pkgsrc.git
19 years agoPullup ticket 159 - requested by Havard Eidnes
salo [Tue, 30 Nov 2004 00:04:43 +0000 (00:04 +0000)]
Pullup ticket 159 - requested by Havard Eidnes
security fix for libxml2

        Module Name:    pkgsrc
        Committed By:   xtraeme
        Date:           Thu Oct 21 05:28:17 UTC 2004

        Modified Files:
                pkgsrc/doc: CHANGES TODO
                pkgsrc/textproc/libxml2: Makefile distinfo

        Log Message:
        Update textproc/libxml2 to 2.6.14, this is a bugfix release.
---
        Module Name:    pkgsrc
        Committed By:   recht
        Date:           Sun Oct 31 10:40:51 UTC 2004

        Modified Files:
                pkgsrc/textproc/libxml2: Makefile buildlink3.mk distinfo
                pkgsrc/textproc/libxml2/patches: patch-aa patch-ab

        Log Message:
        update to libxml2-2.6.15

        changes:

        * security fixes on the nanoftp and nanohttp modules
        For details see:
        http://www.securityfocus.com/archive/1/379383/2004-10-24/2004-10-30/0

        * build fixes:
          - xmllint detection bug in configure
          - building outside the source tree (Thomas Fitzsimmons)
        * bug fixes:
          - HTML parser on broken ASCII chars in names (William)
          - Python paths (Malcolm Tredinnick)
          - xmlHasNsProp and default namespace (William)
          - saving to python file objects (Malcolm Tredinnick)
          - DTD lookup fix (Malcolm)
          - save back <group> in catalogs (William)
          - tree build fixes (DV and Rob Richards)
          - Schemas memory bug
          - structured error handler on Python 64bits
          - thread local memory deallocation
          - memory leak reported by Volker Roth
          - xmlValidateDtd in the presence of an internal subset
          - entities and _private problem (William)
          - xmlBuildRelativeURI error (William).
        * improvements:
          - better XInclude error reports (William)
          - tree debugging module and tests
          - convenience functions at the Reader API (Graham Bennett)
          - add support for PI in the HTML parser.

        Update BUILDLINK_RECOMMENDED to 2.6.15 for the security fix.
---
        Module Name:    pkgsrc
        Committed By:   minskim
        Date:           Wed Nov  3 16:41:56 UTC 2004

        Modified Files:
                pkgsrc/textproc/py-libxml2: Makefile distinfo

        Log Message:
        Sync with libxml2-2.6.15.

        Changes since 2.6.12:
           - saving to python file objects (Malcolm Tredinnick)
           - structured error handler on Python 64bits
           - Python space/tabs cleanups
           - Python libxml2 driver improvement
---
        Module Name:    pkgsrc
        Committed By:   recht
        Date:           Thu Nov 11 21:01:15 UTC 2004

        Modified Files:
                pkgsrc/textproc/libxml2: Makefile distinfo
                pkgsrc/textproc/libxml2/patches: patch-aa patch-ab

        Log Message:
        update to 2.6.16

        2.6.16: Nov 10 2004:
           - general hardening and bug fixing crossing all the API based on
             new automated regression testing
           - build fix: IPv6 build and test on AIX (Dodji Seketeli)
           - bug fixes: problem with XML::Libxml reported by Petr Pajas,
             encoding conversion functions return values, UTF-8 bug affecting
             XPath reported by Markus Bertheau, catalog problem with NULL
             entries (William Brack)
           - documentation: fix to xmllint man page, some API function
             descritpion were updated.
           - improvements: DTD validation APIs provided at the Python level
             (Brent Hendricks)
---
        Module Name:    pkgsrc
        Committed By:   minskim
        Date:           Thu Nov 25 18:37:43 UTC 2004

        Modified Files:
                pkgsrc/textproc/py-libxml2: Makefile distinfo
                pkgsrc/textproc/py-libxml2/patches: patch-aa

        Log Message:
        Update py-libxml2 to 2.6.16.

        Changes:
          - improvements: DTD validation APIs provided at the Python level.

19 years ago#155
snj [Sun, 28 Nov 2004 00:39:43 +0000 (00:39 +0000)]
#155

19 years agoPullup ticket 155 - requested by Havard Eidnes
snj [Sun, 28 Nov 2004 00:38:14 +0000 (00:38 +0000)]
Pullup ticket 155 - requested by Havard Eidnes
remove gnats4 package

"The gnats4 pkg has been superseced by the gnats pkg."

19 years agoPullup ticket 155 - requested by Havard Eidnes
snj [Sun, 28 Nov 2004 00:33:50 +0000 (00:33 +0000)]
Pullup ticket 155 - requested by Havard Eidnes
security fix for gnats

Module Name:    pkgsrc
Committed By:   soren
Date:           Wed Nov 10 21:34:46 UTC 2004

Modified Files:
        pkgsrc/databases/gnats: DESCR MESSAGE Makefile PLIST distinfo
        pkgsrc/databases/gnats/patches: patch-aa patch-ab
Removed Files:
        pkgsrc/databases/gnats/patches: patch-ac patch-ad patch-ae patch-af
            patch-ag

Log Message:
Update using the databases/gnats4 package. gnats3 has numerous security
problems and is no longer supported.
---
Module Name:    pkgsrc
Committed By:   soren
Date:           Sun Nov 14 10:59:58 UTC 2004

Modified Files:
        pkgsrc/databases/gnats: Makefile PLIST distinfo

Log Message:
Update to gnats 4.0.1.
Fixes vulnerabilities described in
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0623 .

19 years ago#160
salo [Sat, 27 Nov 2004 16:53:45 +0000 (16:53 +0000)]
#160

19 years agoPullup ticket 160 - requested by Thomas Klausner
salo [Sat, 27 Nov 2004 16:51:06 +0000 (16:51 +0000)]
Pullup ticket 160 - requested by Thomas Klausner
remove apache6 package

removed from -current because of too many vulnerabilities and no newer
version available (people are expected to switch to apache2).

19 years ago#158
salo [Sat, 27 Nov 2004 16:45:43 +0000 (16:45 +0000)]
#158

19 years agoPullup ticket 158 - requested by Quentin Garnier
salo [Sat, 27 Nov 2004 16:43:19 +0000 (16:43 +0000)]
Pullup ticket 158 - requested by Quentin Garnier
security fix for sudo

        Module Name: pkgsrc
        Committed By: cube
        Date: Fri Nov 26 16:23:57 UTC 2004

        Modified Files:
         pkgsrc/security/sudo: Makefile distinfo

        Log Message:
        sudo is nominated for crapware of the year.  Now at version 1.6.8pl4!

        Just as for pl2, changes are about environment sanitizing, meaning
        there are possible security issues with current versions.

        Changes:

        550) The CDPATH variable is now stripped from the environment passed
             to the program to be executed.
        551) Fix temp file generation on systems where the _PATH_VARTMP macro
             lacks a trailing slash.
        552) The KRB5CCNAME environment variable is preserved during sudo
             execution for password lookups that use GSSAPI.

19 years ago#148
salo [Sat, 27 Nov 2004 16:32:00 +0000 (16:32 +0000)]
#148

19 years agoPullup ticket 148 - requested by Jan Schaumann
salo [Sat, 27 Nov 2004 16:29:07 +0000 (16:29 +0000)]
Pullup ticket 148 - requested by Jan Schaumann
security fix for sun-jdk13 and sun-jre13

        Module Name: pkgsrc
        Committed By: jschauma
        Date: Tue Nov 23 16:56:33 UTC 2004

        Modified Files:
         pkgsrc/lang/sun-jdk13: Makefile distinfo
         pkgsrc/lang/sun-jre13: Makefile distinfo

        Log Message:
        Update to version 1.3.1_13.
        Addresses security issue
          http://sunsolve.sun.com/search/document.do?assetkey=1-26-57591-1

        Changes since _12 according to
          http://java.sun.com/j2se/1.3/ReleaseNotes.html

        Can't display localized exception messages of the native method
        correctly java.lang.IndexOutOfBoundsException: Index: 0, Size: 0

19 years ago#119
snj [Fri, 26 Nov 2004 20:00:21 +0000 (20:00 +0000)]
#119

19 years agoPullup ticket 119 - requested by Jeremy C. Reed
snj [Fri, 26 Nov 2004 19:59:09 +0000 (19:59 +0000)]
Pullup ticket 119 - requested by Jeremy C. Reed
security fix for apache2

Module Name: pkgsrc
Committed By: reed
Date: Sat Oct  2 15:47:03 UTC 2004

Modified Files:
pkgsrc/devel/apr: distinfo
pkgsrc/www/apache2: Makefile Makefile.common distinfo
Removed Files:
pkgsrc/www/apache2/patches: patch-ab

Log Message:
Update apache to apache-2.0.52.

Also added comment to www/apache2/Makefile.common to remind to
update checksum in devel/apr also.

No actual devel/apr changes seen.

Also removed www/apache2/patches/patch-ab because it is identical to
fix for security in new version.

Changes with Apache 2.0.52
  *) Use HTML 2.0 <hr> for error pages. PR 30732 [AndrĂ© Malo]
  *) Fix the global mutex crash when the global mutex is never allocated
     due to disabled/empty caches. [Jess Holle <jessh ptc.com>]
  *) Fix a segfault in the LDAP cache when it is configured switched
     off. [Jess Holle <jessh ptc.com>]
  *) SECURITY: CAN-2004-0811 (cve.mitre.org)
     Fix merging of the Satisfy directive, which was applied to
     the surrounding context and could allow access despite configured
     authentication.  PR 31315.  [Rici Lake <rici ricilake.net>]
  *) Fix the handling of URIs containing %2F when AllowEncodedSlashes
     is enabled.  Previously, such urls would still be rejected.
     [Jeff Trawick, Bill Stoddard]
  *) mod_mem_cache: Fixed race condition causing segfault because of memory being
     freed twice, or reused after being freed.
     [J. Clar, W. Stoddard, G. Ames]
  *) Add -l option to rotatelogs to let it use local time rather than
     UTC.  PR 24417.  [Ken Coar, Uli Zappe <uli ritual.org>]
  *) mod_log_config: Fix a bug which prevented request completion time
     from being logged for I_INSIST_ON_EXTRA_CYCLES_FOR_CLF_COMPLIANCE
     processing.  PR 29696.  [Alois Treindl <alois astro.ch>]
---
Module Name: pkgsrc
Committed By: reed
Date: Sat Oct  2 16:38:38 UTC 2004

Modified Files:
pkgsrc/www/apache2: Makefile PLIST

Log Message:
Sort the share/httpd/manual entries in the PLIST.

Added 35 share/httpd/manual entries to PLIST. Most are .ko.euc-kr,
.ko, ja.euc-jp, and .ja files.

I don't know when these were added.

Bump PKGREVISION because now package has several more files.

19 years ago#150
snj [Thu, 25 Nov 2004 18:08:46 +0000 (18:08 +0000)]
#150

19 years agoPullup ticket 150 - requested by Dieter Baron
snj [Thu, 25 Nov 2004 18:08:24 +0000 (18:08 +0000)]
Pullup ticket 150 - requested by Dieter Baron
security fix for xpdf

Module Name:    pkgsrc
Committed By:   dillo
Date:           Thu Nov 25 13:20:36 UTC 2004

Modified Files:
        pkgsrc/print/xpdf: Makefile distinfo

Log Message:
update to 3.00.1 (pl1): fix various buffer overflows
---
Module Name:    pkgsrc
Committed By:   dillo
Date:           Thu Nov 25 13:26:16 UTC 2004

Modified Files:
        pkgsrc/print/xpdf: Makefile

Log Message:
on second thought, let's call it pl1, as was done before

19 years ago#147
salo [Wed, 24 Nov 2004 22:41:58 +0000 (22:41 +0000)]
#147

19 years agoPullup ticket 147 - requested by Julio M. Merino Vidal
salo [Wed, 24 Nov 2004 22:40:34 +0000 (22:40 +0000)]
Pullup ticket 147 - requested by Julio M. Merino Vidal
security fix for libxml

        Module Name: pkgsrc
        Committed By: jmmv
        Date: Sat Nov 20 22:07:49 UTC 2004

        Modified Files:
         pkgsrc/textproc/libxml: Makefile buildlink3.mk distinfo
        Added Files:
         pkgsrc/textproc/libxml/patches: patch-ad patch-ae

        Log Message:
        Backport security fixes (in the nanohttp and the nanoftp modules)
        from libxml2 (several buffer overflows).  Bump PKGREVISION to 3.

19 years agoAdd files from parent branch HEAD:
branch-fixup [Sat, 20 Nov 2004 22:07:49 +0000 (22:07 +0000)]
Add files from parent branch HEAD:
textproc/libxml/patches/patch-ae

19 years ago#143
salo [Fri, 19 Nov 2004 17:45:08 +0000 (17:45 +0000)]
#143

19 years agoPullup ticket 143 - requested by Takahiro Kambe
salo [Fri, 19 Nov 2004 17:38:15 +0000 (17:38 +0000)]
Pullup ticket 143 - requested by Takahiro Kambe
security and usability fixes for ja-squirrelmail

        Module Name: pkgsrc
        Committed By: taca
        Date: Wed Oct 20 14:38:58 UTC 2004

        Modified Files:
         pkgsrc/mail/ja-squirrelmail: Makefile distinfo

        Log Message:
        Update ja-squirrelmail to 20041014 release (1.4.3a-ja-20041014).

        Fix these bugs..

        (1) A problem with displaying mails in Japanese unless they are specified
            charset to ISO-2022-JP in Content-Type header;

         - encoded with euc-JP or Shift_JIS
         - encoded with ISO-2022-JP but no Content-Type header

        (2) A problem with replying to a mail with HTML format.

        Bump package revision.
---
        Module Name: pkgsrc
        Committed By: taca
        Date: Tue Nov 16 11:51:16 UTC 2004

        Modified Files:
         pkgsrc/mail/ja-squirrelmail: Makefile distinfo

        Log Message:
        Apply XSS patch:

         http://article.gmane.org/gmane.mail.squirrelmail.user/21169

        Bump package revision.

19 years ago#137
salo [Thu, 18 Nov 2004 22:30:35 +0000 (22:30 +0000)]
#137

19 years agoPullup ticket 137 - requested by Juan Romero Pardines
salo [Thu, 18 Nov 2004 22:25:13 +0000 (22:25 +0000)]
Pullup ticket 137 - requested by Juan Romero Pardines
security, build and usability fixes for samba

        Module Name: pkgsrc
        Committed By: jmmv
        Date: Sat Nov  6 11:07:17 UTC 2004

        Modified Files:
         pkgsrc/net/samba: Makefile PLIST options.mk

        Log Message:
        When cups support is enabled, link smbspool into cups' backend directory
        as smb (as the manual says).  This enables samba printing through cups
        (at least, the option appears in the web configuration form).
        Bump PKGREVISION to 2.
---
        Module Name: pkgsrc
        Committed By: grant
        Date: Tue Nov  9 08:21:27 UTC 2004

        Modified Files:
         pkgsrc/net/samba: Makefile PLIST distinfo

        Log Message:
        update to samba-3.0.8.

        Common bugs fixed in 3.0.8 include:

            o Compile fixes for HP-UX
            o Fixes for the printer publishing code used when joined to
              an AD domain.
            o Incompatibilities with file system quotas.
            o Several bugs in the spoolss printing code and print system
              backends.
            o Inconsistencies in the username map functionality when
              configured on domain member servers.
            o Various compile warnings and errors on various platforms.
            o Fixes for kerberos interoperability with Windows 200x
              domains when using DES keys.
            o Fix for CAN-2004-0930 -- smbd remote DoS vulnerability.

        New features included in the 3.0.8 release are:

            o New migration functionality added the the net tool
              for files/directories, printers, and shares.
            o New experimental idmap backend for assigning uids/gids
              directly based on the user/group RID when acting as a
              member of single domain without any trusts.
            o Additional printer migration support for XP/2003 platforms.
---
        Module Name: pkgsrc
        Committed By: sketch
        Date: Fri Nov 12 08:42:58 UTC 2004

        Modified Files:
         pkgsrc/net/samba: Makefile

        Log Message:
        Use ${VARBASE} instead of hardcoding /var.
---
        Module Name: pkgsrc
        Committed By: kim
        Date: Sat Nov 13 21:48:11 UTC 2004

        Modified Files:
         pkgsrc/net/samba: Makefile distinfo
        Added Files:
         pkgsrc/net/samba/patches: patch-ag

        Log Message:
        Fix full name expansion (again).

19 years ago#142
salo [Mon, 15 Nov 2004 21:28:21 +0000 (21:28 +0000)]
#142

19 years agoPullup ticket 142 - requested by Takahiro Kambe
salo [Mon, 15 Nov 2004 21:26:45 +0000 (21:26 +0000)]
Pullup ticket 142 - requested by Takahiro Kambe
security fix for ruby-base

        Module Name: pkgsrc
        Committed By: taca
        Date: Tue Nov  9 14:11:33 UTC 2004

        Modified Files:
         pkgsrc/lang/ruby-base: Makefile distinfo
        Added Files:
         pkgsrc/lang/ruby-base/patches: patch-ar

        Log Message:
        Fix potential DoS problem in CGI module from Ruby's CVS repository.
        (noted by CAN-2004-0983)

        Bump package revision.

19 years ago#140
salo [Mon, 15 Nov 2004 08:03:46 +0000 (08:03 +0000)]
#140

19 years agoPullup ticket 140 - requested by Quentin Garnier
salo [Mon, 15 Nov 2004 08:02:54 +0000 (08:02 +0000)]
Pullup ticket 140 - requested by Quentin Garnier
security fix for sudo

        Module Name: pkgsrc
        Committed By: cube
        Date: Fri Nov 12 16:47:31 UTC 2004

        Modified Files:
         pkgsrc/security/sudo: Makefile PLIST.NetBSD PLIST.SunOS distinfo

        Log Message:
        Update to version 1.6.8pl2.  Fixes a security flaw for the sad people using
        bash-as-sh (and people allowing bash scripts to be run through sudo).  The
        user could override commands by functions of her own.

        ChangeLog:

        549) Bash exported functions and the CDPATH variable are now stripped from
             the environment passed to the program to be executed.

19 years agoPullup ticket 136
salo [Wed, 10 Nov 2004 21:04:18 +0000 (21:04 +0000)]
Pullup ticket 136

19 years agoPullup ticket 136 - requested by Thomas Klausner
salo [Wed, 10 Nov 2004 21:03:12 +0000 (21:03 +0000)]
Pullup ticket 136 - requested by Thomas Klausner
PLIST fix for jakarta-tomcat

19 years agoPullup ticket 138
salo [Wed, 10 Nov 2004 20:47:49 +0000 (20:47 +0000)]
Pullup ticket 138

19 years agoPullup ticket 138 - requested by Thomas Klausner
salo [Wed, 10 Nov 2004 20:46:45 +0000 (20:46 +0000)]
Pullup ticket 138 - requested by Thomas Klausner
remove gaim1 packages, they have been vulnerable for a long time,
and no fixes will be forthcoming.

19 years agoAdd files from parent branch HEAD:
branch-fixup [Tue, 9 Nov 2004 14:11:33 +0000 (14:11 +0000)]
Add files from parent branch HEAD:
lang/ruby-base/patches/patch-ar

19 years agoPullup ticket 134
salo [Tue, 9 Nov 2004 08:52:05 +0000 (08:52 +0000)]
Pullup ticket 134

19 years agoPullup ticket 134 - requested by Matthias Scheler
salo [Tue, 9 Nov 2004 08:50:38 +0000 (08:50 +0000)]
Pullup ticket 134 - requested by Matthias Scheler
security fix for mpg123

        Module Name: pkgsrc
        Committed By: tron
        Date: Sun Nov  7 08:55:04 UTC 2004

        Modified Files:
         pkgsrc/audio/mpg123: Makefile distinfo
         pkgsrc/audio/mpg123-esound: Makefile
         pkgsrc/audio/mpg123-nas: Makefile
         pkgsrc/audio/mpg123/patches: patch-aq

        Log Message:
        Add fix for security vulnerability reported in CAN-2004-0982 based on
        patches from Debian's advisory DSA-578. Bump package revision because
        of this fix.

19 years agoPullup ticket 126
salo [Mon, 8 Nov 2004 16:45:02 +0000 (16:45 +0000)]
Pullup ticket 126

19 years agoPullup ticket 126 - requested by Havard Eidnes
salo [Mon, 8 Nov 2004 16:43:29 +0000 (16:43 +0000)]
Pullup ticket 126 - requested by Havard Eidnes
security and bug fixes for postgresql73

        Module Name:    pkgsrc
        Committed By:   jdolecek
        Date:           Sun Oct 10 15:58:03 UTC 2004

        Modified Files:
                pkgsrc/databases/postgresql73-client: Makefile

        Log Message:
        kill -O pax argument - it's not portable, and it's not needed here
        in first place

        fixes PR pkg/23829 by Michal Pasternak
---
        Module Name:    pkgsrc
        Committed By:   jdolecek
        Date:           Sun Oct 10 17:27:43 UTC 2004

        Modified Files:
                pkgsrc/databases/postgresql73: Makefile.common
        Added Files:
                pkgsrc/databases/postgresql73/files: netbsd.c netbsd.h

        Log Message:
        Update the NetBSD dynloader wrapper code to use straigh dl*() calls on all
        archs. This fixes support for dynamic loading on mips and also improves
        error reporting.

        Fixes PR pkg/25473 by Byron Servies.

        PKGREVISION not bumped, will ride update to 7.3.7
---
        Module Name:    pkgsrc
        Committed By:   jdolecek
        Date:           Sun Oct 10 17:46:07 UTC 2004

        Modified Files:
                pkgsrc/databases/postgresql73: Makefile.common distinfo
                pkgsrc/databases/postgresql73-client: Makefile
                pkgsrc/databases/postgresql73-lib: Makefile
                pkgsrc/databases/postgresql73-pltcl: Makefile
                pkgsrc/databases/postgresql73-server: Makefile
                pkgsrc/doc: CHANGES

        Log Message:
        Update to PostgreSQL 7.3.7.

        Changes:
             * Prevent possible loss of committed transactions during crash
               Due to insufficient interlocking between transaction commit and
               checkpointing, it was possible for transactions committed just
               before the most recent checkpoint to be lost, in whole or in part,
               following a database crash and restart. This is a serious bug that
               has existed since PostgreSQL 7.1.
             * Remove asymmetrical word processing in tsearch (Teodor)
             * Properly schema-qualify function names when pg_dump'ing a CAST
---
        Module Name:    pkgsrc
        Committed By:   jdolecek
        Date:           Sun Oct 10 17:48:34 UTC 2004

        Modified Files:
                pkgsrc/databases/jdbc-postgresql: Makefile distinfo
                pkgsrc/doc: CHANGES

        Log Message:
        Update to JDBC driver included with PostgreSQL 7.3.7.

        Notable change in 7.3.5:
             * Remove  ability  to bind a list of values to a single parameter in
               JDBC (prevents possible SQL-injection attacks)
---
        Module Name:    pkgsrc
        Committed By:   kristerw
        Date:           Thu Oct 14 17:58:43 UTC 2004

        Modified Files:
                pkgsrc/databases/postgresql73-docs: Makefile PLIST

        Log Message:
        Correct PLIST.
        Bump PKGREVISION.
---
        Module Name:    pkgsrc
        Committed By:   jdolecek
        Date:           Sun Oct 10 18:26:00 UTC 2004

        Modified Files:
                pkgsrc/databases/postgresql73: distinfo
                pkgsrc/databases/postgresql73/patches: patch-ad
        Added Files:
                pkgsrc/databases/postgresql73/patches: patch-aj

        Log Message:
        add patches to make it possible to compile PL/Python
---
        Module Name:    pkgsrc
        Committed By:   jdolecek
        Date:           Mon Oct 25 17:40:01 UTC 2004

        Modified Files:
                pkgsrc/databases/jdbc-postgresql: Makefile distinfo
                pkgsrc/databases/postgresql73: Makefile.common distinfo
                pkgsrc/databases/postgresql73-docs: Makefile
                pkgsrc/doc: CHANGES

        Log Message:
        Update all postgresql73 packages to 7.3.8. This fixes following two issues:

        * A vulnerability exists due to the insecure creation of temporary files,
          which could possibly let a malicious user overwrite arbitrary files

        * Repair possible failure to update hint bits on disk
          Under rare circumstances this oversight could lead to "could not access
          transaction status" failures, which qualifies it as a potential-data-loss bug.
---
        Module Name:    pkgsrc
        Committed By:   he
        Date:           Mon Nov  1 22:32:26 UTC 2004

        Modified Files:
                pkgsrc/databases/postgresql73-docs: PLIST

        Log Message:
        Correct PLIST after upgrade to postgresql 7.3.8.

19 years agoPullup ticket 127
salo [Mon, 8 Nov 2004 00:05:38 +0000 (00:05 +0000)]
Pullup ticket 127

19 years agoPullup ticket 127 - requested by Grant Beattie
salo [Mon, 8 Nov 2004 00:04:17 +0000 (00:04 +0000)]
Pullup ticket 127 - requested by Grant Beattie
clamav update

        Module Name: pkgsrc
        Committed By: grant
        Date: Tue Oct 19 00:02:44 UTC 2004

        Modified Files:
         pkgsrc/mail/clamav: MESSAGE Makefile PLIST distinfo
         pkgsrc/mail/clamav/patches: patch-aa patch-ad

        Log Message:
        update clamav to 0.80.

        many changes since 0.75.1, most notably, the latest virus databases
        need at least 0.80.

        see the ChangeLog for full details.
---
        Module Name: pkgsrc
        Committed By: grant
        Date: Tue Oct 19 00:37:41 UTC 2004

        Modified Files:
         pkgsrc/mail/clamav: distinfo
        Added Files:
         pkgsrc/mail/clamav/patches: patch-ag

        Log Message:
        fix typo in #define used for backward compatibility. ride the 0.80
        update.
---
        Module Name: pkgsrc
        Committed By: grant
        Date: Wed Oct 20 06:30:24 UTC 2004

        Modified Files:
         pkgsrc/mail/clamav: buildlink3.mk

        Log Message:
        bump BUILDLINK_RECOMMENDED to >=0.80 since the latest virus
        signatures require 0.80.
---
        Module Name: pkgsrc
        Committed By: grant
        Date: Wed Oct 20 09:12:11 UTC 2004

        Modified Files:
         pkgsrc/mail/clamav: Makefile

        Log Message:
        take over maintainership from David Ferlier, who is no longer
        maintaining this package.
---
        Module Name: pkgsrc
        Committed By: grant
        Date: Wed Oct 20 10:18:15 UTC 2004

        Modified Files:
         pkgsrc/mail/clamav: Makefile

        Log Message:
        add dependency on www/curl via PKG_OPTIONS.clamav. reported by Timo
        Schöler.

        bump PKGREVISION.
---
        Module Name: pkgsrc
        Committed By: xtraeme
        Date: Sat Oct 30 09:50:33 UTC 2004

        Modified Files:
         pkgsrc/mail/clamav: distinfo
         pkgsrc/mail/clamav/patches: patch-aa patch-ad

        Log Message:
        Add missing NetBSD RCSID and regen.
---
        Module Name: pkgsrc
        Committed By: grant
        Date: Sat Oct 30 10:23:02 UTC 2004

        Modified Files:
         pkgsrc/mail/clamav: MESSAGE Makefile
        Added Files:
         pkgsrc/mail/clamav/files: freshclamd.sh

        Log Message:
        add freshclamd rc.d script from xtraeme@. bump PKGREVISION.
---
        Module Name: pkgsrc
        Committed By: grant
        Date: Sat Oct 30 10:23:47 UTC 2004

        Modified Files:
         pkgsrc/mail/clamav: Makefile

        Log Message:
        whitespace police
---
        Module Name: pkgsrc
        Committed By: recht
        Date: Sat Oct 30 12:09:12 UTC 2004

        Modified Files:
         pkgsrc/mail/clamav: Makefile
         pkgsrc/mail/clamav/files: clamd.sh

        Log Message:
        The name of the configuration file has changed to clamd.conf recently, so
        change the rc.d script to look for that one.
        Fix suggested by Mirko Thiesen in PR pkg/27618
---
        Module Name: pkgsrc
        Committed By: grant
        Date: Sat Oct 30 12:34:51 UTC 2004

        Modified Files:
         pkgsrc/mail/clamav: distinfo
        Added Files:
         pkgsrc/mail/clamav/patches: patch-ah

        Log Message:
        apply patch from Koji Mori in PR pkg/27337 to fix bad fprintf()
        format string.

19 years agoSolaris Portability Pullup - requested by Grant Beattie
agc [Tue, 2 Nov 2004 10:53:15 +0000 (10:53 +0000)]
Solaris Portability Pullup - requested by Grant Beattie
portability fix for m4

Module Name:    pkgsrc
Committed By:   gavan
Date:           Tue Oct 26 17:00:44 UTC 2004

Modified Files:
pkgsrc/devel/m4: Makefile distinfo

Log Message:
Update to 1.4.2:

* configure.in (VERSION): Bump to 1.4.2.
* NEWS: Describe 1.4.2's changes.

* src/m4.c (reference_error): Preserve errno, since M4ERROR
relies on this.
* src/builtin.c (m4_esyscmd): Clear errno before calling popen.
(m4_maketemp): Clear errno before calling mkstemp.
* src/path.c (path_search): Don't let "free" trash errno when
returning NULL.
* src/output.c (insert_file): Don't assume errno has a valid
value simply because fread returns zero.  This fixes a
portability bug reported by Marion Hakanson in
<http://lists.gnu.org/archive/html/bug-m4/2004-07/msg00029.html>.

Fixes PR pkg/27301.

19 years agoSecurity Pullup - requested by Havard Eidnes
agc [Tue, 2 Nov 2004 10:47:01 +0000 (10:47 +0000)]
Security Pullup - requested by Havard Eidnes
security fix for apache2

Module Name:    pkgsrc
Committed By:   reed
Date:           Thu Sep 23 21:07:25 UTC 2004

Modified Files:
pkgsrc/www/apache2: Makefile
Added Files:
pkgsrc/www/apache2/patches: patch-ab

Log Message:
Add patch for Apache security issue.

2.0.51 had a regression where the Satisfy directive could take
effect for different directories (and could bypass some access
control).

This patch is direct from Apache.

Also bumped the package revision.
---
Module Name:    pkgsrc
Committed By:   grant
Date:           Thu Sep 23 22:51:52 UTC 2004

Modified Files:
pkgsrc/www/apache2: distinfo

Log Message:
update checksum for patch-ab (hi, reed!)

19 years agoSecurity Pullup - requested by Grant Beattie and Havard Eidnes
agc [Tue, 2 Nov 2004 10:39:08 +0000 (10:39 +0000)]
Security Pullup - requested by Grant Beattie and Havard Eidnes
security fix for wv

Module Name:    pkgsrc
Committed By:   adam
Date:           Tue Sep 21 14:45:49 UTC 2004

Modified Files:
pkgsrc/converters/wv: Makefile PLIST distinfo

Log Message:
Changes 1.0.2:
* Fix iDEFENSE buffer overrun security problem
(thanks to Matthias for heads-up)

To generate a diff of this commit:
cvs rdiff -r1.37 -r1.38 pkgsrc/converters/wv/Makefile
cvs rdiff -r1.6 -r1.7 pkgsrc/converters/wv/PLIST
cvs rdiff -r1.9 -r1.10 pkgsrc/converters/wv/distinfo

19 years agoSecurity Pullup - requested by Grant Beattie and Havard Eidnes
agc [Tue, 2 Nov 2004 10:33:50 +0000 (10:33 +0000)]
Security Pullup - requested by Grant Beattie and Havard Eidnes
security fix for cabextract

Module Name:    pkgsrc
Committed By:   wiz
Date:           Thu Oct 28 10:35:56 UTC 2004

Modified Files:
pkgsrc/archivers/cabextract: Makefile distinfo
Added Files:
pkgsrc/archivers/cabextract/patches: patch-aa

Log Message:
Update to 1.1:
  * A security vulnerability has been fixed. If the files within a
    cabinet file include "../" in their filenames, this will be
    changed to "xx/", so cabinets cannot access the parent directory
    of where you want to extract them.
  * cabextract should now compile cleanly on AIX and Cygwin.
----
Module Name:    pkgsrc
Committed By:   tv
Date:           Fri Oct 29 14:31:27 UTC 2004

Modified Files:
pkgsrc/archivers/cabextract: distinfo
Added Files:
pkgsrc/archivers/cabextract/patches: patch-ab

Log Message:
Make build on Interix (and possibly AIX).  mempcpy() is not actually used
anywhere, yet configure.ac declared an AC_REPLACE_FUNCS() for it.  Rip out
the offending code from configure until it is rebuilt at the source.

(Patch to remove the AC_REPLACE_FUNCS submitted to author.)

19 years agoAdd files from parent branch HEAD:
branch-fixup [Tue, 2 Nov 2004 00:55:20 +0000 (00:55 +0000)]
Add files from parent branch HEAD:
mail/clamav/files/freshclamd.sh

19 years agoAdd files from parent branch HEAD:
branch-fixup [Sat, 30 Oct 2004 12:34:51 +0000 (12:34 +0000)]
Add files from parent branch HEAD:
mail/clamav/patches/patch-ah

19 years agoAdd files from parent branch HEAD:
branch-fixup [Fri, 29 Oct 2004 14:31:27 +0000 (14:31 +0000)]
Add files from parent branch HEAD:
archivers/cabextract/patches/patch-ab

19 years agoSecurity Pullup - requested by Adrian Portelli
agc [Tue, 26 Oct 2004 11:25:05 +0000 (11:25 +0000)]
Security Pullup - requested by Adrian Portelli
security fix for socat

Includes the following modifications:

Module Name:    pkgsrc
Committed By:   adrianp
Date:           Thu Sep 30 12:42:46 UTC 2004

Modified Files:
pkgsrc/net/socat: Makefile distinfo
pkgsrc/net/socat/patches: patch-aa

Log Message:
Update socat to 1.4.0.2

- Change to my NetBSD email address

####################### V 1.4.0.2:

corrections:
exec'd write-only addresses get a chance to flush before being killed
error handler: print notice on error-exit
filan printed wrong file type information

####################### V 1.4.0.1:

corrections:
socks4a constructed invalid header. Problem found, reported, and fixed
by Thomas Themel, by Peter Palfrader, and by rik
with nofork, don't forget to apply some process related options
(chroot, setsid, setpgid, ...)

####################### V 1.4.0.0:

new features:
simple openssl server (ssl-l), experimental openssl trust
new options "cafile", "capath", "key", "cert", "egd", and "pseudo" for
openssl
new options "retry", "forever", and "intervall"
option "fork" for address TCP improves `gender changerŽ
options "sigint", "sigquit", and "sighup" control passing of signals to
sub process (thanks to David Shea who contributed to this issue)
readline takes respect to the prompt issued by the peer address
options "prompt" and "noprompt" allow to override readline's new
default behaviour
readline supports invisible password with option "noecho"
socat option -lp allows to set hostname in log output
socat option -lu turns on microsecond resolution in log output

corrections:
before reading available data, check if writing on other channel is
possible
tcp6, udp6: support hostname specification (not only IP address), and
map IP4 names to IP6 addresses
openssl client checks server certificate per default
support unidirectional communication with exec/system subprocess
try to restore original terminal settings when terminating
test.sh uses tmp dir /tmp/$USER/$$ instead of /tmp/$$
socks4 failed on platforms where long does not have 32 bits
(thanks to Peter Palfrader and Thomas Seyrat)
hstrerror substitute wrote wrong messages (HP-UX, Solaris)
proxy error message was truncated when answer contained multiple spaces

porting:
compiles with AIX xlc, HP-UX cc, Tru64 cc (but might not link)

To generate a diff of this commit:
cvs rdiff -r1.2 -r1.3 pkgsrc/net/socat/Makefile
cvs rdiff -r1.1.1.1 -r1.2 pkgsrc/net/socat/distinfo
cvs rdiff -r1.1.1.1 -r1.2 pkgsrc/net/socat/patches/patch-aa
---
Module Name:    pkgsrc
Committed By:   adrianp
Date:           Mon Oct 25 17:13:51 UTC 2004

Modified Files:
pkgsrc/net/socat: Makefile distinfo

Log Message:
- Update to 1.4.0.3
- Security fix for: http://www.dest-unreach.org/socat/advisory/socat-adv-1.html

To generate a diff of this commit:
cvs rdiff -r1.4 -r1.5 pkgsrc/net/socat/Makefile
cvs rdiff -r1.2 -r1.3 pkgsrc/net/socat/distinfo

19 years agoSecurity Pullup - requested by Grant Beattie
agc [Tue, 26 Oct 2004 11:09:16 +0000 (11:09 +0000)]
Security Pullup - requested by Grant Beattie
security fix for firefox

Includes the following modifications:

Module Name:    pkgsrc
Committed By:   grant
Date:           Mon Oct  4 09:11:30 UTC 2004

Modified Files:
pkgsrc/www/firefox: Makefile-firefox.common distinfo

Log Message:
update to Firefox 0.10.1, bugfix for a security issue:

http://www.mozilla.org/press/mozilla-2004-10-01-02.html

To generate a diff of this commit:
cvs rdiff -r1.3 -r1.4 pkgsrc/www/firefox/Makefile-firefox.common
cvs rdiff -r1.16 -r1.17 pkgsrc/www/firefox/distinfo
---
Module Name:    pkgsrc
Committed By:   grant
Date:           Mon Oct  4 09:15:29 UTC 2004

Modified Files:
pkgsrc/www/firefox: distinfo
pkgsrc/www/firefox/patches: patch-br

Log Message:
commit a patch for using thread-safe resolver library functions on
NetBSD >=2.0F - I've been running with it for months on -current
without any problems.

To generate a diff of this commit:
cvs rdiff -r1.17 -r1.18 pkgsrc/www/firefox/distinfo
cvs rdiff -r1.2 -r1.3 pkgsrc/www/firefox/patches/patch-br
---
Module Name:    pkgsrc
Committed By:   reed
Date:           Sat Oct 16 20:08:48 UTC 2004

Modified Files:
pkgsrc/www/firefox: Makefile-firefox.common

Log Message:
Use cp(1)'s -RL instead of -r, because coreutils's
cp -r copies symlinks as symlinks (which caused
files to be missing in install).

Hopefully, this is portable. I tested under NetBSD and with coreutils.
And I brought this up on tech-pkg in July.

To generate a diff of this commit:
cvs rdiff -r1.4 -r1.5 pkgsrc/www/firefox/Makefile-firefox.common

---
Module Name:    pkgsrc
Committed By:   reed
Date:           Tue Oct 19 21:01:47 UTC 2004

Modified Files:
pkgsrc/www/firefox: Makefile-firefox.common

Log Message:
Instead of non-portable cp -RL, use pax with -Lrw
to copy the extensions files.

On Solaris, cp doesn't know -L. (Reported by R. Quinn.)
Using pax was suggested by grant@.

To generate a diff of this commit:
cvs rdiff -r1.5 -r1.6 pkgsrc/www/firefox/Makefile-firefox.common
---
Module Name:    pkgsrc
Committed By:   xtraeme
Date:           Thu Oct 21 00:55:36 UTC 2004

Modified Files:
pkgsrc/www/firefox: distinfo
Added Files:
pkgsrc/www/firefox/patches: patch-cd

Log Message:
Only include <stdbool.h> if !defined(_cplusplus) in nptypes.h.

Fixes build on NetBSD/macppc and maybe others, tested by Peter Bex
on 2-0/macppc and i386/-current/2-0 by me, closes PR pkg/27033.

To generate a diff of this commit:
cvs rdiff -r1.18 -r1.19 pkgsrc/www/firefox/distinfo
cvs rdiff -r0 -r1.1 pkgsrc/www/firefox/patches/patch-cd
---
Module Name:    pkgsrc
Committed By:   grant
Date:           Sun Oct 24 05:41:25 UTC 2004

Modified Files:
pkgsrc/www/firefox: distinfo
Added Files:
pkgsrc/www/firefox/patches: patch-ce patch-cf

Log Message:
apply patch from mozilla CVS to fix bug id #260337 (installer missing
libnsl on Solaris), as well as another sh(1) portability fix.

https://bugzilla.mozilla.org/show_bug.cgi?id=260337

no PKGREVISION bump because this didn't build on Solaris without
libnsl.

To generate a diff of this commit:
cvs rdiff -r1.19 -r1.20 pkgsrc/www/firefox/distinfo
cvs rdiff -r0 -r1.1 pkgsrc/www/firefox/patches/patch-ce \
    pkgsrc/www/firefox/patches/patch-cf

19 years agoUpdate meta-pkgs/kde3 for the previous kdegraphics3 patch (kpdf
agc [Mon, 25 Oct 2004 21:28:01 +0000 (21:28 +0000)]
Update meta-pkgs/kde3 for the previous kdegraphics3 patch (kpdf
security fix).

19 years agoSecurity Pullup - requested by Mark Davies
agc [Mon, 25 Oct 2004 21:25:25 +0000 (21:25 +0000)]
Security Pullup - requested by Mark Davies
security fix for kpdf, part of kdegraphics3

PKGREVISION is set to 2 so that it's newer than the 3.3.0nb1 that was
in HEAD before 3.3.1.

Module Name: pkgsrc
Committed By: markd
Date:  Sat Oct 23 13:19:12 UTC 2004

Modified Files:
 pkgsrc/graphics/kdegraphics3: Makefile distinfo

Log Message:
Fix integer overflow and integer arithmetic flaws in kpdf.
From http://www.kde.org/info/security/advisory-20041021-1.txt
Bump PKGREVISION.

19 years agoPull-up patch-aa from the HEAD, and re-generate its checksum.
agc [Mon, 25 Oct 2004 18:55:59 +0000 (18:55 +0000)]
Pull-up patch-aa from the HEAD, and re-generate its checksum.

Fixes build on pkgsrc-2004Q3 branch.

Thanks to Soren Jacobsen for pointing this one out.

19 years agoSecurity Pullup - requested by Matthias Scheler
agc [Sun, 24 Oct 2004 11:52:09 +0000 (11:52 +0000)]
Security Pullup - requested by Matthias Scheler
security fix for ap-ssl

Modified Files:
pkgsrc/www/ap-ssl: Makefile distinfo

Log Message:
Update "ap-ssl" package to version 2.8.20. Changes since version 2.8.19:
- With OpenSSL 0.9.7, prevent session resumption during a
  renegotiation to force the client to negotiate a new (and
  acceptable to mod_ssl) cipher suite. Additionally, ensure
  that a correct cipher suite has been negotiated afterwards
  (CAN-2004-0885).
- Fixed more printf(3) style format string bugs (not security
  related) which could crash the server if mod_ssl's trace
  or debug log level is enabled.

To generate a diff of this commit:
cvs rdiff -r1.83 -r1.84 pkgsrc/www/ap-ssl/Makefile
cvs rdiff -r1.22 -r1.23 pkgsrc/www/ap-ssl/distinfo

19 years agoAdd files from parent branch HEAD:
branch-fixup [Sun, 24 Oct 2004 05:41:25 +0000 (05:41 +0000)]
Add files from parent branch HEAD:
www/firefox/patches/patch-ce
www/firefox/patches/patch-cf

19 years agoCorrect the version number in the Makefile on the pkgsrc-2004Q3 branch.
agc [Sat, 23 Oct 2004 07:41:20 +0000 (07:41 +0000)]
Correct the version number in the Makefile on the pkgsrc-2004Q3 branch.
Pointed out by Soren Jacobsen.

19 years agoAdd files from parent branch HEAD:
branch-fixup [Thu, 21 Oct 2004 00:55:36 +0000 (00:55 +0000)]
Add files from parent branch HEAD:
www/firefox/patches/patch-cd

19 years agoPullup (via patch) ticket 123 - requested by Takahiro Kambe
agc [Wed, 20 Oct 2004 16:33:44 +0000 (16:33 +0000)]
Pullup (via patch) ticket 123 - requested by Takahiro Kambe
security fix for squid

Modified Files:
pkgsrc/www/squid: Makefile distinfo
pkgsrc/www/squid/patches: patch-ag patch-an patch-bb
Removed Files:
pkgsrc/www/squid/patches: patch-ba

Log Message:
Update squid package to 2.5.7.

This includes security problem with SNMP support which enabled by default.

<http://www.idefense.com/application/poi/display?id=152&type=vulnerabilities>

* pkgsrc changes:

  - Don't use PKGNAME within DIST_SUBDIR.  Instead, date based DIST_STAMP.
    This change prevent extra DIST_SUBDIR change asked by kim@.
  - Remove setproctitle(3) hack for dnsserver helper program since use of
    dnsserver itself is problematic with huge size of squid process.

* Changes to squid-2.5.STABLE7 (11 Oct 2004)

  - [Medium] No objects cached in ufs cache_dir type in some
    configurations. Issue introduced in 2.5.STABLE6 by the patch for
    Bug #676. (Bug #1011)
  - [Minor] LDAP helpers update to correct LDAP connection management
    and add support for literal password compare instead of binding
  - [Minor] A large number of queued DNS lookups for the same domain
    (Bug #852)
  - [Cosmetic] request_header_max_size configuration partly ignored
    (Bug #899)
  - [Minor] Partial hit results in TCP_HIT, not TCP_MISS. (Bug #1001)
  - Bug #1012: [Cosmetic] HEAD requests may return stale information
    (Bug #1012)
  - [Cosmetic] Warn if cache_dir ufs can not create files. (Bug #918)
  - [Minor] case insensitive authentication (Bug #431)
  - [Cosmetic] Add delay pools information to active_requests. (Bug
    #882)
  - [Minor] Apparent memory leak in client_db (Bug #833)
  - [Minor] NTLM authentication truncated causing failures. (Bug
    #1016)
  - [Cosmetic] Grammatical corrections in squid.conf.default
  - [Cosmetic] Unknown %X errorpage codes incorrectly quoted. (Bug
    #1030)
  - [Medium] Segfaults and other strange crashes when using heap
    policies. (Bug #1009)
  - [Minor] Supplementary group memberships not set (Bug #1021)
  - [Cosmetic] ERR_TOO_BIG Portugese translation
  - [Minor] external_acl does not handle newlines (Bug #1038)
  - [Major] NTLM authentication denial of service when using msnt_auth
    or fake_auth (Bug #1045)
  - [Medium] Memory leaks when using NTLM authentication without
    challenge reuse. (Bug #994)
  - [Minor] Temporary NTLM memory leak with challenge reuse enabled
    (Bug #910)
  - [Minor] assertion failed: "n_ufs_dirs <=
    Config.cacheSwap.n_configured". (Bug #1053)
  - [Minor] Segfault in authenticateDigestHandleReply. (Bug #1031)
  - [Minor] acl time fails to parse multiple time specifications
    (Bug #1060)
  - [Minor] cachemgr config dumps mixed up Range and Request-Range
    headers in http_header_access & replace directives. (Bug #1056)
  - [Minor] Content-Disposition added as a well known header (Bug #961)
  - [Cosmetic] Don't warn about arp acls not being supported on FreeBSD
    (Bug #1074)
  - [Cosmetic] Limit internal send/receive buffer sizes (Bug #1075)
  - [Medium] New acl types to match arbitrary HTTP headers. In addition
    the http_header_access & replace directivess now support arbitrary
    headers and not only the well known ones. (Bug #961)
  - [Cosmetic] ncsa_auth now accepts Window formatted password files
    (Bug #1078)
  - [Cosmetic] Support the --program-prefix/suffix options or other
    configure program name transforms (Bug #1019)
  - [Minor] Fix race condition in CONNECT and also handle aborts of
    CONNECT requests in a more graceful manner. (Bug #859)
  - [Minor] New balance_on_multiple_ip directive to work around certain
    broken load balancers and optimized ipcache on reload requests
    (Bug #1058)
  - [Medium] New reply_header_max_size directive (Bug #874)
  - [Minor] Suspected instability on aborted PUT/POST requests (Bug #1089)
  - [Security] SNMP Denial of Service fix (CAN-2004-0918)

19 years agoPullup ticket 120 - requested by Todd Vierling
agc [Tue, 19 Oct 2004 13:33:41 +0000 (13:33 +0000)]
Pullup ticket 120 - requested by Todd Vierling
security fix for gzip

Modified Files:
pkgsrc/mk: bsd.pkg.mk

Log Message:
Automatic inclusion of gzip-base needs a version number in the BUILD_DEPENDS.

Modified Files:
pkgsrc/mk: bsd.pkg.mk

Log Message:
Bump gzip-base to 1.2.4b for security fix.

Modified Files:
pkgsrc/archivers/gzip: Makefile
pkgsrc/archivers/gzip-base: Makefile distinfo
Added Files:
pkgsrc/archivers/gzip-base/patches: patch-ab

Log Message:
Update gzip to 1.2.4b, fixing a filename buffer overflow.

19 years agoPullup ticket 118 - requested by Adrian Portelli
agc [Tue, 19 Oct 2004 12:53:01 +0000 (12:53 +0000)]
Pullup ticket 118 - requested by Adrian Portelli
build and security fixes for freeradius

Based on patches provided by Adrian.

19 years agoAdd files from parent branch HEAD:
branch-fixup [Tue, 19 Oct 2004 00:37:41 +0000 (00:37 +0000)]
Add files from parent branch HEAD:
mail/clamav/patches/patch-ag

19 years agoPullup ticket 122 - requested by Matthias Scheler
agc [Mon, 18 Oct 2004 17:03:48 +0000 (17:03 +0000)]
Pullup ticket 122 - requested by Matthias Scheler
security fix for tiff

Modified Files:
pkgsrc/graphics/tiff: Makefile

Log Message:
Derive "PKGNAME" from "DISTNAME" instead of defining it manually.

Modified Files:
pkgsrc/graphics/tiff: Makefile

Log Message:
Add mirror on "ftp.fu-berlin.de" to master site list.

Modified Files:
pkgsrc/graphics/tiff: Makefile distinfo
pkgsrc/graphics/tiff/patches: patch-ag
Added Files:
pkgsrc/graphics/tiff/patches: patch-ai patch-aj patch-ak patch-al
    patch-am patch-an patch-ao patch-ap patch-aq patch-ar patch-as
    patch-at patch-au patch-av patch-aw patch-ax

Log Message:
Add various bug fixes taken from Debian's unstable distribution which
include fixes for CESA-2004-006. Bump package revision.

19 years agoPullup ticket 121 - requested by Quentin Garnier
agc [Mon, 18 Oct 2004 16:53:54 +0000 (16:53 +0000)]
Pullup ticket 121 - requested by Quentin Garnier
security fix for sox

Modified Files:
pkgsrc/audio/sox: Makefile distinfo
Added Files:
pkgsrc/audio/sox/patches: patch-aa
Removed Files:
pkgsrc/audio/sox/patches: patch-ab

Log Message:
Update to version 12.17.6.  Note that this version fixes some
buffer overflows in the WAV parser that could lead to arbitrary
code execution.

sox-12.17.6
-----------
  o Changed comment code to always use copies of strings to
    fix bug in WAV handlering freeing argv[] memory.
  o Use calloc() to create ft_t structures so that all
    memory is initialized before being referenced.
  o Fixed VOC EOF bug were it thought there was an extra
    block when there wasn't.
  o Restructured directory layout so that source code is in
    a seperate directory.
  o Modified SoX to accept multiple input files.  Concatenates
    files together in this case.
  o Removed map effect so that loops and instr could be removed
    from effects structures.  This makes effects engine stand
    alone from the rest of the sox package.
  o Benedikt Zeyen found a bug in synth effect when generating
    brown noise that could cause clipping.
  o David Leverton sent another patch to prevent crashes on
    amd64's when resampling.
  o Fixed a bug were MP3 files with large ID3v2 tags could
    cause SoX to stick in a loop forever.  Now, it will
    abort on IDv3 tags larger then 100k.  Could still be
    improved to handle any size.
  o Changed volume option (-v) so that it tracks the file
    it was specified.  This means that when specified with
    the input file, it changes volume before effects engine
    and when specified with output file, its done after effects
    engine.
  o Added crossfade_cat.sh script that will concatenate to
    audio files and do a crossfade between them.
  o Fixed bug in fade effect were it was impossible to do a
    fadeout starting from the beginning of the audio file.
  o Removed rounding error when changing volume of audio with
    "-v" option.  This error caused doing a "-v -1.0" twice
    to not result in the original file.
  o Fixed a possible overflow in lots of effects were MIN
    value was treated as -MAX instead of -MAX-1.
  o Modifed sox so its OK for effects to not process any
    input or output bytes as long as they return ST_EOF.
  o When effects output data and reported ST_EOF at the
    same time, that buffer was discarded as well as
    data from any chained effect.
  o Added patch from Eric Benson that attempts to do a seek()
    if the first effect is trim.  This greatly speeds up
    processing large files.
  o Daniel Pouzzner implemented a multi-band compander (using
    the butterworth filters to split the audio into bands).
  o Donnie Smith updated the silence effect so that its possible
    to remove silence from the middle of a sound file by
    using a negative value for stop_periods.
  o Changed float routines to only work with normalized values
    from -1:1.
  o Modifed .au handler to be able to read and write 32-bit
    and 64-bit float data.  Only tested reading so far.
  o WAV with GSM data now always pads data to even number of bytes.
  o Added support for writing 32-bit audio to AIFF.

sox-12.17.5
-----------
  o Thomas Klausner sent in patches to compile audio drivers under
    NetBSD.
  o Rahul Powar pointed out a memory leak in the WAV file handler.
    It wasn't calling the correct close() function when closing
    input files.
  o Modified play.1 man page to not use multiple name lines.  This
    appears to confuse some conversion programs.  Updated sox.1
    man page for typo in reverb option.
  o Andrew Church fixed problem with header of stereo 8SVX files.
  o Jimen Ching added support to scan over garbage data at the
    beginning of MP3 files to find valid frames.  This is useful
    to play WAV and AIFF files that have MP3 data in them until
    those handlers support it directly.  To play those, force
    sox to use the mp3 handler with the "-t mp3" option.
  o Added patch from Ulf Harnhammar to wav handler to prevent
    buffer overflows.
  o Added patch from Redhat to allow resample to work on certain 64-bit
    machines (Sam Varshavchik)
  o Tony Seebregts added a file handler for headerless Dialogic/OKI ADPCM
    files (VOX files).
  o Jan Paul Schmidt added a repeat effect to do loops the brute force way.
    This is also good for file format that don't support loops as well.
  o Fix for OSS driver in rate tolerance calcs that were off because
    of type conversion problems.  Guenter Geiger.
  o Allow reading sphere files with headers greater then 256 bytes.  Jimen
    Ching.
  o Fix for vorbis were comments are displayed in KEY=value format always.
    Stop printing some info to stdout in case output is a pipe. Guenter
    Geiger.
  o J Robert Ray submitted fix for AIFF handler to ignore lowercase
    chunks that are unknown.
  o Bugfix for 8-bit voc files.  Jimen Ching
  o General warning cleanups (cbagwell)
  o Memory leaks in reading WAV files (Ufuk Kayserilioglu)
  o Rearrange link order of ogg vorbis libraries so that they
    can be compiled as static. (Christian Weisgerbr)

19 years agoAdd files from parent branch HEAD:
branch-fixup [Mon, 18 Oct 2004 14:37:24 +0000 (14:37 +0000)]
Add files from parent branch HEAD:
graphics/tiff/patches/patch-ai
graphics/tiff/patches/patch-aj
graphics/tiff/patches/patch-ak
graphics/tiff/patches/patch-al
graphics/tiff/patches/patch-am
graphics/tiff/patches/patch-an
graphics/tiff/patches/patch-ao
graphics/tiff/patches/patch-ap
graphics/tiff/patches/patch-aq
graphics/tiff/patches/patch-ar
graphics/tiff/patches/patch-as
graphics/tiff/patches/patch-at
graphics/tiff/patches/patch-au
graphics/tiff/patches/patch-av
graphics/tiff/patches/patch-aw
graphics/tiff/patches/patch-ax

19 years agoAdd files from parent branch HEAD:
branch-fixup [Tue, 12 Oct 2004 18:28:29 +0000 (18:28 +0000)]
Add files from parent branch HEAD:
archivers/gzip-base/patches/patch-ab

19 years agoAdd files from parent branch HEAD:
branch-fixup [Sun, 10 Oct 2004 18:26:00 +0000 (18:26 +0000)]
Add files from parent branch HEAD:
databases/postgresql73/patches/patch-aj

19 years agoAdd files from parent branch HEAD:
branch-fixup [Sun, 10 Oct 2004 17:27:43 +0000 (17:27 +0000)]
Add files from parent branch HEAD:
databases/postgresql73/files/netbsd.c
databases/postgresql73/files/netbsd.h

19 years agoAdd files from parent branch HEAD:
branch-fixup [Sat, 2 Oct 2004 12:06:03 +0000 (12:06 +0000)]
Add files from parent branch HEAD:
net/freeradius/PLIST.ldap
net/freeradius/PLIST.mysql
net/freeradius/PLIST.pgsql
net/freeradius/options.mk
net/freeradius/patches/patch-aj
net/freeradius/patches/patch-ak

19 years agoPullup ticket 116 - requested by Eric Gillespie
agc [Thu, 30 Sep 2004 14:08:35 +0000 (14:08 +0000)]
Pullup ticket 116 - requested by Eric Gillespie
security fix for subversion

Modified Files:
pkgsrc/devel/subversion: Makefile.version distinfo

Log Message:
Version 1.0.8
(22 September 2004, from /branches/1.0.8)
http://svn.collab.net/repos/svn/tags/1.0.8

 User-visible-changes:
 * fixed: mod_authz_svn path and log-message metadata leaks.
  See CAN-2004-0749, and descriptive advisory at
  http://subversion.tigris.org/security/CAN-2004-0749-advisory.txt

19 years agoPullup ticket 115, requested by Lubomir Sedlacik.
agc [Thu, 30 Sep 2004 14:05:22 +0000 (14:05 +0000)]
Pullup ticket 115, requested by Lubomir Sedlacik.

Modified Files:
pkgsrc/net/lftp: Makefile distinfo

Log Message:
Updated to version 3.0.9.

Changes:
- fixed a hang up when filtering output via an external command
  (the bug appeared in 3.0.8).
- don't use ftp:port-ipv4 in FXP mode.

19 years agoPullup ticket 114, requested by Matthias Scheler.
agc [Thu, 30 Sep 2004 13:58:22 +0000 (13:58 +0000)]
Pullup ticket 114, requested by Matthias Scheler.

Security fix for apache

Modified Files:
pkgsrc/www/apache: Makefile distinfo
Added Files:
pkgsrc/www/apache/patches: patch-ap

Log Message:
Apply fix for security vulnerability in proxy module reported in
CAN-2004-0492. Bump package revision package of this.

19 years agoAdd a file to record changes on the pkgsrc-2004Q3 branch
agc [Thu, 30 Sep 2004 13:54:11 +0000 (13:54 +0000)]
Add a file to record changes on the pkgsrc-2004Q3 branch

19 years agoAdd files from parent branch HEAD:
branch-fixup [Thu, 23 Sep 2004 19:51:22 +0000 (19:51 +0000)]
Add files from parent branch HEAD:
net/freeradius/patches/patch-ah
net/freeradius/patches/patch-ai

19 years agoAdd files from parent branch HEAD:
branch-fixup [Mon, 20 Sep 2004 17:19:34 +0000 (17:19 +0000)]
Add files from parent branch HEAD:
www/apache2/Makefile
www/apache2/Makefile.common
www/apache2/PLIST
www/apache2/buildlink3.mk
www/apache2/distinfo
www/apache2/patches/patch-ah
www/apache2/patches/patch-ar
www/apache2/patches/patch-as

19 years agoAdd files from parent branch HEAD:
branch-fixup [Mon, 20 Sep 2004 17:13:06 +0000 (17:13 +0000)]
Add files from parent branch HEAD:
devel/apr/Makefile
devel/apr/buildlink3.mk
devel/apr/distinfo
devel/apr/patches/patch-aa
devel/apr/patches/patch-ab

19 years agoAdd files from parent branch HEAD:
branch-fixup [Mon, 20 Sep 2004 15:59:26 +0000 (15:59 +0000)]
Add files from parent branch HEAD:
www/firefox-gtk2-bin/distinfo

19 years agoAdd files from parent branch HEAD:
branch-fixup [Mon, 20 Sep 2004 15:50:21 +0000 (15:50 +0000)]
Add files from parent branch HEAD:
doc/CHANGES

19 years agoAdd files from parent branch HEAD:
branch-fixup [Mon, 20 Sep 2004 15:48:58 +0000 (15:48 +0000)]
Add files from parent branch HEAD:
www/firefox-gtk2-bin/Makefile
www/firefox-gtk2-bin/Makefile.Linux.i386
www/firefox-gtk2-bin/Makefile.NetBSD.i386
www/firefox-gtk2-bin/Makefile.SunOS.sparc
www/firefox-gtk2-bin/files/mozilla.sh

19 years agoAdd files from parent branch HEAD:
branch-fixup [Mon, 20 Sep 2004 15:45:32 +0000 (15:45 +0000)]
Add files from parent branch HEAD:
www/mozilla-bin/Makefile.common

19 years agoAdd files from parent branch HEAD:
branch-fixup [Mon, 20 Sep 2004 14:50:46 +0000 (14:50 +0000)]
Add files from parent branch HEAD:
mail/GNUMail/PLIST

19 years agoAdd files from parent branch HEAD:
branch-fixup [Mon, 20 Sep 2004 14:50:28 +0000 (14:50 +0000)]
Add files from parent branch HEAD:
devel/gnustep-make/buildlink3.mk

19 years agoAdd files from parent branch HEAD:
branch-fixup [Mon, 20 Sep 2004 12:55:43 +0000 (12:55 +0000)]
Add files from parent branch HEAD:
mail/thunderbird-gtk2/PLIST
mail/thunderbird/Makefile-thunderbird.common
mail/thunderbird/PLIST
mail/thunderbird/distinfo

19 years agoAdd files from parent branch HEAD:
branch-fixup [Mon, 20 Sep 2004 12:33:20 +0000 (12:33 +0000)]
Add files from parent branch HEAD:
graphics/RenderKit/PLIST

19 years agoAdd files from parent branch HEAD:
branch-fixup [Mon, 20 Sep 2004 12:30:16 +0000 (12:30 +0000)]
Add files from parent branch HEAD:
graphics/GeometryKit/PLIST

19 years agoAdd files from parent branch HEAD:
branch-fixup [Mon, 20 Sep 2004 11:39:15 +0000 (11:39 +0000)]
Add files from parent branch HEAD:
doc/TODO

19 years agoAdd files from parent branch HEAD:
branch-fixup [Mon, 20 Sep 2004 10:43:56 +0000 (10:43 +0000)]
Add files from parent branch HEAD:
bootstrap/README.Solaris

19 years agoAdd files from parent branch HEAD:
branch-fixup [Mon, 20 Sep 2004 10:09:15 +0000 (10:09 +0000)]
Add files from parent branch HEAD:
graphics/gwenview/Makefile
graphics/gwenview/PLIST
graphics/gwenview/distinfo

19 years agoAdd files from parent branch HEAD:
branch-fixup [Mon, 20 Sep 2004 08:03:42 +0000 (08:03 +0000)]
Add files from parent branch HEAD:
www/firefox-gtk2/PLIST
www/firefox/Makefile-firefox.common
www/firefox/PLIST
www/firefox/distinfo

19 years agoAdd files from parent branch HEAD:
branch-fixup [Mon, 20 Sep 2004 07:58:20 +0000 (07:58 +0000)]
Add files from parent branch HEAD:
devel/m4/Makefile
devel/m4/distinfo
devel/m4/patches/patch-ac
devel/m4/patches/patch-ad

19 years agoAdd files from parent branch HEAD:
branch-fixup [Mon, 20 Sep 2004 02:08:58 +0000 (02:08 +0000)]
Add files from parent branch HEAD:
cad/fasthenry/Makefile
cad/fasthenry/distinfo
cad/fasthenry/patches/patch-aa
cad/fasthenry/patches/patch-ab
cad/fasthenry/patches/patch-ac
cad/fasthenry/patches/patch-ad
cad/fasthenry/patches/patch-ae
cad/fasthenry/patches/patch-af
cad/fasthenry/patches/patch-ag
cad/fasthenry/patches/patch-ah
cad/fasthenry/patches/patch-ai
cad/fasthenry/patches/patch-aj
cad/fasthenry/patches/patch-ak
cad/fasthenry/patches/patch-al
cad/fasthenry/patches/patch-am
cad/fasthenry/patches/patch-an
cad/fasthenry/patches/patch-ao
cad/fasthenry/patches/patch-ap
cad/fasthenry/patches/patch-aq
cad/fasthenry/patches/patch-ar
cad/fasthenry/patches/patch-as
cad/fasthenry/patches/patch-at
cad/fasthenry/patches/patch-au
cad/fasthenry/patches/patch-av
cad/fasthenry/patches/patch-aw
cad/fasthenry/patches/patch-ax

19 years agoAdd files from parent branch HEAD:
branch-fixup [Sun, 19 Sep 2004 21:38:21 +0000 (21:38 +0000)]
Add files from parent branch HEAD:
net/tcptraceroute/Makefile
net/tcptraceroute/distinfo
net/tcptraceroute/patches/patch-ab

19 years agoAdd files from parent branch HEAD:
branch-fixup [Sun, 19 Sep 2004 20:13:26 +0000 (20:13 +0000)]
Add files from parent branch HEAD:
Packages.txt

19 years agoAdd files from parent branch HEAD:
branch-fixup [Sun, 19 Sep 2004 19:51:04 +0000 (19:51 +0000)]
Add files from parent branch HEAD:
lang/tcl/Makefile

19 years agoAdd files from parent branch HEAD:
branch-fixup [Sun, 19 Sep 2004 14:31:36 +0000 (14:31 +0000)]
Add files from parent branch HEAD:
sysutils/vifm/Makefile

19 years agoAdd files from parent branch HEAD:
branch-fixup [Sun, 19 Sep 2004 13:48:52 +0000 (13:48 +0000)]
Add files from parent branch HEAD:
www/mozilla-bin/Makefile
www/mozilla-bin/distinfo

19 years agoAdd files from parent branch HEAD:
branch-fixup [Sun, 19 Sep 2004 13:41:24 +0000 (13:41 +0000)]
Add files from parent branch HEAD:
mail/wl/Makefile
mail/wl/distinfo

19 years agoAdd files from parent branch HEAD:
branch-fixup [Sun, 19 Sep 2004 13:02:55 +0000 (13:02 +0000)]
Add files from parent branch HEAD:
mail/msmtp/options.mk

19 years agoAdd files from parent branch HEAD:
branch-fixup [Sun, 19 Sep 2004 13:02:00 +0000 (13:02 +0000)]
Add files from parent branch HEAD:
mail/msmtp/Makefile
mail/msmtp/distinfo

19 years agoAdd files from parent branch HEAD:
branch-fixup [Sun, 19 Sep 2004 13:00:28 +0000 (13:00 +0000)]
Add files from parent branch HEAD:
mk/bsd.sites.mk

19 years agoAdd files from parent branch HEAD:
branch-fixup [Sun, 19 Sep 2004 12:48:45 +0000 (12:48 +0000)]
Add files from parent branch HEAD:
security/gsasl/Makefile
security/gsasl/PLIST
security/gsasl/buildlink3.mk
security/gsasl/distinfo

19 years agoAdd files from parent branch HEAD:
branch-fixup [Sun, 19 Sep 2004 12:32:27 +0000 (12:32 +0000)]
Add files from parent branch HEAD:
security/gss/Makefile
security/gss/PLIST
security/gss/distinfo

19 years agoAdd files from parent branch HEAD:
branch-fixup [Sun, 19 Sep 2004 04:17:22 +0000 (04:17 +0000)]
Add files from parent branch HEAD:
audio/arts/Makefile
meta-pkgs/kde3/kde3.mk
x11/kdelibs3/Makefile

19 years agoAdd files from parent branch HEAD:
branch-fixup [Sun, 19 Sep 2004 04:08:18 +0000 (04:08 +0000)]
Add files from parent branch HEAD:
www/Makefile
www/quanta-docs/DESCR
www/quanta-docs/Makefile
www/quanta-docs/PLIST
www/quanta-docs/distinfo
www/quanta/DESCR
www/quanta/Makefile
www/quanta/PLIST
www/quanta/distinfo

19 years agoAdd files from parent branch HEAD:
branch-fixup [Sun, 19 Sep 2004 01:54:01 +0000 (01:54 +0000)]
Add files from parent branch HEAD:
chat/scrollz/Makefile

19 years agoAdd files from parent branch HEAD:
branch-fixup [Sun, 19 Sep 2004 00:14:52 +0000 (00:14 +0000)]
Add files from parent branch HEAD:
devel/subversion/Makefile.version
devel/subversion/distinfo
devel/subversion/patches/patch-aa