Commit History - (may be incomplete: for full details, see links to repositories near top of page) |
Commit | Credits | Log message |
1.1_1 05 May 2006 20:45:21
 |
simon  |
Document awstat -- arbitrary command execution vulnerability.
Fix a incorrect use of cvename in the latest firefox entry, which I
missed when reviewing the entry (and which make validate did not / can
not catch). |
1.1_1 03 May 2006 20:14:48
 |
mnag  |
phpwebftp -- "language" Local File Inclusion |
1.1_1 03 May 2006 08:00:56
 |
vd  |
Document firefox -- denial of service vulnerability
Reviewed by: simon |
1.1_1 03 May 2006 01:01:55
 |
mnag  |
trac -- Wiki Macro Script Insertion Vulnerability |
1.1_1 03 May 2006 00:56:33
 |
mnag  |
rsync -- "xattrs.diff" Patch Integer Overflow Vulnerability |
1.1_1 03 May 2006 00:45:52
 |
mnag  |
clamav -- Freshclam HTTP Header Buffer Overflow Vulnerability |
1.1_1 01 May 2006 15:09:47
 |
mnag  |
- Add last jabberd entry:
jabberd -- SASL Negotiation Denial of Service Vulnerability |
1.1_1 27 Apr 2006 11:12:19
 |
simon  |
Also mark linux-seamonkey vulnerable to recent mozilla
vulnerabilities.
Reported by: Andrew Pantyukhin infofarmer at gmail dotty com |
1.1_1 27 Apr 2006 04:30:54
 |
mnag  |
cacti -- ADOdb "server.php" Insecure Test Script Security Issue |
1.1_1 27 Apr 2006 03:48:33
 |
mnag  |
amaya -- Attribute Value Buffer Overflow Vulnerabilities |
1.1_1 27 Apr 2006 03:22:26
 |
mnag  |
lifetype -- ADOdb "server.php" Insecure Test Script Security Issue |
1.1_1 27 Apr 2006 02:46:41
 |
mnag  |
ethereal -- Multiple Protocol Dissector Vulnerabilities |
1.1_1 25 Apr 2006 20:57:47
 |
remko  |
My 100th commit to the vuln.xml file:
- Document Asterisk -- denial of service vulnerability, local system access. |
1.1_1 25 Apr 2006 17:40:50
 |
anholt  |
Change paraview checks to be < 2.4.3 now that paraview uses system libtiff. |
1.1_1 23 Apr 2006 21:46:35
 |
remko  |
Document zgv, xzgv -- heap overflow vulnerability. |
1.1_1 23 Apr 2006 14:14:52
 |
remko  |
Document crossfire-server -- denial of service and remote code execution
vulnerability. |
1.1_1 23 Apr 2006 10:25:28
 |
remko  |
Document p5-DBI -- insecure temporary file creation vulnerability. |
1.1_1 23 Apr 2006 09:58:04
 |
remko  |
Document wordpress -- full path disclosure. |
1.1_1 23 Apr 2006 09:35:38
 |
remko  |
Document xine -- multiple remote string vulnerabilities. |
1.1_1 21 Apr 2006 16:51:13
 |
ume  |
Add an entry for cyrus-sasl -- DIGEST-MD5 Pre-Authentication
Denial of Service. |
1.1_1 19 Apr 2006 17:53:27
 |
remko  |
Also mark all other versions of FreeBSD (That were released) as
vulnerable.
Noticed by: brueffer
Discussed with: brueffer, simon |
1.1_1 19 Apr 2006 17:36:57
 |
remko  |
Add FreeBSD -- FPU information disclosure (SA-06:14) to the
vuxml list. |
1.1_1 18 Apr 2006 19:39:22
 |
simon  |
Add some CERT references to latest Mozilla entry. |
1.1_1 18 Apr 2006 13:48:47
 |
mnag  |
plone -- "member_id" Parameter Portrait Manipulation Vulnerability |
1.1_1 16 Apr 2006 22:02:11
 |
simon  |
Fix copy/paste error in last commit and mark linux-mozilla < 1.7.13 as
vulnerable. |
1.1_1 16 Apr 2006 21:52:31
 |
simon  |
Document mozilla/firefox/thunderbirds's latest attempt at Internet
Explorer compatibility.
Note that I omitted marking some really old mozilla versions as
vulnerable this time, since there is already a bunch of entries
covering these versions (which haven't been in ports for a while). |
1.1_1 16 Apr 2006 13:00:05
 |
ehaupt  |
Update entry for sysutils/heartbeat. The insecure temporary file creation
vulnerability is fixed in 1.2.4.
Approved by: secteam (simon) |
1.1_1 16 Apr 2006 01:52:17
 |
mnag  |
mailman -- Private Archive Script Cross-Site Scripting |
1.1_1 10 Apr 2006 19:11:15
 |
remko  |
Document f2c -- insecure temporary files.
It is not very clear to me to see what version is fixed. The one fixing
this port should import the latest available one which is fixed. |
1.1_1 08 Apr 2006 14:53:01
 |
mnag  |
mplayer -- Multiple integer overflows |
1.1_1 07 Apr 2006 14:15:02
 |
mnag  |
- Add Secunia references for last phpMyAdmin issue. |
1.1_1 07 Apr 2006 11:23:07
 |
remko  |
Document kaffeine -- buffer overflow vulnerability. |
1.1_1 07 Apr 2006 10:38:53
 |
remko  |
Document thunderbird -- javascript execution. |
1.1_1 06 Apr 2006 17:30:16
 |
remko  |
Update the latest zoo entry to match the latest update to the port.
This will mark zoo-2.10.1_2 and later as not vulnerable for this
issue. |
1.1_1 06 Apr 2006 16:44:46
 |
mnag  |
phpmyadmin -- XSS vulnerabilities
phpmyadmin -- 'set_theme' Cross-Site Scripting |
1.1_1 06 Apr 2006 15:30:13
 |
mnag  |
clamav -- Multiple Vulnerabilities |
1.1_1 06 Apr 2006 04:47:47
 |
remko  |
Add cvename to the recent OpenVPN entry.
Submitted by: Matthias Andree <matthias dot andree at gmx dot de> |
1.1_1 05 Apr 2006 20:00:18
 |
remko  |
Document mediawiki -- hardcoded placeholder string security bypass
vulnerability. |
1.1_1 05 Apr 2006 19:50:25
 |
remko  |
Document netpbm -- buffer overflow in pnmtopng. |
1.1_1 05 Apr 2006 19:23:10
 |
remko  |
Document zoo -- stack based buffer overflow. |
1.1_1 05 Apr 2006 19:02:44
 |
remko  |
Document mediawiki -- cross site scripting vulnerability. |
1.1_1 05 Apr 2006 17:37:38
 |
mnag  |
dia -- XFig Import Plugin Buffer Overflow |
1.1_1 05 Apr 2006 14:57:46
 |
mnag  |
openvpn -- LD_PRELOAD code execution on client through malicious or compromised
server
PR: 95343
Submitted by: Matthias Andree <matthias.andree__gmx.de> |
1.1_1 05 Apr 2006 04:33:25
 |
mnag  |
samba -- Exposure of machine account credentials in winbind log files |
1.1_1 05 Apr 2006 03:46:56
 |
brooks  |
Upgrade pubcookie from 3.3.0-beta2 to 3.3.0a fixing serious XSS
vulnerabilities. |
1.1_1 01 Apr 2006 05:01:12
 |
edwin  |
Fill in the version numbers for the vids
6e3b12e2-6ce3-11da-b90c-000e0c2e438a and
82a41084-6ce7-11da-b90c-000e0c2e438a to show which Mantis versions
are vulnerable.
Submitted by: In cooperation with dvl |
1.1_1 30 Mar 2006 06:53:31
 |
simon  |
For horde -- remote code execution vulnerability in the help viewer
entry:
- Add more references.
- Reformat description to follow normal formatting style better.
- Remove a redundant line in the description to make the meaning more
clear. |
1.1_1 29 Mar 2006 19:08:51
 |
mnag  |
freeradius -- EAP-MSCHAPv2 Authentication Bypass |
1.1_1 28 Mar 2006 18:13:15
 |
thierry  |
Add an entry about Horde's remote code execution vulnerability in the
help viewer. |
1.1_1 27 Mar 2006 19:06:54
 |
mnag  |
linux-realplayer -- buffer overrun
linux-realplayer -- heap overflow
Reviewed by: simon |
1.1_1 24 Mar 2006 18:02:29
 |
remko  |
s/8 spaces/tab/ in the sendmail entry.
Noticed by: simon |
1.1_1 24 Mar 2006 17:10:24
 |
remko  |
Record that our sendmail port was also vulnerable.
Bump modification date. |
1.1_1 24 Mar 2006 13:08:54
 |
remko  |
Update the 'Evolution - remote format string vulnerabilities' entry. |
1.1_1 24 Mar 2006 12:25:59
 |
remko  |
Document the latest three FreeBSD Security Advisories:
SA-06:13
SA-06:12
SA-06:11 |
1.1_1 21 Mar 2006 17:05:15
 |
lesi  |
xorg-server -- privilege escalation
Reviewed by: simon |
1.1_1 20 Mar 2006 15:21:49
 |
mnag  |
- heimdal -- Multiple vulnerabilities
Reviewed by: simon |
1.1_1 20 Mar 2006 12:58:16
 |
vd  |
Document ftp/curl's TFTP packet buffer overflow vulnerability
Reworked by: simon
Approved by: security-officer (simon) |
1.1_1 17 Mar 2006 23:24:43
 |
brooks  |
Add drupal <= 4.6.5 vulns. |
1.1_1 15 Mar 2006 21:27:34
 |
thierry  |
Add an entry for Horde < 3.1 (SA19246).
Noticed by: mnag |
1.1_1 15 Mar 2006 07:10:35
 |
simon  |
Document linux-flashplugin -- arbitrary code execution vulnerability. |
1.1_1 12 Mar 2006 21:25:13
 |
remko  |
Document nfs -- remote denial of service (FreeBSD: SA-06:10)
Approved by: portmgr (blanket VuXML) |
1.1_1 12 Mar 2006 19:57:53
 |
remko  |
Add OpenSSH Remote Denial of Service (FreeBSD SA-06:09.openssh) to the
vuxml list.
Approved by: portmgr (Blanket VuXML) |
1.1_1 11 Mar 2006 10:38:11
 |
remko  |
Correct the gpg entry wrt. style.
Approved by: portmgr (Blanket VuXML) |
1.1_1 09 Mar 2006 22:44:23
 |
kuriyama  |
Update to 1.4.2.2.
Security: GnuPG does not detect injection of unsigned data
References:
http://lists.gnupg.org/pipermail/gnupg-announce/2006q1/000216.html
Probbed by: simon
Approved by: portmgr (erwin) |
1.1_1 09 Mar 2006 10:53:15
 |
vd  |
Document multimedia/mplayer's heap overflow in the ASF demuxer
Reviewed by: simon
Approved by: portmgr (implicit), security-officer (simon) |
1.1_1 06 Mar 2006 12:15:26
 |
marius  |
Add the ssh2-nox11 slave port to the list of ports affected by
VID 594ad3c5-a39b-11da-926c-0800209adf0e.
Prodded by: Dmitry Pryanishnikov <dmitry@atlantis.dp.ua>
Approved by: portmgr (erwin) |
1.1_1 04 Mar 2006 17:31:07
 |
marius  |
Document a SSH.COM SFTP server format string vulnerability affecting
the security/ssh2 port.
Approved by: portmgr (erwin) |
1.1_1 04 Mar 2006 15:03:46
 |
naddy  |
Document GNU tar invalid headers buffer overflow.
Approved by: portmgr (erwin) |
1.1_1 27 Feb 2006 20:16:34
 |
remko  |
Remove the pinentry entry. It was gentoo specific and I overlooked
that.
Noticed by: Dejan Lesjak <dejan dot lesjak at ijs dot si>
Pointyhat: remko
Approved by: portmgr (implicit VuXML) |
1.1_1 27 Feb 2006 14:36:53
 |
skv  |
Document Bugzilla [2.*, 2.20.1) vulnerabilities.
Approved by: security-officer (simon)
Approved by: portmgr (implicit) |
1.1_1 24 Feb 2006 19:56:28
 |
delphij  |
Document squirrelmail (< 1.4.6) vulnerabilities:
CVE-2006-0377 (IMAP injection)
CVE-2006-0195 (XSS)
CVE-2006-0188 (XSS)
Approved by: security-officer (simon)
Approved by: portmgr (implicit) |
1.1_1 20 Feb 2006 19:15:17
 |
remko  |
Remove the latest squid entry, it already existed.
Noticed by: Thomas-Martin Seck <tmseck at netcologne dot de> |
1.1_1 20 Feb 2006 16:03:37
 |
remko  |
Document gedit -- format string vulnerability. |
1.1_1 20 Feb 2006 15:43:53
 |
remko  |
Add koffice to the RTF import issue. |
1.1_1 20 Feb 2006 15:17:49
 |
remko  |
Documenet WebCalendar -- unauthorized access vulnerability. |
1.1_1 20 Feb 2006 14:29:51
 |
remko  |
Document abiword -- stack based buffer overflow vulnerabilities. |
1.1_1 20 Feb 2006 12:26:23
 |
remko  |
Document pinentry -- local privilege escalation.
Correct previous entry (the entry time was invalid). |
1.1_1 20 Feb 2006 12:02:10
 |
remko  |
Document squid -- dns lookup spoofing. |
1.1_1 18 Feb 2006 14:22:42
 |
simon  |
Document postgresql81-server -- SET ROLE privilege escalation. |
1.1_1 17 Feb 2006 09:53:59
 |
simon  |
Document gnupg -- false positive signature verification. |
1.1_1 16 Feb 2006 15:05:14
 |
remko  |
Document rssh -- privilege escalation vulnerability.
The port will be marked forbidden due to possible
root access. |
1.1_1 16 Feb 2006 14:33:21
 |
remko  |
Document tor -- malicious tor server can locate a hidden service. |
1.1_1 16 Feb 2006 14:20:23
 |
remko  |
Document sudo -- arbitrary command execution. |
1.1_1 16 Feb 2006 14:08:27
 |
remko  |
Document libtomcrypt -- weak signature scheme with ECC keys. |
1.1_1 16 Feb 2006 13:19:08
 |
remko  |
Document mantis -- "view_filters_page.php" cross site scripting vulnerability. |
1.1_1 16 Feb 2006 12:59:21
 |
remko  |
Document phpbb -- multiple vulnerabilities.
Reviewed by: simon |
1.1_1 16 Feb 2006 12:50:36
 |
remko  |
Document postgresql -- character conversion and tsearch2 vulnerabilities. |
1.1_1 16 Feb 2006 09:08:04
 |
remko  |
Document heartbeat -- insecure temporary file creation vulnerability. |
1.1_1 15 Feb 2006 13:25:56
 |
remko  |
Document kpdf -- heap based buffer overflow |
1.1_1 15 Feb 2006 12:53:21
 |
remko  |
Document perl, webmin, usermin -- perl format string integer wrap vulnerability
PR: ports/91202
Submitted by: KOMATSU Shinichiro <koma2 at lovepeers dot org>
(slightly modified). |
1.1_1 15 Feb 2006 12:33:37
 |
remko  |
Document phpicalendar -- cross site scripting vulnerability and
document phpicalendar -- file disclosure vulnerability [1].
Reviewed by: simon [1]
Spotted on: cvs-ports@ [1] |
1.1_1 14 Feb 2006 10:35:41
 |
remko  |
Document FreeBSD -- Infinite loop in SACK handling (FreeBSD SA 06.08) |
1.1_1 14 Feb 2006 10:28:54
 |
remko  |
Document pf -- IP fragment handling panic, FreeBSD SA 06.07 |
1.1_1 14 Feb 2006 10:09:23
 |
remko  |
Document FreeBSD -- Local kernel memory disclosure
(FreeBSD SA 06.07). |
1.1_1 14 Feb 2006 09:57:32
 |
remko  |
Document IEEE 802.11 -- buffer overflow (FreeBSD SA 06.05). |
1.1_1 14 Feb 2006 08:13:54
 |
remko  |
Add FreeBSD SA 06.04.ipfw to the vuln.xml list. |
1.1_1 07 Feb 2006 20:43:51
 |
simon  |
Mark ivtools 1.2.3 as fixed for jpeg vulnerabilities. Note that this
version is not yet in ports, but marking the new version fixed now
make porting a bit simpler. |
1.1_1 07 Feb 2006 20:09:16
 |
simon  |
Document kpopup -- local root exploit and local denial of service.
PR: ports/92359
Submitted by: Ion-Mihai "IOnut" Tetcu <itetcu@people.tecnik93.com> |
1.1_1 27 Jan 2006 19:07:32
 |
remko  |
Oops. Forgot to modify the discovery date.
Spotted by: simon (again) |
1.1_1 27 Jan 2006 12:20:06
 |
remko  |
Add 4 FreeBSD advisories to the VuXML database.
The other recently released advisories will be
added later today.
o SA-06:03.cpio
o SA-06:02.ee
o SA-06:01.texindex
o SA-05:20.cvsbug |