summaryrefslogtreecommitdiff
AgeCommit message (Collapse)AuthorFilesLines
2006-08-02#1774.ghen1-1/+3
2006-08-02Pullup ticket 1774 - requested by saloghen10-3/+677
security fix for tiff Revisions pulled up: - pkgsrc/graphics/tiff/Makefile 1.84 - pkgsrc/graphics/tiff/distinfo 1.39 - pkgsrc/graphics/tiff/patches/patch-av 1.5 - pkgsrc/graphics/tiff/patches/patch-aw 1.5 - pkgsrc/graphics/tiff/patches/patch-ax 1.5 - pkgsrc/graphics/tiff/patches/patch-ay 1.3 - pkgsrc/graphics/tiff/patches/patch-az 1.1 - pkgsrc/graphics/tiff/patches/patch-ba 1.1 - pkgsrc/graphics/tiff/patches/patch-bb 1.1 - pkgsrc/graphics/tiff/patches/patch-bc 1.1 Module Name: pkgsrc Committed By: salo Date: Wed Aug 2 15:42:25 UTC 2006 Modified Files: pkgsrc/graphics/tiff: Makefile distinfo Added Files: pkgsrc/graphics/tiff/patches: patch-av patch-aw patch-ax patch-ay patch-az patch-ba patch-bb patch-bc Log Message: Security fixes for SA21304: "Some vulnerabilities have been reported in libTIFF, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system. The vulnerabilities are caused due to various heap and integer overflows when processing TIFF images and can be exploited via a specially crafted TIFF image. Successful exploitation allows crashing applications linked against libTIFF and may also allow execution of arbitrary code." http://secunia.com/advisories/21304/ http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3459 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3460 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3461 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3462 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3463 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3464 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3465 Patches from Tavis Ormandy, Google Security Team via SUSE. Bump PKGREVISION.
2006-08-02#1769, #1770salo1-1/+5
2006-08-02Pullup ticket 1770 - requested by rilligsalo1-90/+218
improved upload script for bulk builds Revisions pulled up: - pkgsrc/mk/bulk/upload 1.31, 1.32, 1.33 Module Name: pkgsrc Committed By: jschauma Date: Sun Jul 30 14:31:10 UTC 2006 Modified Files: pkgsrc/mk/bulk: upload Log Message: - use ${BMAKE} instead of 'make' in one instance - if we can't build one of the required packages, bail out --- Module Name: pkgsrc Committed By: dmcmahill Date: Tue Aug 1 00:53:24 UTC 2006 Modified Files: pkgsrc/mk/bulk: upload Log Message: - add a -h|--help flag - add a -n|--no-upload flag which does everything but actually executing the upload to help see what would happen - add a -d|--debug flag to preserve the temporary files to help with debugging - add a -V|--version flag --- Module Name: pkgsrc Committed By: rillig Date: Tue Aug 1 13:16:42 UTC 2006 Modified Files: pkgsrc/mk/bulk: upload Log Message: Rewrote upload to use the newly introduced sort-packages program. While here, ... - Added stricter checking by using "set -eu". - The bulk build configuration file is properly included, and the MAKECONF definition that it may contain is properly exported. - All progress messages and error messages are prefixed by üpload>", so that it is obvious where the messages come from. - Since extracting the make(1) variables takes quite a long time, print an informational message before doing that. - Removed the use of the error-prone lintpkgsrc to detect whether a package is restricted or vulnerable. - If an error occurs, the upload program returns an exitcode of 1, which is common among Unix utilities. - Removed almost all pipe operators, since they tend to hide program failures. - All error messages are redirected to stderr instead of stdout.
2006-08-02Pullup ticket 1769 - requested by rilligsalo1-0/+94
add sort-packages program for bulk building Revisions pulled up: - pkgsrc/mk/bulk/sort-packages 1.1 Module Name: pkgsrc Committed By: rillig Date: Tue Aug 1 06:05:15 UTC 2006 Added Files: pkgsrc/mk/bulk: sort-packages Log Message: Added a program that sorts binary packages into categories, depending on whether they may be uploaded, are vulnerable, or good.
2006-08-02#1773.ghen1-1/+3
2006-08-02Pullup ticket 1773 - requested by saloghen10-36/+36
security updates for suse100_freetype2 and suse100_libtiff Revisions pulled up: - pkgsrc/emulators/suse100_freetype2/Makefile 1.5 - pkgsrc/emulators/suse100_freetype2/Makefile.i386 1.3 - pkgsrc/emulators/suse100_freetype2/Makefile.powerpc 1.3 - pkgsrc/emulators/suse100_freetype2/Makefile.x86_64 1.3 - pkgsrc/emulators/suse100_freetype2/distinfo 1.3 - pkgsrc/emulators/suse100_libtiff/Makefile 1.5 - pkgsrc/emulators/suse100_libtiff/Makefile.i386 1.3 - pkgsrc/emulators/suse100_libtiff/Makefile.powerpc 1.3 - pkgsrc/emulators/suse100_libtiff/Makefile.x86_64 1.3 - pkgsrc/emulators/suse100_libtiff/distinfo 1.3 Module Name: pkgsrc Committed By: salo Date: Wed Aug 2 14:26:13 UTC 2006 Modified Files: pkgsrc/emulators/suse100_freetype2: Makefile Makefile.i386 Makefile.powerpc Makefile.x86_64 distinfo pkgsrc/emulators/suse100_libtiff: Makefile Makefile.i386 Makefile.powerpc Makefile.x86_64 distinfo Log Message: Sync with latest SUSE Linux security updates.
2006-08-02#1772.ghen1-1/+3
2006-08-02Pullup ticket 1772 - requested by saloghen4-36/+12
security update for gnupg Revisions pulled up: - pkgsrc/security/gnupg/Makefile 1.87-1.89 - pkgsrc/security/gnupg/distinfo 1.41-1.43 - pkgsrc/security/gnupg/PLIST 1.19 - pkgsrc/security/gnupg/patches/patch-ba removed
2006-08-02#1771salo1-1/+3
2006-08-02Pullup ticket 1771 - requested by tacasalo5-5/+46
security fixes for ruby18-base Revisions pulled up: - pkgsrc/lang/ruby18-base/Makefile 1.23 - pkgsrc/lang/ruby18-base/distinfo 1.13 - pkgsrc/lang/ruby18-base/patches/patch-ag 1.1 - pkgsrc/lang/ruby18-base/patches/patch-ah 1.1 - pkgsrc/lang/ruby18-base/patches/patch-cp 1.1 Module Name: pkgsrc Committed By: taca Date: Wed Aug 2 07:02:44 UTC 2006 Modified Files: pkgsrc/lang/ruby18-base: Makefile distinfo Added Files: pkgsrc/lang/ruby18-base/patches: patch-ag patch-ah patch-cp Log Message: Add three patches accidently left on my work area. - Add two miscellaneous patches for openssl and yaml libraries. They were left from last year, sigh. - Add one more part for CVE-2006-3694. Bump PKGREVISION.
2006-08-01#1768salo1-1/+3
2006-08-01Pullup ticket 1768 - requested by ghensalo11-146/+25
security update for gimp Revisions pulled up: - pkgsrc/graphics/gimp/Makefile 1.143 - pkgsrc/graphics/gimp/PLIST 1.25 - pkgsrc/graphics/gimp/buildlink3.mk 1.13 - pkgsrc/graphics/gimp/distinfo 1.30 - pkgsrc/graphics/gimp/patches/patch-aa 1.16 - pkgsrc/graphics/gimp/patches/patch-ab 1.17 - pkgsrc/graphics/gimp/patches/patch-ac removed - pkgsrc/graphics/gimp/patches/patch-ae removed - pkgsrc/graphics/gimp/patches/patch-af removed - pkgsrc/graphics/gimp/patches/patch-ag removed - pkgsrc/graphics/gimp/patches/patch-ah removed Module Name: pkgsrc Committed By: adam Date: Mon Jul 10 22:06:32 UTC 2006 Modified Files: pkgsrc/graphics/gimp: Makefile PLIST buildlink3.mk distinfo pkgsrc/graphics/gimp/patches: patch-aa patch-ab Removed Files: pkgsrc/graphics/gimp/patches: patch-ae patch-ac patch-af patch-ag patch-ah Log Message: Changes 2.2.12: - fixed display problem in the Animation Playback plug-in - fixed misbehaviour of the user installation dialog - make sure that session-managed windows are mapped completely inside a monitor - don't use long deprecated libpng API - fixed possible segfault when closing image while saving it - halt tools when the image mode changes - fixed problem in Scale and Resize widgets - fixed wrong offset in transform PDB functions - fixed bugs in the Dicom load plug-in - make sure text widgets get all key events first - fixed problems with default values in the PNG save plug-in - fixed Save As dialog not displaying the filename - fixed compilation problem with gcc 4.1 - plugged a possible buffer overrun in the XCF parser - don't save image parasites twice in XCF files
2006-08-01#1766salo1-1/+3
2006-08-01Pullup ticket 1766 - requested by ghensalo7-24/+53
security update for seamonkey Revisions pulled up: - pkgsrc/www/seamonkey/Makefile 1.6 - pkgsrc/www/seamonkey/distinfo 1.7, 1.8 - pkgsrc/www/seamonkey/patches/patch-cn 1.2 - pkgsrc/www/seamonkey/patches/patch-dw 1.1 - pkgsrc/www/seamonkey-bin/Makefile 1.4 - pkgsrc/www/seamonkey-bin/distinfo 1.4 - pkgsrc/www/seamonkey-gtk1/Makefile 1.5 Module Name: pkgsrc Committed By: christos Date: Mon Jul 10 13:17:13 UTC 2006 Modified Files: pkgsrc/www/seamonkey: distinfo Added Files: pkgsrc/www/seamonkey/patches: patch-dw Log Message: Make this compile under gcc-4 --- Module Name: pkgsrc Committed By: ghen Date: Mon Jul 31 11:58:04 UTC 2006 Modified Files: pkgsrc/www/seamonkey: Makefile distinfo pkgsrc/www/seamonkey-bin: Makefile distinfo pkgsrc/www/seamonkey-gtk1: Makefile pkgsrc/www/seamonkey/patches: patch-cn Log Message: Update the Seamonkey packages to 1.0.3. Changes: * Improved stability * Several security fixes (see below) * A bug was introduced in SeaMonkey 1.0.2 that sometimes caused the URL bar to stop working properly when switching tabs. This has been fixed. (Bug 332874) * If you have more bookmarks on your personal toolbar than there is space for, the ">>" overflow icon will now display more reliably (Bug 338803) * If you choose to update SeaMonkey when it notifies you that an update is available, the update page will load in a more useful browser window (with navigation buttons and toolbars) (Bug 334903) Security fixes: MFSA 2006-56 chrome: scheme loading remote content MFSA 2006-55 Crashes with evidence of memory corruption (rv:1.8.0.5) MFSA 2006-54 XSS with XPCNativeWrapper(window).Function(...) MFSA 2006-53 UniversalBrowserRead privilege escalation MFSA 2006-52 PAC privilege escalation using Function.prototype.call MFSA 2006-51 Privilege escalation using named-functions and redefined "new Object()" MFSA 2006-50 JavaScript engine vulnerabilities MFSA 2006-49 Heap buffer overwrite on malformed VCard MFSA 2006-48 JavaScript new Function race condition MFSA 2006-47 Native DOM methods can be hijacked across domains MFSA 2006-46 Memory corruption with simultaneous events MFSA 2006-45 Javascript navigator Object Vulnerability MFSA 2006-44 Code execution through deleted frame reference For a detailed ChangeLog, see: http://www.mozilla.org/projects/seamonkey/releases/seamonkey1.0.3/changelog.html
2006-08-01#1767salo1-1/+3
2006-08-01Pullup ticket 1767 - requested by ghensalo2-7/+6
bugfix update for postfix Patch provided by the submitter. This patch is a back-port of fixes from Postfix 2.3. The main changes are: - The PostgreSQL client was updated after major database API changes in response to PostgreSQL security issues. This breaks support for PGSQL versions prior to 8.1.4, 8.0.8, 7.4.13, and 7.3.15. Support for these older releases requires major code changes that will have to wait until Postfix 2.4. - The Postfix SMTP client enforced Mandatory TLS only when talking to an ESMTP server; enforcement did not happen if Postfix could somehow be forced to send HELO instead of EHLO. This is minor compared to the DNS spoofing issues that were fixed with Postfix 2.2.10.
2006-07-31#1765salo1-1/+3
2006-07-31Pullup ticket 1765 - requested by gdtsalo2-1/+46
resolve szip license issue Revisions pulled up: - pkgsrc/archivers/szip/Makefile 1.7 - pkgsrc/licenses/szip-license 1.1 Module Name: pkgsrc Committed By: gdt Date: Thu Jul 6 14:43:27 UTC 2006 Modified Files: pkgsrc/archivers/szip: Makefile Log Message: Add RESTRICTED/NO_*_ON_* since the license does not grant permission to redistribute. --- Module Name: pkgsrc Committed By: gdt Date: Thu Jul 6 14:41:38 UTC 2006 Added Files: pkgsrc/licenses: szip-license Log Message: COPYING file from szip tarball
2006-07-31#1764salo1-1/+3
2006-07-31Pullup ticket 1764 - requested by tacasalo10-319/+2931
security fix for ruby18-base Module Name: pkgsrc Committed By: taca Date: Sun Jul 30 23:12:50 UTC 2006 Modified Files: pkgsrc/lang/ruby18-base: Makefile PLIST distinfo pkgsrc/lang/ruby18-base/patches: patch-ad patch-cc Added Files: pkgsrc/lang/ruby18-base/patches: patch-ck patch-cl patch-cm patch-cn patch-co Log Message: - Security fix for CVE-2006-3694 (JVN#13947696 and JVN#83768862). - Import yaml problem and fix document generation for ri(1). - minor clean up to pkgsrc. Bump PKGREVISION. --- Module Name: pkgsrc Committed By: taca Date: Mon Jul 31 11:29:03 UTC 2006 Modified Files: pkgsrc/lang/ruby18-base: Makefile PLIST distinfo pkgsrc/lang/ruby18-base/patches: patch-cm Log Message: - Fix PLIST problem; a extra entry. - Reduce warning of optparse.rb when generating ri(1) database. Bump PKGREVISION.
2006-07-30#1761, #1762, #1763salo1-1/+7
2006-07-30Pullup ticket 1763 - requested by wizsalo4-19/+19
security update for apache Revisions pulled up: - pkgsrc/www/apache/Makefile 1.188 - pkgsrc/www/apache/distinfo 1.53 - pkgsrc/www/ap-ssl/Makefile 1.103 - pkgsrc/www/ap-ssl/distinfo 1.33 Module Name: pkgsrc Committed By: jdolecek Date: Sun Jul 30 11:17:51 UTC 2006 Modified Files: pkgsrc/www/apache: Makefile distinfo Log Message: Update to 1.3.37: Changes with Apache 1.3.37 *) SECURITY: CVE-2006-3747 (cve.mitre.org) mod_rewrite: Fix an off-by-one security problem in the ldap scheme handling. For some RewriteRules this could lead to a pointer being written out of bounds. Reported by Mark Dowd of McAfee. [Mark Cox] --- Module Name: pkgsrc Committed By: jdolecek Date: Sun Jul 30 11:19:38 UTC 2006 Modified Files: pkgsrc/www/ap-ssl: Makefile distinfo Log Message: Update to 2.8.28, for apache-1.3.37 No changes besides the apache version update.
2006-07-30Pullup ticket 1762 - requested by wizsalo2-8/+8
sync ap-ssl with apache update Revisions pulled up: - pkgsrc/www/ap-ssl/Makefile 1.102 - pkgsrc/www/ap-ssl/distinfo 1.32 Module Name: pkgsrc Committed By: wiz Date: Sun Jul 23 17:25:56 UTC 2006 Modified Files: pkgsrc/www/ap-ssl: Makefile distinfo Log Message: Update to 2.8.27, for apache-1.3.36. Fixes PR 34060. Changes unknown.
2006-07-30Pullup ticket 1761 - requested by wizsalo5-50/+38
security update for apache Revisions pulled up: - pkgsrc/www/apache/Makefile 1.186, 1.187 - pkgsrc/www/apache/buildlink3.mk 1.16 - pkgsrc/www/apache/distinfo 1.52 - pkgsrc/www/apache/module.mk 1.11 - pkgsrc/www/apache/patches/patch-ap removed Module Name: pkgsrc Committed By: rillig Date: Sun Jul 2 10:43:19 UTC 2006 Modified Files: pkgsrc/www/apache: Makefile buildlink3.mk module.mk Log Message: Fixed some easy pkglint warnings. --- Module Name: pkgsrc Committed By: wiz Date: Wed Jul 19 22:45:14 UTC 2006 Modified Files: pkgsrc/www/apache: Makefile distinfo Removed Files: pkgsrc/www/apache/patches: patch-ap Log Message: Update to 1.3.36: Changes with Apache 1.3.36 *) Reverted SVN rev #396294 due to unwanted regression. The new feature introduced in 1.3.35 (Allow usage of the "Include" configuration directive within previously "Include"d files) has been removed in the meantime. (http://svn.apache.org/viewcvs?rev=396294&viewàev) Changes with Apache 1.3.35 *) SECURITY: CVE-2005-3352 (cve.mitre.org) mod_imap: Escape untrusted referer header before outputting in HTML to avoid potential cross-site scripting. Change also made to ap_escape_html so we escape quotes. Reported by JPCERT. [Mark Cox] *) core: Allow usage of the "Include" configuration directive within previously "Include"d files. [Colm MacCarthaigh] *) HTML-escape the Expect error message. Not classed as security as an attacker has no way to influence the Expect header a victim will send to a target site. Reported by Thiago Zaninotti [Mark Cox] *) mod_cgi: Remove block on OPTIONS method so that scripts can respond to OPTIONS directly rather than via server default. [Roy Fielding] PR 15242
2006-07-30#1758salo1-1/+3
2006-07-30Pullup ticket 1758 - requested by adrianpsalo3-3/+27
security fix for zoo Revisions pulled up: - pkgsrc/archivers/zoo/Makefile 1.27 - pkgsrc/archivers/zoo/distinfo 1.8 - pkgsrc/archivers/zoo/patches/patch-ak 1.1 Module Name: pkgsrc Committed By: adrianp Date: Wed Jul 19 19:34:38 UTC 2006 Modified Files: pkgsrc/archivers/zoo: Makefile distinfo Added Files: pkgsrc/archivers/zoo/patches: patch-ak Log Message: Add a patch for CVE-2006-0855 via Gentoo/Fedora Bump to nb2
2006-07-30#1759, #1760salo1-1/+5
2006-07-30Pullup ticket 1760 - requested by uebayasisalo2-6/+6
security update for thunderbird Revisions pulled up: - pkgsrc/mail/thunderbird/Makefile-thunderbird.common 1.16 - pkgsrc/mail/thunderbird/distinfo 1.25 Module Name: pkgsrc Committed By: uebayasi Date: Sat Jul 29 02:13:04 UTC 2006 Modified Files: pkgsrc/mail/thunderbird: Makefile-thunderbird.common distinfo Log Message: Update Thunderbird to 1.5.0.5. This is a security update announce at July 26, 2006. See the following URLs in detail: http://www.mozilla.org/security/announce/2006/mfsa2006-56.html http://www.mozilla.org/security/announce/2006/mfsa2006-55.html http://www.mozilla.org/security/announce/2006/mfsa2006-54.html http://www.mozilla.org/security/announce/2006/mfsa2006-53.html http://www.mozilla.org/security/announce/2006/mfsa2006-52.html http://www.mozilla.org/security/announce/2006/mfsa2006-51.html http://www.mozilla.org/security/announce/2006/mfsa2006-50.html http://www.mozilla.org/security/announce/2006/mfsa2006-49.html http://www.mozilla.org/security/announce/2006/mfsa2006-48.html http://www.mozilla.org/security/announce/2006/mfsa2006-47.html http://www.mozilla.org/security/announce/2006/mfsa2006-46.html http://www.mozilla.org/security/announce/2006/mfsa2006-45.html http://www.mozilla.org/security/announce/2006/mfsa2006-44.html
2006-07-30Pullup ticket 1759 - requested by uebayasisalo3-20/+28
security update for firefox Revisions pulled up: - pkgsrc/www/firefox/Makefile-firefox.common 1.35 - pkgsrc/www/firefox/distinfo 1.51, 1.52 - pkgsrc/www/firefox/patches/patch-cn 1.2 Module Name: pkgsrc Committed By: perry Date: Fri Jul 28 14:22:29 UTC 2006 Modified Files: pkgsrc/www/firefox: Makefile-firefox.common distinfo Log Message: Update package to 1.5.0.5 in response to CERT warnings of severe security problems with 1.5.0.4. No functional changes at all in the package -- this is purely a security update. See CERT advisory TA06-208A (last revised July 27) for details. --- Module Name: pkgsrc Committed By: uebayasi Date: Fri Jul 28 17:40:50 UTC 2006 Modified Files: pkgsrc/www/firefox: distinfo pkgsrc/www/firefox/patches: patch-cn Log Message: Fix build. (Don't bump because this must have never been built since 1.5.0.5 update.)
2006-07-28#1757salo1-1/+3
2006-07-28Pullup ticket 1757 - requested by tronsalo3-10/+10
security update for apache2 Revisions pulled up: - pkgsrc/devel/apr/distinfo 1.18 Updated via patch provided by the submitter. Module Name: pkgsrc Committed By: tron Date: Fri Jul 28 10:38:36 UTC 2006 Modified Files: pkgsrc/devel/apr: distinfo pkgsrc/www/apache2: Makefile Makefile.common distinfo options.mk Log Message: Update "apr" package to version 0.9.12.2.0.59 and "apache2" package to version 2.0.59. Changes since *2.0.58: - SECURITY: CVE-2006-3747 (cve.mitre.org) mod_rewrite: Fix an off-by-one security problem in the ldap scheme handling. For some RewriteRules this could lead to a pointer being written out of bounds. Reported by Mark Dowd of McAfee.
2006-07-27revert previous: wrong branchlukem1-3/+5
2006-07-27Remove ftp.au.netbsd.orglukem1-5/+3
2006-07-27#1756salo1-1/+3
2006-07-27Pullup ticket 1756 - requested by wizsalo4-8/+8
build fixes for python23 modules Revisions pulled up: - pkgsrc/x11/py-gtk2/buildlink3.mk 1.20 - pkgsrc/devel/py-game/buildlink3.mk 1.10 - pkgsrc/x11/py-qt3-base/buildlink3.mk 1.9 - pkgsrc/x11/py-qt3-modules/buildlink3.mk 1.9 - pkgsrc/x11/py-qt3-sip/buildlink3.mk 1.10 Module Name: pkgsrc Committed By: wiz Date: Wed Jul 26 16:56:53 UTC 2006 Modified Files: pkgsrc/x11/py-gtk2: buildlink3.mk Log Message: Fix BUILDLINK_ABI_DEPENDS line to use PYPKGPREFIX. --- Module Name: pkgsrc Committed By: wiz Date: Wed Jul 26 17:56:25 UTC 2006 Modified Files: pkgsrc/devel/py-game: buildlink3.mk pkgsrc/x11/py-qt3-base: buildlink3.mk pkgsrc/x11/py-qt3-modules: buildlink3.mk pkgsrc/x11/py-qt3-sip: buildlink3.mk Log Message: Fix BUILDLINK_ABI_DEPENDS to use PYPKGPREFIX.
2006-07-27#1755salo1-1/+3
2006-07-27Pullup ticket 1755 - requested by tronsalo2-6/+6
security update for firefox-bin Revisions pulled up: - pkgsrc/www/firefox-bin/Makefile 1.19 - pkgsrc/www/firefox-bin/distinfo 1.18 Module Name: pkgsrc Committed By: tron Date: Thu Jul 27 10:34:33 UTC 2006 Modified Files: pkgsrc/www/firefox-bin: Makefile distinfo Log Message: Update "firefox-bin" package to version 1.5.0.5. Changes since 1.5.0.4: - Improvements to product stability - Several security fixes: MFSA 2006-56 chrome: scheme loading remote content MFSA 2006-55 Crashes with evidence of memory corruption (rv:1.8.0.5) MFSA 2006-54 XSS with XPCNativeWrapper(window).Function(...) MFSA 2006-53 UniversalBrowserRead privilege escalation MFSA 2006-52 PAC privilege escalation using Function.prototype.call MFSA 2006-51 Privilege escalation using named-functions and redefined "new Object()" MFSA 2006-50 JavaScript engine vulnerabilities MFSA 2006-48 JavaScript new Function race condition MFSA 2006-47 Native DOM methods can be hijacked across domains MFSA 2006-46 Memory corruption with simultaneous events MFSA 2006-45 Javascript navigator Object Vulnerability MFSA 2006-44 Code execution through deleted frame reference
2006-07-26#1754salo1-1/+3
2006-07-26Pullup ticket 1754 - requested by drochnersalo4-20/+20
security update for gdm Revisions pulled up: - pkgsrc/x11/gdm/Makefile 1.116 - pkgsrc/x11/gdm/distinfo 1.40 - pkgsrc/x11/gdm/patches/patch-ab 1.16 - pkgsrc/x11/gdm/patches/patch-ae 1.12 Module Name: pkgsrc Committed By: drochner Date: Wed Jul 26 12:36:12 UTC 2006 Modified Files: pkgsrc/x11/gdm: Makefile distinfo pkgsrc/x11/gdm/patches: patch-ab patch-ae Log Message: update to 2.14.9 changes: - Backporting some useful features from 2.15 to 2.14. Per-display configuration and new gdmgreeter theming options -bugfixes -Better configure support for FreeBSD -Translation updates -Added gestures to the AccessKeyMouseEvents configuration file
2006-07-25#1753salo1-1/+3
2006-07-25Pullup ticket 1753 - requested by tacasalo3-9/+10
bugfix update for geeklog Revisions pulled up: - pkgsrc/www/geeklog/Makefile 1.11 - pkgsrc/www/geeklog/PLIST 1.6 - pkgsrc/www/geeklog/distinfo 1.5 Module Name: pkgsrc Committed By: taca Date: Mon Jul 24 16:13:55 UTC 2006 Modified Files: pkgsrc/www/geeklog: Makefile PLIST distinfo Log Message: Update geeklog package to 1.4.0.5.1 (1.4.0sr5-1). - Fix display problem with comment preview. - Add afrikaans language support.
2006-07-23#1752salo1-1/+3
2006-07-23Pullup ticket 1752 - requested by tronsalo3-14/+44
bugfixes for wireshark Revisions pulled up: - pkgsrc/net/wireshark/Makefile 1.2 - pkgsrc/net/wireshark/distinfo 1.2 - pkgsrc/net/wireshark/patches/patch-aa 1.2 Module Name: pkgsrc Committed By: drochner Date: Sun Jul 23 17:31:08 UTC 2006 Modified Files: pkgsrc/net/wireshark: Makefile distinfo pkgsrc/net/wireshark/patches: patch-aa Log Message: -remove old patch for the offset calculation of the inner packet, the original code is fixed now -re-add alignment fixes for variable radiotap elements bump PKGREVISION
2006-07-23#1750salo1-1/+3
2006-07-23Pullup ticket 1750 - requested by tacasalo5-25/+16
bugfixes for geeklog Revisions pulled up: - pkgsrc/www/geeklog/DEINSTALL 1.3 - pkgsrc/www/geeklog/INSTALL 1.2 - pkgsrc/www/geeklog/MESSAGE 1.3 - pkgsrc/www/geeklog/Makefile 1.10 - pkgsrc/www/geeklog/PLIST 1.5 Module Name: pkgsrc Committed By: taca Date: Sun Jul 23 13:21:09 UTC 2006 Modified Files: pkgsrc/www/geeklog: DEINSTALL INSTALL MESSAGE Makefile PLIST Log Message: - Fix bad handling of some cofiguration files noted by ghen@ behalf of pkgsrc release engineering team. - Keep current directory with DEINSTALL and INSTALL script. - remove extra processing with POST-DEINSTALL action from DEINSTALL script. - Suggest use of additional graphic package. - Add APACHE_GROUP to BUILD_DEFS. - install ${GEEKLOG_EXAMPLESDIR}/createdb.php with INSTALL_SCRIPT. Bump PKGREVISION.
2006-07-23#1749salo1-1/+3
2006-07-23Pullup ticket 1749 - requested by adrianpsalo2-3/+4
functionality fix for drupal Revisions pulled up: - pkgsrc/www/drupal/Makefile 1.14 - pkgsrc/www/drupal/files/drupal.conf 1.3 Module Name: pkgsrc Committed By: adrianp Date: Sun Jul 23 12:03:45 UTC 2006 Modified Files: pkgsrc/www/drupal: Makefile pkgsrc/www/drupal/files: drupal.conf Log Message: Add in an AllowOverride directive so that drupal access to a directory is controlled properly Fix by Takahiro Kambe in private mail. Bump to nb1.
2006-07-23#1751salo1-1/+3
2006-07-23Pullup ticket 1751 - requested by adrianpsalo3-3/+19
security fix for php5 Revisions pulled up: - pkgsrc/lang/php5/Makefile 1.38 - pkgsrc/lang/php5/distinfo 1.25 - pkgsrc/lang/php5/patches/patch-av 1.1 Module Name: pkgsrc Committed By: adrianp Date: Tue Jul 18 21:57:30 UTC 2006 Modified Files: pkgsrc/lang/php5: Makefile distinfo Added Files: pkgsrc/lang/php5/patches: patch-av Log Message: Fix for CVE-2006-3011 Bump to nb2