aboutsummaryrefslogtreecommitdiff
path: root/security
Commit message (Collapse)AuthorAgeFilesLines
* MFH: r464085, r464247Tijl Coosemans2018-03-157-15/+19
| | | | | | | | | | | - Update security/polarssl13 to 1.3.22. - Update security/mbedtls to 2.7.1 and bump dependent ports. Security: https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security-advisory-2018-01 Approved by: ports-secteam (swills) Notes: svn path=/branches/2018Q1/; revision=464595
* MFH: r463768Yuri Victorovich2018-03-112-0/+24
| | | | | | | | | | | | | | security/strongswan: Fix crash in public key authentication with 5.6.2 While here, added LICENSE_FILE. PR: 226404 Submitted by: strongswan@Nanoteq.com (maintainer) Approved by: tcberner (mentor, implicit) Approved by: ports-secteam (lists@eitanadler.com) Notes: svn path=/branches/2018Q1/; revision=464151
* MFH: r458993 r463489Mark Felder2018-03-104-13/+12
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | security/tor: Update to 0.3.2.9 This release contains many new features and many bugfixes. Plesee see the complete list here: https://blog.torproject.org/tor-0329-released-we-have-new-stable-series Additionally, this update adds "#include <osreldate.h>" to qualm the compiler warning that was caused by the previous fix. Now security/tor and security/tor-devel are identical. security/tor: Update to 0.3.2.10 Backport of countermeasures to mitigate denial-of-service attacks against the Tor network. Changelog is in: https://gitweb.torproject.org/tor.git/tree/ChangeLog None of these fixes appear to be essential for clients, but relays should upgrade. Port changes: * Changed the implementation of 'tor_setuid': now it is done through the command line argument, instead of the torrc file. Notes: svn path=/branches/2018Q1/; revision=464074
* MFH: r463696Jan Beich2018-03-097-37/+78
| | | | | | | | | | | | security/nss: update to 3.36 Changes: https://developer.mozilla.org/docs/Mozilla/Projects/NSS/NSS_3.36_release_notes Changes: https://hg.mozilla.org/projects/nss/shortlog/NSS_3_36_RTM ABI: https://abi-laboratory.pro/tracker/timeline/nss/ Approved by: ports-secteam (riggs) Notes: svn path=/branches/2018Q1/; revision=463940
* MFH: r463323Renato Botelho2018-03-053-9/+18
| | | | | | | | | | | | | | | | - Update security/strongswan to 5.6.2 [1] - Enable CURL option by default [2] PR: 226043 [1], 220488 [2] Submitted by: strongswan@Nanoteq.com (maintainer) [1] karl@denninger.net [2] Approved by: maintainer [2] Security: CVE-2018-6459 Sponsored by: Rubicon Communications, LLC (Netgate) Approved by: ports-secteam (riggs) Notes: svn path=/branches/2018Q1/; revision=463645
* MFH: r463540Jan Beich2018-03-032-5/+24
| | | | | | | | | | | | security/clamfs: unbreak with boost 1.65 PR: 220725 Submitted by: Walter Schwarzenfeld <w.schwarzenfeld@utanet.at> Approved by: maintainer timeout (7 months) Approved by: ports-secteam blanket Notes: svn path=/branches/2018Q1/; revision=463541
* MFH: r463407Larry Rosenman2018-03-022-4/+4
| | | | | | | | | | | | | | | | | | security/clamav: upgrade to 0.99.4 Release notes: http://blog.clamav.net/2018/03/clamav-0994-has-been-released.html Submitted by: mmokhi Security: CVE-2012-6706 Security: CVE-2017-6419 Security: CVE-2017-11423 Security: CVE-2018-1000085 Security: CVE-2018-0202 Differential Revision: https://reviews.freebsd.org/D14562 Approved by: ports-secteam (zi) Notes: svn path=/branches/2018Q1/; revision=463453
* MFH: r461924 r462351 r462460Craig Leres2018-03-023-21/+37
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | Use USE_GITHUB instead of hand crafting urls. Sponsored by: Absolight Add a NETMAP option to build and install the bro netmap plugin. PR: 224918 Reported by: Shane Peters Reviewed by: matthew (mentor) Approved by: matthew (mentor) Differential Revision: https://reviews.freebsd.org/D14378 Update to 2.5.3 which fixes an integer overflow: http://blog.bro.org/2018/02/bro-253-released-security-update.html Note that a CVE has not been assigned yet. Reviewed by: matthew (mentor) Approved by: matthew (mentor) Differential Revision: https://reviews.freebsd.org/D14444 Approved by: ports-secteam (swills) Notes: svn path=/branches/2018Q1/; revision=463362
* MFH: r462211Antoine Brodin2018-02-181-0/+2
| | | | | | | | | Mark BROKEN: fails to package Reported by: pkg-fallout Notes: svn path=/branches/2018Q1/; revision=462212
* MFH: r460718Kurt Jaeger2018-02-034-16/+15
| | | | | | | | | | | | | | | | | security/softether: update 4.20.9608 -> 4.25.9656 - There are 11 vulnerabilities on SoftEther VPN. There vulnerabilities are found by the source code audit process conducted by Max Planck Institute for Molecular Genetics and Mr. Guido Vranken in late 2017. This build fixes all of these vulnerabilities. PR: 225618 Submitted by: net@arrishq.net (maintainer) Relnotes: http://www.softether.org/5-download/history Approved by: portmgr (swills) Notes: svn path=/branches/2018Q1/; revision=460792
* MFH: r457913Mark Felder2018-02-022-76/+79
| | | | | | | | | | | | | | | | | | | Update to upstream version 0.0.62 Detailed maintainer log: - v0.0.62: Miscellaneous tweaks - Updated Let's Encrypt agreement URL in example response file. - Now builds for current Go 1.x version in Travis rather than Go 1.8. - More error details are now available for challenge errors in the acmeapi package. - Error when trying to prompt the user in non-interactive mode now advises user to remove --batch flag. PR: 224627 Submitted by: samm@os2.kiev.ua (maintainer) Notes: svn path=/branches/2018Q1/; revision=460685
* MFH: r460648Mark Felder2018-02-012-1/+21
| | | | | | | | | security/snort3: Fix build with FreeBSD 10.3 Reference: https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=210890 Notes: svn path=/branches/2018Q1/; revision=460649
* MFH: r460389 r460412 r460638 r460641Mark Felder2018-02-013-21/+61
| | | | | | | | | | | | | | | | | | | | | | | | Upgrade to build 242 Approved by: feld (maintainer) Unbreak last commit. Pointy hat: dvl Sponsored by: Absolight security/snort3: Update to Alpha BUILD_242 - Use cmake now as autotools will be going away - Fix segfaulting which was actually caused by devel/hwloc security/snort3: Bump PORTREVISION Bump for sanity Add missing DOCS to OPTIONS_DEFINE Notes: svn path=/branches/2018Q1/; revision=460642
* MFH: r459458 r460255Jan Beich2018-01-316-22/+35
| | | | | | | | | | | | security/nss: update to 3.35 Changes: https://developer.mozilla.org/docs/Mozilla/Projects/NSS/NSS_3.35_release_notes Changes: https://hg.mozilla.org/projects/nss/shortlog/NSS_3_35_RTM ABI: https://abi-laboratory.pro/tracker/timeline/nss/ Approved by: ports-secteam (swills) Notes: svn path=/branches/2018Q1/; revision=460533
* MFH: r459048 r459972Larry Rosenman2018-01-264-32/+9
| | | | | | | | | | | | | | | | | | | | | | | | | | security/clamav: remove LHA from default options. r459039 made distribution of the lha binary not allowed. PR: 225180 Submitted by: antoine security/clamav: upgrade to 0.99.3. * Update to 0.99.3. * Fix following portlint warnings. ** Move position of USES in Makefile. ** Remove reference of undefined LLVM option. ** Regenerate files/patch-libclamav_regex_pcre.c by 'make makepatch ** add USES=ssl PR: 225461 Submitted by: yasu@utahime.org Approved by: ports-secteam (swills) Security: b464f61b-84c7-4e1c-8ad4-6cf9efffd025 Notes: svn path=/branches/2018Q1/; revision=459992
* Merge missed commit needed by r459482Steve Wills2018-01-194-0/+32
| | | | | | | | | | | | | | | | MFH: r458139 security/rubygem-rbnacl4: create port 4.x version required by gitlab PR: 224931 Submitted by: Matthias Fechner <idefix@fechner.net> (maintainer) Approved by: ports-secteam (implicit) Notes: svn path=/branches/2018Q1/; revision=459484
* Pull in GitLab security update and all commits needed for it to run properlySteve Wills2018-01-192-4/+4
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Approved by: ports-secteam (implicit) MFH: r457863 r457866 r457872 r457873 r457876 r457879 r457890 r457898 r457899 r458098 r458142 r458267 r458333 r458634 r458650 r458652 r459076 r459170 r459191 r459256 r459284 r459288 r459346 textproc/rubygem-twitter-text: add required dependency on rubygem-idn-ruby PR: 224838 Submitted by: Matthias Fechner <idefix@fechner.net> www/gitlab: fix Gemfile for updated dependencies PR: 224836 Submitted by: Matthias Fechner <idefix@fechner.net> (maintainer) Add rubygem-redis3 3.3.5 (copied from rubygem-redis) - Add PORTSCOUT Add rubygem-jwt1 1.5.6 (copied from rubygem-jwt) - Add PORTSCOUT Update to 4.0.1 Changes: https://github.com/redis/redis-rb/blob/master/CHANGELOG.md Update to 2.1.0 Changes: https://github.com/jwt/ruby-jwt/releases Change RUN_DEPENDS from rubygem-redis and rubygem-jwt to rubygem-redis3 and rubygem-jwt1 - Bump PORTREVISION for dependency change devel/rubygem-licensee: update to 9.6.0 PR: 224758 Approved by: Matthias Fechner <idefix@fechner.net> (maintainer www/gitlab: remove spurious newline Reported by: sunpoet Pointyhat to: swills security/rubygem-rbnacl: update to 5.0.0 www/gitlab: fix Gemfile for updated dependencies PR: 224932 Submitted by: Matthias Fechner <idefix@fechner.net> (maintainer) Fix Gemfile for rubygem-fog-core 2.0.0 update - Bump PORTREVISION for package change Fix Gemfile for rubygem-jquery-atwho-rails 1.5.4 update - Bump PORTREVISION for package change Fix Gemfile for rubygem-fog-google 1.0.0 update - Bump PORTREVISION for package change Fix gitlab issue by creating rubygem-licensee8 PR: 225047 Submitted by: Matthias Fechner <idefix@fechner.net> (maintainer) devel/rubygem-licensee: update to 9.7.0 PR: 224999 Approved by: Matthias Fechner <idefix@fechner.net> (maintainer) textproc/rubygem-rouge: update to 3.1.0 PR: 224785 Approved by: maintainer timeout (kuriyama, > 2 weeks) textproc/rubygem-rouge2: create port for 2.x ver Needed by GitLab textproc/rubygem-rouge2: add missing PKGNAMESUFFIX Pointyhat to: swills Reported by: antoine textproc/rubygem-rouge2: add conflict www/rubygem-gollum-lib: depend on 2.x version of rouge This version is required by gollum-lib www/gitlab: update to 10.1.6 Approved by: idefix@fechner.net (maintainer, via private email) Obtained from: http://gitlab.toco-domains.de/FreeBSD/GitLab/commits/10.1 Security: 65fab89f-2231-46db-8541-978f4e87f32a Mark CONFLICTS_INSTALL with rubygems-rouge2 Notes: svn path=/branches/2018Q1/; revision=459482
* MFH: r458856Kurt Jaeger2018-01-192-4/+4
| | | | | | | | | | | | | security/trousers: fix distinfo - see the PR for the diff between the two distfiles PR: 221105 Approved by: hrs (maintainer timeout) Approved by: portmgr Notes: svn path=/branches/2018Q1/; revision=459452
* MFH: r457965 r458047Richard Gallamore2018-01-1124-23/+54
| | | | | | | | | | | | | | | | | | | | Update devel/json-c to 0.13 - Add TEST_TARGET - While I'm here, fix shebang for net/opensips - Bump PORTREVISION of dependent ports for shlib change Changes: https://github.com/json-c/json-c/blob/master/ChangeLog PR: 224675 Exp-run by: antoine * Revision bump for libevhtp * Fix build errors for updated libevhtp Approved by: ports-secteam (swills) Notes: svn path=/branches/2018Q1/; revision=458710
* MFH: r458625Dmitry Marakasov2018-01-101-2/+10
| | | | | | | | | | - Fix build on mips by disabling unknown warning flag Approved by: portmgr blanket With hat: ports-secteam Notes: svn path=/branches/2018Q1/; revision=458626
* MFH: r458622Dmitry Marakasov2018-01-101-2/+3
| | | | | | | | | | | - Don't try to use lib32 directory, fixes build on mips - While here, tiny whitespace fix With hat: ports-secteam Approved by: portmgr blanket Notes: svn path=/branches/2018Q1/; revision=458623
* MFH: r458103Jan Beich2018-01-051-11/+2
| | | | | | | | | | | security/gnutls: revert r431494 per FreeBSD 11.0 EOL PR: 216045 Approved by: portmgr blanket Approved by: ports-secteam blanket Notes: svn path=/branches/2018Q1/; revision=458106
* Remove expired ports:Rene Ladan2018-01-015-205/+0
| | | | | | | | | | 2017-12-31 security/gnupg20: Will reach EOL upstream on 2017-12-31 2018-01-01 dns/dualserver: Please migrate to dns/dnsmasq. Over the years dualserver becomes unmaintenaible. 2018-01-01 devel/p5-Parse-Pidl44: yes 2018-01-01 sysutils/DTraceToolkit: Now maintained as part of the base system Notes: svn path=/head/; revision=457766
* security/gpa: update instructions to use the port actually used.Rene Ladan2018-01-011-1/+1
| | | | Notes: svn path=/head/; revision=457764
* security/webfwlog: update 1.01 -> 1.1.0Kurt Jaeger2017-12-314-75/+95
| | | | | | | | | | | | | - unbreak, remove DEPRECATED, EXPIRATION_DATE - PORTREVISION needed because 1.1.0 is not larger than 1.01 PR: 219755 Submitted by: zeus@ix.netcom.com (maintainer) Changes: https://sourceforge.net/p/webfwlog/code/HEAD/tree/webfwlog/trunk/ChangeLog Relnotes: https://sourceforge.net/p/webfwlog/code/HEAD/tree/webfwlog/trunk/ReleaseNotes Notes: svn path=/head/; revision=457724
* Update to 4.16.28Antoine Brodin2017-12-312-4/+5
| | | | Notes: svn path=/head/; revision=457705
* Update to 0.1.10Antoine Brodin2017-12-312-4/+4
| | | | Notes: svn path=/head/; revision=457702
* Update to 0.2.16Antoine Brodin2017-12-312-4/+4
| | | | Notes: svn path=/head/; revision=457701
* Update to 20171231Antoine Brodin2017-12-312-4/+4
| | | | Notes: svn path=/head/; revision=457700
* Update to 20171230Antoine Brodin2017-12-312-4/+4
| | | | Notes: svn path=/head/; revision=457699
* Update to 20171228Antoine Brodin2017-12-312-4/+4
| | | | Notes: svn path=/head/; revision=457698
* security/vuxml: Fix FreeBSD PR bugs referencesDanilo G. Baio2017-12-311-3/+6
| | | | Notes: svn path=/head/; revision=457696
* - update to 0.7.3Olli Hauer2017-12-313-24/+31
| | | | Notes: svn path=/head/; revision=457688
* security/rubygem-omniauth-saml: update to 1.8.1Steve Wills2017-12-312-4/+4
| | | | Notes: svn path=/head/; revision=457670
* security/clamav: handle memfs/tmpfs /var/run.Larry Rosenman2017-12-303-2/+23
| | | | | | | | PR: 224728 Submitted by: O. Harmann <ohartmann@walstatt.org> Notes: svn path=/head/; revision=457649
* security/vault: Update to 0.9.1Steve Wills2017-12-302-5/+5
| | | | | | | | PR: 224635 Submitted by: Dani <i.dani@outlook.com> Notes: svn path=/head/; revision=457625
* Update to 1.8.1Sunpoet Po-Chuan Hsieh2017-12-302-4/+4
| | | | | | | Changes: https://github.com/omniauth/omniauth/commits/master Notes: svn path=/head/; revision=457622
* security/vuxml: Document vulnerabilities in www/otrsDanilo G. Baio2017-12-301-0/+49
| | | | | | | | | | | | Security: CVE-2017-16664 Security: CVE-2017-16854 Security: CVE-2017-16921 PR: 224729 Reported by: Vidar Karlsen <vidar@karlsen.tech> Notes: svn path=/head/; revision=457604
* Fix cut-n-paste error in the previous addition for bouncycastle15Eugene Grosbein2017-12-291-1/+1
| | | | | | | (6a131fbf-ec76-11e7-aa65-001b216d295b). Notes: svn path=/head/; revision=457503
* Document security defect in the Bouncy Castle Crypto APIs: CVE-2017-13098 ↵Eugene Grosbein2017-12-291-0/+31
| | | | | | | | | | ("ROBOT") Obtained from: https://www.bouncycastle.org/releasenotes.html Security: https://vuxml.FreeBSD.org/freebsd/6a131fbf-ec76-11e7-aa65-001b216d295b Notes: svn path=/head/; revision=457501
* Simplify some USES=pythonAntoine Brodin2017-12-293-3/+3
| | | | | | | With hat: portmgr Notes: svn path=/head/; revision=457499
* Update to 1.8.0Sunpoet Po-Chuan Hsieh2017-12-282-4/+4
| | | | | | | Changes: https://github.com/omniauth/omniauth/commits/master Notes: svn path=/head/; revision=457458
* devel/google{test,mock}: update to 1.8.0.450Jan Beich2017-12-271-1/+1
| | | | | | | Changes: https://github.com/google/googletest/compare/f1a87d7...5490beb Notes: svn path=/head/; revision=457386
* Fix build on arm (the port is for 32-bit only). While here, canonicalizeMark Linimon2017-12-271-4/+4
| | | | | | | the ARCH statements. Notes: svn path=/head/; revision=457382
* security/afl: Switch to devel/llvm50Tobias Kortkamp2017-12-271-1/+5
| | | | | | | | | | and follow Mesa, Beignet, gecko@, USES=compiler:c++14-lang PR: 224619 Submitted by: jbeich Notes: svn path=/head/; revision=457379
* Update security/erlang-fast_tls to 1.0.18Babak Farrokhi2017-12-272-4/+4
| | | | Notes: svn path=/head/; revision=457365
* Deprecate ports broken for more than 6 monthsAntoine Brodin2017-12-274-0/+8
| | | | Notes: svn path=/head/; revision=457358
* security/otpw: set LLD_UNSAFE to avoid linking with lldEd Maste2017-12-271-0/+1
| | | | | | | | | | | | | lld does not have built-in search paths, so direct link invocations that specify a library (e.g. -lcrypto) but do not specify a search path (e.g. -L/usr/lib) will fail. PR: 214864 Submitted by: krion Approved by: portmgr (LLD_UNSAFE blanket) Notes: svn path=/head/; revision=457344
* Update to 1.7.0Sunpoet Po-Chuan Hsieh2017-12-262-4/+4
| | | | | | | Changes: https://github.com/nov/rack-oauth2/commits/master Notes: svn path=/head/; revision=457340
* Update to 1.03Sunpoet Po-Chuan Hsieh2017-12-262-4/+4
| | | | | | | Changes: http://search.cpan.org/dist/Digest-SHA3/Changes Notes: svn path=/head/; revision=457337