| Commit message (Collapse) | Author | Age | Files | Lines |
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
254033
252385
Security: CVE-2021-20254
Updated net/samba412 and net/samba413 to fix CVE-2021-20254.
Also fixed:
* Incorrect include line for the bind backend(255415)
* Broken pkg-plist with NO_PYTHON(254033)
* Broken URL parsing in LDAP client(252385)
|
|
|
|
|
| |
Changes: https://github.com/unicode-org/icu/releases/tag/release-69-1
Reported by: GitHub (watch releases)
|
| |
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
| |
> Please ignore the 4.14.1, 4.13.6 and 4.12.13 releases and only use 4.14.2, 4.13.7 and 4.12.14.
Bump samba412 to 4.12.14.
Security: CVE-2020-27840
CVE-2021-20277
Notes:
svn path=/head/; revision=569182
|
|
|
|
|
|
|
|
|
|
| |
Mark net/samba411 s deprecated.
Relnotes: CVE-2020-27840
CVE-2021-20277
Notes:
svn path=/head/; revision=569181
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
With recent versions of clang, samba could dump core shortly after
startup, terminating with either SIGILL or SIGSEGV.
Investigation showed that samba is using C99 variable length arrays
(VLAs), and in some cases the length of these arrays would become zero.
Since this is undefined behavior, various interesting things would
happen, often ending in segfaults.
Fix this by avoiding to use zero as the length for these VLA
declarations.
A similar patch was also sent upstream, and was accepted and included in
subsequent samba releases.
See also: https://bugzilla.samba.org/show_bug.cgi?id=14605
Reported by: Dries Michiels <driesm.michiels@gmail.com>
PR: 252157
MFH: 2021Q1
Notes:
svn path=/head/; revision=563405
|
|
|
|
| |
Notes:
svn path=/head/; revision=559087
|
|
|
|
|
|
|
| |
Reported by: jhibbits (for powerpcspe)
Notes:
svn path=/head/; revision=556601
|
|
|
|
|
|
|
|
|
| |
Changes: http://site.icu-project.org/download/68
ABI: https://abi-laboratory.pro/tracker/timeline/icu4c/
Reported by: GitHub (watch releases)
Notes:
svn path=/head/; revision=553940
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
CVE-2020-14318 (Missing handle permissions check in SMB1/2/3 ChangeNotify)
CVE-2020-14323 (Unprivileged user can crash winbind)
CVE-2020-14383 (An authenticated user can crash the DCE/RPC DNS with easily crafted records)
Security: CVE-2020-14318
CVE-2020-14323
CVE-2020-14383
Notes:
svn path=/head/; revision=553733
|
|
|
|
| |
Notes:
svn path=/head/; revision=552357
|
|
|
|
| |
Notes:
svn path=/head/; revision=550234
|
|
Notes:
svn path=/head/; revision=550233
|