--- - branch: MAIN date: Sun Aug 2 19:18:40 UTC 2009 files: - new: '1.55' old: '1.54' path: pkgsrc/chat/silc-client/Makefile pathrev: pkgsrc/chat/silc-client/Makefile@1.55 type: modified - new: '1.13' old: '1.12' path: pkgsrc/chat/silc-client/Makefile.common pathrev: pkgsrc/chat/silc-client/Makefile.common@1.13 type: modified - new: '1.35' old: '1.34' path: pkgsrc/chat/silc-client/distinfo pathrev: pkgsrc/chat/silc-client/distinfo@1.35 type: modified - new: '1.14' old: '1.13' path: pkgsrc/chat/silc-client/patches/patch-aa pathrev: pkgsrc/chat/silc-client/patches/patch-aa@1.14 type: modified - new: '1.4' old: '1.3' path: pkgsrc/chat/silc-client/patches/patch-ae pathrev: pkgsrc/chat/silc-client/patches/patch-ae@1.4 type: modified id: 20090802T191840Z.57facaccfb51a1912c1ddcd534950ca365bfc957 log: | Update silc-client to version 1.1.8 to fix a security problem. Changes: - Portability: Check threads support in OpenBSD. - Security: Fixed string format vulnerability in client entry handling. - Autoconf upgrade. - PacketEngine: Don't free underlaying stream in packet stream create error - If packet stream creation failed it freed the stream given as argument. This is wrong. It is the caller's responsibility to free it if the packet stream creation failed. - SKE: When failure is received mark SKE always failed Mark the SKE failed even if we don't receive error from remote. Fixes crash where the callback is called back to application without valid key material and without error status. module: pkgsrc subject: 'CVS commit: pkgsrc/chat/silc-client' unixtime: '1249240720' user: tonnerre