Commit History - (may be incomplete: for full details, see links to repositories near top of page) |
Commit | Credits | Log message |
1.1_1 02 Aug 2006 01:40:25 |
kuriyama |
Add recent gnupg issue. |
1.1_1 30 Jul 2006 14:07:15 |
remko |
We are not affected by: CAN-2005-0018 in the
f2c entry (43cb40b3-c8c2-11da-a672-000e0c2e438a). We do not have
the shellscript, and it is not installed.
Reported by: thierry |
1.1_1 30 Jul 2006 13:58:31 |
simon |
Unbreak latest ruby entry by adding missing </lt>. |
1.1_1 30 Jul 2006 13:32:42 |
simon |
Run make tidy to clean up some style issues. |
1.1_1 30 Jul 2006 13:18:32 |
simon |
Only sort on entry date, not modified date. It simply causes too much
repo churn with little value to resort all entries which have been
modified. |
1.1_1 30 Jul 2006 09:58:18 |
sem |
- The last vulnerabilities was fixed in ruby18 port |
1.1_1 29 Jul 2006 20:58:27 |
remko |
OK, I misunderstood Simon with this one. The <gt>1.8.*</gt> entry
should have stayed and I interpreted that wrong.
Pointyhat: remko |
1.1_1 29 Jul 2006 20:40:55 |
remko |
Fix my previous version commit. The two entries matched twice when you
have ruby installed. You learn something new everyday...
Noticed/discussed with: simon |
1.1_1 29 Jul 2006 17:41:13 |
remko |
Mark all 1.6 and 1.8 versions as vulnerable, we do not have a fix
yet and are unable to tell what the naming scheme will be with
those patches. We can narrow down the scope later, we should
not do so before we know the mentioned scheme.
Triggered by: sem |
1.1_1 29 Jul 2006 16:54:34 |
remko |
Add a BID to the latest vuxml entry.
Some minor changes to the markup of the entry. |
1.1_1 29 Jul 2006 16:34:04 |
shaun |
- Document Ruby vulnerability. [1]
- Fix URL in previous mutt entry while here.
Reported by: Joel Hatton via freebsd-ports [1] |
1.1_1 29 Jul 2006 12:48:38 |
simon |
Add linux-thunderbird to mozilla -- multiple vulnerabilities entry.
Prodded by: sat |
1.1_1 28 Jul 2006 21:59:23 |
simon |
Document apache -- mod_rewrite ldap buffer overflow vulnerability.
Thanks to remko for doing initial list of apache package names in an
earlier VuXML entry. |
1.1_1 27 Jul 2006 23:51:20 |
simon |
Fix error in latest mozilla entry which marked all firefox version as
vulnerable.
Reported by: Craig Leres |
1.1_1 27 Jul 2006 13:59:06 |
simon |
Document mozilla -- multiple vulnerabilities.
Note I assume that linux-firefox-devel 3.0.a2006.07.26 is fixed, I
haven't actually checked (way to many issues to check for). |
1.1_1 14 Jul 2006 11:03:58 |
garga |
Add "zope -- information disclosure vulnerability" entry
Reviewed by: simon |
1.1_1 14 Jul 2006 10:57:17 |
simon |
For latest drupal entry:
- Unbreak vuln.xml format by adding content to the references section.
- Remove vulnerabilities already documented in
40a0185f-ec32-11da-be02-000c6ec775d9. |
1.1_1 13 Jul 2006 16:19:54 |
brooks |
Add entry for drupal issues. |
1.1_1 11 Jul 2006 13:23:42 |
erwin |
Add shoutcast crosssite scripting.
Submitted by: gabor
Reviewed by: simon |
1.1_1 11 Jul 2006 12:24:24 |
simon |
Cancel VID 0a4cd819-0291-11db-bbf7-000c6ec775d9 / opera -- JPEG
processing integer overflow vulnerability, since it turns out that the
issue does not affect the FreeBSD or Linux versions of Opera.
Source: http://www.opera.com/support/search/supsearch.dml?index=834 |
1.1_1 11 Jul 2006 11:23:47 |
simon |
Correct dates in latest mambo entry by resetting entry date and adding
a modified date.
OK'ed by: itetcu |
1.1_1 11 Jul 2006 11:04:36 |
itetcu |
Bump modified date for previous commit.
Requested by: simon |
1.1_1 11 Jul 2006 10:19:16 |
itetcu |
The two two SQL injection vulnerabilities in Mambo described in
vid f70d09cb-0c46-11db-aac7-000c6ec775d9 are fixed in 4.5.4
PR: ports/100044
Submited by: maintainer |
1.1_1 10 Jul 2006 22:59:36 |
simon |
Fix markup breakage that slipped in just before commit of the latest
samba entry. |
1.1_1 10 Jul 2006 22:38:50 |
simon |
Document samba -- memory exhaustion DoS in smbd. |
1.1_1 10 Jul 2006 11:48:01 |
simon |
- For the latest trac entry include information from the release
announcements about setups which are not affected. To avoid having
to reference two documents simply reference the release notes for
all the information (it's basically the same as the changelog with
slightly different wording).
- Add a modified date tag. |
1.1_1 10 Jul 2006 08:56:13 |
simon |
Document twiki -- multiple file extensions file upload vulnerability. |
1.1_1 10 Jul 2006 08:39:43 |
simon |
Improve markup for last entry. No content change. |
1.1_1 09 Jul 2006 23:31:15 |
kuriyama |
Add trac DoS. |
1.1_1 05 Jul 2006 17:45:15 |
thierry |
Add an entry for Horde's latest vulnerabilities. |
1.1_1 05 Jul 2006 17:30:40 |
simon |
Document mambo -- SQL injection vulnerabilities. |
1.1_1 03 Jul 2006 12:45:31 |
miwi |
Document phpmyadmin -- cross site scripting vulnerability
Approved by: markus (co mentor) |
1.1_1 02 Jul 2006 13:09:45 |
remko |
Document webmin, usermin -- arbitrary file disclosure vulnerability.
Details are unknown, all sources talk about an "unspecified" vulnerability. |
1.1_1 01 Jul 2006 12:19:21 |
shaun |
Document mutt -- Remote Buffer Overflow Vulnerability.
Approved by: ahze (mentor) |
1.1_1 30 Jun 2006 22:48:34 |
miwi |
Document joomla -- multiple vulnerabilities
Approved by: markus (co mentor) |
1.1_1 27 Jun 2006 19:55:05 |
remko |
Document hashcash -- heap overflow vulnerability. |
1.1_1 25 Jun 2006 18:39:19 |
simon |
Document gnupg -- user id integer overflow vulnerability. |
1.1_1 23 Jun 2006 08:32:02 |
simon |
Document opera -- JPEG processing integer overflow vulnerability. |
1.1_1 17 Jun 2006 14:36:33 |
remko |
Update the webcalendar entry, use alphabetic sorting, no functional
change of information. |
1.1_1 17 Jun 2006 07:11:10 |
thierry |
Add an entry for Horde's latest XSS vulnerabilities. |
1.1_1 16 Jun 2006 22:38:16 |
simon |
Add webcalendar -- information disclosure vulnerability.
PR: ports/98993
Submitted by: Gregory C. Larkin <glarkin@sourcehosting.net> |
1.1_1 14 Jun 2006 16:30:58 |
remko |
Add FreeBSD-SA-06:17.sendmail to the VuXML database. |
1.1_1 12 Jun 2006 15:41:35 |
remko |
Bump modification date in the last entry and earn my own pointyhat.
Forgotten by/pointyhat: remko |
1.1_1 12 Jun 2006 15:26:46 |
remko |
Fix the latest entry by using the entity for &, this passes make validate.
Reported by: Michal Kaps <michal at ionic dot co dot uk>
Pointyhat by: aaron, (tobez implicit) |
1.1_1 12 Jun 2006 06:22:59 |
aaron |
- Added multiple dokuwiki vulnerabilities
Approved by: tobez |
1.1_1 11 Jun 2006 12:55:21 |
nobutaka |
Add an entry for libxine -- buffer overflow vulnerability. |
1.1_1 09 Jun 2006 13:32:10 |
remko |
Document FreeBSD-SA-06:15.ypserv and FreeBSD-SA-06:16.smbfs.
Add the proper freebsdsa tag for older entries and bump
their modification date. |
1.1_1 08 Jun 2006 17:10:56 |
remko |
Document two freeradius issues, one newer and one older issue:
freeradius -- multiple vulnerabilities
freeradius -- authentication bypass vulnerability |
1.1_1 08 Jun 2006 12:21:36 |
ehaupt |
Mark graphics/fractorama 1.6.7_1 "clean". This port now links against libtiff
from ports.
Approved by: simon (secteam) |
1.1_1 07 Jun 2006 18:51:20 |
simon |
The awstats port has PORTEPOCH bumped, so update the vuxml entry awstats
-- arbitrary command execution vulnerability to reflect that. |
1.1_1 06 Jun 2006 10:57:44 |
simon |
Mumble, back out local changes which should not have been committed. |
1.1_1 06 Jun 2006 10:55:10 |
simon |
Mark squirrelmail-1.4.6_1 as fixed for squirrelmail -- plugin.php
local file inclusion vulnerability. |
1.1_1 05 Jun 2006 20:18:51 |
simon |
Document squirrelmail -- plugin.php local file inclusion vulnerability. |
1.1_1 05 Jun 2006 19:57:27 |
simon |
Document dokuwiki -- spellchecker remote PHP code execution. |
1.1_1 05 Jun 2006 19:48:00 |
simon |
Document drupal -- multiple vulnerabilities. |
1.1_1 01 Jun 2006 18:30:07 |
mnag |
- Add last two MySQL vulnerabilities
MySQL -- SQL-injection security vulnerability
MySQL -- Information Disclosure and Buffer Overflow Vulnerabilities |
1.1_1 23 May 2006 19:23:48 |
simon |
Document frontpage -- cross site scripting vulnerability and point
FORBIDDEN from the frontpage ports at it.
While this is "only" a cross site scripting vulnerability it has some
rather serious implications which can allow an attacker to take over a
web site, so I'm keeping FORBIDDEN. |
1.1_1 23 May 2006 15:20:45 |
mnag |
cscope -- buffer overflow vulnerabilities |
1.1_1 22 May 2006 15:25:55 |
mnag |
coppermine -- Multiple File Extensions Vulnerability
coppermine -- "file" Local File Inclusion Vulnerability
coppermine -- File Inclusion Vulnerabilities |
1.1_1 21 May 2006 01:02:29 |
mnag |
phpmyadmin -- XSRF vulnerabilities |
1.1_1 18 May 2006 21:19:02 |
pav |
- Normalize the topic of last entry
Requested by: remko |
1.1_1 18 May 2006 16:12:17 |
pav |
- Add VuXML entry for vnc 4.1.1 |
1.1_1 14 May 2006 03:57:14 |
mnag |
- Add vulnerabilities in last topic. |
1.1_1 14 May 2006 03:56:08 |
mnag |
phpldapadmin -- Cross-Site Scripting and Script Insertion |
1.1_1 11 May 2006 19:17:55 |
tobez |
Modify the entry for p5-DBI insecure temporary files creation to reflect
the fact that version 1.37_1 of p5-DBI-137 is OK now.
Reviewed by: simon |
1.1_1 06 May 2006 10:56:39 |
kuriyama |
Add www/fswiki vulnerability. |
1.1_1 05 May 2006 22:24:37 |
simon |
- Add missing s in latest awstats entry's title.
- Document mysql50-server -- COM_TABLE_DUMP arbitrary code execution. |
1.1_1 05 May 2006 21:39:22 |
mnag |
- Cancel last rsync entry. Does not affect FreeBSD port.
Notified by: simon, pav
Discussed with: simon |
1.1_1 05 May 2006 20:45:21 |
simon |
Document awstat -- arbitrary command execution vulnerability.
Fix a incorrect use of cvename in the latest firefox entry, which I
missed when reviewing the entry (and which make validate did not / can
not catch). |
1.1_1 03 May 2006 20:14:48 |
mnag |
phpwebftp -- "language" Local File Inclusion |
1.1_1 03 May 2006 08:00:56 |
vd |
Document firefox -- denial of service vulnerability
Reviewed by: simon |
1.1_1 03 May 2006 01:01:55 |
mnag |
trac -- Wiki Macro Script Insertion Vulnerability |
1.1_1 03 May 2006 00:56:33 |
mnag |
rsync -- "xattrs.diff" Patch Integer Overflow Vulnerability |
1.1_1 03 May 2006 00:45:52 |
mnag |
clamav -- Freshclam HTTP Header Buffer Overflow Vulnerability |
1.1_1 01 May 2006 15:09:47 |
mnag |
- Add last jabberd entry:
jabberd -- SASL Negotiation Denial of Service Vulnerability |
1.1_1 27 Apr 2006 11:12:19 |
simon |
Also mark linux-seamonkey vulnerable to recent mozilla
vulnerabilities.
Reported by: Andrew Pantyukhin infofarmer at gmail dotty com |
1.1_1 27 Apr 2006 04:30:54 |
mnag |
cacti -- ADOdb "server.php" Insecure Test Script Security Issue |
1.1_1 27 Apr 2006 03:48:33 |
mnag |
amaya -- Attribute Value Buffer Overflow Vulnerabilities |
1.1_1 27 Apr 2006 03:22:26 |
mnag |
lifetype -- ADOdb "server.php" Insecure Test Script Security Issue |
1.1_1 27 Apr 2006 02:46:41 |
mnag |
ethereal -- Multiple Protocol Dissector Vulnerabilities |
1.1_1 25 Apr 2006 20:57:47 |
remko |
My 100th commit to the vuln.xml file:
- Document Asterisk -- denial of service vulnerability, local system access. |
1.1_1 25 Apr 2006 17:40:50 |
anholt |
Change paraview checks to be < 2.4.3 now that paraview uses system libtiff. |
1.1_1 23 Apr 2006 21:46:35 |
remko |
Document zgv, xzgv -- heap overflow vulnerability. |
1.1_1 23 Apr 2006 14:14:52 |
remko |
Document crossfire-server -- denial of service and remote code execution
vulnerability. |
1.1_1 23 Apr 2006 10:25:28 |
remko |
Document p5-DBI -- insecure temporary file creation vulnerability. |
1.1_1 23 Apr 2006 09:58:04 |
remko |
Document wordpress -- full path disclosure. |
1.1_1 23 Apr 2006 09:35:38 |
remko |
Document xine -- multiple remote string vulnerabilities. |
1.1_1 21 Apr 2006 16:51:13 |
ume |
Add an entry for cyrus-sasl -- DIGEST-MD5 Pre-Authentication
Denial of Service. |
1.1_1 19 Apr 2006 17:53:27 |
remko |
Also mark all other versions of FreeBSD (That were released) as
vulnerable.
Noticed by: brueffer
Discussed with: brueffer, simon |
1.1_1 19 Apr 2006 17:36:57 |
remko |
Add FreeBSD -- FPU information disclosure (SA-06:14) to the
vuxml list. |
1.1_1 18 Apr 2006 19:39:22 |
simon |
Add some CERT references to latest Mozilla entry. |
1.1_1 18 Apr 2006 13:48:47 |
mnag |
plone -- "member_id" Parameter Portrait Manipulation Vulnerability |
1.1_1 16 Apr 2006 22:02:11 |
simon |
Fix copy/paste error in last commit and mark linux-mozilla < 1.7.13 as
vulnerable. |
1.1_1 16 Apr 2006 21:52:31 |
simon |
Document mozilla/firefox/thunderbirds's latest attempt at Internet
Explorer compatibility.
Note that I omitted marking some really old mozilla versions as
vulnerable this time, since there is already a bunch of entries
covering these versions (which haven't been in ports for a while). |
1.1_1 16 Apr 2006 13:00:05 |
ehaupt |
Update entry for sysutils/heartbeat. The insecure temporary file creation
vulnerability is fixed in 1.2.4.
Approved by: secteam (simon) |
1.1_1 16 Apr 2006 01:52:17 |
mnag |
mailman -- Private Archive Script Cross-Site Scripting |
1.1_1 10 Apr 2006 19:11:15 |
remko |
Document f2c -- insecure temporary files.
It is not very clear to me to see what version is fixed. The one fixing
this port should import the latest available one which is fixed. |
1.1_1 08 Apr 2006 14:53:01 |
mnag |
mplayer -- Multiple integer overflows |
1.1_1 07 Apr 2006 14:15:02 |
mnag |
- Add Secunia references for last phpMyAdmin issue. |
1.1_1 07 Apr 2006 11:23:07 |
remko |
Document kaffeine -- buffer overflow vulnerability. |