Commit History - (may be incomplete: for full details, see links to repositories near top of page) |
Commit | Credits | Log message |
1.1_1 24 Jan 2006 06:38:31
 |
edwin  |
SHA256ify
Approved by: krion@ |
1.1_1 23 Jan 2006 21:29:47
 |
brooks  |
Document local root exploit in SGE. |
1.1_1 23 Jan 2006 15:35:22
 |
barner  |
Document "fetchmail -- crash when bouncing a message" DOS vulnerability.
Reviewed by: secteam (simon) |
1.1_1 14 Jan 2006 23:36:11
 |
simon  |
- Update description and references for "clamav -- possible heap
overflow in the UPX code" now that more information is available.
- Remove some EOL whitespace. |
1.1_1 10 Jan 2006 14:02:52
 |
ehaupt  |
Add an entry for clamav/clamav-devel
Reviewed by: simon (secteam) |
1.1_1 09 Jan 2006 21:47:30
 |
simon  |
Document milter-bogom -- headerless message crash.
Reported by: Victor Balada Diaz <victor@bsdes.net> |
1.1_1 09 Jan 2006 20:49:54
 |
simon  |
Mark latest bnc version as fixed wrt. to "fd_set -- bitmap index
overflow in multiple applications".
Reported by: Christian Elmerot <Chreo At chreo , net> |
1.1_1 07 Jan 2006 14:56:01
 |
simon  |
Document two bogofilter vulnerabilities.
Submitted by: Matthias Andree <matthias.andree@gmx.de> |
1.1_1 04 Jan 2006 23:00:39
 |
thierry  |
Add an entry for rxvt-unicode < 6.3: root privileges were not restored
before the call to openpty(), so the permissions on the pty device node
remain root:wheel 666 after opening a new terminal.
Discovered by: Ryan Beasley <ryanb (at) rainbowdevilsland.co.uk> |
1.1_1 03 Jan 2006 18:40:54
 |
lev  |
`ru-apache' and `ru-apache+mod_ssl' was patchet against CAN-2005-3352
(http://www.FreeBSD.org/ports/portaudit/9fff8dc8-7aa7-11da-bf72-00123f589060.html)
Yes, changes are validated with xmllint at this time. |
1.1_1 02 Jan 2006 18:32:20
 |
remko  |
Correct a little typo. |
1.1_1 01 Jan 2006 21:40:15
 |
remko  |
Document apache -- mod_imap cross-site scripting flaw.
I expanded the diff from the PR a bit to denote other
affected apache ports as well. Therefor mistakes in
that should be redirected to me.
Also bump the copyright year for the vuxml file.
PR: ports/91157 (based on)
Submitted by: KOMATSU Shinichiro <koma2 at lovepeers dot org> |
1.1_1 01 Jan 2006 09:03:32
 |
hrs  |
Fix the affected versions of 9b4facec-6761-11da-99f6-00123ffe8333.
PR: ports/91156
Submitted by: KOMATSU Shinichiro (koma2 at lovepeers dot org) |
1.1_1 25 Dec 2005 22:23:52
 |
simon  |
Add missing "</package>" tag from rev. 1.917, which caused the file to
be invalid XML and in turn caused the portaudit database to be only
partially built.
Bump modification date of all entries which had modification date on
the 23'rd to make sure VuXML consumers catch the updates.
Portaudit problem reported by: Peter Vohmann
Pointy hat to: lev |
1.1_1 23 Dec 2005 13:33:27
 |
lev  |
russian/apache13 and russian/apache13-modssl were updated and new version
doesn't
contain any known vulnerabilities. |
1.1_1 23 Dec 2005 12:10:22
 |
simon  |
Bump modification date for entries touched by last commit. |
1.1_1 23 Dec 2005 11:47:24
 |
remko  |
Update the phpSysInfo entries, PR ports/90849 will solve the documented
issues.
Requested by: Babak Farrokhi <babak at farrokhi dot net> |
1.1_1 23 Dec 2005 10:29:50
 |
remko  |
Fix another typo in my nbd entry.
Spotted by: Linus Nordberg <linus at nordberg dot se> |
1.1_1 22 Dec 2005 21:25:07
 |
remko  |
Correct a typo.
Submitted by: Linus Nordberg <linus at nordberg dot se> |
1.1_1 22 Dec 2005 21:08:08
 |
remko  |
Update the affected range.
Prodded by: erwin |
1.1_1 22 Dec 2005 21:07:15
 |
remko  |
The previous entry should have read:
Document ndb-server -- buffer overflow vulnerability |
1.1_1 22 Dec 2005 21:05:32
 |
remko  |
: |
1.1_1 22 Dec 2005 16:25:10
 |
garga  |
- Register scponly-4.1 vulnerabilities
PR: ports/90813
Submitted by: maintainer
Security:
https://lists.ccs.neu.edu/pipermail/scponly/2005-December/001027.html |
1.1_1 22 Dec 2005 15:49:32
 |
remko  |
Correct the recent horde entries as per the FDP
(made the entries max 72 chars wide). |
1.1_1 19 Dec 2005 15:14:35
 |
barner  |
Document fetchmail vulnerability:
http://fetchmail.berlios.de/fetchmail-SA-2005-03.txt (CVE-2005-4348)
Reviewed by: secteam (simon@) |
1.1_1 14 Dec 2005 21:51:50
 |
remko  |
Document the following mantis vulnerabilities:
o "t_core_path" file inclusion vulnerability
o "view_filters_page.php" cross-site scripting vulnerability |
1.1_1 11 Dec 2005 21:41:22
 |
thierry  |
- Add entries for several XSS vulnerabilities in Horde, Kronolith, Nag
Turba and Mnemo;
- Fix a typo in the previous Horde entry. |
1.1_1 09 Dec 2005 12:24:22
 |
mnag  |
Add curl -- URL buffer overflow vulnerability
Reviewed by: simon |
1.1_1 07 Dec 2005 21:59:01
 |
mnag  |
Add phpmyadmin -- register_globals emulation "import_blacklist" manipulation
Add phpmyadmin -- XSS vulnerabilities |
1.1_1 07 Dec 2005 11:53:08
 |
mnag  |
Add ffmpeg -- libavcodec buffer overflow vulnerability
Reviewed by: simon |
1.1_1 07 Dec 2005 11:34:34
 |
mnag  |
Add trac -- search module SQL injection vulnerability
Reviewed by: simon |
1.1_1 01 Dec 2005 16:08:47
 |
mnag  |
Add drupal -- multiple vulnerabilities
Reviewed by: simon |
1.1_1 30 Nov 2005 20:55:37
 |
simon  |
Document opera -- multiple vulnerabilities. |
1.1_1 30 Nov 2005 20:35:51
 |
simon  |
Document opera -- command line URL shell command injection. |
1.1_1 30 Nov 2005 13:41:54
 |
mnag  |
Add entry to www/mambo
Reviewed by: simon |
1.1_1 29 Nov 2005 08:46:13
 |
simon  |
Backup rev 1.9 which should not have been committed since it was just my
local hack.
Note to self: Do not commit before having at least two cups of coffee.
Pointy hat to: simon |
1.1_1 29 Nov 2005 08:41:52
 |
simon  |
Mark flyspar 0.9.8 as fixed wrt. "flyspray -- cross-site scripting
vulnerabilities" since our port version of 0.9.8 includes update1 which
fixes the issue.
Reported by: Volodymyr Kostyrko via pav |
1.1_1 28 Nov 2005 15:37:04
 |
mnag  |
Change topic zope28 to zope (www/zope affected too)
Add <cvename> to zope entry
Change CAN-XXXX-XXXX to CVE-XXXX-XXXX
Reviewed by: simon |
1.1_1 27 Nov 2005 17:57:19
 |
hrs  |
Security fix: several shell scripts included in the Ghostscript package
allow local users to overwrite files via a symlink attack on temporary
files.
Security: CAN-2004-0967 |
1.1_1 26 Nov 2005 10:58:05
 |
remko  |
Forced commit to notice that I also added some references to the
latest horde entry. |
1.1_1 26 Nov 2005 10:54:22
 |
remko  |
Standarize the horde -- Cross site scripting vulnerabilities in MIME
viewers entry as per the FDP-primer and the vuxml layout (topic).
Also correct the qpopper vulnerability to match 4.0 and above since
the 2.x range is listed as affected at the moment but has an entirely
different base. After checking it appears that the information all
point to >= 4.0. [1]
Noticed by: ache [1] |
1.1_1 22 Nov 2005 19:56:54
 |
thierry  |
Add an entry for cross site scripting vulnerabilities in Horde's MIME
viewers. |
1.1_1 16 Nov 2005 14:17:44
 |
mnag  |
phpmyadmin -- HTTP Response Splitting vulnerability
Reviewed by: simon |
1.1_1 14 Nov 2005 16:57:26
 |
simon  |
Add CVE name to an old sudo entry. |
1.1_1 14 Nov 2005 08:45:09
 |
simon  |
Update latest phpSysInfo entry to reflect that 2.4 was in fact not fixed
(or rather, had an incorrect "fix").
Reported by: Christopher Kunz (advisory author)
Security: http://www.hardened-php.net/advisory_222005.81.html |
1.1_1 13 Nov 2005 21:39:56
 |
sem  |
- Micromedia -> Macromedia
- Standard FDP primer documentation rules apply
- Two dots fixed
Noted by: remko |
1.1_1 13 Nov 2005 21:21:16
 |
sem  |
- Document phpSysInfo vulnerability |
1.1_1 13 Nov 2005 20:59:47
 |
sem  |
- Document flashplugin vulnerability |
1.1_1 10 Nov 2005 11:09:56
 |
sem  |
- Document p5-Mail-SpamAssassin vulnerabily (alread fixed in ports)
- Document flyspray cross-site scripting vulnerabilities |
1.1_1 08 Nov 2005 17:34:40
 |
remko  |
Update the recent gallery2 and webcalendar entries:
o Add a better topic (description)
o Reword the webcalendar entry to have some more usefull data
o Add references (bid's and CVE names). |
1.1_1 07 Nov 2005 20:44:06
 |
remko  |
Document qpopper -- multiple privilege escalation vulnerabilities.
Note that the current version is not affected anymore. |
1.1_1 06 Nov 2005 17:28:04
 |
sem  |
- Add missed </p> tag [1]
- Modify 594eb447-e398-11d9-a8bd-000cf18bbe54 entry:
ruby 1.6.x is not affected this vulnerability,
it have no XMLRPC support.
Pointy hat to: simon [1] |
1.1_1 04 Nov 2005 22:49:34
 |
simon  |
Add a bit more info from the PEAR advisory about the vulnerability to
make the scope of the vulnerability a bit more clear.
Disussed with: thierry |
1.1_1 04 Nov 2005 22:35:06
 |
simon  |
The two latest OpenVPN vulnerabilities were both only for 2.0 and
newer, so mark the correctly as such.
Submitted by: Matthias Andree <matthias.andree@gmx.de> |
1.1_1 04 Nov 2005 21:23:28
 |
thierry  |
Add an entry for pear-PEAR arbitrary code execution vulnerability. |
1.1_1 02 Nov 2005 10:16:51
 |
simon  |
Correct skype entry to match the correct fixed port version number.
Noted by: Stefan Lambrev, cheffo FreeBSD-BG org |
1.1_1 01 Nov 2005 22:49:20
 |
simon  |
Document two OpenVPN vulnerabilities.
Submitted by: Matthias Andree <matthias.andree@gmx.de> |
1.1_1 01 Nov 2005 21:39:25
 |
naddy  |
As Peter Jeremy points out, the recent lynx vulnerability also concerns
lynx-ssl. |
1.1_1 01 Nov 2005 09:33:41
 |
sem  |
- Document skype vulnerabilities
- Document PHP vulnerabilities
- Convert first letters in titles from upcase to lowercase
in my last additions. |
1.1_1 01 Nov 2005 08:44:37
 |
sem  |
- Document CVE-2005-3258:
Squid FTP Server Response Handling Denial of Service |
1.1_1 31 Oct 2005 19:03:13
 |
sem  |
- Document a BASE Basic Analysis and Security Engine vulnerability |
1.1_1 31 Oct 2005 18:02:10
 |
simon  |
Back out the accidentally committed white-space modification parts of
rev. 1.869, but keep the lynx entry.
Pointy hat to: naddy
OK'ed by: naddy |
1.1_1 31 Oct 2005 09:04:22
 |
barner  |
Add entry for "fetchmail -- fetchmailconf local password exposure",
which was fixed with fetchmail-6.2.5.2_1 and above. |
1.1_1 30 Oct 2005 22:17:55
 |
naddy  |
Document lynx remote buffer overflow in NNTP header handling. |
1.1_1 27 Oct 2005 19:40:25
 |
sem  |
- Fix a ruby vulnerabuility in the safe level settings.
Based on: ports/87816
Submitted by: Phil Oleson <oz@nixil.net>
Security:
http://vuxml.FreeBSD.org/1daea60a-4719-11da-b5c6-0004614cc33d.html |
1.1_1 26 Oct 2005 19:53:25
 |
simon  |
Add more references to entry net-snmp -- remote DoS vulnerability. |
1.1_1 26 Oct 2005 10:00:18
 |
simon  |
- Mark linux-firefox 1.0.7 as fixed
wrt. 8665ebb9-2237-11da-978e-0001020eed82 (Mozilla/firefox IDN buffer
overflow) [1].
- Correct some of the the earlier linux-firefox entries to match
versions before 1.0.7, not after (whoops)...
Prodded by: Andrew P. <infofarmer@gmail.com> [1] |
1.1_1 25 Oct 2005 19:52:37
 |
lesi  |
Add misc/compat5x to "openssl -- potential SSL 2.0 rollback".
Reviewed by: simon |
1.1_1 23 Oct 2005 17:10:48
 |
simon  |
Also mark xli as vulnerable to xloadimage -- buffer overflows in NIFF
image title handling, and latest port version as fixed.
Reported by: jkoshy |
1.1_1 23 Oct 2005 16:50:43
 |
simon  |
For entry libgadu -- multiple vulnerabilities:
- Mark latest centericq port version as fixed.
- Fix cite in description. |
1.1_1 23 Oct 2005 09:09:47
 |
simon  |
For entry zope28 -- expose RestructuredText functionality to untrusted
users:
- Do not match zope 2.7.8 which has been fixed. [1]
- Fix typo in topic.
- Add another reference.
Reported by: Gerhard Schmidt <estartu augusta de> [1] |
1.1_1 22 Oct 2005 13:41:20
 |
simon  |
Add another reference to clamav -- arbitrary code execution and DoS
vulnerabilities entry. |
1.1_1 20 Oct 2005 13:52:35
 |
naddy  |
Document x11/xloadimage buffer overflows in NIFF image title handling. |
1.1_1 19 Oct 2005 18:17:47
 |
nectar  |
Rename all CAN-yyyy-nnnn to CVE-yyyy-nnnn, with the exception of text
inside <blockquote>s.
See <URL:http://www.cve.mitre.org/cve/renumber.html>. |
1.1_1 18 Oct 2005 19:45:58
 |
simon  |
For entry: snort -- Back Orifice preprocessor buffer overflow vulnerability:
- Sort references.
- Add ISS advisory to references. |
1.1_1 18 Oct 2005 17:42:14
 |
simon  |
- Document snort -- Back Orifice preprocessor buffer overflow vulnerability.
- Use standard topic format for webcalendar entry.
- Fix package name in webcalendar so it matches the actual package
name. |
1.1_1 14 Oct 2005 21:57:41
 |
sem  |
- Document www/webcalendar vulnerability. |
1.1_1 14 Oct 2005 21:38:08
 |
sem  |
- Document www/gallery2 vulnerability. |
1.1_1 12 Oct 2005 22:53:00
 |
simon  |
Improve last couple of entries:
- Use standard topic format.
- Fix packagename in phpmyadmin and zone entries.
- Fix indention and remove EOL white-space.
- Make lead in a bit more verbose.
- Add more references to phpmyadmin issue.
- Remove some redundant quoted text in zope issue. |
1.1_1 12 Oct 2005 14:51:14
 |
mnag  |
Add entry for openssl
Remove entry about safe mode in phpmyadmin |
1.1_1 12 Oct 2005 00:24:39
 |
mnag  |
Add entry for phpmyadmin (PMASA-2005-4) |
1.1_1 12 Oct 2005 00:12:21
 |
mnag  |
Fix typo with range values |
1.1_1 12 Oct 2005 00:01:03
 |
mnag  |
Add entry from zope28 |
1.1_1 09 Oct 2005 21:03:07
 |
simon  |
For libxine -- format string vulnerability entry:
- Add reference to xine security announcement.
- Fix indention on a few lines. |
1.1_1 09 Oct 2005 16:14:41
 |
nobutaka  |
Add an entry for libxine format string vulnerability. |
1.1_1 09 Oct 2005 10:14:28
 |
simon  |
Mark older revisions linux_base-suse 9.3 as vulnerable to kdebase --
Kate backup file permission leak. |
1.1_1 07 Oct 2005 07:31:51
 |
sergei  |
- Mark cfengine's arbitrary file overwriting vulnerability as fixed in 2.1.6_1
- Add another possible variant of package name - cfengine2 |
1.1_1 05 Oct 2005 17:44:06
 |
thierry  |
Add an entry for UW-IMAP Mailbox Name Handling Remote Buffer Overflow
Vulnerability (CAN-2005-2933). |
1.1_1 05 Oct 2005 15:55:08
 |
ehaupt  |
Add credit for recent ftp/weex incident
Approved by: novel (mentor) |
1.1_1 04 Oct 2005 13:23:00
 |
garga  |
rinetd >= 0.62_1 has no more vulnerabilities |
1.1_1 02 Oct 2005 20:10:42
 |
remko  |
Add references to three squid entries.
Submitted by: Thomas-Martin Seck <tmseck at netcologne dot de>
(except for the bid's which i added myself). |
1.1_1 02 Oct 2005 17:46:23
 |
simon  |
Use the <freebsdpr> tag to markup a PR in weex -- remote format string
vulnerability entry. |
1.1_1 02 Oct 2005 16:11:30
 |
jylefort  |
Document a format string vulnerability in ftp/weex. |
1.1_1 02 Oct 2005 07:45:29
 |
simon  |
Document picasm -- buffer overflow vulnerability. |
1.1_1 01 Oct 2005 16:43:38
 |
nobutaka  |
Add an URL to the entry of the japanese/uim. |
1.1_1 01 Oct 2005 16:35:20
 |
nobutaka  |
Document japanese/uim privilege escalation vulnerability. |
1.1_1 01 Oct 2005 15:21:57
 |
simon  |
Document cfengine -- arbitrary file overwriting vulnerability. |
1.1_1 01 Oct 2005 10:17:19
 |
remko  |
Mark zsync <= 0.4.1 vulnerable to the zlib buffer overflow vulnerability.
Inspired by: gordon's commit |
1.1_1 01 Oct 2005 08:40:58
 |
simon  |
Add more references to unace -- multiple vulnerabilities entry. |
1.1_1 01 Oct 2005 07:14:34
 |
simon  |
Add CVE name to an older ProZilla entry. |