summaryrefslogtreecommitdiff
path: root/security
AgeCommit message (Collapse)AuthorFilesLines
2006-10-04Update cyrus-sasl (and plugins, authd) to 2.1.22.obache21-118/+92
New in 2.1.22 ------------- * Added support for spliting big data blocks (bigger than maxbuf) into multiple SASL packets in sasl_encodev * Various sasl_decode64() fixes * Increase canonicalization buffer size to 1024 bytes * Call do_authorization() after successful APOP authentication * Allow for configuration file location to be configurable independently of plugin location (bug # 2795) * Added sasl_set_path function, which provides a more convenient way of setting plugin and config paths. Changed the default sasl_getpath_t/sasl_getconfpath_t callbacks to calculate the value only once and cache it for later use. * Fixed load_config to search for the config file in all directories (bug # 2796). Changed the default search path to be /usr/lib/sasl2:/etc/sasl2 * Don't ignore log_level configuration option in default UNIX syslog logging callback * (Windows) Minor IPv6 related changes in Makefiles for Visual Studio 6 * (Windows) Fixed bug of not setting the CODEGEN (code generation option) nmake option if STATIC nmake option is set. * Several fixed to DIGEST-MD5 plugin: - Enable RC4 cipher in Windows build of DIGEST-MD5 - Server side: handle missing realm option as if realm="" was sent - Fix DIGEST-MD5 to properly advertise maxssf when both DES and RC4 are disabled - Check that DIGEST-MD5 SASL packet are no shorter than 16 bytes * Several changes/fixed to SASLDB plugin: - Prevent spurious SASL_NOUSER errors - Added ability to keep BerkleyDB handle open between operations (for performance reason). New behavior can be enabled with --enable-keep-db-open. * Better error checking in SQL (MySQL) auxprop plugin code * Added support for HTTP POST password validation in saslauthd * Added new application ("pluginviewer") that helps report information about installed plugins * Allow for building with OpenSSL 0.9.8 * Allow for building with OpenLDAP 2.3+ * Several quoting fixes to configure script * A large number of other minor bugfixes and cleanups
2006-10-03Update to 0.0.6:gdt2-7/+7
** Parse "group" configuration parameters of GnuPG. ** epg-verify-file and epg-verify-string now return the plaintext after successful verification. ** Obey the decoding coding-system determined by decode-coding-inserted-region. ** Improved progress display. ** Allow file names starting with "-".
2006-10-03The self test sometimes ends in an endless loop.rillig1-1/+4
2006-10-03Update security/pgpdump to 0.25 applying patch by PR pkg/34701 fromtaca2-6/+6
jun@. From CHANGES: 0.25 2006/10/02 * Catching upto ID 18. Adding SHA224.
2006-10-02Imported p5-Crypt-PasswdMD5.rillig2-10/+10
This code provides various crypt()-compatible interfaces to the MD5-based crypt() function found in various *nixes.
2006-10-02Update amavisd-new to 2.4.3, based on PR 34041.obache4-26/+27
--------------------------------------------------------------------------- June 27, 2006 amavisd-new-2.4.2 release notes SUMMARY OF CHANGES: - new feature: "pen pals soft-whitelisting" lowers spam score of received replies to a message previously sent by a local user to this address; - new feature: added command line options to override certain configuration settings from a config file, see below; - documentation bug fixes, especially on the use of SQL data type TIMESTAMP; - zoo decoder interface routine can now use utility unzoo(1) or zoo(1); --------------------------------------------------------------------------- May 8, 2006 amavisd-new-2.4.1 release notes INCOMPATIBLE CHANGE WITH 2.4.0: - notification templates incompatibility with 2.4.0 (but not with versions 2.3.3 or older): major contents category numbers are renumbered due to a newly inserted category CC_SPAMMY; it affects the use of macro ccat_maj in templates (one field added), and only affect users which provide non-default templates based on 2.4.0 templates; older templates (2.3.3 or earlier) are unaffected as they do not use macro ccat_maj; --------------------------------------------------------------------------- April 3, 2006 amavisd-new-2.4.0 release notes The most important changes since 2.3.3 at a glance: Delivery status notifications (DSN) are now supported, both as a SMTP protocol extension and in notifications. Header fields like X-Amavis and X-Spam are now prepended to mail header for DomainKeys compatibility. Configuration variables can be chosen based on mail contents category, which is now represented explicitly. A built-in macro expander is enhanced, providing new macros and call types. Added support for passive operating system fingerprinting with the use of p0f, supplying collected information as a header field to SpamAssassin. Provide compatibility with Net::Server 0.91 and later.
2006-10-01Fixed some pkglint warnings.rillig1-4/+5
2006-10-01The "test" phase is interactive.rillig1-1/+4
2006-09-30Apply patches which fixes recent security problem of OpenSSL.taca14-3/+337
http://secunia.com/advisories/22130/ Bump PKGREVISION.
2006-09-28Always use "unsigned int" for a 32 bit unsigned integer which is correcttron4-7/+35
on all platforms supported by pkgsrc. This should fix LP64 problems reported in PR pkg/19765 by John Heasley.
2006-09-28Update to openssh-4.3.2 (OpenSSH 4.3p2). I missed existence of PR/32858taca2-8/+8
at previous commit. Note: OpenSSH 4.4p1 has already released, there is no hpn-patch patch yet, so I don't update to it while pkgsrc-freeze is in effect. 20060211 - (dtucker) [README] Bump release notes URL. - (djm) Release 4.3p2 20060208 - (tim) [session.c] Logout records were not updated on systems with post auth privsep disabled due to bug 1086 changes. Analysis and patch by vinschen at redhat.com. OK tim@, dtucker@. - (dtucker) [configure.ac] Typo in Ultrix and NewsOS sections (NEED_SETPRGP -> NEED_SETPGRP), reported by Berhard Simon. ok tim@ 20060206 - (tim) [configure.ac] Remove unnecessary tests for net/if.h and netinet/in_systm.h. OK dtucker@. 20060205 - (tim) [configure.ac] Add AC_REVISION. Add sys/time.h to lastlog.h test for Solaris. OK dtucker@. - (tim) [configure.ac] Bug #1149. Changes in QNX section only. Patch by kraai at ftbfs.org. 20060203 - (tim) [configure.ac] test for egrep (AC_PROG_EGREP) before first AC_CHECK_HEADERS test. Without it, if AC_CHECK_HEADERS is first run by a platform specific check, builtin standard includes tests will be skipped on the other platforms. Analysis and suggestion by vinschen at redhat.com, patch by dtucker@. OK tim@, djm@. 20060202 - (dtucker) [configure.ac] Bug #1148: Fix "crippled AES" test so that it works with picky compilers. Patch from alex.kiernan at thus.net.
2006-09-27Add patches to fix the problem reported by Secunia Advisory SA22091 (alsotaca5-5/+167
CVS-2006-4924); "OpenSSH Identical Blocks Denial of Service Vulnerability" referring to OpenBSD's CVS repository. Bump PKGREVISION.
2006-09-22 Fixed RSA e=3 bug (most likely nobody uses e=3 rsa keyskivinen20-5/+475
on ssh anyways, but better to make sure). Fixed some more ssh_*_{en,de}code calls missing necessary casts. Disabled x11-security extension on x86_64 as it does not work there (uses xauth instead). Updated pkgrevision.
2006-09-20Fixed the path to the manual pages.rillig1-8/+10
2006-09-17Fix build on DragonFly and other platforms without LOCAL_CREDS.joerg2-1/+34
No idea how this code was ever tested, it can't compile for obvious reaons.
2006-09-16Bump revisions due to gnome-vfs2 update: dbus-glib is now a dependency.jmmv6-11/+12
This fixes problems when some installed packages are outdated. Per wiz@'s request. Grrr, I really hate this kind of change.
2006-09-16Update to 1.4.4:wiz2-6/+6
* Version 1.4.4 (released 2006-09-12) ** Relax the test that caught signatures that exploit the variant of ** Bleichenbacher's Crypto 06 rump session attack on our ** verification logic flaw. In particular, we now permit the digestAlgorithm.parameters field to be present but empty, whereas in 1.4.3 we actually checked that the field was absent. ** Revert the removal of debug information for the GNUTLS-SA-2006-3 problem. The messages are only printed in debug mode, which is not recommended for normal use, and thus logging this situation cannot be abused as an oracle in typical recommended situations. ** API and ABI modifications: No changes since last version.
2006-09-15Update to 2.16.0:jmmv4-33/+31
2006-09-05 Fernando Herrera <fherrera@onirica.com> * configure.ac: Release 2.16.0 2006-09-02 Daniel Nylander <po@danielnylander.se> * docs/sv/sv.po: Updated Swedish translation. 2006-08-22 Fernando Herrera <fherrera@onirica.com> * configure.ac: Relase 2.15.92 2006-08-22 Fernando Herrera <fherrera@onirica.com> * src/gnome-keyring-manager-keyring-editor.c: (gkm_keyring_editor_set_acl): Chage a crash by leak :) 2006-08-03 German Poo-Caaman~o <gpoo@ubiobio.cl> * MAINTAINERS: Added myself there (Fernando Herrera asked me to co-maintain this module) 2006-08-03 German Poo-Caaman~o <gpoo@ubiobio.cl> Patch from Przemysrlaw Grzegorczyk <pgrzegorczyk@gmail.com> * po/LINGUAS: New file listing all supported languages. * configure.ac: Use po/LINGUAS instead of including all languages directly in this file. See the wiki for more information: http://live.gnome.org/GnomeGoals/PoLinguas. Fixed #337908 2006-08-03 Jovan Naumovski <jovan@lugola.net> * Added sl.po to po/ and 'sl' to configure.ac 2006-08-02 German Poo-Caaman~o <gpoo@ubiobio.cl> * data/gnome-keyring-manager.desktop.in.in: Switched 'GNOME;GTK;' instead 'GNOME;' in 'Categories' in order to fix #328039. 2006-08-02 German Poo-Caaman~o <gpoo@ubiobio.cl> * MAINTAINERS: Added this file in order to fix #335041. At the moment I just set to Fernando Herrera as the current maintainer. 2006-08-02 Fernando Herrera <fherrera@onirica.com> * src/gnome-keyring-manager.c: (main): Port to GOption API. Patch by Sebastien Bacher. Closes bug #336077 2006-08-02 Fernando Herrera <fherrera@onirica.com> * configure.ac: Branched for gnome-2-14, bump version number to 2.15.91 2006-07-23 Christophe Bliard <christophe.bliard@trux.info> * docs/fr/fr.po: Added French translation. * docs/Makefile.am: Added fr to DOC_LINGUAS. 2006-07-23 Daniel Nylander <po@danielnylander.se> * sv/sv.po: Updated Swedish translation. 2006-07-03 Runa Bhattacharjee <runabh@gmail.com> * configure.ac: Added Bengali India (bn_IN) to ALL_LINGUAS. 2006-06-29 Daniel Nylander <po@danielnylander.se> * docs/sv/sv.po: Added Swedish translation. 2006-06-19 Raivis Dejus <orvils@gmail.com> * configure.ac: Added "lv" Latvian in to ALL_LINGUAS line. 2006-06-12 Ahmad Riza H Nst <rizahnst@gnome.org> * configure.ac: Added "id" Indonesian in to ALL_LINGUAS line. * po/id.po: Added Indonesian translation. 2006-05-25 Åsmund Skjæveland <aasmunds@fys.uio.no> * po/nn.po: Added Norwegian Nynorsk translation. * configure.ac: Added nn to ALL_LINGUAS. 2006-04-17 Kjartan Maraas <kmaraas@gnome.org> * configure.ac: Remove obsolete entry for no_NO. * po/no.po: And the translation. 2006-04-05 Behdad Esfahbod <behdad@gnome.org> Approved by Fernando Herrera on IRC. * gnome-keyring-manager-attribute-editor.h: * gnome-keyring-manager-attribute-editor.c: * gnome-keyring-manager-new-item-dialog.h: * gnome-keyring-manager-new-item-dialog.c: * gnome-keyring-manager-password-dialog.h: * gnome-keyring-manager-password-dialog.c: Remove. Not needed because of UI changes. * po/POTFILES.in: Remove above files. 2006-04-05 Behdad Esfahbod <behdad@gnome.org> * configure.ac, Makefile.am: Get rid of m4 directory that does not exist. (bug #337310) 2006-04-03 Dan Williams <dcbw@redhat.com> * src/gnome-keyring-manager-util.c - (gkm_get_application_path): implement for FreeBSD 2006-04-03 Dan Williams <dcbw@redhat.com> * src/gnome-keyring-manager-acl-display.c - (gkm_acl_display_set_acl): deal with possibly NULL application path 2006-04-03 Dan Williams <dcbw@redhat.com> * src/gnome-keyring-manager.c - (gkm_application_open_keyring_manager): Fix "unused result" error on return from g_slist_append() 2006-04-03 Dan Williams <dcbw@redhat.com> Patch from Brent Smith <gnome@nextreality.net> Bug #327946 * Makefile.am, configure.ac, docs/gnome-keyring-manager.omf.in, docs/Makefile.am: updates for gnome-doc-utils 2006-04-03 Dan Williams <dcbw@redhat.com> Patch from Matthias Clasen <mclasen@redhat.com> Bug #317037 * src/gnome-keyring-manager-keyring-editor.c - (gkm_keyring_editor_new): don't set edited keyring if not passed a keyring name * src/gnome-keyring-manager-main-ui.c - (gkm_main_ui_init): Don't open 'default' keyring, but defer setting the edited keyring until keyrings are loaded - (on_keyrings_model_row_changed): new function; if there is no currently edited keyring, use the first item in the keyring list - (gkm_main_ui_connect_glade_signals): connect keyring treeview row-changed signal 2006-04-03 Dan Williams <dcbw@redhat.com> * data/gnome-keyring-manager.glade - Remove "invisible_char" items because they override the GTK default, which is now pretty, with ugly obfuscation characters 2006-04-03 Dan Williams <dcbw@redhat.com> * src/gnome-keyring-manager-util.c - (gkm_show_about_dialog): don't use "GNOME" in about dialog title. Bug #326273 2006-04-03 Dan Williams <dcbw@redhat.com> Patch from Christian Persch <chpe@gnome.org>, bug #336497 * src/gnome-keyring-manager-main-ui.c - (on_about_activate): call gkm_show_about_dialog instead * src/gnome-keyring-manager-util.c src/gnome-keyring-manager-util.h - (gkm_about_dialog_new): renamed to gkm_show_about_dialog - (gkm_show_about_dialog): use gtk_show_about_dialog() rather than gtk_about_dialog_new() * src/gnome-keyring-manager.c src/gnome-keyring-manager.h - (gkm_application_open_about_dialog): removed 2006-04-03 Dan Williams <dcbw@redhat.com> Fix network attribute mishandling when a default attribute isn't present in the attribute list. For example, if the attribute list had no 'port', but the user modified the 'port' in gnome-keyring-manager, the 'user' attribute would be set instead. * src/gnome-keyring-manager-attribute-display.c - (gkm_attribute_display_init, network_password_update_page, gkm_attribute_display_clear, on_attribute_entry_changed): Replace usage of "NUM_ENTRIES - 3" with NON_PASSWORD_ENTRIES_MAX - (gkm_attribute_display_init): initialize mappings to -1 - (network_password_update_page): enable widgets for attributes that are present, and disable widgets for attributes that are not. Reset attribute to widget mapping when changing keyring entries, since not all entries have every default attribute. - (on_attribute_entry_changed): don't do anything for attributes which don't have a mapping, should we ever get here (widget should be disabled), and clean up function a bit 2006-04-03 Dan Williams <dcbw@redhat.com> * data/gnome-keyring-manager.glade - Allow ports higher than 100. Bug #336692 2006-04-03 Dan Williams <dcbw@redhat.com> Patch from Christian Persch <chpe@gnome.org> * src/gnome-keyring-manager.c - (gkm_application_window_destroyed_callback): Fix "unused result" error on return from g_slist_remove() 2006-03-24 Tommi Vainikainen <thv@iki.fi> * configure.ac (ALL_LINGUAS): Added Dzongkha (dz). 2006-03-21 Vladimer Sichinava <vlsichinava@gmail.com> * configure.ac: Added "ka" (Georgian) to ALL_LINGUAS
2006-09-15Changes in version 0.6.0 are:jmmv4-115/+33
* NetBSD fixes * Crash fix * Typo fix * Translations Changes in version 0.5.2 are: * Translation updates * Better title in docs * Fixed crashes * New function: gnome_keyring_item_grant_access_rights_sync Changes in version 0.5.1 are: * Support changing password of a keyring * Create ~/.gnome2 if needed * Save keyring when an ACL is added * Add password strength meter * Small bugfixes
2006-09-14Add emacs21no and xemacs21.4 as acceptable.gdt1-2/+2
From John Nemeth.
2006-09-13epg is now EasyPGgdt4-44/+0
2006-09-13rename epg to EasyPGgdt1-2/+2
2006-09-13move EasyPG from epg to EasyPG, and change PKGNAME to EasyPG.gdt4-0/+44
2006-09-10Update to 1.4.3:wiz2-6/+6
* Version 1.4.3 (released 2006-09-08) ** Fix PKCS#1 verification to avoid a variant of Bleichenbacher's ** Crypto 06 rump session attack. In particular, we check that the digestAlgorithm.parameters field is empty, to avoid that it can contain "garbage" that may be used to alter the numeric properties of the signature. See <http://www.imc.org/ietf-openpgp/mail-archive/msg14307.html> (which is not exactly the same as the problem we fix here). Reported by Yutaka OIWA <y.oiwa@aist.go.jp>. See GNUTLS-SA-2006-4 on http://www.gnutls.org/security.html for more up to date information. ** Fix PKCS#1 decryption to avoid Bleichenbacher's Crypto 98 attack. See <http://www.bell-labs.com/user/bleichen/papers/pkcs.ps.gz>. Reported by Werner Koch <wk@gnupg.org>. See GNUTLS-SA-2006-3 on http://www.gnutls.org/security.html for more up to date information. ** Fix crash in gnutls_x509_crt_sign2 if passed a NULL issuer_key. ** API and ABI modifications: No changes since last version. * Version 1.4.2 (released 2006-08-12) ** Fix a crash (strcmp() on a NULL value) in the certificate verification logic. This can happen if you call gnutls_certificate_verify_peers2 and have a certain mix of local CA certificates and the peer send special certificates, that together trigger certain behaviour. It is not known at this point whether the crash can be triggered without the special local CA certificate, and thus turn this into a remote crash of clients that verify server certificates when they talk to a server with the special server certificate. See GNUTLS-SA-2006-2 on http://www.gnu.org/software/gnutls/security.html for more up to date information. Reported by satyakumar <satyam_kkd@hyd.hellosoft.com>. ** Change SRP and Cert-Type extensions to match IANA registry. ** OpenCDK updated to 0.5.9 to fix some problems with OpenPGP support. ** Make --without-included-libtasn1 work. Reported by Daniel Black <dragonheart@gentoo.org>. ** API and ABI modifications: No changes since last version.
2006-09-10Update to 0.5.9:wiz2-7/+6
Noteworthy changes in version 0.5.9 (2006-08-06) ------------------------------------------------ * Fix cdk_kbnode_write_to_mem to return CDK_Too_Short when buf is NULL, tiny patch from Mario Lenz. * Fixed opencdk-config script to include -lz, thanks to Weng Liong, Low. * Fix prototypes for AIX compiler, reported by John Heiden. * Don't use trailing comma in last enum constant, for IBM C v6. Tiny patch from Albert Chin.
2006-09-10Updated to version 2.10.heinz2-7/+6
This resolves PR pkg/34394 by Martin Wilke. Pkgsrc changes: - none Changes since version 2.09: =========================== 2.10 Fri Dec 02 07:36:18 EST 2005 - updated the README file to remove the reference to CBC_R - no longer available. - updated the README file to include performance results for G4/1.2GHz PPC Mac OS X 10.4.X
2006-09-10Updated to version 5.43.heinz2-7/+7
This resolves PR pkg/34407 by Martin Wilke. Pkgsrc changes: - took maintainership Changes since version 5.41: =========================== 5.43 Sat Aug 5 02:36:18 MST 2006 - undid Perl Best Practice of favoring 3-argument "open" -- 3-arg version uses different semantics for "-" causing bugs in addfile and shasum - modified underlying C functions to use ANSI prototypes -- requested by Steve Hay (ref. Smoke [5.9.4] 28630) -- K&R style was causing numerous warnings from Borland compiler 5.42 Mon Jul 24 04:04:40 MST 2006 - minor code changes suggested by Perl::Critic -- e.g. no bareword filehandles, no 2-argument open's - updated public key (ref. B538C51C) -- previous one (0AF563FE) expired July 2, 2006 - added documentation to warn that Base64 digests are NOT padded -- padding must be done by user if interoperability with other software is required
2006-09-10Updated to version 2.19.heinz2-6/+6
This resolves PR pkg/34398 by Martin Wilke. Pkgsrc changes: - none Changes since version 2.17: =========================== 2.19 Tue Jul 18 18:39:57 EDT 2006 - Renamed Crypt::CBC-2.16-vulnerability.txt so that package installs correctly under Cygwin 2.18 2006/06/06 23:17:04 - added more documentation describing how to achieve compatibility with old encrypted messages
2006-09-10add epggdt1-1/+2
2006-09-10EasyPG is a GnuPG interface for Emacs. It has two aspects: convenientgdt4-0/+44
tools which allow to use GnuPG from Emacs (EasyPG Assistant), and a fully functional interface library to GnuPG (EasyPG Library.) It does not cache passphrases, so gpg-agent (security/gnupg-devel) is recommended.
2006-09-09Rename variable MAKEFILE to MAKE_FILE.obache3-6/+6
2006-09-07Sort PLIST.taca1-2/+2
2006-09-07Add a patch to address CVE-2006-4339adrianp3-3/+32
2006-09-07Update kth-krb4 to 1.2.2 (the current release).wennmach9-81/+70
New in 1.2.2: * cross-realm disabled in the server Addresses PR pkg/31431 by Zafer Aydogan. While there, make package pkglint-clean.
2006-09-06Fix MASTER_SITES. Use VARBASE. Bump PKGREVISION.wiz1-4/+4
From Shaun Amott in PR 34423.
2006-09-06libgcrypt 1.2.3 may have fixed the name of the random device on NetBSD butmarkd3-2/+17
it broke the name of the urandom device. Bump PKGREVISION
2006-09-05Update to 0.10; fixes PR pkg/34408. Changes:tv2-7/+6
0.10 Sat Mar 18 21:07:22 2004 - adapted behaviour to Digest
2006-09-05Update security/p5-IO-Socket-SSL from 0.998 to 0.999abs2-6/+6
- If SSL_cipher_list is not given it uses the openssl default instead of setting it to 'ALL:!LOW:!EXP' like before. The old value included ADH and this might be a bad idea, see BUGS why. Resolves PR pkg/34392 by Martin Wilke
2006-09-03Update to 1.2.3:wiz2-7/+6
Noteworthy changes in version 1.2.3 (2006-08-28) ------------------------------------------------ * Rewrote gcry_mpi_rshift to allow arbitrary shift counts. * Minor bug fixes.
2006-09-03Reset maintainer for people who lost their commit bit.wiz1-2/+2
2006-08-31Replaced GENERATE_PLIST with PLIST_SRC, as suggested by wiz.rillig2-5/+7
2006-08-31Fixed a few pkglint warnings.rillig2-7/+9
2006-08-31Fixed the PLISTs according to Krister's latest bulk build on NetBSD 3.0.rillig3-6/+7
Made the "perl" option work and tested all four option combinations.
2006-08-29If using the fake krb5-config then set KRB5_CONFIG to point at it. Fixesmarkd1-1/+5
build of imap-uw package with the kerberos option.
2006-08-29Update to 1.9.22.shannonjr4-33/+8
2006-08-28gnome-keyring cannot currently provide applications' paths under NetBSD sojmmv3-3/+26
be sure not to use them (NULL pointers) when showing information to the user. Fixes crashes when clicking on saved keyring items. Bump PKGREVISION to 2.
2006-08-28Redo LOCAL_CREDS support in a way that does not change the communicationjmmv4-135/+31
protocol (it's more likely to be accepted and is much easier on the code). Bump PKGREVISION to 3.
2006-08-27Implement support for LOCAL_CREDS socket credentials. Bump PKGREVISION to 2.jmmv4-3/+211
This fixes gnome-keyring under NetBSD which, AFAICT, didn't work at all. There are still some problems remaining in gnome-keyring-manager, but I think these are not related to this issue.
2006-08-27Also enable assembler files for NetBSD-*-sparc.jdc1-2/+3
Makes this package build on NetBSD/sparc.
2006-08-24Update to 0.9.6. Changes:shannonjr2-7/+6
- In case an IDMEF-Service object contain neither name or port attribute, set name to "unknown" in order to avoid IDMEF DTD validation issue. - Normalize analyzer(*).node.