1.1_1 30 Sep 2006 20:52:36 |
simon |
Document openssh -- multiple vulnerabilities AKA
FreeBSD-SA-06:22.openssh. |
1.1_1 30 Sep 2006 10:25:32 |
sat |
- Document multiple vulnerabilities in dokuwiki |
1.1_1 30 Sep 2006 09:36:44 |
sat |
- Document multiple vulnerabilities in tikiwiki |
1.1_1 30 Sep 2006 09:10:14 |
sat |
- Document NULL byte injection vulnerability in punbb |
1.1_1 26 Sep 2006 18:43:41 |
sat |
- Concisify a Secunia report
- Use <gt>0 for an unpatched bug
Suggested by: simon |
1.1_1 26 Sep 2006 06:29:20 |
sat |
- Document (another) Denial of Service Vulnerability in freeciv |
1.1_1 26 Sep 2006 06:12:16 |
sat |
- Document Packet Parsing Denial of Service Vulnerability in freeciv |
1.1_1 26 Sep 2006 05:47:04 |
sat |
- Document multiple vulnerabilities in plans |
1.1_1 26 Sep 2006 05:27:16 |
sat |
- Update the unace advisory |
1.1_1 25 Sep 2006 19:38:39 |
sat |
- Document multiple XSS security bugs in eyeOS |
1.1_1 22 Sep 2006 13:05:33 |
sat |
- Document restructuredText "csv_table" Information Disclosure in zope |
1.1_1 22 Sep 2006 12:23:28 |
sat |
- Document stack-based buffer overflow in libmms |
1.1_1 22 Sep 2006 07:08:56 |
sat |
- Document Opera SSL RSA Signature Forgery |
1.1_1 22 Sep 2006 05:59:58 |
simon |
Bump modified data which was missed in last commit. |
1.1_1 21 Sep 2006 17:07:15 |
sat |
- Mark latest linux-{firefox,seamonkey}-devel safe |
1.1_1 15 Sep 2006 10:18:04 |
simon |
Document mozilla -- multiple vulnerabilities. |
1.1_1 14 Sep 2006 14:26:44 |
remko |
In the PHP entry, replace mod-php with mod_php [1].
Rewrite the win32-codecs entry to even better explain the vulnerability [2].
Noticed by: Dan Langille (with FreshPorts.org) [1]
Discussed with: simon [2] |
1.1_1 14 Sep 2006 11:31:27 |
remko |
Try to explain a bit better that users who have the Quicktime plugin
as a browser plugin can be directly affected by the remote code
execution.
Also mention that I changed the entry date in the previous entry
(PHP) which I had forgotten to do yesterday and did not mention
in the previous commit. |
1.1_1 14 Sep 2006 11:03:34 |
remko |
Document win32-codecs -- multiple vulnerabilities |
1.1_1 13 Sep 2006 22:07:28 |
remko |
Attempt two:
Document php -- multiple vulnerabilities |
1.1_1 13 Sep 2006 22:01:57 |
remko |
OK, I do not know WHAT went wrong but it went wrong, revert to the old
situation and i will re-adopt the PHP entry. |
1.1_1 13 Sep 2006 21:53:27 |
remko |
Document php -- multiple vulnerabilities |
1.1_1 13 Sep 2006 18:39:38 |
novel |
Cancel latest gnutls entry (GNUTLS-SA-2006-3) - it is a false alarm:
http://lists.gnupg.org/pipermail/gnutls-dev/2006-September/001208.html |
1.1_1 13 Sep 2006 18:03:26 |
brooks |
Upgrade drupal-pubcookie to the latest version fixing a security hole
allowing anyone to bypass the authenication system and become an
arbitrary drupal user.
Security: vid:c0fd7890-4346-11db-89cc-000ae42e9b93 |
1.1_1 13 Sep 2006 15:17:36 |
novel |
Style neats for the latest gnutls entry.
Reviewed by: remko |
1.1_1 12 Sep 2006 20:48:18 |
remko |
correct the tomcat entry (change the ,5 to _5 since we talk about PORTREVISION
instead of PORTEPOCH) [1]
correct the jdk -- jar directory traversal vulnerability entry, the
FreeBSD Foundation uses different package names [2], [3].
For both entries the modification date was bumped.
Reported by: Gabor Kovesdan (on #bsdports) [1]
David Robillard <david dot robillard at gmail dot com>
[2]
Tim Zingelman <zingelman at fnal dot gov> |
1.1_1 12 Sep 2006 20:31:47 |
simon |
Document linux-flashplugin7 -- arbitrary code execution vulnerabilities. |
1.1_1 11 Sep 2006 13:02:11 |
lawrance |
Mark jakarta-tomcat5 as fixed since 5.0.30,5 regarding minor XSS issue. |
1.1_1 10 Sep 2006 17:50:17 |
novel |
Add an info about GNUTLS-SA-2006-3. |
1.1_1 04 Sep 2006 14:59:30 |
mnag |
- mailman -- Multiple Vulnerabilities |
1.1_1 03 Sep 2006 14:24:45 |
garga |
Bump modification date for last jabber entry change
Noted by: remko |
1.1_1 03 Sep 2006 12:51:30 |
garga |
Fix jabber entry |
1.1_1 02 Sep 2006 19:47:15 |
remko |
Document hlstats -- multiple cross site scripting vulnerabilities. |
1.1_1 02 Sep 2006 19:27:03 |
remko |
Document gtetrinet -- remote code execution |
1.1_1 02 Sep 2006 18:32:42 |
remko |
Bump modified date in the entry changed by garga.
Forgotten by: garga |
1.1_1 02 Sep 2006 17:14:27 |
garga |
net-im/jabber -- Mark the correct versions with fd_set vulnerability, author
fixed the problem on trunk and 2 new releases (1.4.3.1 and 1.4.4.1) is comming
soon |
1.1_1 30 Aug 2006 18:14:23 |
remko |
Update the latest FreeBSD-SA entry, ppp got replaced by sppp.
Also implement a suggestion from Simon, mark all versions before
the latest version vulnerable. |
1.1_1 30 Aug 2006 12:32:07 |
remko |
Document joomla -- multiple vulnerabilities
Note that I only documented the high level
threats, there are several others which can
be found at the link provided [1]
Reference: http://www.joomla.org/content/view/1841/78/ [1] |
1.1_1 23 Aug 2006 23:09:56 |
remko |
Document FreeBSD-SA-06:18.ppp |
1.1_1 20 Aug 2006 10:40:53 |
remko |
Minor whitespace cleanup (we need a blank line every after </entry>
so that we can easily see the different entries). |
1.1_1 18 Aug 2006 02:31:06 |
shaun |
- Add imp to the previous entry.
- Add some SecurityFocus BIDs too. |
1.1_1 17 Aug 2006 22:54:47 |
shaun |
Document horde -- Phishing and Cross-Site Scripting Vulnerabilities. |
1.1_1 15 Aug 2006 21:26:36 |
remko |
Convert 8 spaces to tab as per the FDP for the latest
entry. |
1.1_1 15 Aug 2006 21:09:15 |
brooks |
Add entry for globus tmpfile creation bugs. |
1.1_1 15 Aug 2006 20:07:50 |
brueffer |
The lang/f2c port has been updated, update affected versions.
Reviewed by: simon |
1.1_1 13 Aug 2006 20:33:47 |
remko |
Document x11vnc -- authentication bypass vulnerability.
The 1.1111th commit, yay. |
1.1_1 13 Aug 2006 19:28:13 |
remko |
Document alsaplayer -- multiple vulnerabilities. |
1.1_1 13 Aug 2006 16:44:13 |
remko |
Document postgresql -- encoding based SQL injection.
Reported by: Radim Kolar <hsn at netmag dot cz> |
1.1_1 13 Aug 2006 15:33:34 |
remko |
Bump modified date in the older entry I just corrected.
Spotted by: simon (again) |
1.1_1 13 Aug 2006 15:25:17 |
remko |
Document postgresql -- multiple vulnerabilities.
These are all older vulnerabilities which had not yet been documented
by the Security Team.
Also fix a minor mistake in an older PostgreSQL entry. |
1.1_1 13 Aug 2006 14:14:56 |
remko |
Fix the discovery date in the latest MySQL entry.
Spotted by: simon |
1.1_1 13 Aug 2006 13:40:40 |
remko |
Document mysql -- format string vulnerability. |
1.1_1 12 Aug 2006 19:44:22 |
remko |
OK after some more discussions with Simon it appeared that the ,2
marked all future releases of squirrelmail as vulnerable.
The negative side-effect of PORTEPOCH. Split the previous entry
into two seperated entries again, restoring the old entry for
squirrelmail, and having the 'new' entry for ja-squirrelmail.
This would grab any future versions of ja-squirrelmail if it were
to be readded, and does not conflict with future versions of
squirrelmail.
For more information about the portepoch discussion etc:
http://lists.freebsd.org/pipermail/freebsd-vuxml/2006-July/000185.html |
1.1_1 12 Aug 2006 18:36:38 |
remko |
Simon provided me with the necessary clue to mark the appropriate ports
as vulnerable. I was soo close.. |
1.1_1 12 Aug 2006 17:10:26 |
remko |
Document squirrelmail -- random variable overwrite vulnerability.
Note that I marked all ja-squirrelmail entries as vulnerable, it
does no longer exist on it's own and the portepoch is giving me
matching problems. |
1.1_1 10 Aug 2006 21:06:26 |
simon |
Document rubygem-rails -- evaluation of ruby code.
Submitted by: Marius Nuennerich <marius.nuennerich@gmx.net> |
1.1_1 08 Aug 2006 20:01:12 |
simon |
Add CVE name to recent ClamAV entry. |
1.1_1 08 Aug 2006 14:46:36 |
garga |
Document clamav and clamav-devel vulnerability
Reviewed by: secteam (mnag) |
1.1_1 08 Aug 2006 14:03:32 |
mnag |
- Fix discovery date in latest entry
- Remove extra "." in latest entry |
1.1_1 02 Aug 2006 22:24:21 |
brooks |
Update drupal to 4.6.9 to fix yet another XSS vulnerability.
Security: vuxml vid c905298c-2274-11db-896e-000ae42e9b93 |