summaryrefslogtreecommitdiff
path: root/www
AgeCommit message (Collapse)AuthorFilesLines
2006-08-13+ap2-auth-xradiusadrianp1-1/+2
2006-08-13mod_auth_xradius provides high performance authentication againstadrianp6-0/+65
RFC 2865 RADIUS Servers. Features: * Supports popular RADIUS Servers including OpenRADIUS, FreeRADIUS and commercial servers. * Distributed Authentication Cache using apr_memcache. * Local Authentication Cache using DBM. * Uses standard HTTP Basic Authentication, unlike mod_auth_radius which uses cookies for sessions.
2006-08-10Update to 4.4.3adrianp11-173/+97
All PHP 4.x users are encouraged to upgrade to this release as soon as possible. The security issues resolved include the following: * Disallow certain characters in session names. * Fixed a buffer overflow inside the wordwrap() function. * Prevent jumps to parent directory via the 2nd parameter of the tempnam() function. * Improved safe_mode check for the error_log() function. * Fixed cross-site scripting inside the phpinfo() function. The release also includes about 20 bug fixes and an upgraded PCRE library (version 6.6). For a full list of changes in PHP 4.4.3, see the ChangeLog: http://www.php.net/ChangeLog-4.php#4.4.3 This also contains a fix for CVE-2006-4020 (SA21403)
2006-08-10Update to 7.15.5, convert to options.mk.wiz4-13/+23
Version 7.15.5 (7 August 2006) Daniel (2 August 2006) - Mark Lentczner fixed how libcurl was not properly doing chunked encoding if the header "Transfer-Encoding: chunked" was set by the application. http://curl.haxx.se/bug/view.cgi?id=1531838 Daniel (1 August 2006) - Maciej Karpiuk fixed a crash that would occur if we passed Curl_strerror() an unknown error number on glibc systems. http://curl.haxx.se/bug/view.cgi?id=1532289 Daniel (31 July 2006) - *ALERT* curl_multi_socket() and curl_multi_socket_all() got modified prototypes: they both now provide the number of running handles back to the calling function. It makes the functions resemble the good old curl_multi_perform() more and provides a nice way to know when the multi handle goes empty. ALERT2: don't use the curl_multi_socket*() functionality in anything production-like until I say it's somewhat settled, as I suspect there might be some further API changes before I'm done... Daniel (28 July 2006) - Yves Lejeune fixed so that replacing Content-Type: when doing multipart formposts work exactly the way you want it (and the way you'd assume it works). Daniel (27 July 2006) - David McCreedy added --ftp-ssl-reqd which makes curl *require* SSL for both control and data connection, as the existing --ftp-ssl option only requests it. - [Hiper-related work] Added a function called curl_multi_assign() that will set a private pointer added to the internal libcurl hash table for the particular socket passed in to this function: CURLMcode curl_multi_assign(CURLM *multi_handle, curl_socket_t sockfd, void *sockp); 'sockp' being a custom pointer set by the application to be associated with this socket. The socket has to be already existing and in-use by libcurl, like having already called the callback telling about its existance. The set hashp pointer will then be passed on to the callback in upcoming calls when this same socket is used (in the brand new 'socketp' argument). Daniel (26 July 2006) - Dan Nelson added the CURLOPT_FTP_ALTERNATIVE_TO_USER libcurl option and curl tool option named --ftp-alternative-to-user. It provides a mean to send a particular command if the normal USER/PASS approach fails. - Michael Jerris added magic that builds lib/curllib.vcproj automatically for newer MSVC. Daniel (25 July 2006) - Georg Horn made the transfer timeout error message include more details. Daniel (20 July 2006) - David McCreedy fixed a build error when building libcurl with HTTP disabled, problem added with the curl_formget() patch. Daniel (17 July 2006) - Jari Sundell did some excellent research and bug tracking, figured out that we did wrong and patched it: When nodes were removed from the splay tree, and we didn't properly remove it from the splay tree when an easy handle was removed from a multi stack and thus we could wrongly leave a node in the splay tree pointing to (bad) memory. Daniel (14 July 2006) - David McCreedy fixed a flaw where the CRLF counter wasn't properly cleared for FTP ASCII transfers. Daniel (8 July 2006) - Ates Goral pointed out that libcurl's cookie parser did case insensitive string comparisons on the path which is incorrect and provided a patch that fixes this. I edited test case 8 to include details that test for this. - Ingmar Runge provided a source snippet that caused a crash. The reason for the crash was that libcurl internally was a bit confused about who owned the DNS cache at all times so if you created an easy handle that uses a shared DNS cache and added that to a multi handle it would crash. Now we keep more careful internal track of exactly what kind of DNS cache each easy handle uses: None, Private (allocated for and used only by this single handle), Shared (points to a cache held by a shared object), Global (points to the global cache) or Multi (points to the cache within the multi handle that is automatically shared between all easy handles that are added with private caches). Daniel (4 July 2006) - Toshiyuki Maezawa fixed a problem where you couldn't override the Proxy-Connection: header when using a proxy and not doing CONNECT. Daniel (24 June 2006) - Michael Wallner added curl_formget(), which allows an application to extract (serialise) a previously built formpost (as with curl_formadd()). Daniel (23 June 2006) - Arve Knudsen found a flaw in curl_multi_fdset() for systems where curl_socket_t is unsigned (like Windows) that could cause it to wrongly return a max fd of -1. Daniel (20 June 2006) - Peter Silva introduced CURLOPT_MAX_SEND_SPEED_LARGE and CURLOPT_MAX_RECV_SPEED_LARGE that limit tha maximum rate libcurl is allowed to send or receive data. This kind of adds the the command line tool's option --limit-rate to the library. The rate limiting logic in the curl app is now removed and is instead provided by libcurl itself. Transfer rate limiting will now also work for -d and -F, which it didn't before. Daniel (19 June 2006) - Made -K on a file that couldn't be read cause a warning to be displayed. Daniel (13 June 2006) - Dan Fandrich implemented --enable-hidden-symbols configure option to enable -fvisibility=hidden on gcc >= 4.0. This reduces the size of the libcurl binary and speeds up dynamic linking by hiding all the internal symbols from the symbol table.
2006-08-10Remove teTeX2 from TEX_ACCEPTED, because the teTeX2 packages will be removedminskim3-6/+6
shortly.
2006-08-09Added www/ap2-auth-radius version 1.5.7adrianp1-1/+2
2006-08-09Specify this is for apache 2.xadrianp1-1/+1
2006-08-09This is the Apache 2.x RADIUS authentication module. It allows any Apache 2.xadrianp5-0/+79
web-server to become a RADIUS client for authentication and accounting requests. You will, however, need to supply your own RADIUS server to perform the actual authentication.
2006-08-09Update to 1.10:wiz2-7/+17
Bug fixes and support for apache2. XXX: compilation for apache2 works, but installation fails -- if you know apxs, please take a look: apxs:Error: Sorry, cannot determine bootstrap symbol name. apxs:Error: Please specify one with option `-n'.
2006-08-08fix the build for gcc-4.christos2-1/+22
2006-08-06Update to Opera 9.01 - fixes various smaller issues - for full listjdolecek2-14/+14
see: http://www.opera.com/docs/changelogs/linux/901/
2006-08-06Update to 2.0.3:jmmv4-22/+14
* Improvements: - Added a View Journal button to the LiveJournal Friends dialog - Refresh Recent Entries menu after posting or updating an entry - Use D-BUS to detect current music * Fixes: - Correctly fetch LiveJournal attributes - Compilation fixes for OpenBSD and GCC 2.95 - Expand username compatibility - Fix several double mnemonics - Improve XML-RPC compatibility - Support HTTP redirections - Resolve problem opening draft entries - Numerous fixes for Atom/Blogger 2.0 * Translations: - Added Nepali translation (Pawan Chitrakar) - Added Lithuanian translation (Žygimantas Beručka) - Added Catalan translation (Gil Forcada) - Added Vietnamese translation (Clytie Siddall) - Added Finnish translation (Ilkka Tuohela) - Added French translation (Jeff Coquery) - Added Russian translation (Valek Filippov) - Updated Czech translation (Miloslav Trmac) - Updated German translation (Frank Arnold) - Updated Dutch translation (Vincent van Adrighem) - Updated Simplified Chinese translation (Funda Wang) - Updated Bulgarian translation (Yavor Doganov) - Updated Swedish translation (Daniel Nylander) - Updated Spanish translation (Francisco Javier F. Serrador)
2006-08-06Remove BROKEN_IN for packages that built in the latestkristerw2-6/+2
NetBSD 3.0_STABLE/i386 bulk build.
2006-08-05Update to 4.7.3adrianp2-7/+6
Only change appears to be a fix for an XSS bug
2006-08-04The sarg tool depends on sorting fields by month name (M), which is aben1-2/+12
GNU extension. Depend on GNU coreutils and hardcode the path to GNU sort.
2006-08-03update to 2.14.3drochner3-7/+16
changes: translation updates
2006-08-03update to 3.10.3drochner2-7/+6
changes: -bugfixes -translation updates
2006-08-03update to 1.0.19drochner3-20/+6
changes: * Fixes a uninitialized value bug -some dbus related changes not relevant for the pkg yet -fix for 64bit issue -manpage update
2006-08-03Update www/firefox* to Firefox 1.5.0.6 and www/seamonkey* to Seamonkey 1.0.4.ghen7-21/+20
Just one change: - Fixed an issue with playing Windows Media content
2006-08-03Update "firefox-bin" package to version 1.5.0.6. Changes since 1.5.0.5:tron3-9/+10
- Fixed an issue with playing Windows Media content
2006-08-02Update to KDE 3.5.4markd1-4/+4
2006-08-01Update skipstone to version 0.9.6. ChangeLog:ghen2-7/+6
0.9.6 ------ - Plugins were creatd in toolbar even if they were asked not to in pop up windows, fixed. - Fixed Window Orphan and New Window popups so that they don't display menubars and other uwanted contents. - Implemented ContentHandler so that we dont see Mozilla's ugly File picker which did not work for save even! - Now we display our own file picker and then redirect for mozilla download for those users who opt to use Mozilla's own MIME info/downloading or direct to user's own downloader. 0.9.5 ----- - Plugin compile was broken, fixed. - Changed a plugin function (skipstone_load_url) to (skipstone_load_url_cb) to distinguish from skipstone's internal message. - Distribution cleanups. XXX We really should make this package compile with recent firefox/seamonkey versions, otherwise it will soon become unusable (with mozilla no longer being maintained). I had a patch to make it compile with Firefox 1.0.x, but it no longer works for Firefox 1.5.x.
2006-07-31Import www/py-moin. MoinMoin is a wiki engine written in Python.joerg1-1/+2
2006-07-31Make pkglint happy.joerg2-5/+5
2006-07-31Import www/py-moin. From DESCR:joerg4-0/+2811
A WikiWikiWeb is a collaborative hypertext environment, with an emphasis on easy access to and modification of information. MoinMoin is a Python WikiClone that allows you to easily set up your own wiki, only requiring a Python installation.
2006-07-31Update the Seamonkey packages to 1.0.3.ghen6-24/+33
Changes: * Improved stability * Several security fixes (see below) * A bug was introduced in SeaMonkey 1.0.2 that sometimes caused the URL bar to stop working properly when switching tabs. This has been fixed. (Bug 332874) * If you have more bookmarks on your personal toolbar than there is space for, the ">>" overflow icon will now display more reliably (Bug 338803) * If you choose to update SeaMonkey when it notifies you that an update is available, the update page will load in a more useful browser window (with navigation buttons and toolbars) (Bug 334903) Security fixes: MFSA 2006-56 chrome: scheme loading remote content MFSA 2006-55 Crashes with evidence of memory corruption (rv:1.8.0.5) MFSA 2006-54 XSS with XPCNativeWrapper(window).Function(...) MFSA 2006-53 UniversalBrowserRead privilege escalation MFSA 2006-52 PAC privilege escalation using Function.prototype.call MFSA 2006-51 Privilege escalation using named-functions and redefined "new Object()" MFSA 2006-50 JavaScript engine vulnerabilities MFSA 2006-49 Heap buffer overwrite on malformed VCard MFSA 2006-48 JavaScript new Function race condition MFSA 2006-47 Native DOM methods can be hijacked across domains MFSA 2006-46 Memory corruption with simultaneous events MFSA 2006-45 Javascript navigator Object Vulnerability MFSA 2006-44 Code execution through deleted frame reference For a detailed ChangeLog, see: http://www.mozilla.org/projects/seamonkey/releases/seamonkey1.0.3/changelog.html
2006-07-30Update to 2.8.28, for apache-1.3.37jdolecek2-8/+8
No changes besides the apache version update.
2006-07-30Update to 1.3.37:jdolecek2-11/+11
Changes with Apache 1.3.37 *) SECURITY: CVE-2006-3747 (cve.mitre.org) mod_rewrite: Fix an off-by-one security problem in the ldap scheme handling. For some RewriteRules this could lead to a pointer being written out of bounds. Reported by Mark Dowd of McAfee. [Mark Cox]
2006-07-29Update DIST_SUBDIR as it looks like the tarball on the awstats siteadrianp2-6/+10
has been re-generated.
2006-07-28Fix build.uebayasi2-15/+23
(Don't bump because this must have never been built since 1.5.0.5 update.)
2006-07-28Update package to 1.5.0.5 in response to CERT warnings of severeperry2-6/+6
security problems with 1.5.0.4. No functional changes at all in the package -- this is purely a security update. See CERT advisory TA06-208A (last revised July 27) for details.
2006-07-28Make sure that the directory "share/httpd/manual/style/lang" is createdtron2-2/+4
when installing a binary package. Problem pointed out by Lubomir Sedlacik in private e-mail. Bump package revision because of this fix.
2006-07-28Added two patches for SunPro.rillig3-1/+41
2006-07-28Update "apr" package to version 0.9.12.2.0.59 and "apache2" packagetron4-24/+24
to version 2.0.59. Changes since *2.0.58: - SECURITY: CVE-2006-3747 (cve.mitre.org) mod_rewrite: Fix an off-by-one security problem in the ldap scheme handling. For some RewriteRules this could lead to a pointer being written out of bounds. Reported by Mark Dowd of McAfee.
2006-07-27Rename "SITES_* to "SITES.*" for file-specific lists of sites from whichjlam4-8/+8
to fetch the file. This completes the renaming described in revision 1.1799 of bsd.pkg.mk.
2006-07-27Apply the "convention over configuration" principle:jlam3-6/+3
If ${FILESDIR}/getsite.sh exists, then use it to determine the fetch URL for each of the distfiles for the package. Otherwise, use SITE_<file> and MASTER_SITES, in order, to determine the URL for each distfile. If the script path differs from ${FILESDIR}/getsite.sh, then set DYNAMIC_SITE_SCRIPT to the full path to that script. Remove the need to set DYNAMIC_MASTER_SITES explicitly in the package Makefile for: graphics/ns-cult3d wm/sawfish-themes www/apache-tomcat55 www/jakarta-tomcat4 www/jakarta-tomcat5
2006-07-27Update "firefox-bin" package to version 1.5.0.5. Changes since 1.5.0.4:tron2-6/+6
- Improvements to product stability - Several security fixes: MFSA 2006-56 chrome: scheme loading remote content MFSA 2006-55 Crashes with evidence of memory corruption (rv:1.8.0.5) MFSA 2006-54 XSS with XPCNativeWrapper(window).Function(...) MFSA 2006-53 UniversalBrowserRead privilege escalation MFSA 2006-52 PAC privilege escalation using Function.prototype.call MFSA 2006-51 Privilege escalation using named-functions and redefined "new Object()" MFSA 2006-50 JavaScript engine vulnerabilities MFSA 2006-48 JavaScript new Function race condition MFSA 2006-47 Native DOM methods can be hijacked across domains MFSA 2006-46 Memory corruption with simultaneous events MFSA 2006-45 Javascript navigator Object Vulnerability MFSA 2006-44 Code execution through deleted frame reference
2006-07-25Updated www/jalbum to 6.5.1martti2-6/+6
* Changes unknown
2006-07-24update to 1.0.18drochner3-6/+20
changes: -bugfixes -documentation improvements -Added a gconf key to disable DBUS if necessary
2006-07-24Update geeklog package to 1.4.0.5.1 (1.4.0sr5-1).taca3-9/+10
- Fix display problem with comment preview. - Add afrikaans language support.
2006-07-23Update to 2.8.27, for apache-1.3.36.wiz2-8/+8
Fixes PR 34060. Changes unknown.
2006-07-23- Fix bad handling of some cofiguration files noted by ghen@ behalf oftaca5-25/+16
pkgsrc release engineering team. - Keep current directory with DEINSTALL and INSTALL script. - remove extra processing with POST-DEINSTALL action from DEINSTALL script. - Suggest use of additional graphic package. - Add APACHE_GROUP to BUILD_DEFS. - install ${GEEKLOG_EXAMPLESDIR}/createdb.php with INSTALL_SCRIPT. Bump PKGREVISION.
2006-07-23Add in an AllowOverride directive so that drupal access to a directoryadrianp2-3/+4
is controlled properly Fix by Takahiro Kambe in private mail. Bump to nb1.
2006-07-22enable ap2-jkabs4-13/+13
2006-07-22Split out apache2 version of ap-jk (Apache HTTP -> Tomcat connector)abs4-0/+40
Version 1.2.15 (same as ap-jk)
2006-07-22ap-* should be using apache1 not apache2. Split out most of the Makefileabs2-38/+49
into Makefile.common to be used by upcoming ap2-jk package. Bump package revision
2006-07-22Added "c" to USE_LANGUAGES for packages that use GNU configure scripts,rillig4-10/+8
since they always need a C compiler, even when the source code is completely in C++. For some other packages, stated in the comment that a C compiler is really not needed.
2006-07-21Update HOMEPAGE and MASTER_SITES, and use un-gzipped file provided there.wiz2-8/+8
Compared with previous gzipped version, no change. Fixes bulk build, because it will be able to download the file again :)
2006-07-19Update to 3.54:wiz2-7/+8
2006-04-28 Gisle Aas Release 3.54 Yaakov Belch discovered yet another issue with <script> parsing. Enabling of 'empty_element_tags' got the parser confused if it found such a tag for elements that are normally parsed in literal mode. Of these <script src="..."/> is the only one likely to be found in documents. <http://rt.cpan.org//Ticket/Display.html?id=18965> 2006-04-27 Gisle Aas Release 3.53 When ignore_element was enabled it got confused if the corresponding tags did not nest properly; the end tag was treated it as if it was a start tag. Found and fixed by Yaakov Belch <http://rt.cpan.org/Ticket/Display.html?id=18936> 2006-04-26 Gisle Aas Release 3.52 Make sure the 'start_document' fires exactly once for each document parsed. For earlier releases it did not fire at all for empty documents and could fire multiple times if parse was called with empty chunks. Documentation tweaks and typo fixes. 2006-03-22 Gisle Aas Release 3.51 Named entities outside the Latin-1 range are now only expanded when properly terminated with ";". This makes HTML::Parser compatible with Firefox/Konqueror/MSIE when it comes to how these entities are expanded in attribute values. Firefox does expand unterminated non-Latin-1 entities in plain text, so here HTML::Parser only stays compatible with Konqueror/MSIE. Fixes <http://rt.cpan.org/Ticket/Display.html?id=17962>. Fixed some documentation typos spotted by william at knowmad.com. <http://rt.cpan.org/Ticket/Display.html?id=18062>
2006-07-19Update to 1.81:wiz2-6/+8
1.81 2006-05-23 - Don't unconditionally try to require packages in Apache::Session::Flex (Dave Rolsky).