summaryrefslogtreecommitdiff
path: root/security
AgeCommit message (Collapse)AuthorFilesLines
2005-02-24Add RMD160 digests.agc202-202/+411
2005-02-24Add RMD160 digests.bad2-2/+4
2005-02-24Initial import of fwbuilder-2.0.5.bad10-0/+204
Firewall Builder is a multi-platform firewall configuration and management tool. It consists of a GUI and a set of policy compilers for various firewall platforms. Firewall Builder uses an object-oriented approach, it helps administrators maintain a database of network objects and allows policy editing using simple drag-and-drop operations. Firewall Builder currently supports iptables, IP Filter, ipfw, OpenBSD PF, and Cisco PIX fwbuilder provides the GUI frontend and the policy compilers.
2005-02-24Replace libfwbuilder with version 2.0.5 as the previous version wasn'tbad9-212/+159
useful. Firewall Builder is a multi-platform firewall configuration and management tool. It consists of a GUI and a set of policy compilers for various firewall platforms. Firewall Builder uses an object-oriented approach, it helps administrators maintain a database of network objects and allows policy editing using simple drag-and-drop operations. Firewall Builder currently supports iptables, IP Filter, ipfw, OpenBSD PF, and Cisco PIX libfwbuilder provides the back-end functionality in a library.
2005-02-23Revert previous, fixed in perl5/module.mk.wiz1-5/+2
2005-02-22Changes 2.5.2:adam4-38/+45
Cross-platform fix for checksumming code. This is *incompatible* with version 2.5.1. As a temporary workaround, setting "bugcompatibility 251" will maintain compatibility with release 2.5.1 for little-endian platforms (e.g. Intel). This will be removed from the final production release. Upgrade to Inno Setup 4. More documentation fixes. Increased the default thread stack size to 64k and added "threadstacksize" for debug/test purposes. Fix handling of HTTP/1.1 responses from proxies. Added acceptconnecttimeout (supersedes "connecttimeout") along with connectattempts, serverconnecttimeout and targetconnecttimeout. Fixed bug with "clienthost" not being honoured when Zebedee was used as a service.
2005-02-22Override MAKE_PARAMS returned set by perl5/module.mk; fixes build on -current.wiz1-2/+5
2005-02-21Changes 2.1.20:adam5-19/+21
* Bug-fixes
2005-02-21Sign over maintainership to tech-pkg@hubertf2-4/+4
2005-02-21Fix the authdaemond rc.d script to invoke the correct script to startjlam2-3/+5
the authentication daemon. Fix provided by Inseo Park in private mail. Also, honor VARBASE. Bump the PKGREVISION to 1.
2005-02-21Remove ruby-openssl package since it is included in ruby18 package now.taca4-71/+0
2005-02-21Remove ruby-digest package since it is included in ruby16/ruby18 package now.taca3-45/+0
2005-02-21Delete databases/ruby-dbm, devel/ruby-zlib, security/ruby-digest andtaca1-3/+1
security/ruby-openssl.
2005-02-21Changes 2.2.3:adam10-28/+28
Nessus 2.2.3 contains a new option called "silent dependencies" which can be used to filter out the noise generated by some plugins not directly enabled by the user. It also contains a slightly more intuitive GUI which now contains a "Credentials" tab to put Windows and SSH usernames and passwords.
2005-02-20when linking shared libssl on Solaris, make sure the rpath isgrant2-6/+14
included so it can find libcrypto.
2005-02-20Fix file installation, add missing samples config filesmanu2-4/+29
2005-02-19Add PKGVULNDIR to BUILD_DEFS.wiz1-1/+3
2005-02-19[Changes for 0.44 - 2004-12-16]wiz2-6/+5
* Add "pmfiles.dat" to legacy manifest_skip routine to accomodate early Win32 hacks. Reported by Steve Hay via Michael Schwern. [Changes for 0.43 - 2004-12-16] * Updated t/0-signature.t to be more friendly with Test::More; contributed by Michael Schwern. * Add $Timeout (default 3 seconds) to control the timeout for probing connections to the key server. * Take account of the .ts files produced by newer MakeMakers in the suggested MANIFEST.SKIP list. [Changes for 0.42 - 2004-11-20] * Move under SVK version control management; ditch keyword tags. * Michael Schwern pointed out that during development, the "signature.t" file would keep failing. * Documented how to generate SIGNATURE files as part of "make dist", for Module::Install, ExtUtils::MakeMaker and Module::Build users .
2005-02-19Update to 1.2.0. From the release announcement:wiz4-70/+371
We are pleased to announce the availability of GnuTLS 1.2.0! This release is the result of the 23 development releases made on the development branch (1.1.x). Major changes compared to the 1.0 branch include: * Moved SRP password authentication from the GnuTLS-extra library (licensed under GPL) to the core library (licensed under LGPL). * The API has been cleaned up, and data types now use a '_t' suffix. * Fixes to handle denial of service problem when verifying long certificate chains. * The manual has been converted to Texinfo and is consequently available in many formats, see: <http://josefsson.org/gnutls/manual/> * A reference API manual has been added, and is available in HTML and DevHelp formats, thanks to GTK-DOC, see: <http://josefsson.org/gnutls/reference/gnutls-gnutls.html> The 1.2.0 version is intended to be stable, and to be a drop-in replacement of the stable 1.0.x branch. We encourage developers to move to the 1.2 branch as soon as possible, since we will now spend less time improving version 1.0.x. We are not planning to open a 1.3 development branch soon, because there are no plans to start work on any major new feature today. Instead, we will continue to carefully improve the quality of this release over time. Improving GnuTLS is costly, but you can help! We are looking for organizations that find GnuTLS useful and wish to contribute back. You can contribute by reporting bugs, improve the software, or donate money or equipment.
2005-02-18Update security/courier-authlib to 0.54. Changes from version 0.53jlam6-16/+47
include: * userdb/makeuserdb.in: Report dangling symlinks.
2005-02-18Update to 0.96:wiz2-7/+6
- Makefile's error messages now correct if output is redirected (patch from Ilya Zakharevich). - Non-blocking connects/accepts now work (Problem found by Uri Guttman). - new_from_fd() now works. - getline() and <> in scalar context now return undef instead of '' when the read failed. (Problem found by Christian Gilmore). - Broken pipe signals are now ignored during socket close to prevent a SSL shutdown message from killing the parent program. (Problem found by Christian Gilmore). - Tests should proceed much more quickly, and a semi-race was fixed, meaning that on slow machines the tests should be more reliable. - Check for Scalar::Util and Weakref now uses default $SIG{__DIE__} instead of a potentially user-altered one (suggestion from Olaf Schneider). This only applies to Perl 5.6.0 & above. - Session caching support (patch from Marko Asplund). - set_default_context() added to alter the behavior of modules that use IO::Socket::SSL from the main program. - get_ssl_object() renamed to _get_ssl_object() to reflect the fact that it's only supposed to be used internally (not that you should have cared, of course). - Added patch for Net::SSLeay to take advantage of client-side session caching. (i.e. use 1.26 of Net-SSLeay)
2005-02-18Update to (inofficial) 1.26 needed by p5-IO-Socket-SSL-0.96:wiz2-7/+8
(1.26)** 30.4.2004 - added get1_session()
2005-02-18Upgraded ipsec-tools to release version 0.5manu11-188/+7
2005-02-17Accidently committed the wrong distinfo.peter1-2/+2
2005-02-17Get rid of the invalid extern for malloc and include stdlib.h for thepeter2-1/+21
prototype. Suggested by Thomas Klausner. Should fix PR pkg/29362 from A L Meyers.
2005-02-15Apparently autoconf 2.5x has some very sane reasons for not using atv3-11/+42
cache file by default; one of them is that recursion isn't re-parsing the values correctly (and hosing up on multiple spaces in things like CPPFLAGS). Amusingly enough, this hosage does not happen with a site cache file such as the one generated by autoswc. The switch to using :Q on these variables tripped over this stupidity bug, so turn off the Cyrus configure.in stupidity where it tries to force use of a cache file. Fixes PR pkg/29375 and PR pkg/29380.
2005-02-11Update audit-packages to 1.33:agc2-8/+8
In download-vulnerability-list, first set the PKGVULNDIR, then create the directory if it doesn't already exist. Pointed out by Geert Hendrickx on tech-pkg@
2005-02-10Rearrange so that the MAINTAINER and HOMEPAGE are stored with thejlam2-6/+6
package Makefile instead of Makefile.common. Also, fix the HOMEPAGE for the courier-authlib component of the Courier package.
2005-02-10Add a buildlink3.mk file for use by other package Makefiles.jlam1-0/+18
2005-02-10Add and enable courier-authlib.jlam1-1/+2
2005-02-10Import courier-authlib-0.53 as security/courier-authlib.jlam10-0/+419
The Courier authentication library provides authentication services for other Courier applications. In this context, the term "authentication" refers to the following functions: 1. Take a userid or a loginid, and a password. Determine whether the loginid and the password are valid. 2. Given a userid, obtain the following information about the userid: A. The account's home directory. B. The numeric system userid and groupid that owns all files associated with this account. C. The location of the account's maildir. D. Any maildir quota defined for this account. See the Courier documentation for more information on maildir quotas. E. Other miscellaneous account-specific options. 3. Change the password associated with a loginid. 4. Obtain a complete list of all loginids.
2005-02-10Update security/openpam to 20050201 (Feterita). Changes from versionjlam4-17/+20
20040210 (Eelgrass) include: - BUGFIX: Correct numerous markup errors, invalid cross-references, and other issues in the manual pages, with kind assistance from Ruslan Ermilov <ru@freebsd.org>. - BUGFIX: Avoid multiple evaluation of macro arguments in ENTERX() and RETURNX() macros. - BUGFIX: Remove an unnecessary and non-portable pointer cast in pam_get_data(3). - BUGFIX: Fix identical typos in PAM_ACCT_EXPIRED case in pam_strerror(3) and gendoc.pl. - ENHANCE: Minor overhaul of the autoconf / build system. - ENHANCE: Add openpam_free_envlist(3).
2005-02-09Update fprot-workstation-bin to version 4.5.3.ben3-14/+14
This addresses PR#29271. Changes include: Version 4.5.3 adds a new commandline switch to f-protd, '-fullreport' and new possible summary codes (see man page for details). Version 4.5.2 is a bugfix release; f-protd would misidentify .pdf files and block them from being delivered. Version 4.5.1 is a bugfix release to fix a bug in scan-mail.pl where scan-mail.pl would exit after first scan request on some unix platforms, because of differing signal mechanism between BSD and SysV Version 4.5.0 contains various bugfixes and improvements to the documentation and software. o check-updates.pl has been modified. It now identifies itself with a unique user-agent string containing information on OS, kernel and architecture. o contains a major overhaul of the virus scanning engine (new engine version 3.16.1). These changes improve its detection capabilities. The engine can now better detect and handle executable packers, often used by malware authors to conceal malicious code. o includes a more generic JPEG GDI+ exploit detection o includes EMF/WMF image format exploit detection o encrypted executables inside archives are now reported as "could be a suspicious file (encrypted program in archive)", previously reported as "could be a security risk". o The argument switch "-archive" has been changed to support the form "-archive=n" where n is a non-negative integer. This causes f-prot to scan only n levels deep into nested archives of supported types in order to protect against 'arhcive-bombs'. The old form "-archive" is still supported, although depreciated, and implies n==5. See the man page for details. o Minor modifications in the DTD for the f-prot daemon XML. o Bugfix where f-prot would return IO_ERROR when attempting to scan unsupported partial archive files, e.g. .z01 files o Improved RAR support. F-Prot fully supports rar versions 1.5, 2.0 and 2.6 and partially supports rar 2.9 (doesn't support RAR Virtual Machine and the PPM model features)
2005-02-09Disable gnupg's new iconv code on platforms that have problems with itmarkd1-1/+5
in the default locale (NetBSD < 2.0 and Solaris). OK'ed by wiz. Fixes PR pkg/28895.
2005-02-07Instantly deprecate USE_PAM from pkgsrc as its value is being set fromjlam2-6/+14
within NetBSD-current's bsd.own.mk, which conflicts with its usage in pkgsrc. The package that use USE_PAM have been converted to use the bsd.options.mk framework. This should fix PR pkg/29257.
2005-02-05Fix BUILDLINK_DEPENDS.libnet for bulk-buildsadrianp2-4/+4
2005-02-02Modify openssl/Makefile so that it's easier to test the -STABLE andjlam1-6/+22
-SNAP OpenSSL snapshots.
2005-02-01Updated keychain to 2.5.1martti2-5/+5
Don't accidentally inherit a forwarded agent when inheritwhich=local-once. Move the --stop warning after the version splash. Add inheritance support via --inherit. Add parameters to --stop for more control. Change the default behavior of keychain to inherit if there's no keychain agent running ("--inherit local-once"), and refrain from killing other agents unless "--stop others" is specified.
2005-02-01Update to 2.2.1, provided by the maintainer, Julian Dunn, in PR 29183.wiz2-6/+5
Release notes: December 22, 2004 amavisd-new-2.2.1 release notes SECURITY: - add support for the pax(1) archive decoder, which can handle tar/cpio/pax archives (including legacy format variants). Due to limitations in cpio (and in Archive::Tar), for security reasons it is preferred to decode such archives with pax and no longer with cpio; please add a line: $pax = 'pax'; to amavisd.conf and verify that the program pax is installed on the system (and in the jail if running in chroot); - perform additional tests at startup time on the proper protection of the configuration file; - add file name extensions wmf, emf and grp to the example list of banned extension, according to recent Microsoft security bulletins; suggested by Stephane Lentz; - introduces 'clean but inconclusive' av scanner result to avoid a specialized or quick partial av scanner like jpeg checker to claim mail is clean when all other general purpose av scanners fail (see below); INCOMPATIBILITY: - removed some legacy $*_ldap variables, as they are no longer needed; These variables were still declared but ignored in 2.2.0 for compatibility with older amavisd.conf files. Such variables need to be removed from the amavisd.conf if they are still present there from older versions, otherwise Perl will complain with 'Global symbol ... requires explicit package name"; OTHER FIXES: - files_to_scan and decompose_mail are now able to remove unexpected directories which may have been left behind by some failed decoding and were causing temporary failures and mail delivery retries; error recovery problem after failed unarj reported by Ralf Hildebrandt; - error recovery code in files_to_scan and rmdir_recursively now tries to change protection on directories and files, and retry if the first attempt to access them fails because of denied permission; - pre-load some additional Perl modules needed by SA when running in chroot; - add module Net::LDAP::Search to a list of pre-fetched modules; omission pointed out by Paul Jacobson; - when quarantining is disabled by keeping $QUARANTINEDIR undefined, the log entry and administrator notification message inappropriately suggested that mail was quarantined, which in fact (appropriately) it was not. Setting $QUARANTINEDIR='' did work as expected. Reported by Sascha Lucas; - avoid the use of Encode::is_utf8 due to a Perl bug (still present in 5.8.5) where Encode::is_utf8 on tainted utf8 character string produces false; - modify safe_encode() to guarantee the result is a string of octets, not a string of UTF-8 characters; it saves some unnecessary work in further processing and keeps MIME::Entity from UTF swamp when running in chroot; problem pointed out by Branko F. Gracnar; - avoid braindead Perl default where an empty regexp implies the last successfully matched regexp, which (if not being very careful) brings in some completely unrelated last-executed regular expression; - change kill 'TERM' into kill 'KILL' when a forked process within run_command and run_command_consumer gets into deep trouble, to avoid exit handlers being invoked in the subprocess (which could lead to two processes trying to clean the same set of temporary files); - in an old sendmail setup using the amavis(.c) helper program without LDA arguments, avoid inappropriate warning: "WARN: no recips left (forgot to set $forward_method=undef using milter?) and return status 0 instead of 99 when message is to be blocked, as the helper program amavis(.c) does not recognize status 99 in this situation and inappropriately passed it on to sendmail; reported by The Mindflayer; - the @bypass_header_checks_maps is now able to also bypass the bad header checks as provided by MIME::Parser; inconsitency reported by CRivera; - avoid some Perl warning messages; thanks to Bill Landry; CHANGES AND MINOR NEW FEATURES: - add configuration variable @newvirus_admin_maps (and $newvirus_admin, along with corresponding SQL field 'newvirus_admin') which works like the existing @virus_admin_maps (and $virus_admin), except that it sends virus administrator notification to specified e-mail address only for newly encountered viruses which have not yet been encountered since the amavisd startup. It makes use of by-virusname counters in the SNMP counters database. If more than one child process starts working on infected message containing a not-yet-accounted-for virus, there might be more than one 'first time' notification, this is not a malfunction. Both the @newvirus_admin_maps and the @virus_admin_maps may be enabled, each (possibly both) would receive their notifications as appropriate. A useful setting is to globally enable only the new virus notifications, and additionally enable _all_ administrator notifications for internally originating mail only (by the use of policy banks); - provide separate configuration variables @banned_admin_maps and @bad_header_admin_maps, along with corresponding SQL fields 'banned_admin' and 'bad_header_admin'; their function was previously covered by @virus_admin_maps, which now only still controls administrator notifications in case of viruses; - introduces 'clean but inconclusive' av scanner result to avoid a specialized or quick partial av scanner like jpeg checker to claim mail is clean when all other general purpose av scanners fail: in av scanner entries (lists @av_scanners and @av_scanners_backup) give an extended meaning to undefined fourth argument (the 'match for clean' list or regexp). The interpretation of the fourth argument is now: 4. an array ref of av scanner exit status values, or a regexp (to be matched against scanner output), indicating NO VIRUSES found; a special case is a value undef, which does not claim file to be clean (i.e. it never matches, similar to []), but suppresses a failure warning; to be used when the result is inconclusive (useful for specialized and quick partial scanners such as jpeg checker); Also modified example jpeg checker entry in amavisd.conf accordingly. - NOD32 av scanner: changed @av_scanners entry to match the new version of the scanner; thanks to Nejc Skoberne; - added @av_scanners entry for File::Scan; - when preparing a SQL SELECT clause for white/blacklisting lookup, take into account a relative position of ? and %k in the $sql_select_white_black_list template to improve flexibility of specifying the clause; suggested by Matt Petteys; - reduce the log level of some more common and harmless log messages; - macro %p and the log entry now reports full policy bank path, not just the last loaded policy bank name; - added LDAP attributes amavisWarnVirusRecip, amavisWarnBannedRecip, and amavisWarnBadHeaderRecip; by Joel Nimety and Michael Hall; - renamed LDAP attribute name amavisSpamModifiesSubject to amavisSpamModifiesSubj in order to match the documented LDAP schema; noticed by Kees Bos, patch by Michael Hall; - add support for ripOLE decoder, which attempt to extract embedded documents from MS OLE documents (MS Office) (http://www.pldaniels.com/ripole/, by Paul L Daniels)); ripOLE is still experimental/alpha code; To be make amavisd-new find the installed program 'ripole', add the: $ripole = 'ripole'; to the amavisd.conf; suggested by David Wilson and Noel Jones; - allow multiple occurrences of command line option: -c config_file and execute the provided configuration files one after the other; based on a subset of functionality provided as a patch by Davor Ocelic; - a slight improvement (in default $map_full_type_to_short_type_re) in classifying mpeg and some other multimedia files; - several minor code cleanups; - add a recommendation by Daniel J McDonald to a documentation file INSTALL: If different UID is preferred for an AV scanner, a solution for ClamAV is to add user clamav to the amavis group, and then add AllowSupplementaryGroups to clamd.conf; - enclosed a simple demonstrational Perl program amavis.pl, which is functionally much like the amavis.c helper program, but talks the new AM.PDP protocol with the amavisd daemon. See README.protocol for the description of AM.PDP protocol. To be placed in amavisd.conf: $protocol='AM.PDP'; $unix_socketname='/var/amavis/amavisd.sock'; Usage: amavis.pl sender recip1 recip2 ... < message.txt - documentation updates;
2005-01-30Commit some fixes from the maintainer:wiz3-6/+7
python-2.4 is not usable for this package. The python wrapper scripts' names have changed, adapt patch-aa. Bump PKGREVISION.
2005-01-30Remove "--disable-setreuid" -- the configure scripts seems to havekim1-3/+3
adequate logic for determining when to use setreuid. This makes sudoedit work on NetBSD again. Closes PR pkg/28998
2005-01-28Force all current packages using the libnet 1.0.x tree to use aadrianp2-2/+6
verision of libnet <= 1.0.1b. This will prevent the case where the user has installed the libnet 1.1.x branch and then tries to install an application that is not compatible with the 1.1.x tree. Over time the list of these applications that require the 1.0.x branch will be reduced as they are updated to later versions that support the libnet 1.1.x branch. This addresses PR# 29056 opened by diro (at) nixsys.bz, thanks for the PR !
2005-01-28Oops, make sure to bump PKG_REVISION.taca1-1/+2
2005-01-28Add RUBY_HAS_ARCHLIB which have machine dependent extention libraries.taca2-2/+5
Bump PKG_REVISION.
2005-01-27Changes 0.2.13:adam3-9/+31
- Version number in libtasn1.h updated properly. Changes 0.2.12: - Manual converted to Texinfo format. - Manual in GTK-DOC and DevHelp formats added. - Man pages for all functions added. - Various internal cleanups.
2005-01-23Build Python with thread support by default and turn the existingrecht3-6/+6
python*-pth packages into meta-packages which will install the non-pth packages. Bump PKGREVISIONs on the non-pth versions to propagate the thread change, but leave the *-pth versions untouched to not affect existing installations. Sync all PYTHON_VERSIONS_AFFECTED lines in package Makefiles.
2005-01-23Update to Ruby 1.8.2 base and thses changes:taca1-3/+3
o Use Ruby's version instead of its own (old) version.
2005-01-23Update Ruby 1.8.2.taca1-1/+2
This is basically bug fix release, but official changes aren't provided yet. Please refer ChangeLog. Here is pkgsrc changes: o Set RUBY_HAS_ARCHLIB=yes for Ruby packages including archtecture depending extention library in order to depend more specific Ruby. o Now install database for ri(1). Fix PR pkg/28566. o Net::IMAP * lib/net/imap.rb (u8tou16): fixed typo. fixed: [ruby-list:40546] o NKF: * ext/nkf/nkf-utf8/nkf.c (reinit): should initialize all static variables. fixed: [ruby-list:40445] * ext/nkf/lib/kconv.rb (Kconv::RegexpEucjp): second byte is up to 0xfe. * ext/nkf/lib/kconv.rb (Kconv#kconv): should handle UTF8 and UTF16 properly. o WEBrick * lib/webrick/httpauth/htpasswd.rb (WEBrick::Htpasswd#reload): raise NotImplementedError if password is encrypted by digest algorithms. This patch is contributed by sheepman. [ruby-list:40467] * lib/webrick/httpauth/digestauth.rb (WEBrick::HTTPAuth::DigestAuth#_authenticate): fix digest calculation. This patch is contributed by sheepman. [ruby-list:40482] * lib/webrick/{httpauth.rb,httpauth/basicauth.rb,httpproxy.rb}: use pack/unpack-template char "m" instead of lib/base64.rb to do base64 encoding/decoding. fixed: [ruby-dev:25336]
2005-01-23Fix homepage, pointed out by Jeremy C. Reed.peter1-2/+2
2005-01-22Renamed tls to tcl-tls.peter1-2/+2