summaryrefslogtreecommitdiff
path: root/doc/CHANGES-1.6.1
blob: 4a518cb5487bba0b0af825d340d86aaf821e8bc3 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
796
797
798
799
800
801
802
803
804
805
#	$NetBSD: CHANGES-1.6.1,v 1.1.2.44 2003/10/23 02:51:24 jmc Exp $

Changes to the pkgsrc-1-6-1 branch:

File						Revision(s)
----						--------
mk/texinfo.mk					1.9

	When comparing install-info version, ignore non [0-9.] - treat 4.0b 
	as 4.0
	[abs]

mail/imap-uw/Makefile				1.54

	Linux cp -R behaves differently to NetBSD when given a directory as 
	a source argument. Handle differently.
	[abs]

devel/opencm/distinfo				1.6
devel/opencm/patches/patch-aa			1.3

	Unset GZIP from the environment before calling GZIP_CMD.  Should fix 
	problems shown in Hubert's bulk build.
	[jmmv]

devel/oaf/Makefile				1.23
sysutils/gnome-vfs/Makefile			1.26
devel/bonobo/Makefile				1.35
www/gtkhtml/Makefile				1.27

	Disable gtk-doc detection; not required and causes problems.
	[jmmv]

graphics/avifile-devel/Makefile			1.30
graphics/avifile-devel/buildlink2.mk		1.4
graphics/avifile-devel/distinfo			1.13
graphics/avifile-devel/patches/patch-ac		1.3 (new)

	Add suitable arguments to "avifile-config --libs" for 
	autodetected XFree 4 static libraries, where required. 
	[You can't have a shared library run-time dependency on a static 
	library.] This may let "apla" build again on systems with 
	XFree 4 -- not tested.
	[fredb]

graphics/apla/Makefile				1.14

	This builds again on NetBSD 1.6.1, but only against the latest version
	of avifile-devel. Bump pkgrevision.
	[fredb]

mk/bulk/bsd.bulk-pkg.mk				1.43

	Correct the 'broken due to depends' processing.  This change makes the
	summary email list correctly the packages which are broken because of
	their dependencies.  
	[dmcmahill]

pkgtools/pkg_install/files/lib/pkgdb.c		1.7

	Correct #ifdef misplacement.
	[grant]

pkgsrc/textproc/crimson/Makefile		1.7-1.8
pkgsrc/textproc/crimson/distinfo		1.2

	Pull up changes from trunk to the netbsd-1-6-1 branch to allow 
	this to be extracted.
	[salo]

misc/kdepim3/distinfo/distinfo			1.7
misc/kdeutils3/distinfo				1.10
net/kdenetwork3/distinfo			1.9
misc/kdepim3/patches/patch-ai			1.1 (new)
misc/kdeutils3/patches/patch-ao			1.1 (new)
net/kdenetwork3/patches/patch-aa		1.1 (new)

	Remove some more bogus sizeof(size_t) == sizeof(unsigned int) checks.
	[skrll]

x11/kdebase3/Makefile				1.18
x11/kdebase3/distinfo				1.20
x11/kdebase3/patches/patch-de			1.3

	Let platforms that don't have apm compile ksysguard. This fixes 
	PR#18340 and PR#20439.
	[skrll]

x11/kdebase3/distinfo				1.19
x11/kdebase3/patches/patch-aa			1.4

	Fix typo in configure script which incorrectly determines that a 
	prototype for strlcat is needed.  Unfortunately that had the effect 
	of providing a bad (for 64 bit systems) prototype.
	[dmcmahill]

audio/kdemultimedia3/Makefile			1.13

	Unlimit datasize to allow this to build on alpha
	[dmcmahill]

net/kdenetwork3/distinfo			1.10
net/kdenetwork3/patches/patch-aa		1.4

	Fix typo in check for strlcat which caused a build failure on alpha.
	[dmcmahill]

misc/kdeutils3/distinfo				1.11
misc/kdeutils3/patches/patch-ao			1.2
misc/kdepim3/distinfo				1.8
misc/kdepim3/patches/patch-ai			1.2

	Fix typo in check for strlcat which caused a failure on alpha
	[dmcmahill]

graphics/xv/distinfo				1.7
graphics/xv/patches/patch-ab			1.6

	Fix a broken #ifdef, noted on Linux.
	[grant]

misc/openoffice/distinfo			1.15
misc/openoffice/patches/patch-eq		1.1 (new)

	Reduce optimisation for a particular file to avoid a gcc internal
	compiler error.
	[mrauch]

misc/openoffice-linux/Makefile			1.5
misc/openoffice-linux/PLIST			1.3

	Automate the creation of /emul/linux/etc/mtab:
	Use the code from Johnny (jlam) again, but do an additional copy at
	pre-install, because the file has to be present during do-install 
	already.
	[mrauch]

games/nethack-lib/Makefile.common		1.8
games/nethack-lib/distinfo			1.5
games/nethack-lib/patches/patch-aa		1.8
games/nethack-lib/patches/patch-ab		1.9
games/nethack-lib/patches/patch-ac		1.4
games/nethack-lib/patches/patch-ae		1.4
games/nethack-qt/Makefile			1.35
games/nethack-qt/distinfo			1.9
games/nethack-qt/patches/patch-aa		1.8
games/nethack-qt/patches/patch-ab		1.6
games/nethack-qt/patches/patch-ac		1.11
games/nethack-qt/patches/patch-ae		1.2
games/nethack-qt/patches/patch-ah		1.3
games/nethack-qt/patches/patch-ai		1.2
games/nethack-tty/distinfo			1.5
games/nethack-x11/Makefile			1.20
games/nethack-x11/distinfo			1.8
games/nethack-x11/patches/patch-aa		1.6
games/nethack-x11/patches/patch-ab		1.9
games/nethack-x11/patches/patch-ac		1.2
games/nethack-x11/patches/patch-ah		1.3

	Pullup nethack version 3.4.1 to netbsd-1-6-1 pkgsrc branch.
	[pooka]

devel/mrproject/Makefile			1.10
devel/mrproject/PLIST				1.6

	Make this build again, without evolution support. Bump PKGREVISION.
	[wiz, ticket #1196]

net/snort/DEINSTALL				delete
net/snort/Makefile.common			1.7
net/snort/PLIST					1.8
net/snort/distinfo				1.14
net/snort-pgsql/Makefile			1.8

	Snort RPC preprocessing buffer overflow when decoding fragmented RPC
	records (http://www.kb.cert.org/vuls/id/916785).
	Versions affected <1.9.1.
	[salo, ticket #1192]

comms/p5-Device-SerialPort/Makefile		1.9-1.10

	Makes this pkg build on 1.6.1.
	[hubertf, ticket #1197]

devel/cvs/Makefile				1.59
devel/cvs/distinfo				1.11

	Don't use .bz2 distfile, as it doesn't appear to exist on various 
	mirrors.
	[grant, ticket #1198]

mail/hypermail/Makefile				1.4
mail/hypermail/PLIST				1.2
mail/hypermail/distinfo				1.3
mail/hypermail/patches/patch-aa			1.2
mail/hypermail/patches/patch-ab			1.1 (new)
mail/hypermail/patches/patch-ac			1.1 (new)

	Update to 2.1.7: Many bug and security fixes; you should upgrade..
	[bouyer, ticket #1201]

lang/wonka/Makefile				1.5

	Restrict to x86 and arm as no other ports are done ATM
	[skrll, ticket #1203]

net/ethereal/Makefile				1.71
net/ethereal/PLIST				1.7
net/ethereal/distinfo				1.17

	Updated to version 0.9.10.

	This release fixes a security hole discovered by Georgi Guninski in
	the SOCKS dissector.  All users of previous versions are encouraged
	to upgrade.  For more details see

	  http://www.ethereal.com/appnotes/enpa-sa-00008.html
	[salo, ticket #1204]

net/soup/patches/patch-ac			1.1 (new)
net/soup/distinfo				1.4

	Fix bug with static initializers which prevented compilition on 64 bit
	platforms
	[dmcmahill, ticket #1209]

mail/evolution/Makefile				1.33

	Add --disable-gtk-doc to CONFIGURE_ARGS to allow this to build without
	an active X display.
	[dmcmahill, ticket #1211]

cad/qcad/Makefile				1.10
cad/qcad/distinfo				1.6
cad/qcad/patches/patch-aa			1.5

	On alpha lower optimization level on a handful of key problem files that
	triggered a compiler error.   This package now builds and seems to run
	on NetBSD-1.6/alpha
	[dmcmahill, ticket #1213]

net/ethereal/Makefile				1.72
net/ethereal/distinfo				1.18

	Updated to version 0.9.11.
	(0.9.10 was improperly packaged)
	[salo, ticket #1214]

audio/xsidplay/Makefile				1.23
audio/xsidplay/distinfo				1.4
audio/xsidplay/patches/patch-aa			1.8

	Lower optimization on 8 problem files on alpha which trigger compiler
	bugs. This package now builds on NetBSD-1.6/alpha and even seems to
	run the GUI. Audio output not verified due to lack of hardware.
	[dmcmahill, ticket #1215]

graphics/aqsis/distinfo				1.2
graphics/aqsis/patches/patch-af			1.1 (new)

	Use a time_t * as the argument to time(3) to let this compile on 
	64 bit systems.  Fixes recently noted compile problems on alpha.
	[dmcmahill, ticket #1216]

www/mozilla/Makefile				1.115
www/mozilla/files/moz-install			1.6

	moz-install treated element between @comment begin DIRS & @comment 
	end DIRS in PLIST.
	if @exec ${MKDIR} -p %D/lib/${MOZILLA}/plugins in such a section,
	directory '@exec', '${MKDIR}', '-p', '%D/lib/${MOZILLA}/plugins' are 
	created.

	This commit fixes this problem.
	[taya, ticket #1208]

graphics/xpaint/distinfo			1.7
graphics/xpaint/patches/patch-ag		1.2

	Don't try and do ${XMFMF} -a because that produces 'xmkmf -a -a' which
	causes an error.  This builds and runs on alpha now.
	[dmcmahill, ticket #1217]

mail/mutt/Makefile				1.93
mail/mutt/distinfo				1.13
mail/mutt/patches/patch-af			1.4

	Update mutt to 1.4.1:

	 fix a buffer overflow in mutt's IMAP client code which
	 was identified by Core Security Technologies, and fixed by Edmund
	 Grimley Evans.  A more detailed advisory will be published by Core
	 Security.
	[jschauma, ticket #1223]

mk/bsd.pkg.defaults.mk				1.133

	provide CDRECORD_CONF.

	[grant, ticket #1200]

sysutils/cdrecord/MESSAGE.cdrecord.conf		1.1 (new)
sysutils/cdrecord/Makefile			1.47
sysutils/cdrecord/distinfo			1.9
sysutils/cdrecord/patches/patch-ca		1.1 (new)
sysutils/cdrecord/patches/patch-cb		1.1 (new)
sysutils/cdrecord/patches/patch-cc		1.1 (new)

	Default the config file to PKG_SYSCONFDIR/cdrecord.conf unless
	overridden by the user via CDRECORD_CONF.

	You must move your config file to the new location if you update!

	Patch man pages and print a MESSAGE if CDRECORD_CONF is not set to
	`/etc/default/cdrecord', as required by license.

	Bump PKGREVISION.
	[grant, ticket #1200]

net/samba/Makefile				1.94
net/samba/distinfo				1.26
net/samba/patches/patch-ar			1.1 (new)

	open_file_shared(): when falling back to O_RDONLY open_file() call 
	after O_RDWR fails in fcbopen case, remember the errno from 
	previous open_file() call and set errno back to this value if the 
	second open_file() call fails too.

	This makes samba report EACCESS instead of confusing ENOENT if 
	creation of file fails due to insufficient permissions for 
	SMBcreate/SMBmknew call.

	Bump package revision.
	[bouyer, ticket #1218]

x11/lablgtk/Makefile				1.4
x11/lablgtk/PLIST.noopt				1.1 (new)

	Make this go on non-i386 systems.  Currently ocamlopt is only available
	on i386 so avoid using that on non-i386 systems.  Compiles and 
	seems to work on alpha.
	[dmcmahill, ticket #1219]

net/samba/Makefile				1.95
net/samba/Makefile.common			1.6
net/samba/distinfo				1.27
net/samba/patches/patch-aa			1.24
net/samba/patches/patch-ab			1.20
net/samba/patches/patch-ad			1.12
net/samba/patches/patch-ar			1.2

	Updated samba to 2.2.8

	****************************************
	* IMPORTANT: Security bugfix for Samba *
	****************************************

	The SuSE security audit team, in particular Sebastian Krahmer
	<krahmer@suse.de>, has found a flaw in the Samba main smbd code which
	could allow an external attacker to remotely and anonymously gain
	Super User (root) privileges on a server running a Samba server.
	
	This flaw exists in previous versions of Samba from 2.0.x to 2.2.7a
	inclusive.  This is a serious problem and all sites should either
	upgrade to Samba 2.2.8 immediately or prohibit access to TCP ports 139
	and 445. Advice created by Andrew Tridgell, the leader of the Samba
	Team, on how to protect an unpatched Samba server is given at the end
	of this section.

	The SMB/CIFS protocol implemented by Samba is vulnerable to many
	attacks, even without specific security holes.  The TCP ports 139 and
	the new port 445 (used by Win2k and the Samba 3.0 alpha code in
	particular) should never be exposed to untrusted networks.
	[bouyer, ticket #1220]

chat/bitchx/Makefile				1.16-1.17
chat/bitchx/distinfo				1.7
chat/bitchx/patches/patch-ag			1.1 (new)
chat/bitchx/patches/patch-ah			1.1 (new)
chat/bitchx/patches/patch-ai			1.1 (new)
chat/bitchx/patches/patch-aj			1.1 (new)
chat/bitchx/patches/patch-ak			1.1 (new)
chat/bitchx/patches/patch-al			1.1 (new)

	Bump PKGREVISION: fix several potential buffer overflows found by Timo
	Sirainen <tss at iki dot fi>, see the following url for more details:

	 http://securityfocus.com/archive/1/315057

	Patch from bugtraq by <caf at guarana dor org>.
	[salo, ticket #1239]

www/php4/Makefile				1.32
www/php4/distinfo				1.19
www/php4/patches/patch-ak			1.1 (new)

	Fix for wordwrap() buffer overflow, per
		http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-1396
	(Patch obtained from RedHat's php-4.2.2-8.0.7.src.rpm.)

	Bump PKGREVISION.
	[aymeric, ticket #1253]

net/samba/Makefile.common			1.8
net/samba/distinfo				1.28

	Update to Samba 2.2.8a.

	Changes since 2.2.8:
	Digital Defense, Inc. has alerted the Samba Team to a serious
	vulnerability in all stable versions of Samba currently shipping.
	The Common Vulnerabilities and Exposures (CVE) project has assigned
	the ID CAN-2003-0201 to this defect.

	This vulnerability, if exploited correctly, leads to an anonymous
	user gaining root access on a Samba serving system. All versions
	of Samba up to and including Samba 2.2.8 are vulnerable. An active
	exploit of the bug has been reported in the wild.
	[cjep, ticket #1251]

chat/ircII/Makefile				1.21-1.22
chat/ircII/PLIST				1.12
chat/ircII/distinfo				1.17-1.18

	update to ircii 20030314.  changes since ircII 20021103:

	  o  server's added by /server are no longer removed if they fail to
	     connect.
	  o  SEVERAL REMOTE HOLES FIXED in ctcp, status & other code
	  o  fix ICB /msg to names starting with a /.  you can now /msg
	     \/oink to send a message to "/oink".  if you previously were
	     able to /msg \oink you now have to /msg \\oink.
	  o  arithmetic "|" now works properly
	  o  fix ICB /msg with a user the same name as the channel
	  o  fix ICB group's and user's with comma's in them
	  o  /notify and /timer always go to level crap now
	  o  fix nickname response lossage
	  o  fix $connect() hich was broken recently
	  o  fix "irc -h" which was broken recently
	  o  fix "dcc close raw" which was broken recently
	[aymeric, ticket #1254]

net/snort/Makefile.common			1.8
net/snort/PLIST					1.9
net/snort/distinfo				1.15
net/snort/patches/patch-aa			1.9
net/snort/patches/patch-ad			1.2
net/snort/patches/patch-ae			1.2

	Updated to version 2.0.0.

	IMPORTANT: This version fixes remotely exploitable heap overflow in the stream4
	           preprocessor module.

	Advisory:  http://www.coresecurity.com/common/showdoc.php?idx=313&idxseccion=10

	Changes:

	2.0.0:
	======
	- Enhanced high-performance detection engine
	- Stateful Pattern Matching
	- New detection keywords: byte_test & byte_jump
	- The Snort code base has undergone an external third party professional
	  security audit funded by Sourcefire (http://www.sourcefire.com)
	- Many new and updated rules
	- snort.conf has been updated
	- Enhancements to self preservation mechanisms in stream4 and frag2
	- State tracking fixes in stream4
	- New HTTP flow analyzer
	- Enhanced protocol decoding (TCP options, 802.1q, etc)
	- Enhanced protocol anomaly detection (IP, TCP, UDP, ICMP, RPC, HTTP, etc)
	- Enhanced flexresp mode for real-time TCP session sniping
	- Better chroot()'ing
	- Tagging system updated
	- Several million bugs addressed....
	- Updated FAQ (thanks to Erek Adams and Dragos Ruiu) Snort 2.0 can be
	  downloaded at http://www.snort.org/dl/snort-2.0.0.tar.gz. Binary
	  versions of the codebase will be built over the next several days and
	  made available at here.
	
	2.0.rc4:
	========
	- byte_jump/byte_test don't force relative content options
	- byte_jump/byte_test absolute offsets work
	- Better FIN handling in Stream4
	
	2.0.rc3:
	========
	- A low memory usage detection method (enabled via "config detection:
	  search-method lowmem")
	- Moved the default unix socket location to LOGDIR
	
	2.0.rc2:
	========
	- syslog should work on win32 and unix
	- major tagging updates
	- new UDP decoding alerts
	- snort.conf updates
	
	2.0.rc1:
	========
	- Higher performance (due to a new pattern matcher and rebuilt detection
	  engine)
	- Better decoders
	- Enhanced stream reassembly and defragmentation
	- Tons of bug fixes
	- Updated rules
	- Updated snort.conf
	- New detection keywords (byte_test, byte_jump, distance, within) &
	  stateful pattern matching
	- New HTTP flow analyzer
	- Enhanced anomaly detection (HTTP, RPC, TCP, IP, etc)
	- Better self preservation in stateful subsystems
	- Xrefs fixed
	- Flexresp works faster and more effectively
	- Better chroot()'ing
	- Fixed 802.1q decoding
	- Better async state handling
	- New alerting option: -A cmg!!
	[salo, ticket #1257]

databases/edb/distinfo				1.3
databases/edb/patches/patches-aa		1.1 (new)

	configure script changed in distfile on server.
	[jmmv, ticket #1261]

graphics/GMT/distinfo				1.8

	distfile changed on server.
	[hubertf, ticket #1262]

fonts/dbz-ttf/Makefile				1.5

	Bump PKGREVISION: Resale is prohibited, set RESTRICTED accordingly.
	[salo, ticket #1259]

misc/xjdic/Makefile				1.2-1.3
misc/xjdic/distinfo				1.2

	Update dictionary files to latest version.
	Closes PR 19885.
	[hubertf, ticket #1263]

net/snort/Makefile				1.22
net/snort/Makefile.common			1.9
net/snort/distinfo				1.16
net/snort/patches/patch-aa			1.10
net/snort/patches/patch-ad			1.9
net/snort-mysql/Makefile			1.5
net/snort-pgsql/Makefile			1.10

	Bump PKGREVISION: honour PKG_SYSCONFDIR for real.
	[salo, ticket #1258]

net/snort-mysql/Makefile			1.2-1.4

	- don't use _USE_RPATH
	- Add FILESDIR definition so the rc.d script can be installed
	[hubertf, ticket #1264]

textproc/crimson/distinfo			patch

	correct distfile to allow this to build.
	[hubertf, ticket #1265]

games/nethack-qt/patches/patch-aj		1.1 (new)

	initial patch which cvs missed the first time.
	[pooka, ticket #1267]

sysutils/apcupsd/Makefile			1.21
sysutils/apcupsd/distinfo			1.6

	Update to 3.8.6.
	Changelog: Fixed root exploit of slave machines
	If you use the network features of apcupsd, you probably want to upgrade.
	[bouyer, ticket #1235]

misc/dialog/Makefile				1.14-1.15

	Mark NetBSD 1.6 version as imcompatible.
	bump PKGREVISION.
	[jdc, ticket #1246]

net/ja-samba/MESSAGE.security			1.1-1.2 (new)
net/ja-samba/MESSAGE.smbpasswd			1.2
net/ja-samba/Makefile				1.10-1.13
net/ja-samba/Makefile.common			1.1-1.2 (new)
net/ja-samba/patches/patch-aa			1.3
net/ja-samba/patches/patch-ab			1.1-1.3 (new)
net/ja-samba/patches/patch-ac			1.1-1.3 (new)
net/ja-samba/patches/patch-ai			1.3
net/ja-samba/patches/patch-ao			1.1 (new)
net/ja-samba/patches/patch-ap			1.1-1.2 (new)
net/ja-samba/patches/patch-aq			1.1 (new)
net/ja-samba/patches/patch-bd			0.0 (delete)

	Update samba package to samba-2.2.7b-1.0.
	This fixes samba's known security problem.
	[taca, ticket #1268]

print/teTeX-bin/Makefile			1.40

	Use wildcard dependence on "dialog" package.
	[tron, ticket #1247]

mk/pthread.buildlink2.mk			1.8

	s/SILIENT/SILENT/ (makes the pthread buildlink2 stage quiet
	by default)
	[jmmv, ticket #1273]

textproc/gsed/buildlink2.mk			1.1 (new)

	Provide a buildlink structure so sed and gsed appear in buildlink/bin
	as some programs require GNU sed, but refer to 'sed' directly in their
	scripts.
	[required by ethereal update below]

net/ethereal/DESCR				1.2
net/ethereal/Makefile				1.73-1.74, 1.76
net/ethereal/PLIST				1.8
net/ethereal/distinfo				1.19
net/ethereal/patches/patch-aa			1.1 (new)
net/ethereal/patches/patch-ab			1.1 (new)
net/ethereal/patches/patch-ac			1.1 (new)
net/ethereal/patches/patch-ad			1.1 (new)
net/ethereal/patches/patch-ae			1.1 (new)
net/ethereal/patches/patch-af			1.1 (new)
net/ethereal/patches/patch-ag			1.1 (new)

	Updated to version 0.9.12.

	This release fixes several off-by-one and integer overflow errors
	discovered by Timo Sirainen.  See the following url for more details:

	  http://www.ethereal.com/appnotes/enpa-sa-00009.html

	On solaris use gsed's buildlink2 to provide sed to configure/etc
	(it requires GNU sed)
	[salo, ticket #1280]

chat/bitchx/Makefile				1.19
chat/bitchx/distinfo				1.8
chat/bitchx/patches/patch-aj			1.2

	PKGREVISION++
	- Fix major core bug with channel mode -k * on hybrid7 servers.  For
	  more information see:  http://www.securityfocus.com/archive/1/321093

	Patch from BitchX CVS.
	[salo, ticket #1289]

devel/zlib/buildlink2.mk			1.5-1.7
devel/zlib/Makefile				1.17-1.18
devel/zlib/distinfo				1.4
devel/zlib/patches/patch-aa			1.1 (new)
devel/zlib/patches/patch-ac			1.1 (new)
devel/zlib/patches/patch-ad			1.1 (new)

	Darwin has no static libz, mark it incompatible.

	mark Linux zlib as incompatible to avoid using base zlib which can
	cause problems with pkgsrc libtool, eg.

	libtool: link: AGE `4' is greater than the current interface number `1'
	libtool: link: `1:1:4' is not valid version information
	libtool: install: `libz.la' is not a valid libtool archive

	Added fix for CAN-2003-0107 -
	Buffer overflow in the gzprintf function in zlib 1.1.4, when zlib is
	compiled without vsnprintf or when long inputs are truncated using
	vsnprintf, allows attackers to cause a denial of service or possibly
	execute arbitrary code.
	From OpenBSD.

	Restore configure target and add check for [v]snprintf.

	Bump PKGREVISION.
	[salo, ticket #1291]

sysutils/mc/Makefile				1.43 (via patch)
sysutils/mc/Makefile.common			1.19
sysutils/mc/distinfo				1.7
sysutils/mc/patches/patch-aj			1.1 (new)

	PKGREVISION++
	- use included slang library, fixes various issues with colours and
	  character printing (e.g., TERM=wsvt25 in color mode on wscons console
	  or TERM=xterm in xterm).  From Pavel Arnost via PR pkg/21539.
	- add patch from devel/libslang
	[salo, ticket #1293]

sysutils/mtools/Makefile			1.27
sysutils/mtools/PLIST				1.3
sysutils/mtools/distinfo			1.3
sysutils/mtools/patches/patch-aa		1.6
sysutils/mtools/patches/patch-ab		1.5
sysutils/mtools/patches/patch-ad		1.1 (new)

	PKGREVISION++
	- fix device handling on NetBSD ELF (from Pavel Arnost via PR
	  pkg/21530)
	- fix floppyd handling in better and simpler way
	- don't hardcode -R, use RPATH_FLAG instead
	- remove unused cruft, style nits
	[salo, ticket #1294]

print/acroread5/Makefile			1.14
print/acroread5/distinfo			1.2

	Update "acroread5" package to version 5.07. This version fixes a
	remotely exploitable security whole in version 5.06 an older.
	[tron, ticket #1335]


ImageMagick/Makefile				1.94-1.96, 1.98
ImageMagick/Makefile.common			1.1-1.2 (new)
ImageMagick/PLIST				1.9-1.10
ImageMagick/distinfo				1.13-1.14
p5-PerlMagick/Makefile				1.25-1.28

	Update "ImageMagick" and "p5-PerlMagick" packages to version 5.5.7.9.
                                                                                
	Implement suggestion from last commit: Split out common part of
	p5-PerlMagick and ImageMagick into Makefile.common.

	Update ImageMagick and p5-PerlMagick to 5.5.6.

	Changes are lots of bug fixes and minor enhancements (several pages
	worth of it).

	XXX Those two should probably be using a Makefile.common instead
	XXX of just copying the appropriate bits.

	Place WRKSRC where it belongs, to make pkglint happy; ok'ed by wiz.
	[tron, ticket #1359]

mk/bsd.pkg.mk					1.1145 (via patch)

	Add a MASTER_SITE_APACHE variable with a bunch of apache.org mirrors.
	[tron, ticket #1380]

www/apache/Makefile				1.121, 1.123-1.125, 1.127, 1.131-1.132
www/apache/distinfo				1.26-1.27
www/apache/PLIST				1.8

	Update "apache" package to version 1.3.28.
	[tron, ticket #1380]

www/ap-ssl/Makefile				1.68, 1.71-1.72
www/ap-ssl/distinfo				1.17-1.18
www/ap-ssl/patches/patch-ac			1.1 (new)

	Update "ap-ssl" package to version 2.8.15.
	[tron, ticket #1381]

ham/tnt/Makefile				1.11

	Wildcard dialog depends.
	[dmcmahill, ticket #1382]

net/ethereal/Makefile				via patch
net/ethereal/PLIST				via patch
net/ethereal/distinfo				via patch

	Update to ethereal-0.9.14 to address known security issues.
	In addition several other bugs have been fixed.
	[dmcmahill, ticket #1407]

www/horde/MESSAGE				1.5 (via patch)
www/horde/Makefile				1.24 (via patch)
www/horde/PLIST					1.5 (via patch)
www/horde/distinfo				1.8 (via patch)
www/horde/patches/patch-aa			1.4 (via patch)
mail/imp/DESCR					1.2 (via patch)
mail/imp/MESSAGE				1.6 (via patch)
mail/imp/Makefile				1.21 (via patch)
mail/imp/PLIST					1.5 (via patch)
mail/imp/distinfo				1.8 (via patch)

	Update horde to 2.2.4rc1 and imp to 3.2.2rc1, for the 
	"session fixation" security problem.
	[bouyer, ticket #1419]

www/horde/Makefile				1.26
www/horde/PLIST					1.6
www/horde/distinfo				1.9

	Update to 2.2.4, based on patch from Adrian Portelli in PR#22629.
	Changes since 2.2.4rc1:
	SECURITY: Add dereferer to strip off session information from links to
	the outside of the Horde system to protect against session hijacking.
	Fix a bug with importing vCard 2.1 data. 
	Add Arabic (Syria) translation.
	[bouyer, ticket #1467]

mail/imp/Makefile                               1.22
mail/imp/PLIST                                  1.7 (via patch)
mail/imp/distinfo                               1.9

        Update to 3.2.2, based on patch from Adrian Portelli in PR#22656
        [bouyer, ticket #1468]