--- - branch: pkgsrc-2008Q3 date: Thu Oct 9 11:50:35 UTC 2008 files: - new: 1.17.18.1 old: '1.17' path: pkgsrc/net/tnftpd/Makefile pathrev: pkgsrc/net/tnftpd/Makefile@1.17.18.1 type: modified - new: 1.2.42.1 old: '1.2' path: pkgsrc/net/tnftpd/PLIST pathrev: pkgsrc/net/tnftpd/PLIST@1.2.42.1 type: modified - new: 1.9.18.1 old: '1.9' path: pkgsrc/net/tnftpd/distinfo pathrev: pkgsrc/net/tnftpd/distinfo@1.9.18.1 type: modified - new: 1.1.28.1 old: '1.1' path: pkgsrc/net/tnftpd/options.mk pathrev: pkgsrc/net/tnftpd/options.mk@1.1.28.1 type: modified - new: '0' old: '1.5' path: pkgsrc/net/tnftpd/patches/patch-aa pathrev: pkgsrc/net/tnftpd/patches/patch-aa@0 type: deleted id: 20081009T115035Z.c673738e760b13d6128f21ce3bd9013f0d3f19a3 log: "Pullup ticket #2549 - requested by lukem\ntnftpd: security update\n\nRevisions pulled up:\n- net/tnftpd/Makefile\t\t1.18\n- net/tnftpd/PLIST\t\t1.3\n- net/tnftpd/distinfo\t\t1.10\n- net/tnftpd/options.mk\t\t1.2\n- net/tnftpd/patches/patch-aa\tdelete\n---\nModule Name:\tpkgsrc\nCommitted By:\tlukem\nDate:\t\tThu Oct 9 04:14:29 UTC 2008\n\nModified Files:\n\tpkgsrc/net/tnftpd: Makefile PLIST distinfo options.mk\nRemoved Files:\n\tpkgsrc/net/tnftpd/patches: patch-aa\n\nLog Message:\nUpdate to tnftpd 20081009. Notable changes since 20061217:\n\n* Don't split large commands into multiple commands; just fail on them.\n This prevents cross-site request forgery (CSRF)-like attacks,\n when a web browser is used to access an ftp server.\n* Enhance -C to support an optional @host ('-C user[@host]'):\n checks whether user as connecting from host would be granted\n \ access by ftpusers(5).\n* Support IPv6 in the host directive of ftpusers(5).\n* Implement -n to disable hostname lookups.\n\n* Disable SOCKS support; I don't have the ability to test it,\n and the autoconf checks were very out of date.\n* Add configure --with-pam to enable PAM authentication support.\n Defaults to checking for PAM.\n* Add configure --with-skey to enable S/Key authentication support.\n Incompatible with --with-pam, defaults to no.\n* Fix pathnames in the installed manual pages to contain\n the appropriate $(prefix) substitution.\n* Use fcntl(3) locking instead of flock(3) or lockf(3).\n* Various other portability improvements.\n" module: pkgsrc subject: 'CVS commit: [pkgsrc-2008Q3] pkgsrc/net/tnftpd' unixtime: '1223553035' user: tron