summaryrefslogtreecommitdiff
AgeCommit message (Collapse)AuthorFilesLines
2009-10-04Update samba package to 3.0.37.taca11-69/+82
This is a security release in order to address CVE-2009-2813, CVE-2009-2948 and CVE-2009-2906. Please note that Samba 3.0 is not maintained any longer. This security release is shipped on a voluntary basis. o CVE-2009-2813: In all versions of Samba later than 3.0.11, connecting to the home share of a user will use the root of the filesystem as the home directory if this user is misconfigured to have an empty home directory in /etc/passwd. o CVE-2009-2948: If mount.cifs is installed as a setuid program, a user can pass it a credential or password path to which he or she does not have access and then use the --verbose option to view the first line of that file. o CVE-2009-2906: Specially crafted SMB requests on authenticated SMB connections can send smbd into a 100% CPU loop, causing a DoS on the Samba server.
2009-10-04update master_sites. stick to official distribution sites. remove neu.edu.zafer1-2/+1
2009-10-04update master_sites. remove ftp entry. service has been suspended.zafer1-3/+2
2009-10-04Note update of net/filezilla to 3.2.8zafer1-1/+2
2009-10-04Update filezilla to 3.2.8.zafer3-8/+8
Changelog: * Changing directories at the same time an upload finishes no longer disturbs synchronized browsing * *nix: Ensure dialogs can be closed using escape key * *nix: Fix height of settings dialog * Remember last used search conditions * Display link overlay on icons of links in remote file list * Display of average transfer speed should converge faster to overall average * Simplify default file exists action dialogs * Apply decimal places size formatting option also to total queue size * MSW: Reduce number of needed user interactions in installer if update started from within FileZilla * MSW: Check that there are no running instances of FileZilla before installing * Fix handling of remote directory names with leading or trailing spaces * *nix: Fix memory leaks in D-Bus session management and power management inhibitor client code * *nix: Fall back to org.gnome.SessionManager if org.freedesktop.PowerManagment does not exit to inhibit idle sleep during transfers * Increase default size of SO_RCVBUF (TCP advertised window) to fix performance issues on high-latency connections * MSW: Fix displaying list of shares on local network resources * MSW: Remote file editing no longer gets confused if two filenames only differ in character case * Fix dialog line wrapping issues * Ensure width of site manager is large enough to fit all tabs * Better guard against filename columns being moved or hidden * *nix, OS X: Handle filesystems without advisory file locking instead of falsely warning about site manager being opened in a different instance of FileZilla
2009-10-04Note update of the "apache22" package to version 2.2.13nb3.tron1-1/+2
2009-10-04Add patch from the Apache SVN repository to the vulnerability reportedtron3-14/+27
in CVE-2009-3095.
2009-10-04Note update of mail/squirrelmail package to 1.4.20rc2nb2.taca1-1/+2
2009-10-04Add two small fix:taca4-3/+50
* Use case ignore match for detecting encoded header. This is language independent problem. * Improve handling of file name of attachment in Japanese environment. These fixes make squirrelmail usable after remove of japaneses patch. Bump PKGREVISION.
2009-10-03Set the correct cpu in macppc and macppc64 so that this builds. Onlyjmmv1-1/+9
verified in macppc though.
2009-10-03mgetty 1.1.36nb1 actually didn't include the security patch.is1-1/+2
2009-10-03fix GNUism in find syntax in the news.daily script sourcespz3-6/+15
(reported by Geoff Wing <gcw@pobox.com>)
2009-10-03Updated mail/thunderbird and mail/thunderbird-gtk1 to 2.0.0.23.ghen2-3/+4
2009-10-03Update thunderbird and thunderbird-gtk1 to 2.0.0.23.ghen12-153/+68
Security fixes in this version: MFSA 2009-43 Heap overflow in certificate regexp parsing MFSA 2009-42 Compromise of SSL-protected communication For more info, see http://www.mozilla.com/en-US/thunderbird/2.0.0.23/releasenotes/
2009-10-03Actually, the security patch was missing from my last commit. PKGREVISIONis3-5/+37
increased to distinguish.
2009-10-03Avoid getline breakage.ahoka1-0/+49
Now with the patch actually committed.
2009-10-03Avoid getline breakage.ahoka1-1/+2
2009-10-03Mark a few packages for which I have updates ready.wiz1-4/+5
2009-10-03Add TODO entry for missing xorg packages,wiz1-22/+51
e.g.: mkcomposecache, xscope, windowswmproto + MesaLib-7.6.0, asymptote-1.88, calibre-0.6.16, clive-2.2.7, cln-1.3.1, compositeproto-0.4.1, conserver-8.1.17, db4-4.8.24, dbxml-2.5.13, delegate-9.9.5, f-spot-0.6.1.3, fontcacheproto-0.1.3, glib2-2.22.1 [GNOME 2.28], gnome-bluetooth-2.28.1 [GNOME 2.28], gnome-menus-2.28.0.1 [GNOME 2.28], gtk2-2.18.1 [GNOME 2.28], gtksourceview2-2.8.1 [GNOME 2.28], inputproto-2.0, java-db3-3.87, libX11-1.3, libXext-1.1, libXi-1.3, libXinerama-1.1, libXrender-0.9.5, libgee-0.5.0, libssh2-1.2.1, libusb-1.0, luit-1.0.4, mDNSResponder-212.1, modular-xorg-server-1.7.0, mp3diags-0.99.06.040, nut-15.0, py-bsddb3-4.8.0, py-usb-0.4.2, qt4-libs-4.5.3, recordproto-1.14, saxon-9.2, tea-26.0.0, totem-2.28.1 [GNOME 2.28], totem-pl-parser-2.28.1 [GNOME 2.28], vte-0.22.2 [GNOME 2.28], windowlab-1.36, xf86dgaproto-2.1, xf86vidmodeproto-2.3, xineramaproto-1.2, xkeyboard-config-1.7, xterm-249.
2009-10-03Remove wip artefacts.wiz4-8/+8
2009-10-02Use kde4 from pkgsrc.wiz1-3/+3
2009-10-02Add kde 4.3.1markd2-3/+30
2009-10-02Add kde4 l10n packagesmarkd1-1/+4
2009-10-02Import KDE4.3.1 from wipmarkd4-0/+1548
OKed during freeze by wiz and agc
2009-10-02Import KDE4.3.1 from wipmarkd8-0/+3475
OKed during freeze by wiz and agc
2009-10-02Import KDE4.3.1 from wipmarkd36-1/+3488
OKed during freeze by wiz and agc
2009-10-02Import KDE4.3.1 from wipmarkd25-0/+10722
OKed during freeze by wiz and agc
2009-10-02Add kdetoys4 and kdegames4markd1-1/+3
2009-10-02Import KDE4.3.1 from wipmarkd10-0/+2239
OKed during freeze by wiz and agc
2009-10-02Add kdesdk4markd1-1/+2
2009-10-02Import KDE4.3.1 from wipmarkd6-0/+933
OKed during freeze by wiz and agc
2009-10-02Add kdemultimedia4markd1-1/+2
2009-10-02Import KDE4.3.1 from wipmarkd12-0/+344
OKed during freeze by wiz and agc
2009-10-02Add kdenetwork4markd1-1/+2
2009-10-02Import KDE4.3.1 from wipmarkd6-0/+1550
OKed during freeze by wiz and agc
2009-10-02Add kdegraphics4 and oxygen-icons.markd1-1/+3
2009-10-02Import KDE4.3.1 from wipmarkd6-0/+569
OKed during freeze by wiz and agc
2009-10-02Import oxygen icon set for KDE4.3.1 from wipmarkd4-0/+5433
OKed during freeze by wiz and agc
2009-10-02Add kdewebdev4.markd1-1/+2
2009-10-02Import KDE4.3.1 from wipmarkd4-0/+272
OKed during freeze by wiz and agc
2009-10-02add kde4 packagesmarkd1-1/+7
2009-10-02Import KDE4.3.1 from wipmarkd7-0/+937
OKed during freeze by wiz and agc
2009-10-02Import KDE4.3.1 from wipmarkd26-0/+3613
OKed during freeze by wiz and agc
2009-10-02Import KDE4.3.1 from wipmarkd20-0/+1831
OKed during freeze by wiz and agc
2009-10-02Update mgetty to 1.1.36, at the same time patching faxspool to useis10-92/+53
mktemp(1) to avoid symlink vulnerabilities in tmp file/directory creation/removal (mitre.org CVE-2008-4936). Named 1.1.36nb1 to emphasize difference from upstream. Commit ok'd by agc@.
2009-10-02Import KDE4.3.1 from wipmarkd14-0/+4572
OKed during freeze by wiz and agc
2009-10-02add ortpmarkd1-1/+2
2009-10-02Import ortp 0.16.0 from wipmarkd6-0/+91
oRTP - a Real-time Transport Protocol (RFC3550) stack under LGPL Features: * Written in C, works under Linux (and probably any Unix) and Windows. * Implement the RFC3550 (RTP) with a easy to use API with high and low level access. * Includes support for multiples profiles, AV profile (RFC3551) being the one by default. * Includes a packet scheduler for to send and recv packet "on time", according to their timestamp. Scheduling is optional, rtp sessions can remain not scheduled. * Supports mutiplexing IO, so that hundreds of RTP sessions can be scheduled by a single thread. * Features an adaptive jitter algorithm for a receiver to adapt to the clockrate of the sender. * Supports part of RFC2833 for telephone events over RTP. * The API is well documented using gtk-doc. * Licensed under the Lesser Gnu Public License. * RTCP messages sent periodically since 0.7.0 (compound packet including sender report or receiver report + SDES) * Includes an API to parse incoming RTCP packets. OKed during freeze by wiz and agc.
2009-10-02Updated security/opensc-signer to 0.11.9nb1.hasso1-1/+2
2009-10-02Change install location from ${PREFIX}/lib/mozilla/plugins tohasso2-5/+6
${PREFIX}/lib/xulrunner/plugins. Bump PKGREVISION.