--- - branch: pkgsrc-2008Q2 date: Tue Aug 19 00:26:04 UTC 2008 files: - new: 1.27.6.1 old: '1.27' path: pkgsrc/security/ipsec-tools/Makefile pathrev: pkgsrc/security/ipsec-tools/Makefile@1.27.6.1 type: modified - new: 1.14.12.1 old: '1.14' path: pkgsrc/security/ipsec-tools/distinfo pathrev: pkgsrc/security/ipsec-tools/distinfo@1.14.12.1 type: modified id: 20080819T002604Z.5ebbba8dc96bdd12658bbc38bece177388b6b000 log: "pullup ticket #2489 - requested by manu\nipsec-tools: update package for cve\n\nrevisions pulled up:\npkgsrc/security/ipsec-tools/Makefile\t1.28\npkgsrc/security/ipsec-tools/distinfo\t1.15\n\n \ Module Name: pkgsrc\n Committed By: manu\n Date: Sat Aug 16 06:55:18 UTC 2008\n\n Modified Files:\n pkgsrc/doc: CHANGES-2008\n \ pkgsrc/security/ipsec-tools: Makefile distinfo\n\n Log Message:\n \ Update to ipsec-tools 0.7.1, fixes CVE-2008-3652\n\n Changes since the 0.6 branch:\n 0.7.1 - 23 July 2008\n o Fixes a memory leak when invalid proposal received\n o Some fixes in DPD\n o do not set default gss id if xauth is used\n o fixed hybrid enabled builds\n o fixed compilation on FreeBSD8\n o cleanup in network port value manipulation\n \ o gets ports from SADB_X_EXT_NAT_T_[SD]PORT if present in\n purge_ipsec_sp\n \ i()\n o Generates a log if cert validation has been disabled by\n \ configuration\n o better handling for pfkey socket read errors\n \ o Fixes in yacc / bison stuff\n o new plog() macro (reduced CPU usage when logging is disabled)\n o Try to works better with huge SPD/SAD\n o Corrected modecfg option syntax\n o Many other various fixes...\n\n 0.7 - 09 August 2007\n o Xauth with pre-shared key PSK\n o Xauth with certificates\n o SHA2 support\n o pkcs7 support\n o system accounting (utmp)\n o Darwin support\n \ o configuration can be reloaded\n o Support for UNIQUE generated policies\n o Support for semi anonymous sainfos\n o Support for ph1id to remoteid matching\n o Plain RSA authentication\n o Native LDAP support for Xauth and modecfg\n o Group membership checks for Xauth and sainfo selection\n o Camellia cipher support\n o IKE Fragment force option\n o Modecfg SplitNet attribute support\n o Modecfg SplitDNS attribute support ( server side )\n o Modecfg Default Domain attribute support\n o Modecfg DNS/WINS server multiple attribute support\n" module: pkgsrc subject: 'CVS commit: [pkgsrc-2008Q2] pkgsrc/security/ipsec-tools' unixtime: '1219105564' user: rtr