Link [ pkgsrc | NetBSD | pkgsrc git mirror | PR fulltext-search | netbsd commit viewer ]


   
        usage: [branch:branch] [user:user] [path[@revision]] keyword [... [-excludekeyword [...]]] (e.g. branch:MAIN pkgtools/pkg)




switch to index mode

recent branches: MAIN (55m)  pkgsrc-2024Q1 (15d)  pkgsrc-2023Q4 (43d)  pkgsrc-2023Q2 (75d)  pkgsrc-2023Q3 (154d) 

2024-05-13 16:55:17 UTC Now

2014-09-26 13:54:38 UTC MAIN commitmail json YAML

Updated lang/go to 1.3.2

(wiz)

2014-09-26 13:54:28 UTC MAIN commitmail json YAML

Update to 1.3.2 for a security fix:

We've just released Go version 1.3.2, a minor point release.

This release includes bug fixes to cgo and the crypto/tls package.
    https://golang.org/doc/devel/release.html#go1.3.minor

The crpyto/tls fix addresses a security bug that affects programs
that use crypto/tls to implement a TLS server from Go 1.1 onwards.
If the server enables TLS client authentication using certificates
(this is rare) and explicitly sets SessionTicketsDisabled to true
in the tls.Config, then a malicious client can falsely assert
ownership of any client certificate it wishes. This issue was
discovered internally and there is no evidence of exploitation.

(wiz)

2014-09-26 13:39:34 UTC MAIN commitmail json YAML

Mark explicitly as broken due to incompatibility with current versions
of libwpg and co.

(joerg)

2014-09-26 10:55:32 UTC MAIN commitmail json YAML

SunOS requires -lsocket -lnsl.

(jperkin)

2014-09-26 10:46:40 UTC MAIN commitmail json YAML

Updated sysutils/xenkernel41 to 4.1.6.1nb11

(bouyer)

2014-09-26 10:45:00 UTC MAIN commitmail json YAML

Add patch for:
XSA-104 (CVE-2014-7154) - Race condition in HVMOP_track_dirty_vram
XSA-105 (CVE-2014-7155) - Missing privilege level checks in x86 HLT, LGDT,
  LIDT, and LMSW emulation
XSA-106 (CVE-2014-7156) - Missing privilege level checks in x86 emulation
  of software interrupts

bump PKGREVISION

(bouyer)

2014-09-26 10:42:10 UTC MAIN commitmail json YAML

Updated sysutils/xenkernel42 to 4.2.5
Updated sysutils/xentools42 to 4.2.5

(bouyer)

2014-09-26 10:40:45 UTC MAIN commitmail json YAML

Update xentools42 and xenkernel42 to Xen 4.2.5, fixing:
CVE-2014-2599 / XSA-89 HVMOP_set_mem_access is not preemptible
CVE-2014-3124 / XSA-92 HVMOP_set_mem_type allows invalid P2M entries to be
  created
CVE-2014-3967,CVE-2014-3968 / XSA-96 Vulnerabilities in HVM MSI injection
CVE-2014-4021 / XSA-100 Hypervisor heap contents leaked to guests

pkgsrc also includes patches from the Xen Security Advisory:
XSA-104 (CVE-2014-7154) - Race condition in HVMOP_track_dirty_vram
XSA-105 (CVE-2014-7155) - Missing privilege level checks in x86 HLT, LGDT,
  LIDT, and LMSW emulation
XSA-106 (CVE-2014-7156) - Missing privilege level checks in x86 emulation
  of software interrupts

(bouyer)

2014-09-26 10:39:32 UTC MAIN commitmail json YAML

Update xentools42 and xenkernel42 to Xen 4.2.5, fixing:
CVE-2014-2599 / XSA-89 HVMOP_set_mem_access is not preemptible
CVE-2014-3124 / XSA-92 HVMOP_set_mem_type allows invalid P2M entries to be
  created
CVE-2014-3967,CVE-2014-3968 / XSA-96 Vulnerabilities in HVM MSI injection
CVE-2014-4021 / XSA-100 Hypervisor heap contents leaked to guests

pkgsrc also includes patches from the Xen Security Advisory:
XSA-104 (CVE-2014-7154) - Race condition in HVMOP_track_dirty_vram
XSA-105 (CVE-2014-7155) - Missing privilege level checks in x86 HLT, LGDT,
  LIDT, and LMSW emulation
XSA-106 (CVE-2014-7156) - Missing privilege level checks in x86 emulation
  of software interrupts

(bouyer)

2014-09-26 07:00:50 UTC MAIN commitmail json YAML

current bootstrap binary kit for SmartOS is built with ncurses5

(obache)

2014-09-26 03:25:22 UTC MAIN commitmail json YAML

security update fixing:
- Incorrect DigestInfo validation in NSS (CVE-2014-1568)
- RSA signature verification vulnerabilities in parsing of DigestInfo
(see https://www.mozilla.org/security/announce/2014/mfsa2014-73.html)

(spz)

2014-09-25 21:47:06 UTC MAIN commitmail json YAML

2014-09-25 21:32:33 UTC MAIN commitmail json YAML

bump pkgrevision for previous

(jmcneill)

2014-09-25 20:28:32 UTC MAIN commitmail json YAML

2014-09-25 20:13:09 UTC MAIN commitmail json YAML

Requires USE_TOOLS+=pkg-config.

(jperkin)

2014-09-25 20:04:53 UTC MAIN commitmail json YAML

USE_TOOLS+=gm4, requires -I support.

(jperkin)

2014-09-25 20:02:51 UTC MAIN commitmail json YAML

SunOS needs -lsocket -lnsl.

(jperkin)

2014-09-25 19:46:26 UTC MAIN commitmail json YAML

Try to only chmod extracted files, recursively chmod'ing WRKDIR runs
into problems with e.g. TOOLS_DIR.

(jperkin)

2014-09-25 19:43:06 UTC MAIN commitmail json YAML

SunOS needs an explicit -lX11.

(jperkin)

2014-09-25 19:41:21 UTC MAIN commitmail json YAML

2014-09-25 19:39:10 UTC MAIN commitmail json YAML

Extract using bsdtar, GNU tar cannot handle pre-1970 timestamps.

(jperkin)

2014-09-25 19:34:46 UTC MAIN commitmail json YAML

Ensure the correct msgfmt tools are picked up.

(jperkin)

2014-09-25 19:27:18 UTC MAIN commitmail json YAML

Requires OpenSSL and BerkeleyDB.

(jperkin)

2014-09-25 19:21:03 UTC MAIN commitmail json YAML

2014-09-25 19:18:01 UTC MAIN commitmail json YAML

2014-09-25 19:15:27 UTC MAIN commitmail json YAML

Pass correct location to OpenSSL.

(jperkin)

2014-09-25 19:13:23 UTC MAIN commitmail json YAML

Pass correct location of OpenSSL.

(jperkin)

2014-09-25 19:12:03 UTC MAIN commitmail json YAML

Requires USE_TOOLS+=flex.

(jperkin)

2014-09-25 19:09:26 UTC MAIN commitmail json YAML

Pass correct location to OpenSSL.

(jperkin)

2014-09-25 18:46:06 UTC MAIN commitmail json YAML

2014-09-25 18:09:49 UTC pkgsrc-2014Q2 commitmail json YAML

2014-09-25 18:08:56 UTC pkgsrc-2014Q2 commitmail json YAML

Pullup ticket #4504 - requested by tron
shells/bash: security patch

Revisions pulled up:
- shells/bash/Makefile                                          1.65
- shells/bash/distinfo                                          1.32
- shells/bash/patches/patch-parse.y                            1.1

-------------------------------------------------------------------
  Module Name: pkgsrc
  Committed By: tron
  Date: Thu Sep 25 14:02:34 UTC 2014

  Modified Files:
  pkgsrc/shells/bash: Makefile distinfo
  Added Files:
  pkgsrc/shells/bash/patches: patch-parse.y

  Log Message:
  Add fix for CVE-2014-7169.

  To generate a diff of this commit:
  cvs rdiff -u -r1.64 -r1.65 pkgsrc/shells/bash/Makefile
  cvs rdiff -u -r1.31 -r1.32 pkgsrc/shells/bash/distinfo
  cvs rdiff -u -r0 -r1.1 pkgsrc/shells/bash/patches/patch-parse.y

(spz)

2014-09-25 17:37:55 UTC MAIN commitmail json YAML

Fix TOOLS_DIR reference in installed file.

(jperkin)

2014-09-25 17:26:56 UTC MAIN commitmail json YAML

Force file from pkgsrc on SunOS, it needs stdin support.

(jperkin)

2014-09-25 16:32:03 UTC MAIN commitmail json YAML

Needs -lsocket on SunOS.  Also required libpcap.

(jperkin)

2014-09-25 16:08:24 UTC MAIN commitmail json YAML

2014-09-25 15:59:14 UTC MAIN commitmail json YAML

Add SunOS 5.10+ to the NOT_FOR_PLATFORMS list.

(jperkin)

2014-09-25 15:21:46 UTC MAIN commitmail json YAML

SunOS needs -lnsl -lresolv.

(jperkin)

2014-09-25 15:18:09 UTC MAIN commitmail json YAML

Mark as not for SunOS, has hardcoded BSD/Linux support.

(jperkin)

2014-09-25 15:10:21 UTC MAIN commitmail json YAML

2014-09-25 15:08:29 UTC MAIN commitmail json YAML

2014-09-25 15:06:23 UTC MAIN commitmail json YAML

2014-09-25 14:53:05 UTC MAIN commitmail json YAML

Requires USE_TOOLS+=lex.

(jperkin)

2014-09-25 14:48:54 UTC MAIN commitmail json YAML

Avoid sys/dir.h on SunOS.

(jperkin)

2014-09-25 14:32:35 UTC MAIN commitmail json YAML

SunOS needs -lsocket -lnsl.

(jperkin)

2014-09-25 14:24:07 UTC MAIN commitmail json YAML

Make bdb a suggested option.  The package doesn't actually build without
a bdb present.  Not bumping PKGREVISION as the only way the package would
have built previously is by using a builtin version anyway.

(jperkin)

2014-09-25 14:14:47 UTC MAIN commitmail json YAML

2014-09-25 14:02:34 UTC MAIN commitmail json YAML

2014-09-25 13:58:23 UTC MAIN commitmail json YAML

Support builtin libmilter.

(jperkin)

2014-09-25 13:56:50 UTC MAIN commitmail json YAML

Support builtin libmilter.

(jperkin)

2014-09-25 13:47:59 UTC MAIN commitmail json YAML

2014-09-25 13:02:30 UTC MAIN commitmail json YAML

Remove broken CPPFLAGS.SunOS.

(jperkin)

2014-09-25 12:59:30 UTC MAIN commitmail json YAML

2014-09-25 12:57:04 UTC MAIN commitmail json YAML

Ensure we use a sane shell.  Fixes build on SunOS.

(jperkin)

2014-09-25 12:55:52 UTC MAIN commitmail json YAML

Don't define _XOPEN_SOURCE to a bogus value on SunOS.

(jperkin)

2014-09-25 12:29:35 UTC MAIN commitmail json YAML

2014-09-25 12:25:07 UTC MAIN commitmail json YAML

Fix build on SunOS.  Make it more likely that other OPSYS can build this
package too.

(jperkin)

2014-09-25 12:25:03 UTC MAIN commitmail json YAML

Make diff call portable. Fixes ruby-clearsilver on SunOS at least.

(fhajny)

2014-09-25 11:03:52 UTC MAIN commitmail json YAML

Put back Mac distfile, lost in previous update.

(jperkin)

2014-09-25 10:58:02 UTC MAIN commitmail json YAML

2014-09-25 10:56:08 UTC MAIN commitmail json YAML

Use -d rather than non-portable --make-directories cpio argument.

(jperkin)

2014-09-25 10:51:31 UTC MAIN commitmail json YAML

When using EXTRACT_ELEMENTS with wildcards we need to set EXTRACT_USING
to bsdtar, as the default tar implementation may be GNU tar which
requires explicitly using --wildcards for inclusion matches.

(jperkin)

2014-09-25 10:50:58 UTC MAIN commitmail json YAML

This package needs OpenSSL to build (no change where OpenSSL is built-in).

(fhajny)

2014-09-25 10:34:45 UTC MAIN commitmail json YAML

Fix directory permissions manually rather than relying on find(1)
which may not be able to traverse if building as non-root.

(jperkin)

2014-09-25 10:21:58 UTC MAIN commitmail json YAML

Fix SunOS configure and build for the (default) pam option.

(fhajny)

2014-09-25 10:13:20 UTC pkgsrc-2014Q2 commitmail json YAML

2014-09-25 10:11:59 UTC pkgsrc-2014Q2 commitmail json YAML

Pullup ticket #4502 - requested by tron
databases/phpmyadmin: security update

Revisions pulled up:
- databases/phpmyadmin/Makefile                                1.134
- databases/phpmyadmin/PLIST                                    1.39
- databases/phpmyadmin/distinfo                                1.91

-------------------------------------------------------------------
  Module Name: pkgsrc
  Committed By: tron
  Date: Tue Sep 23 13:47:31 UTC 2014

  Modified Files:
  pkgsrc/databases/phpmyadmin: Makefile PLIST distinfo

  Log Message:
  Update "phpmyadmin" package to version 4.2.9.

  The following bugs have been fixed since version 4.2.7.1:
  - bug      ajax.js responseHandler: cannot read property of null
  - bug      sql.js: str is undefined
  - bug #4524 Allow for direct selection of "0" on the "user overview" page
  - bug #4529 Undefined index: pos
  - bug #4523 tbl_change.js: insert as new row submit type on multiple
              selected records does not set all AUTO_INCREMENTs to 0 value
  - bug      ajax.js responseHandler: another "cannot read property"
  - bug      tbl_structure.js "cannot read property"
  - bug #4530 [security] DOM based XSS that results to a CSRF that creates a
              ROOT account in certain conditions
  - bug #4516 Odd export behavior
  - bug #4519 Uncaught TypeError: Cannot read property 'success' of null
  - bug #4520 sql.js: cannot read property
  - bug #4521 Initially allowed chart types do not match selected data
  - bug #4518 Export to SQL: CREATE TABLE option AUTO_INCREMENT ignored
  - bug #4522 Duplicate column names while assigning index
  - bug #4487 Export of partitioned table does not import
  - bug      server_privileges.js: cannot read property
  - bug #4527 Importing ODS files with column names having trailing spaces fa=
  ils
  - bug #4413 Navigation Error in Nav Tree for Search Results Past the First =
  Page
  - bug      functions.js: Cannot read property 'replace' of undefined

  To generate a diff of this commit:
  cvs rdiff -u -r1.133 -r1.134 pkgsrc/databases/phpmyadmin/Makefile
  cvs rdiff -u -r1.38 -r1.39 pkgsrc/databases/phpmyadmin/PLIST
  cvs rdiff -u -r1.90 -r1.91 pkgsrc/databases/phpmyadmin/distinfo

(spz)

2014-09-25 09:32:38 UTC MAIN commitmail json YAML

Remove NOT_FOR_BULK_PLATFORM for SunOS, it builds in under 10 minutes
on modern hardware.

(jperkin)

2014-09-25 09:02:06 UTC pkgsrc-2014Q2 commitmail json YAML

Pullup ticket #4503 - requested by tron
shells/bash: security update

NOTE: this version is still vulnerable to CVE-2014-7169

Revisions pulled up:
- shells/bash/Makefile                                          1.64
- shells/bash/distinfo                                          1.31

-------------------------------------------------------------------
  Module Name: pkgsrc
  Committed By: wiz
  Date: Wed Sep 24 15:24:35 UTC 2014

  Modified Files:
  pkgsrc/shells/bash: Makefile distinfo

  Log Message:
  Add all current upstream bash patches including 025, which fixes
  a security issue. Version number bumped in the usual way.

  To generate a diff of this commit:
  cvs rdiff -u -r1.63 -r1.64 pkgsrc/shells/bash/Makefile
  cvs rdiff -u -r1.30 -r1.31 pkgsrc/shells/bash/distinfo

(spz)

2014-09-25 08:49:50 UTC MAIN commitmail json YAML

devel/zlib is needed not just by the main package. Fixes building where
zlib is not built-in.

(fhajny)

2014-09-25 08:18:35 UTC MAIN commitmail json YAML

Set INSTALLATION_DIRS properly. Fixes installation on at least SunOS.

(fhajny)

2014-09-24 23:31:36 UTC MAIN commitmail json YAML

Remove NOT_FOR_BULK_PLATFORM, builds fine for me.

(jperkin)

2014-09-24 23:24:39 UTC MAIN commitmail json YAML

Use portable find constructs.

(jperkin)

2014-09-24 23:10:51 UTC MAIN commitmail json YAML

2014-09-24 22:24:50 UTC MAIN commitmail json YAML

Use portable find constructs.

(jperkin)

2014-09-24 22:00:06 UTC MAIN commitmail json YAML

2014-09-24 21:32:32 UTC MAIN commitmail json YAML

2014-09-24 21:25:54 UTC MAIN commitmail json YAML

2014-09-24 20:46:21 UTC MAIN commitmail json YAML

USE_TOOLS+=gm4, required on SunOS.

(jperkin)

2014-09-24 20:33:31 UTC MAIN commitmail json YAML

Depend on dos2unix and run it on two files. From jperkin.

(wiz)

2014-09-24 20:20:49 UTC MAIN commitmail json YAML

2014-09-24 16:28:40 UTC MAIN commitmail json YAML

Avoid "error: call of overloaded <func> is ambiguous".

(jperkin)

2014-09-24 16:20:39 UTC MAIN commitmail json YAML

+ anjuta-3.14.0, atk-2.14.0, cmake-3.0.2,
  ffmpeg2-2.4, gdl-3.14.0, glu-10.3, gnome-common-3.14.0,
  gst-plugins1-base-1.4.2, gstreamer1-1.4.2, gtk3-3.14.0,
  lablgtk-2.18.2, libdvdcss-5.0.1, libdvdread-5.0.0, libgpg-error-1.16,
  modular-xorg-server-1.16.1, mono-3.8.0, ocaml-findlib-1.5.3,
  puzzles-10233, py-anki2-2.0.29, py-gobject3-3.14.0, py-py-2.4,
  py-setuptools-5.8, py-sqlparse-0.1.12, py-twisted-14.0.2,
  py-vdirsyncer-0.3.0, ruby21-2.1.3, sound-juicer-3.14.0, stella-4.1.1,
  vala-0.26.0, wine-devel-1.7.27, x264-devel-20140920, xscreensaver-5.30,
  xterm-311.

(wiz)

2014-09-24 15:24:44 UTC MAIN commitmail json YAML

Updated shells/bash to 4.3.025

(wiz)

2014-09-24 15:24:35 UTC MAIN commitmail json YAML

Add all current upstream bash patches including 025, which fixes
a security issue. Version number bumped in the usual way.

(wiz)

2014-09-24 14:57:29 UTC MAIN commitmail json YAML

2014-09-24 14:35:33 UTC MAIN commitmail json YAML

USE_TOOLS+=tar as the package contains a hardcoded 'tar' call which may
find the wrong one (needs to support bzip2).

(jperkin)

2014-09-24 14:33:28 UTC MAIN commitmail json YAML

2014-09-24 13:50:54 UTC MAIN commitmail json YAML

Requires USE_TOOLS+=groff to build mandatory documentation.

(jperkin)

2014-09-24 13:44:21 UTC MAIN commitmail json YAML

2014-09-24 13:36:53 UTC MAIN commitmail json YAML

Requires USE_TOOLS+=groff.

(jperkin)

2014-09-24 13:30:59 UTC MAIN commitmail json YAML

Trick dos2unix into actually converting configure.ac, fixes patching
on SunOS at least.

(jperkin)

2014-09-24 13:27:03 UTC MAIN commitmail json YAML

Regen. Hi jnementh@!

(joerg)

2014-09-24 12:51:06 UTC MAIN commitmail json YAML

2014-09-24 12:49:38 UTC MAIN commitmail json YAML

2014-09-24 12:39:28 UTC MAIN commitmail json YAML

2014-09-24 12:33:44 UTC MAIN commitmail json YAML

2014-09-24 12:32:26 UTC MAIN commitmail json YAML

2014-09-24 12:24:40 UTC MAIN commitmail json YAML

USE_TOOLS+=xgettext and work around broken configure test for strcasecmp
on SunOS.

(jperkin)

2014-09-24 12:17:19 UTC MAIN commitmail json YAML

Remove obsolete patch breaking the build.

(jperkin)

2014-09-24 12:04:14 UTC MAIN commitmail json YAML

USE_TOOLS+=xgettext, fixes build on SunOS.

(jperkin)

2014-09-24 11:56:04 UTC MAIN commitmail json YAML

USE_TOOLS+=xgettext, fixes build on SunOS.

(jperkin)

2014-09-24 11:48:48 UTC MAIN commitmail json YAML

USE_TOOLS+=xgettext, fixes build on SunOS.

(jperkin)

2014-09-24 11:48:20 UTC MAIN commitmail json YAML

USE_TOOLS+=xgettext, fixes build on SunOS.

(jperkin)

2014-09-24 11:39:24 UTC MAIN commitmail json YAML

2014-09-24 11:27:51 UTC MAIN commitmail json YAML

2014-09-24 11:23:57 UTC MAIN commitmail json YAML

Ensure RUNPATH is empty to avoid bogus rpaths.

(jperkin)

2014-09-24 11:10:38 UTC MAIN commitmail json YAML

2014-09-24 10:58:51 UTC MAIN commitmail json YAML

USE_TOOLS+=gsed for -r support.

(jperkin)

2014-09-24 10:53:22 UTC MAIN commitmail json YAML

Replace WRAPPER_BINDIR reference with real path in generated file.

(jperkin)

2014-09-24 10:40:57 UTC MAIN commitmail json YAML

Avoid reference to WRAPPER_BINDIR in final binaries.

(jperkin)

2014-09-24 10:31:28 UTC MAIN commitmail json YAML

Remove WRAPPER_BINDIR references in mysqlbug.

(jperkin)

2014-09-24 10:02:39 UTC MAIN commitmail json YAML

Remove WRAPPER_BINDIR references in mysqlbug.

(jperkin)

2014-09-24 10:02:14 UTC MAIN commitmail json YAML

Explicitly disable epoll on SunOS, the MySQL implementation is specific
to Linux at this time.

(jperkin)

2014-09-24 09:47:41 UTC MAIN commitmail json YAML

2014-09-24 05:44:01 UTC MAIN commitmail json YAML

Updated www/nginx to 1.6.2

(kim)

2014-09-24 05:42:48 UTC MAIN commitmail json YAML

Upgrade to nginx-1.6.2 to fix security vulnerability CVE-2014-3616.
Restore module checksums that were lost in last update.

Changes with nginx 1.6.2                                        16 Sep 2014

    *) Security: it was possible to reuse SSL sessions in unrelated contexts
      if a shared SSL session cache or the same TLS session ticket key was
      used for multiple "server" blocks (CVE-2014-3616).
      Thanks to Antoine Delignat-Lavaud.

    *) Bugfix: requests might hang if resolver was used and a DNS server
      returned a malformed response; the bug had appeared in 1.5.8.

    *) Bugfix: requests might hang if resolver was used and a timeout
      occurred during a DNS request.

(kim)

2014-09-24 01:07:19 UTC MAIN commitmail json YAML

Updated devel/mantis to 1.2.17

(rodent)

2014-09-24 01:06:26 UTC MAIN commitmail json YAML

Update to 1.2.17. pkgsrc changes: Add bash:run to USE_TOOLS and
REPLACE_BASH in installed file. Replace PHP interpreter in installed *.php
files. Move options framework into options.mk. Use INSTALLATION_DIRS
instead of INSTALL_DATA_DIR. From doc/RELEASE:

1.2.17 Security Release (2014-03-04)
-------------------------------------------------

MantisBT 1.2.17 is a security update for the stable 1.2.x branch. All
installations that are currently running any 1.2.x version are strongly advised
to upgrade to this release. Download it from [3].

An SQL injection vulnerability (CVE-2014-2238) in adm_config_report.php was
patched. Refer to issue #17055 for detailed information.

This release also includes a few bug fixes for the tracker, including News API
correction for the regression issue #16940 introduced in 1.2.16, as well as
updated translations in many languages.

A full changelog for the 1.2.x series can be found on the official site. [1]

1.2.16 Security Release (2014-02-07)
-------------------------------------------------

MantisBT 1.2.16 is a security update for the stable 1.2.x branch. All
installations that are currently running any 1.2.x version are strongly advised
to upgrade to this release. Download it from [3].

The following security issues were resolved:

- Cross-site scripting (XSS) issue in account_sponsor_page.php, allowing a
  malicious user with project manager access to execute arbitrary JavaScript
  code (CVE-2013-4460). Affects MantisBT 1.1.0 and later.
  Refer to issue #16513 for detailed information.

- SQL injection attacks through the SOAP API's mc_attachment_get() function
  (CVE-2014-1608). Affects MantisBT 1.1.0a4 and later.
  Refer to issue #16879 for detailed information.

- Additional cases of unsanitized SQL query parameters usage were identified,
  potentially allowing SQL injection attacks (CVE-2014-1609).
  Refer to issue #16880 for detailed information.

This release also includes many bug fixes and enhancements to the tracker
and the SOAP api, as well as updated translations in many languages.

A full changelog for the 1.2.x series can be found on the official site. [1]

[1] The changelog is split between multiple releases:

1.2.17    http://www.mantisbt.org/bugs/changelog_page.php?version_id=189
1.2.16    http://www.mantisbt.org/bugs/changelog_page.php?version_id=183

(rodent)

2014-09-23 22:52:01 UTC MAIN commitmail json YAML

2014-09-23 22:40:27 UTC MAIN commitmail json YAML

2014-09-23 22:37:29 UTC MAIN commitmail json YAML

2014-09-23 22:30:30 UTC MAIN commitmail json YAML

Use appropriate build target on SunOS.

(jperkin)

2014-09-23 22:26:24 UTC MAIN commitmail json YAML

2014-09-23 22:24:38 UTC MAIN commitmail json YAML

2014-09-23 22:21:43 UTC MAIN commitmail json YAML

2014-09-23 22:18:22 UTC MAIN commitmail json YAML

2014-09-23 22:13:50 UTC MAIN commitmail json YAML

2014-09-23 21:47:52 UTC MAIN commitmail json YAML

2014-09-23 21:41:07 UTC MAIN commitmail json YAML

SunOS needs -lnsl -lresolv.

(jperkin)

2014-09-23 19:39:50 UTC MAIN commitmail json YAML

Sync PLIST with reality adding various man pages. Bump revision.

(joerg)

2014-09-23 19:39:17 UTC MAIN commitmail json YAML

2014-09-23 19:07:06 UTC MAIN commitmail json YAML

SunOS needs -lsocket -lnsl.

(jperkin)

2014-09-23 18:55:24 UTC MAIN commitmail json YAML

SunOS needs -lsocket -lnsl.

(jperkin)

2014-09-23 18:19:22 UTC MAIN commitmail json YAML

Make sure all patterns provide the upper limit to avoid conflicting
packages getting installed in bulk builds.

(joerg)

2014-09-23 18:18:42 UTC MAIN commitmail json YAML

Fails rather spectaculary with MAKE_JOBS, so disable it.

(joerg)

2014-09-23 17:57:04 UTC MAIN commitmail json YAML

2014-09-23 15:52:13 UTC MAIN commitmail json YAML

Note update of www/fengoffice package to 2.7.1.1.

(taca)

2014-09-23 15:51:43 UTC MAIN commitmail json YAML

Update fengoffice to 2.7.1.1.

Changes from 2.6.1 is too many, please refer <http://sourceforge.net/projects/opengoo/files/fengoffice/fengoffice_2.7.0/> in detail.

And this release contains security fix, XSS.

(taca)

2014-09-23 15:13:23 UTC MAIN commitmail json YAML

Provide flag to set correct RPATH in pkg-config.

(asau)

2014-09-23 15:11:54 UTC MAIN commitmail json YAML

2014-09-23 15:09:54 UTC MAIN commitmail json YAML

Resort, fixes use of undefined variable as mentioned by obache@

(joerg)

2014-09-23 14:59:24 UTC MAIN commitmail json YAML

2014-09-23 14:53:03 UTC MAIN commitmail json YAML

2014-09-23 14:50:03 UTC MAIN commitmail json YAML

2014-09-23 14:40:28 UTC MAIN commitmail json YAML

2014-09-23 14:33:40 UTC MAIN commitmail json YAML

2014-09-23 14:29:51 UTC MAIN commitmail json YAML

2014-09-23 14:26:35 UTC MAIN commitmail json YAML

Provide a catman page where mdoc pages are not supported. PKGREVISION++

(fhajny)

2014-09-23 13:55:00 UTC MAIN commitmail json YAML

2014-09-23 13:50:01 UTC MAIN commitmail json YAML

Updated audio/libxmp to 4.2.7nb1

(jperkin)

2014-09-23 13:49:30 UTC MAIN commitmail json YAML

Avoid versioned symbols on SunOS to fix dependencies.

Bump PKGREVISION as package previously built, was just missing symbols.

(jperkin)

2014-09-23 13:47:47 UTC MAIN commitmail json YAML

Note update of the "phpmyadmin" package to version 4.2.9.

(tron)

2014-09-23 13:47:31 UTC MAIN commitmail json YAML

Update "phpmyadmin" package to version 4.2.9.

The following bugs have been fixed since version 4.2.7.1:
- bug      ajax.js responseHandler: cannot read property of null
- bug      sql.js: str is undefined
- bug #4524 Allow for direct selection of "0" on the "user overview" page
- bug #4529 Undefined index: pos
- bug #4523 tbl_change.js: insert as new row submit type on multiple
            selected records does not set all AUTO_INCREMENTs to 0 value
- bug      ajax.js responseHandler: another "cannot read property"
- bug      tbl_structure.js "cannot read property"
- bug #4530 [security] DOM based XSS that results to a CSRF that creates a
            ROOT account in certain conditions
- bug #4516 Odd export behavior
- bug #4519 Uncaught TypeError: Cannot read property 'success' of null
- bug #4520 sql.js: cannot read property
- bug #4521 Initially allowed chart types do not match selected data
- bug #4518 Export to SQL: CREATE TABLE option AUTO_INCREMENT ignored
- bug #4522 Duplicate column names while assigning index
- bug #4487 Export of partitioned table does not import
- bug      server_privileges.js: cannot read property
- bug #4527 Importing ODS files with column names having trailing spaces fails
- bug #4413 Navigation Error in Nav Tree for Search Results Past the First Page
- bug      functions.js: Cannot read property 'replace' of undefined

(tron)

2014-09-23 13:28:54 UTC MAIN commitmail json YAML

2014-09-23 13:21:16 UTC MAIN commitmail json YAML

Add newly added p5-Net-SSH-Expect.

(he)

2014-09-23 13:13:49 UTC MAIN commitmail json YAML

When using native curses on SunOS we must use X/Open Curses, SYSV curses
doesn't support mvchgat.

(jperkin)

2014-09-23 12:06:49 UTC MAIN commitmail json YAML

Fix some build issues exposed by the cwrappers build:

  - Use REPLACE_SH for echo -n.
  - Use LD_LIBRARY_PATH for tests to find pre-installed libraries.
  - Fix parallel build issues.

(jperkin)

2014-09-23 10:54:09 UTC MAIN commitmail json YAML

Note addition of net/p5-Net-SSH-Expect version 1.09.

(he)

2014-09-23 10:53:09 UTC MAIN commitmail json YAML

2014-09-23 09:08:21 UTC MAIN commitmail json YAML

Remove TOOLS_DIR references from the generated pari.cfg.

(jperkin)

2014-09-23 08:51:00 UTC MAIN commitmail json YAML

Needs rdoc 4.0.0 or newer. Fixes build with RUBY_VERSION_DEFAULT=193,
no change on newer Ruby versions.

(fhajny)

2014-09-23 08:31:14 UTC MAIN commitmail json YAML

Updated lang/nodejs to 0.10.32

(fhajny)

2014-09-23 08:30:58 UTC MAIN commitmail json YAML

Update nodejs to 0.10.32.

2014.09.16, Version 0.10.32 (Stable)
* npm: Update to 1.4.28
* v8: fix a crash introduced by previous release (Fedor Indutny)
* configure: add --openssl-no-asm flag (Fedor Indutny)
* crypto: use domains for any callback-taking method (Chris Dickinson)
* http: do not send `0\r\n\r\n` in TE HEAD responses (Fedor Indutny)
* querystring: fix unescape override (Tristan Berger)
* url: Add support for RFC 3490 separators (Mathias Bynens)

(fhajny)

2014-09-23 07:07:26 UTC MAIN commitmail json YAML

Updated www/moodle to 2.7.2

(wen)

2014-09-23 07:06:10 UTC MAIN commitmail json YAML

Update to 2.7.2(security update)

Upstream changes:
Highlights
MDL-45780 - Atto now working with form change checker and quiz autosave
MDL-46748 - Mathjax address that changed, that caused Atto to fail to load, has been updated in Moodle
MDL-35984 - Gradebook Sum of grades shows correct total if items are hidden
Functional changes
MDL-45724 - Warning given when the same memcached instance is used for both sessions and MUC
MDL-46681 - For Multiple choices questions in the quiz / question bank, the options "Clear incorrect responses" and "Show the number of correct responses" did not make sense for "One answer only" questions. It is now impossible to select that combination of options on the form.
Security issues
MSA-14-0033 URL parameter injection in CAS authentication
MSA-14-0034 Identity information revealed early in Q&A forum
Fixes and improvements
MDL-37509 - Description of assignment hidden in calendar if "always show description" = NO
MDL-46545 - Weekly stats now working again
MDL-46589 - Automatic emails now sent after users import from CSV
MDL-43197 - Parent role only sees course total and no longer individual grades
MDL-46236 - Start New Attempt option is now followed if SCORM is set to appear in a popup

Approved by: wiz@

(wen)

2014-09-22 12:02:05 UTC MAIN commitmail json YAML

Don't bail out on unused local typedefs for clang.

(joerg)

2014-09-22 11:56:54 UTC MAIN commitmail json YAML

Forgotten patch for last commit.

(joerg)

2014-09-22 11:56:39 UTC MAIN commitmail json YAML

Fix implicit prototype conflicts. Always include termios.h for ECHO.

(joerg)

2014-09-22 11:55:59 UTC MAIN commitmail json YAML

Don't bail out on unused local typedefs.

(joerg)

2014-09-22 11:55:37 UTC MAIN commitmail json YAML

2014-09-22 11:55:07 UTC MAIN commitmail json YAML

2014-09-22 11:54:45 UTC MAIN commitmail json YAML

2014-09-22 11:54:15 UTC MAIN commitmail json YAML

2014-09-22 11:53:43 UTC MAIN commitmail json YAML

2014-09-22 11:53:18 UTC MAIN commitmail json YAML

2014-09-22 11:53:00 UTC MAIN commitmail json YAML

Perl script work significantly better with Perl around. Bump revision.

(joerg)

2014-09-22 11:52:18 UTC MAIN commitmail json YAML

Don't bail out on unused local typedefs. Bump revision.

(joerg)

2014-09-22 11:51:14 UTC MAIN commitmail json YAML

2014-09-22 11:50:30 UTC MAIN commitmail json YAML

Simplify. Sync PLIST with reality. Bump revision.

(joerg)

2014-09-22 11:49:42 UTC MAIN commitmail json YAML

Don't bail out on unused local typedefs with clang.

(joerg)

2014-09-22 10:49:57 UTC MAIN commitmail json YAML

Fix build on Linux where the default curses implementation is ncurses.

(jperkin)

2014-09-22 10:47:18 UTC MAIN commitmail json YAML

Fix build on systems which do not defined KEY_CODE_YES, using KEY_MIN
instead (notably SunOS).

(jperkin)

2014-09-21 21:39:54 UTC pkgsrc-2014Q2 commitmail json YAML

2014-09-21 21:39:04 UTC pkgsrc-2014Q2 commitmail json YAML

Pullup ticket #4500 - requested by tron
net/wireshark: security update

Revisions pulled up:
- net/wireshark/Makefile                                        1.125
- net/wireshark/distinfo                                        1.77

-------------------------------------------------------------------
  Module Name: pkgsrc
  Committed By: tron
  Date: Wed Sep 17 22:32:18 UTC 2014

  Modified Files:
  pkgsrc/net/wireshark: Makefile distinfo

  Log Message:
  Update "wireshark" package to version 1.10.10. Changes since 1.10.9:
  - The following vulnerabilities have been fixed.
    * wnpa-sec-2014-12
      RTP dissector crash. (Bug 9920) CVE-2014-6421
      CVE-2014-6422
    * wnpa-sec-2014-13
      MEGACO dissector infinite loop. (Bug 10333)
      CVE-2014-6423
    * wnpa-sec-2014-14
      Netflow dissector crash. (Bug 10370) CVE-2014-6424
    * wnpa-sec-2014-17
      RTSP dissector crash. (Bug 10381) CVE-2014-6427
    * wnpa-sec-2014-18
      SES dissector crash. (Bug 10454) CVE-2014-6428
    * wnpa-sec-2014-19
      Sniffer file parser crash. (Bug 10461)
      CVE-2014-6429 CVE-2014-6430 CVE-2014-6431
      CVE-2014-6432
  - The following bugs have been fixed:
    * Wireshark can crash during remote capture (rpcap)
      configuration. (Bug 3554, Bug 6922,
      ws-buglink:7021)
    * MIPv6 Service Selection Identifier parse error. (Bug
      10323)
    * 802.11 BA sequence number decode is broken. (Bug 10334)
    * TRILL NLPID 0xc0 unknown to Wireshark. (Bug 10382)
    * Wrong decoding of RPKI RTR End of Data PDU. (Bug 10411)
    * Misparsed NTP control assignments with empty values.
      (Bug 10417)
    * 6LoWPAN multicast address decompression problems. (Bug
      10426)
    * GUI Hangs when Selecting Path to GeoIP Files. (Bug
      10434)
    * 6LoWPAN context handling not working. (Bug 10443)
    * SIP: When export to a CSV, Info is changed to differ.
      (Bug 10453)
    * Typo in packet-netflow.c. (Bug 10458)
    * UCP dissector bug of operation 30 - data not decoded.
      (Bug 10464)
  - Updated Protocol Support
    6LoWPAN, DVB-CI, IEEE 802.11, MEGACO, MIPv6, Netflow, NTP, OSI,
    RPKI RTR, RTP, RTSP, SES, SIP, and UCP
  - New and Updated Capture File Support
    DOS Sniffer, and NetScaler

  To generate a diff of this commit:
  cvs rdiff -u -r1.124 -r1.125 pkgsrc/net/wireshark/Makefile
  cvs rdiff -u -r1.76 -r1.77 pkgsrc/net/wireshark/distinfo

(spz)

2014-09-21 14:49:45 UTC MAIN commitmail json YAML

fix inode checks for NetBSD
fix inode check result rrd handling for all BSDish systems; if you use
xymon-4.3.17nb1 on *BSD you may have lots of inode<number>.rrd files
in /var/xymon/rrd, since it used iavail instead of the name of the
filesystem mount to identify the inode usage stats.

(spz)

2014-09-21 11:20:19 UTC MAIN commitmail json YAML

Updated net/mikutter to 3.0.6

(obache)

2014-09-21 11:20:08 UTC MAIN commitmail json YAML

Update mikutter to 3.0.6.

* Update translations
  * Add Portuguese language
* Fixes crash with passing Listner to select of setting DSL
* Remove unused remaining UI settings
  * show retweets
  * show faved
* Fixes to work some checkbox in standard plugins' settings properly.

(obache)

2014-09-21 10:47:37 UTC MAIN commitmail json YAML

Set preferred URL to HOMEPAGE.

(obache)

2014-09-21 04:43:51 UTC MAIN commitmail json YAML

2014-09-21 00:09:24 UTC MAIN commitmail json YAML

The configure script checks for arc4random(), but the program uses
arc4random_buf(); netbsd-5 (and presumably earlier) has the one but
not the other. Just disable it, because all it's using the randomness
for is message-ids. Fixes the netbsd-5 build.

(dholland)

2014-09-20 23:26:50 UTC MAIN commitmail json YAML

nmh 1.6 was added recently.

(dholland)

2014-09-20 23:15:57 UTC MAIN commitmail json YAML

2014-09-20 23:15:03 UTC MAIN commitmail json YAML

This version of nmh specifically needs terminfo and not termcap
Adjust accordingly and bump PKGREVISION.

(dholland)

2014-09-20 23:01:20 UTC MAIN commitmail json YAML

Remove empty patch file. Regen distinfo, which also removes references
to two other patches that apparently no longer exist.

(dholland)

2014-09-20 21:14:35 UTC MAIN commitmail json YAML

Include libSM since it's needed.

(wiz)

2014-09-20 19:12:26 UTC MAIN commitmail json YAML

Updated comms/asterisk to 11.12.1

(jnemeth)

2014-09-20 19:12:16 UTC MAIN commitmail json YAML

Update to Asterisk 11.12.1: this is mainly a security fix for AST-2014-010.

The Asterisk Development Team has announced security releases for Certified
Asterisk 11.6 and Asterisk 11 and 12. The available security releases are
released as versions 11.6-cert6, 11.12.1, and 12.5.1.

Please note that the release of these versions resolves the following security
vulnerability:

* AST-2014-010: Remote Crash when Handling Out of Call Message in Certain
                Dialplan Configurations

Note that the crash described in AST-2014-010 can be worked around through
dialplan configuration. Given the likelihood of the issue, an advisory was
deemed to be warranted.

For more information about the details of these vulnerabilities, please read
security advisories AST-2014-009 and AST-2014-010, which were released at the
same time as this announcement.

For a full list of changes in the current releases, please see the ChangeLogs:

http://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-11.12.1

The security advisories are available at:

* http://downloads.asterisk.org/pub/security/AST-2014-010.pdf

Thank you for your continued support of Asterisk!

(jnemeth)

2014-09-20 18:13:29 UTC MAIN commitmail json YAML

fix path in snobol post-build target

(jakllsch)

2014-09-20 17:56:49 UTC MAIN commitmail json YAML

Updated math/py-pytables to 3.1.1

(wiz)