pkgsrcv2.git
12 years agoPullup tickets #3503, #3506, #3507, #3508, #3509 and #3510.
tron [Mon, 22 Aug 2011 22:22:19 +0000 (22:22 +0000)]
Pullup tickets #3503, #3506, #3507, #3508, #3509 and #3510.

12 years agoPullup ticket #3508 - requested by taca
tron [Mon, 22 Aug 2011 21:39:00 +0000 (21:39 +0000)]
Pullup ticket #3508 - requested by taca
net/bind96: security update

Revisions pulled up:
- net/bind96/Makefile                                           1.20
- net/bind96/PLIST                                              1.8
- net/bind96/distinfo                                           1.13

---
   Module Name: pkgsrc
   Committed By: taca
   Date: Wed Aug 10 15:24:51 UTC 2011

   Modified Files:
    pkgsrc/net/bind96: Makefile PLIST distinfo

   Log Message:
   Update bind96 pacakge to 9.6.3.1.ESV.5 (9.6-ESV-R5).

   For full changes, please refer:
   ftp://ftp.isc.org/isc/bind9/9.6-ESV-R5/RELEASE-NOTES-BIND-9.6-ESV.html

   New Features

   9.6-ESV-R5

        * Added a tool able to generate malformed packets to allow testing of
          how named handles them. [RT #24096]

   Security Fixes

   9.6-ESV-R5

        * named, set up to be a caching resolver, is vulnerable to a user
          querying a domain with very large resource record sets (RRSets)
          when trying to negatively cache the response. Due to an off-by-one
          error, caching the response could cause named to crash. [RT #24650]
          [CVE-2011-1910]
        * Change #2912 populated the message section in replies to UPDATE
          requests, which some Windows clients wanted. This exposed a latent
          bug that allowed the response message to crash named. With this
          fix, change 2912 has been reduced to copy only the zone section to
          the reply. A more complete fix for the latent bug will be released
          later. [RT #24777]

   Feature Changes

   9.6-ESV-R5

        * Merged in the NetBSD ATF test framework (currently version 0.12)
          for development of future unit tests. Use configure --with-atf to
          build ATF internally or configure --with-atf=prefix to use an
          external copy. [RT #23209]
        * Added more verbose error reporting from DLZ LDAP. [RT #23402]
        * Replaced compile time constant with STDTIME_ON_32BITS. [RT #23587]

12 years agoPullup ticket #3506 - requested by taca
tron [Mon, 22 Aug 2011 21:30:23 +0000 (21:30 +0000)]
Pullup ticket #3506 - requested by taca
textproc/namazu: security update

Revisions pulled up:
- textproc/namazu/Makefile                                      1.7
- textproc/namazu/distinfo                                      1.5

---
   Module Name: pkgsrc
   Committed By: mef
   Date: Sun Jul 24 14:31:34 UTC 2011

   Modified Files:
    pkgsrc/textproc/namazu: Makefile distinfo

   Log Message:
   Bump verion  PR#45170

   2011-07-18  Tadamasa Teranishi  <yw3t-trns@asahi-net.or.jp>

           * configure.in: Bumped version number to to 2.0.21.
           * configure.in (LTVERSION): Set "8:3:1".
           * man: update.
           * namazu.cgi:
              Fix IE6,7 cross-site scripting problem.
           * tests, pltests:
              Add New Tests.

   make check have passed by changing '$WATATI =  ;' lines in pl/conf.pl
   for LANG=ja, except $MECAB is set.

12 years agoPullup ticket #3510 - requested by taca
tron [Mon, 22 Aug 2011 21:27:01 +0000 (21:27 +0000)]
Pullup ticket #3510 - requested by taca
www/typo3: security update

Revisions pulled up:
- www/typo3/Makefile                                            1.33
- www/typo3/PLIST                                               1.20
- www/typo3/distinfo                                            1.25
- www/typo3/patches/patch-aa                                    1.6

---
   Module Name: pkgsrc
   Committed By: taca
   Date: Thu Aug 18 12:21:22 UTC 2011

   Modified Files:
    pkgsrc/www/typo3: Makefile PLIST distinfo
    pkgsrc/www/typo3/patches: patch-aa

   Log Message:
   Update typo3 package to 4.5.5.

   4.5.3 and 4.5.5 contains some security fixes.  For more detail,
   please refer these changes.

    http://wiki.typo3.org/wiki/TYPO3_4.5.3
    http://wiki.typo3.org/wiki/TYPO3_4.5.4
    http://wiki.typo3.org/wiki/TYPO3_4.5.5

12 years agoPullup ticket #3509 - requested by taca
tron [Mon, 22 Aug 2011 21:21:34 +0000 (21:21 +0000)]
Pullup ticket #3509 - requested by taca
net/bind97: security update

Revisions pulled up:
- net/bind97/Makefile                                           1.9
- net/bind97/PLIST                                              1.5
- net/bind97/distinfo                                           1.9

---
   Module Name: pkgsrc
   Committed By: taca
   Date: Wed Aug 10 15:26:11 UTC 2011

   Modified Files:
    pkgsrc/net/bind97: Makefile PLIST distinfo

   Log Message:
   Update bind97 package to 9.7.4.

   For full changes, please refer:
   ftp://ftp.isc.org/isc/bind9/9.7.4/RELEASE-NOTES-BIND-9.7.4.html

   New Features

   9.7.4

        * A new test has been added to check the apex NSEC3 records after
          DNSKEY records have been added via dynamic update. [RT #23229]
        * Added a tool able to generate malformed packets to allow testing of
          how named handles them. [RT #24096]

   Security Fixes

   9.7.4

        * named, set up to be a caching resolver, is vulnerable to a user
          querying a domain with very large resource record sets (RRSets)
          when trying to negatively cache the response. Due to an off-by-one
          error, caching the response could cause named to crash. [RT #24650]
          [CVE-2011-1910]
        * Change #2912 (see CHANGES) exposed a latent bug in the DNS message
          processing code that could allow certain UPDATE requests to crash
          named. [RT #24777] [CVE-2011-2464]

   Feature Changes

   9.7.4

        * Merged in the NetBSD ATF test framework (currently version 0.12)
          for development of future unit tests. Use configure --with-atf to
          build ATF internally or configure --with-atf=prefix to use an
          external copy. [RT #23209]
        * Added more verbose error reporting from DLZ LDAP. [RT #23402]
        * Replaced compile time constant with STDTIME_ON_32BITS. [RT #23587]

12 years agoPullup ticket #3501
sbd [Fri, 19 Aug 2011 08:27:15 +0000 (08:27 +0000)]
Pullup ticket #3501

12 years agoPullup ticket #3501 - requested by joerg
sbd [Fri, 19 Aug 2011 08:18:32 +0000 (08:18 +0000)]
Pullup ticket #3501 - requested by joerg
x11/libXfont buffer overflow fix

Revisions pulled up:
- x11/libXfont/Makefile                                         1.18
- x11/libXfont/distinfo                                         1.16
- x11/libXfont/patches/patch-src-fontfile-decompress.c          1.1

---
   Module Name: pkgsrc
   Committed By: joerg
   Date: Thu Aug 18 22:58:24 UTC 2011

   Modified Files:
    pkgsrc/x11/libXfont: Makefile distinfo
   Added Files:
    pkgsrc/x11/libXfont/patches: patch-src-fontfile-decompress.c

   Log Message:
   Fix buffer overflow in LZW handler.

12 years agoPullup tickets #3495, #3496, #3498 and #3499.
tron [Sun, 14 Aug 2011 12:18:59 +0000 (12:18 +0000)]
Pullup tickets #3495, #3496, #3498 and #3499.

12 years agoPullup ticket #3499 - requested by sbd
tron [Sun, 14 Aug 2011 12:17:35 +0000 (12:17 +0000)]
Pullup ticket #3499 - requested by sbd
print/cups: build fix

Revisions pulled up:
- print/cups/distinfo                                           1.80
- print/cups/patches/patch-ae                                   1.28

---
   Module Name: pkgsrc
   Committed By: sbd
   Date: Fri Aug 12 02:03:14 UTC 2011

   Modified Files:
    pkgsrc/print/cups: distinfo
    pkgsrc/print/cups/patches: patch-ae

   Log Message:
   Fix Unprivileged builds.

12 years agoPullup ticket #3498 - requested by dholland
tron [Sun, 14 Aug 2011 11:59:35 +0000 (11:59 +0000)]
Pullup ticket #3498 - requested by dholland
geography/viking: build fix

Revisions pulled up:
- geography/viking/Makefile                                     1.27
- geography/viking/distinfo                                     1.14
- geography/viking/patches/patch-src_osm-traces.c               1.2

---
   Module Name: pkgsrc
   Committed By: gdt
   Date: Sat Jul 30 19:25:56 UTC 2011

   Modified Files:
    pkgsrc/geography/viking: Makefile distinfo
   Added Files:
    pkgsrc/geography/viking/patches: patch-src_osm-traces.c

   Log Message:
   Adapt to modern curl.

   Add patch to remove include of withdrawn header (already changed upstream).
   Set LICENSE (GPL2).
   PKGREVISION++.

12 years agoPullup ticket #3496 - requested by gls
tron [Sun, 14 Aug 2011 11:17:36 +0000 (11:17 +0000)]
Pullup ticket #3496 - requested by gls
audio/libmodplug: security update

Revisions pulled up:
- audio/libmodplug/Makefile                                     1.12
- audio/libmodplug/distinfo                                     1.6

---
   Module Name: pkgsrc
   Committed By: gls
   Date: Tue Aug  9 19:29:27 UTC 2011

   Modified Files:
    pkgsrc/audio/libmodplug: Makefile distinfo

   Log Message:
   Update audio/libmodplug to 0.8.8.4.

   Upstream changes:

        * Improve timidity.cfg parsing capability
        * Add source command capability in timidity.cfg (useful for debian
   default)
        * Fix integer overflow in WAV reader (SA45131/A)
        * Fix S3M stack overflow possibility (SA45131/B)
        * Bound seeking and reading in PAT files
        * Fix AMS/AMSv2 and DSM too large by one (SA45131/C)
        * Use structure in XM decoding (development related)
        * Use bmpvalues in Octamed files when calcuting default tempo
   (Francis Russel)

   Fixes SA45131.

12 years agoPullup ticket #3495 - requested by gls
tron [Sun, 14 Aug 2011 11:15:39 +0000 (11:15 +0000)]
Pullup ticket #3495 - requested by gls
www/moodle: security update

Revisions pulled up:
- www/moodle/Makefile                                           1.5
- www/moodle/PLIST                                              1.4
- www/moodle/distinfo                                           1.4

---
   Module Name: pkgsrc
   Committed By: gls
   Date: Tue Aug  9 18:59:23 UTC 2011

   Modified Files:
    pkgsrc/www/moodle: Makefile PLIST distinfo

   Log Message:
   Update www/moodle to 2.1.1

   pkgsrc changes:
   - replace bash with sh in a script.

   Upstream changes:

   Many, many changes, including security fixes.

   Highlights from version 2.1:

   - New question engine
   - Ability to restore the course contents from Moodle 1.9 backup files
   - Support for mobile devices

   For complete changelog, please refer to:

   http://docs.moodle.org/dev/Moodle_2.0.3_release_notes
   http://docs.moodle.org/dev/Moodle_2.0.4_release_notes
   http://docs.moodle.org/dev/Moodle_2.1_release_notes
   http://docs.moodle.org/dev/Moodle_2.1.1_release_notes

   Fixes SA45487 (MSA-11-0021, MSA-11-0022), among others.

12 years agopullups 3491 and 3494
spz [Mon, 8 Aug 2011 19:59:12 +0000 (19:59 +0000)]
pullups 3491 and 3494

12 years agoPullup ticket #3494 - requested by bouyer
spz [Mon, 8 Aug 2011 19:56:37 +0000 (19:56 +0000)]
Pullup ticket #3494 - requested by bouyer
sysutils/apcupsd: Dragonfly fix

Revisions pulled up:
- sysutils/apcupsd/Makefile                                     1.63

-------------------------------------------------------------------
   Module Name: pkgsrc
   Committed By: bouyer
   Date: Sun Aug  7 17:27:24 UTC 2011

   Modified Files:
    pkgsrc/sysutils/apcupsd: Makefile

   Log Message:
   Apply patch from PR pkg/45171, fixing rc.d script on DragonFly.

   To generate a diff of this commit:
   cvs rdiff -u -r1.62 -r1.63 pkgsrc/sysutils/apcupsd/Makefile

12 years agoPullup ticket #3492 and #3493.
tron [Sun, 7 Aug 2011 09:40:29 +0000 (09:40 +0000)]
Pullup ticket #3492 and #3493.

12 years agoPullup ticket #3493 - requested by bouyer
tron [Sun, 7 Aug 2011 09:39:49 +0000 (09:39 +0000)]
Pullup ticket #3493 - requested by bouyer
sysutils/apcupsd: build fix

Revisions pulled up:
- sysutils/apcupsd/Makefile                                     1.62
- sysutils/apcupsd/PLIST                                        1.13
- sysutils/apcupsd/distinfo                                     1.15
- sysutils/apcupsd/options.mk                                   1.3
- sysutils/apcupsd/patches/patch-aa                             deleted
- sysutils/apcupsd/patches/patch-ae                             1.7
- sysutils/apcupsd/patches/patch-af                             1.7
- sysutils/apcupsd/patches/patch-ag                             1.5
- sysutils/apcupsd/patches/patch-ai                             1.5
- sysutils/apcupsd/patches/patch-aj                             1.8
- sysutils/apcupsd/patches/patch-al                             1.5
- sysutils/apcupsd/patches/patch-an                             1.6
- sysutils/apcupsd/patches/patch-ao                             1.7

---
   Module Name: pkgsrc
   Committed By: bouyer
   Date: Mon Aug  1 14:54:51 UTC 2011

   Modified Files:
    pkgsrc/sysutils/apcupsd: Makefile PLIST distinfo options.mk
    pkgsrc/sysutils/apcupsd/patches: patch-ae patch-af patch-ag patch-ai
        patch-aj patch-al patch-an patch-ao
   Removed Files:
    pkgsrc/sysutils/apcupsd/patches: patch-aa

   Log Message:
   Update to 3.14.9.
   Dragonfly users, please test that is still builds !
   pkgsrc change: as snmp support doesn't depend on net-snmp
   anymore, remove snmp option and always build snmp support.
   cgi option now depend on graphics/gd/

   User-visible changes sinces 3.14.3:

   2010-08-30 14:18  adk0212

           * src/drivers/snmplite/: mge-mib.cpp, mge-oids.h, mibs.cpp:

           Add support for MGE SNMP MIB. Contributed by Lars Täer
           <taeuber@bbaw.de>

   2010-07-30 18:04  adk0212

           * src/drivers/snmplite/: apc-mib.cpp, apc-oids.h, mib.cpp, oids.h,
           rfc1628-mib.cpp, rfc1628-oids.h, snmplite.cpp, snmplite.h:

           Add support for RFC1628 SNMP MIB. Refactor APC MIB and create
           MibStrategy struct for associating MIB/CI mapping with
           corresponding processing function. RFC1628 strategy is coded per
           the MIB but untested.

   2010-01-10 10:29  adk0212

           * include/defines.h, src/apctest.c, src/drivers/usb/usb.c:

           Add apctest support for reading/setting self-test interval on USB.
           Also show current setting in UPS status. Contributed by James
           Belleau <jpbelleau@gmail.com>

   2009-10-25 11:03  adk0212

           * configure, autoconf/config.h.in, autoconf/configure.in,
           autoconf/variables.mak.in, include/struct.h,
           platforms/etc/apcupsd.conf.in, src/drivers/Makefile,
           src/drivers/drivers.c, src/drivers/snmplite/Makefile,
           src/drivers/snmplite/asn.cpp, src/drivers/snmplite/asn.h,
           src/drivers/snmplite/mib.cpp, src/drivers/snmplite/snmp.cpp,
           src/drivers/snmplite/snmp.h, src/drivers/snmplite/snmplite.cpp,
           src/drivers/snmplite/snmplite.h, src/lib/apcconfig.c,
           src/lib/apcstatus.c:

           Add SNMP Lite driver which does not depend on net-snmp library.
           This makes it more portable and eliminates need to move libsnmp.so
           to /lib in order to do a killpower on systems where /usr is
           unmounted.

   2009-09-01 20:30  adk0212

           * src/apctest.c:

           Implement battery calibration in apctest for USB models.  Thanks to
           James Belleau <james@belleau.net> for the original implementation
           which has been modified somewhat in this commit.

   2009-05-02 10:30  adk0212

           * src/action.c:

           Change log level of UPS self-test messages to WARNING from ALERT.
           Given that self-test messages are routine, they do not belong at
           LOG_ALERT.  Contributed by Dave Ewart <davee@ceu.ox.ac.uk>.

   2009-04-25 10:58  adk0212

           * src/lib/apcconfig.c:

           Remove EVENTFILE, EVENTFILEMAX config directives. These were
           replaced by the plural versions that are in use today (EVENTSFILE,
           EVENTSFILEMAX) almost 10 years ago. It's time to kill the old
           names.  (h/t Trevor Roydhouse <trev@sentry.org>)

   2009-03-02 17:48  adk0212

           * doc/apcupsd.man, include/drivers.h, include/extern.h,
           src/action.c, src/apctest.c, src/apcupsd.c, src/device.c,
           src/options.c, src/drivers/drivers.c,
           src/drivers/apcsmart/apcsmart.h, src/drivers/apcsmart/smart.c,
           src/drivers/apcsmart/smartoper.c, src/drivers/usb/usb.c,
           src/drivers/usb/usb.h, src/lib/apclock.c:

           Add support for turning the UPS off completely. This complements
           existing hibernate (aka killpower) functionality. Turn-off is
           implemented for apcsmart and USB drivers, subject to support for
           the relevant commands in the UPS itself. Contributed by Keith
           Campbell <campbell@econnectix.com>.

   2008-06-29 11:12  adk0212

           * src/action.c:

           Fix bug in LOWBATT glitch handling. We must examine LOWBATT for
           changes every time thru the status loop, not just during the
           OnBattery state.  Otherwise we can miss the initial LOWBATT
           assertion, which defeats the glitch rejection logic.

   2008-05-06 20:16  skoona

           * src/gapcmon/gapcmon.c:

           Corrected the use of NOMPOWER and the calc of current usage amount

   2008-05-04 11:13  adk0212

           * src/drivers/usb/usb.c:

           Add a heuristic to fix up incorrect NOMINV or NOMOUTV. Some UPSes
           (RS 500) report decivolts instead of volts. Reported by Kirill S.
           Bychkov <yason@linklevel.net>.

   2008-01-27 12:00  adk0212

           * include/struct.h, platforms/etc/apcupsd.conf.in,
           platforms/mingw/apcupsd.conf.in, src/device.c,
           src/drivers/net/net.c, src/drivers/snmp/drv_powernet.c,
           src/lib/apcconfig.c:

           Add POLLTIME directive to control UPS polling interval. NETTIME is
           accepted as a synonym for compatibility with old config files.

12 years agoPullup ticket #3492 - requested by drocher
tron [Sun, 7 Aug 2011 09:35:39 +0000 (09:35 +0000)]
Pullup ticket #3492 - requested by drocher
graphics/gdk-pixbuf: security update

Revisions pulled up:
- graphics/gdk-pixbuf/Makefile                                  1.43
- graphics/gdk-pixbuf/distinfo                                  1.22
- graphics/gdk-pixbuf/patches/patch-af                          1.2

---
   Module Name:  pkgsrc
   Committed By: drochner
   Date:         Wed Aug  3 10:01:25 UTC 2011
   Modified Files:
         pkgsrc/graphics/gdk-pixbuf: Makefile distinfo
         pkgsrc/graphics/gdk-pixbuf/patches: patch-af
   Log Message:
   pull in boundary check from gdk2-pixbuf to fix a possible buffer
   overflow by invalid GIF images, see redhat bug#727081
   bump PKGREV

12 years agoPullup ticket #3490.
tron [Fri, 5 Aug 2011 12:22:55 +0000 (12:22 +0000)]
Pullup ticket #3490.

12 years agoPullup ticket #3490 - requested by obache
tron [Fri, 5 Aug 2011 12:22:03 +0000 (12:22 +0000)]
Pullup ticket #3490 - requested by obache
lang/openjdk7: build fix

Revisions pulled up:
- lang/openjdk7/options.mk                                      1.2

---
   Module Name: pkgsrc
   Committed By: obache
   Date: Wed Aug  3 13:28:35 UTC 2011

   Modified Files:
    pkgsrc/lang/openjdk7: options.mk

   Log Message:
   Set FETCH_MESSAGE for jce only when it is not fetched yet.
   fixes PR#44983 and PR#45202.

12 years agoPullup tickets #3488 and #3489.
tron [Wed, 3 Aug 2011 21:05:13 +0000 (21:05 +0000)]
Pullup tickets #3488 and #3489.

12 years agoPullup ticket #3489 - requested by drochner
tron [Wed, 3 Aug 2011 21:04:08 +0000 (21:04 +0000)]
Pullup ticket #3489 - requested by drochner
multimedia/vlc: security patch

Revisions pulled up:
- multimedia/vlc/Makefile                                       1.113
- multimedia/vlc/distinfo                                       1.46
- multimedia/vlc/patches/patch-au                               1.7
- multimedia/vlc/patches/patch-av                               1.3

---
   Module Name:  pkgsrc
   Committed By: drochner
   Date:         Mon Jul 18 17:06:43 UTC 2011
   Modified Files:
         pkgsrc/multimedia/vlc: Makefile distinfo
   Added Files:
         pkgsrc/multimedia/vlc/patches: patch-au patch-av
   Log Message:
   add patches from upstream to plug 2 security problems:
   -heap overflow in the AVI file parser (CVE-2011-2588)
   -heap overflow in the Real Media file parser (CVE-2011-2587)
   bump PKGREV

12 years agoPullup ticket #3488 - requested by bouyer
tron [Wed, 3 Aug 2011 17:51:52 +0000 (17:51 +0000)]
Pullup ticket #3488 - requested by bouyer
net/nagios-base: security update

Revisions pulled up:
- net/nagios-base/Makefile                                      1.32
- net/nagios-base/Makefile.common                               1.12
- net/nagios-base/PLIST                                         1.10
- net/nagios-base/distinfo                                      1.13
- net/nagios-base/patches/patch-aa                              1.9
- net/nagios-base/patches/patch-ad                              1.8
- net/nagios-base/patches/patch-ag                              1.8
- net/nagios-base/patches/patch-ah                              1.3
- net/nagios-plugins/Makefile.common                            1.9

---
   Module Name: pkgsrc
   Committed By: bouyer
   Date: Tue Aug  2 14:03:18 UTC 2011

   Modified Files:
    pkgsrc/net/nagios-base: Makefile Makefile.common PLIST distinfo
    pkgsrc/net/nagios-base/patches: patch-aa patch-ad patch-ag patch-ah
    pkgsrc/net/nagios-plugins: Makefile.common

   Log Message:
   Update nagios-base to 3.3.1, fixig CVE-2011-1523 and CVE-2011-2179.
   Changes since 3.2.3:
   ENHANCEMENTS

       * Added support for same host service dependencies with servicegroups (Mathieu Gagn?)
       * Empty hostgroups referenced from services now optionally generate a warning instead of an error.
       * Documentation links now point to online resources
       * Matt Wall's Exfoliation theme is now installed by default. You can reinstall the classic theme with "make install-classicui"
       * Downtime delete commands made "distributable" by deleting by host group name, host name or start time/comment (Opsview team)
       * Allow status.cgi to order by "host urgency" (Jochen Bern)
       * Added news items and quick links to main splash page
       * Added ability to authenticate to CGIs using contactgroup name (Stephen Gran)

   FIXES

       * Fixes status.cgi when called with no parameters, where host should be set to all if none specified (Michael Friedrich)
       * Fixes possible validation error with empty hostgroups/servicegroups (Sven-G?ran Bergh)
       * Performance-data handling and checking is now thread-safe so long as embedded perl is not used.
       * Children should no longer hang on mutex locks held in parent for localtime() (and similar) calls.
       * Debug logging is now properly serialized, using soft-locking with a timeout of 150 milliseconds to avoid multiple threads competing for the privilege to write debug info.
       * Fixed extraneous alerts for services when host is down
       * Fixed incorrect parsing of multi-line host check results (Jochen Bern)
       * Fixed bug with passive host checks being incorrectly sent to event brokers as active checks
       * Fixed bug where passive host check status updates were not being propagated to event brokers
       * Reverted 'Fix for retaining host display name and alias, as well as service display name' as configuration information stored incorrectly over a reload
       * Fixed compile warnings for size_t (Michael Friedrich)
       * Fixed problem where acknowledgements were getting reset when a hard state change occurred
       * Removed duplicated unlinks for check result files with multiple results
       * Fixed race condition on flexible downtime commands when duration not set or zero (Michael Friedrich)
       * Fixed flexible downtime on service hard state change doesn't get triggered/activated (Michael Friedrich)
       * Fixed XSS vulnerability in config.cgi and statusmap.cgi (Stefan Schurtz)
       * Fixed segfault when sending host notifications (Michael Friedrich)
       * Fixed bug where unauthorized contacts could issue hostgroup and servicegroup commands (Sven Nierlein)

12 years agoPullup ticket #3487.
tron [Tue, 2 Aug 2011 08:11:44 +0000 (08:11 +0000)]
Pullup ticket #3487.

12 years agoPullup ticket #3487 - requested by drochner
tron [Tue, 2 Aug 2011 08:11:09 +0000 (08:11 +0000)]
Pullup ticket #3487 - requested by drochner
net/libsoup24: security patch

Revisions pulled up:
- net/libsoup24/Makefile                                        1.33
- net/libsoup24/distinfo                                        1.23
- net/libsoup24/patches/patch-aa                                1.3

---
   Module Name:    pkgsrc
   Committed By:   drochner
   Date:           Fri Jul 29 10:27:29 UTC 2011

   Modified Files:
           pkgsrc/net/libsoup24: Makefile distinfo
   Added Files:
           pkgsrc/net/libsoup24/patches: patch-aa

   Log Message:
   add patch from upstream to fix a directory traversal problem which
   could allow information disclosure  by servers (CVE-2011-2524, does not
   affect client applications)

12 years agoPullup tickets 3483, 3484, 3485 & 3486
sbd [Mon, 1 Aug 2011 04:35:45 +0000 (04:35 +0000)]
Pullup tickets 3483, 3484, 3485 & 3486

12 years agoPullup ticket #3486 - requested by dholland
sbd [Mon, 1 Aug 2011 04:33:23 +0000 (04:33 +0000)]
Pullup ticket #3486 - requested by dholland
chat/amsn build fix

Revisions pulled up:
- chat/amsn/Makefile                                            1.21
- chat/amsn/distinfo                                            1.8-1.9
- chat/amsn/patches/patch-utils_TkCximage_src_CxImage_ximapng.cpp 1.2-1.3

---
   Module Name: pkgsrc
   Committed By: dholland
   Date: Mon Aug  1 00:43:59 UTC 2011

   Modified Files:
    pkgsrc/chat/amsn: distinfo
    pkgsrc/chat/amsn/patches: patch-utils_TkCximage_src_CxImage_ximapng.cpp

   Log Message:
   Improve png-1.5 support. Still broken: writing palettes and transparency.

---
   Module Name: pkgsrc
   Committed By: dholland
   Date: Mon Aug  1 01:16:50 UTC 2011

   Modified Files:
    pkgsrc/chat/amsn: Makefile distinfo
    pkgsrc/chat/amsn/patches: patch-utils_TkCximage_src_CxImage_ximapng.cpp

   Log Message:
   Fix build with png-1.5, fully now. Also add various REPLACE_INTERPRETER
   and add a dependency on Python for the two installed Python scripts. No
   version bump since this hasn't been buildable in a long time.

12 years agoPullup ticket #3485 - requested by dholland
sbd [Mon, 1 Aug 2011 04:32:51 +0000 (04:32 +0000)]
Pullup ticket #3485 - requested by dholland
editors/scite build fix

Revisions pulled up:
- editors/scite/Makefile                                        1.4

---
   Module Name: pkgsrc
   Committed By: dholland
   Date: Sun Jul 31 23:32:10 UTC 2011

   Modified Files:
    pkgsrc/editors/scite: Makefile

   Log Message:
   Needs pkg-config. Depends on glib2 directly. PKGREVISION -> 2. Should fix
   failure seen in bulk builds.

12 years agoPullup ticket #3484 - requested by dholland
sbd [Mon, 1 Aug 2011 04:30:52 +0000 (04:30 +0000)]
Pullup ticket #3484 - requested by dholland
devel/tig build fix

Revisions pulled up:
- devel/tig/distinfo                                            1.5
- devel/tig/patches/patch-tig_c                                 1.1
- devel/tig/patches/patch-tig_h                                 1.1

---
   Module Name: pkgsrc
   Committed By: dholland
   Date: Sun Jul 31 22:15:36 UTC 2011

   Modified Files:
    pkgsrc/devel/tig: distinfo
   Added Files:
    pkgsrc/devel/tig/patches: patch-tig_c patch-tig_h

   Log Message:
   Fix broken build.

12 years agoPullup ticket #3483 - requested by pettai
sbd [Mon, 1 Aug 2011 04:21:26 +0000 (04:21 +0000)]
Pullup ticket #3483 - requested by pettai
security/opensaml security update

Revisions pulled up:
- security/opensaml/Makefile                                    1.8
- security/opensaml/PLIST                                       1.5
- security/opensaml/distinfo                                    1.3

---
   Module Name: pkgsrc
   Committed By: pettai
   Date: Thu Jul 28 22:44:37 UTC 2011

   Modified Files:
    pkgsrc/security/opensaml: Makefile PLIST distinfo

   Log Message:
   Update fixes CVE-2011-2516
   (See http://shibboleth.internet2.edu/secadv/secadv_20110706.txt for details)

12 years agoPullup ticket #3482
sbd [Sat, 30 Jul 2011 05:42:15 +0000 (05:42 +0000)]
Pullup ticket #3482

12 years agoPullup ticket #3482 - requested by pettai
sbd [Sat, 30 Jul 2011 05:40:46 +0000 (05:40 +0000)]
Pullup ticket #3482 - requested by pettai
security/xml-security-c security update

Revisions pulled up:
- security/xml-security-c/Makefile                              1.9
- security/xml-security-c/distinfo                              1.4

---
   Module Name: pkgsrc
   Committed By: pettai
   Date: Thu Jul 28 23:33:31 UTC 2011

   Modified Files:
    pkgsrc/security/xml-security-c: Makefile distinfo

   Log Message:
   [...]

12 years agoAdd patch for recent curl.
gdt [Fri, 29 Jul 2011 20:07:48 +0000 (20:07 +0000)]
Add patch for recent curl.

Drop inclusion of curl/type.h, which no longer exists.
Set LICENSE (GPL2).
PKGREVISION++.

12 years agoPullup tickets 3480 & 3481
sbd [Thu, 28 Jul 2011 02:32:13 +0000 (02:32 +0000)]
Pullup tickets 3480 & 3481

12 years agoPullup ticket #3481 - requested by tez
sbd [Thu, 28 Jul 2011 02:30:24 +0000 (02:30 +0000)]
Pullup ticket #3481 - requested by tez
textproc/groff security/portablity update

Revisions pulled up:
- textproc/groff/Makefile                                       1.59
- textproc/groff/distinfo                                       1.16
- textproc/groff/patches/patch-contrib_pdfmark_pdfroff.sh       1.2

---
   Module Name:   pkgsrc
   Committed By:  tez
   Date:          Wed Jul 27 16:33:25 UTC 2011
   Modified Files:
         pkgsrc/textproc/groff: Makefile distinfo
         pkgsrc/textproc/groff/patches: patch-contrib_pdfmark_pdfroff.sh
   Log Message:
   Adjust pdfroff security patch to not use '-p' option to mktemp which is
   missing on some platforms.  fixes PR#45181

12 years agoPullup ticket #3480 - requested by obache
sbd [Thu, 28 Jul 2011 02:30:16 +0000 (02:30 +0000)]
Pullup ticket #3480 - requested by obache
security/clamav security update

Revisions pulled up:
- security/clamav/Makefile                                      1.4
- security/clamav/distinfo                                      1.4

---
   Module Name: pkgsrc
   Committed By: adam
   Date: Mon Jul 25 22:59:12 UTC 2011

   Modified Files:
    pkgsrc/security/clamav: Makefile distinfo

   Log Message:
   Changes 0.97.2
   ClamAV 0.97.2 fixes problems with the bytecode engine, Safebrowsing detection,
   hash matcher, and other minor issues. Please see the ChangeLog file for
   details.

12 years agoPullup tickets 3478 & 3479
sbd [Wed, 27 Jul 2011 06:40:33 +0000 (06:40 +0000)]
Pullup tickets 3478 & 3479

12 years agoPullup ticket #3479 - requested by taca
sbd [Wed, 27 Jul 2011 06:38:30 +0000 (06:38 +0000)]
Pullup ticket #3479 - requested by taca
net/samba33 security update.

Revisions pulled up:
- net/samba33/Makefile                                          1.15
- net/samba33/distinfo                                          1.7
- net/samba33/patches/patch-af                                  1.2

---
   Module Name: pkgsrc
   Committed By: taca
   Date: Wed Jul 27 00:53:37 UTC 2011

   Modified Files:
    pkgsrc/net/samba33: Makefile distinfo
    pkgsrc/net/samba33/patches: patch-af

   Log Message:
   Update samba33 package to 3.3.16; security fix for swat.

                      ==============================
                      Release Notes for Samba 3.3.16
               July 26, 2011
                      ==============================

   This is a security release in order to address
   CVE-2011-2522 (Cross-Site Request Forgery in SWAT) and
   CVE-2011-2694 (Cross-Site Scripting vulnerability in SWAT).

   o  CVE-2011-2522:
      The Samba Web Administration Tool (SWAT) in Samba versions
      3.0.x to 3.5.9 are affected by a cross-site request forgery.

   o  CVE-2011-2694:
      The Samba Web Administration Tool (SWAT) in Samba versions
      3.0.x to 3.5.9 are affected by a cross-site scripting
      vulnerability.

   Please note that SWAT must be enabled in order for these
   vulnerabilities to be exploitable. By default, SWAT
   is *not* enabled on a Samba install.

   Changes since 3.3.15
   --------------------

   o   Kai Blin <kai@samba.org>
       * BUG 8289: SWAT contains a cross-site scripting vulnerability.
       * BUG 8290: CSRF vulnerability in SWAT.

12 years agoPullup ticket #3478 - requested by taca
sbd [Wed, 27 Jul 2011 06:37:42 +0000 (06:37 +0000)]
Pullup ticket #3478 - requested by taca
net/samba35 security update.

Revisions pulled up:
- net/samba35/Makefile                                          1.8
- net/samba35/distinfo                                          1.5

---
   Module Name: pkgsrc
   Committed By: taca
   Date: Wed Jul 27 00:52:20 UTC 2011

   Modified Files:
    pkgsrc/net/samba35: Makefile distinfo

   Log Message:
   Update samba35 pacakge to 3.5.10; security fix for swat.

                      ==============================
                      Release Notes for Samba 3.5.10
       July 26, 2011
                      ==============================

   This is a security release in order to address
   CVE-2011-2522 (Cross-Site Request Forgery in SWAT) and
   CVE-2011-2694 (Cross-Site Scripting vulnerability in SWAT).

   o  CVE-2011-2522:
      The Samba Web Administration Tool (SWAT) in Samba versions
      3.0.x to 3.5.9 are affected by a cross-site request forgery.

   o  CVE-2011-2694:
      The Samba Web Administration Tool (SWAT) in Samba versions
      3.0.x to 3.5.9 are affected by a cross-site scripting
      vulnerability.

   Please note that SWAT must be enabled in order for these
   vulnerabilities to be exploitable. By default, SWAT
   is *not* enabled on a Samba install.

   Changes since 3.5.9:
   --------------------

   o   Kai Blin <kai@samba.org>
       * BUG 8289: SWAT contains a cross-site scripting vulnerability.
       * BUG 8290: CSRF vulnerability in SWAT.

12 years agoRepo copy files
repo-copy [Mon, 25 Jul 2011 13:52:02 +0000 (13:52 +0000)]
Repo copy files

12 years agoPullup ticket #3477
sbd [Thu, 21 Jul 2011 04:29:04 +0000 (04:29 +0000)]
Pullup ticket #3477

12 years agoPullup ticket #3477 - requested by tez
sbd [Thu, 21 Jul 2011 04:24:07 +0000 (04:24 +0000)]
Pullup ticket #3477 - requested by tez
textproc/groff security fix

Revisions pulled up:
- textproc/groff/Makefile                                       1.58
- textproc/groff/distinfo                                       1.15
- textproc/groff/patches/patch-config.guess                     1.1
- textproc/groff/patches/patch-configure                        1.1
- textproc/groff/patches/patch-contrib_eqn2graph_eqn2graph.sh   1.1
- textproc/groff/patches/patch-contrib_gdiffmk_tests_runtests.in 1.1
- textproc/groff/patches/patch-contrib_grap2graph_grap2graph.sh 1.1
- textproc/groff/patches/patch-contrib_groffer_perl_groffer.pl  1.1
- textproc/groff/patches/patch-contrib_groffer_perl_roff2.pl    1.1
- textproc/groff/patches/patch-contrib_pdfmark_pdfroff.man      1.1
- textproc/groff/patches/patch-contrib_pdfmark_pdfroff.sh       1.1
- textproc/groff/patches/patch-contrib_pic2graph_pic2graph.sh   1.1
- textproc/groff/patches/patch-doc_fixinfo.sh                   1.1
- textproc/groff/patches/patch-doc_groff.info-2                 1.1
- textproc/groff/patches/patch-gendef.sh                        1.1
- textproc/groff/patches/patch-src_roff_groff_pipeline.c        1.1

---
   Module Name:    pkgsrc
   Committed By:   tez
   Date:           Tue Jul 19 21:09:40 UTC 2011

   Modified Files:
           pkgsrc/textproc/groff: Makefile distinfo
   Added Files:
           pkgsrc/textproc/groff/patches: patch-config.guess patch-configure
               patch-contrib_eqn2graph_eqn2graph.sh
               patch-contrib_gdiffmk_tests_runtests.in
               patch-contrib_grap2graph_grap2graph.sh
               patch-contrib_groffer_perl_groffer.pl
               patch-contrib_groffer_perl_roff2.pl
               patch-contrib_pdfmark_pdfroff.man patch-contrib_pdfmark_pdfroff.sh
               patch-contrib_pic2graph_pic2graph.sh patch-doc_fixinfo.sh
               patch-doc_groff.info-2 patch-gendef.sh
               patch-src_roff_groff_pipeline.c

   Log Message:
   Fix many temporary file handling issues, including in pdfroff
   (resolves CVE-2009-5044 / SA44999)
   Patches copied from:

   http://cvsweb.openwall.com/cgi/cvsweb.cgi/Owl/packages/groff/groff-1.20.1-owl-tmp.diff?rev=1.2
   Modified for pkgsrc and excluded a documentaion change to doc/groff.texinfo
   that changes a `makeinfo' is too old warning into a fatal error.

   Added patch to make pdfroff.sh use -dSAFER
   See http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=538338 for details.

12 years agopullup #3476
spz [Wed, 20 Jul 2011 02:38:29 +0000 (02:38 +0000)]
pullup #3476

12 years agoPullup ticket #3476 - requested by tron
spz [Wed, 20 Jul 2011 02:36:13 +0000 (02:36 +0000)]
Pullup ticket #3476 - requested by tron
net/wireshark: security update

Revisions pulled up:
- net/wireshark/Makefile                                        1.66
- net/wireshark/distinfo                                        1.46

-------------------------------------------------------------------
   Module Name: pkgsrc
   Committed By: tron
   Date: Tue Jul 19 21:29:53 UTC 2011

   Modified Files:
    pkgsrc/net/wireshark: Makefile distinfo

   Log Message:
   Update "wireshark" package to version 1.4.8. Changes since 1.4.7:
   - Bug Fixes
     - The following vulnerabilities have been fixed. See the security
       advisory for details and a workaround.
        o The Lucent/Ascend file parser was susceptible to an infinite
          loop.
          Versions affected: 1.2.0 to 1.2.17, 1.4.0 to 1.4.7, and 1.6.0.
          CVE-2011-2597
        o The ANSI MAP dissector was susceptible to an infinite loop.
          (Bug 6044)
          Versions affected: 1.4.0 to 1.4.7, and 1.6.0.
          CVE-2011-????
     - The following bugs have been fixed:
        o TCP dissector doesn't decode TCP segments of length 1. (Bug
          4716)
        o Wireshark 1.4.0rc1 and python - spurious message. (Bug 4878)
        o Missing LUA function. (Bug 5006)
        o Lua API description about creating a new Tvb from a bytearray
          is not correct in wireshark's user guide. (Bug 5199)
        o sflow decode error for some extended formats. (Bug 5379)
        o White space in protocol field abbreviation causes runtime
          failure while registering Lua dissector. (Bug 5569)
        o "File not found" box uses wrong filename encoding. (Bug 5715)
        o capinfos: #ifdef HAVE_LIBGCRYPT block includes a line too
          many. (Bug 5803)
        o Wireshark crashes if Lua contains "Pref.range()" with missing
          arguments. (Bug 5895)
        o The "range" field in Lua's "Pref.range()" serves as default
          while the "default" field does nothing. (Bug 5896)
        o Wireshark crashes when calling TreeItem:set_len() on TreeItem
          without tvb. (Bug 5941)
        o TvbRange_string(lua_State* L) call a wrong function. (Bug
          5960)
        o VoIP call flow graph displays BICC APM as a BICC ANM. (Bug
          5966)
        o H323 rate multiplier wrong. (Bug 6009)
        o tshark crashes when loading Lua script that contains GUI
          function. (Bug 6018)
        o 802.11 Disassociation Packet's "Reason Code" field is
          imprecisely decoded/described. (Bug 6022)
        o Wireshark crashes when setting custom column's field name with
          conditional. (Bug 6028)
        o GTS Descriptor count limited to 3 instead of 7. (Bug 6055)
        o The SSL dissector can not resemble correctly the frames after
          TCP zero window probe packet. (Bug 6059)
        o Packet parser takes too long for this trace. (Bug 6073)
        o 802.11 Association Response Packet's "Status Code" field is
          imprecisely decoded/described. (Bug 6093)
        o Wireshark 1.6.0 and Python support: installer fails to create
          the wspy_dissectors subdirectory and . (Bug 6110)
        o Wireshark crash during RTP stream analysis. (Bug 6120)
        o Tshark custom columns: Why don't I get an error message? (Bug
          6131)
   - Updated Protocol Support
     ANSI MAP, GIOP, H.323, IEEE 802.11, MSRP, RPCAP, sFlow, TCP,
   - New and Updated Capture File Support
     Lucent/Ascend.

   To generate a diff of this commit:
   cvs rdiff -u -r1.65 -r1.66 pkgsrc/net/wireshark/Makefile
   cvs rdiff -u -r1.45 -r1.46 pkgsrc/net/wireshark/distinfo

12 years agopullup #3474
spz [Sat, 16 Jul 2011 21:13:32 +0000 (21:13 +0000)]
pullup #3474

12 years agoPullup ticket #3474 - requested by drochner
spz [Sat, 16 Jul 2011 21:11:49 +0000 (21:11 +0000)]
Pullup ticket #3474 - requested by drochner
print/foomatic4-filters: security patch

Revisions pulled up:
- print/foomatic4-filters/Makefile                              1.10
- print/foomatic4-filters/distinfo                              1.4
- print/foomatic4-filters/patches/patch-ac                      1.2

-------------------------------------------------------------------
   Module Name:    pkgsrc
   Committed By:   drochner
   Date:           Wed Jul 13 19:58:54 UTC 2011

   Modified Files:
           pkgsrc/print/foomatic4-filters: Makefile distinfo
           pkgsrc/print/foomatic4-filters/patches: patch-ac

   Log Message:
   add a patch from Suse bug #698451 (which is said there to originate
   from upstream but I couldn't locate it) to fix possible injection
   of shell commands in print requests which would be executed as
   the "lp" user
   bump PKGREV

   To generate a diff of this commit:
   cvs rdiff -u -r1.9 -r1.10 pkgsrc/print/foomatic4-filters/Makefile
   cvs rdiff -u -r1.3 -r1.4 pkgsrc/print/foomatic4-filters/distinfo
   cvs rdiff -u -r1.1.1.1 -r1.2 pkgsrc/print/foomatic4-filters/patches/patch-ac

12 years agoUpdated package numbers from spz (Thanks, Petra!)
agc [Wed, 13 Jul 2011 19:25:24 +0000 (19:25 +0000)]
Updated package numbers from spz (Thanks, Petra!)

12 years agoPullup ticket #3472.
tron [Wed, 13 Jul 2011 19:10:45 +0000 (19:10 +0000)]
Pullup ticket #3472.

12 years agoPullup ticket #3472 - requested by taca
tron [Wed, 13 Jul 2011 19:09:16 +0000 (19:09 +0000)]
Pullup ticket #3472 - requested by taca
mail/squirrelmail: security update

Revisions pulled up:
- mail/squirrelmail/MESSAGE                                     1.6
- mail/squirrelmail/Makefile                                    1.117-1.118
- mail/squirrelmail/PLIST                                       1.38
- mail/squirrelmail/distinfo                                    1.61

---
   Module Name: pkgsrc
   Committed By: taca
   Date: Wed Jul 13 01:30:34 UTC 2011

   Modified Files:
    pkgsrc/mail/squirrelmail: Makefile

   Log Message:
   take MAINTAINER.

---
   Module Name: pkgsrc
   Committed By: taca
   Date: Wed Jul 13 12:22:44 UTC 2011

   Modified Files:
    pkgsrc/mail/squirrelmail: MESSAGE Makefile PLIST distinfo

   Log Message:
   Update squirrelmail package to 1.4.22.

   Version 1.4.22 - 12 July 2011
   -----------------------------
     - Backported default timezone fix from version 1.5.2; helps mitigate
       timezone errors in environments where a default has not been set
       by the administrator.
     - Fixed system lock-ups caused by a combination of certain rare,
       malformed message headers and buggy versions of PHP mbstring
       (#3053349).
     - Now allow multiple plugins to handle (add links for) a single
       attachment MIME type.
     - Now allow administrators to disable all plugins or enable just
       a select few plugins (overriding the active plugins in the normal
       configuration) by setting $temporary_plugins as an empty array
       (all disabled) or an array with one or more plugin directory names
       in config_local.php.
     - Backport fix for call_user_func_array not supporting NULL as empty
       array in PHP 5.3.3
     - Fixed sqauth_read_password() for plugins on the login_verified hook.
     - Added SMTP SASL PLAIN authentication option to configuration tool
       (core support for such is not new).
     - Gmail doens't support standard search commands; removed sort buttons.
     - Forced addition of a file suffix to attachments that lack a filename
       (helps forwarded messages avoid spam filters) (thanks to Petr
       Kletecka) (#3139004).
     - Fixed missing security token in listcommands plugin.
     - Added smtp_auth hook (thanks to Emmanuel Dreyfus).
     - Made speed enhancements to threaded message display (thanks to Siim
       Poder) (#3288123).
     - Allow administrators to configure subfolders of user INBOXes to be
       treated as special folders by adding $subfolders_of_inbox_are_special
       to config_local.php.
     - Fixed incorrect display of INBOX subfolders under some configurations.
       IMPORTANT: You may need to update your configuration so that
       $default_sub_of_inbox is TRUE if it was FALSE (e.g., Courier IMAP users)
       and after updating to this version, your special folders are no longer
       listed at the top of your folder list.  Also, if this change prevents
       users from logging in with an error such as "ERROR: Could not complete
       request.  Query: CREATE "Trash" Reason Given: Invalid mailbox name.",
       you will need to correct the user preference values for the problem
       folders.  You can do so with commands such as the following for file-
       based preferences (adjust the data directory location as needed):
           find /var/lib/squirrelmail/data/ -name *.pref -exec sed --in-place 's/trash_folder=Trash/trash_folder=INBOX.Trash/g' {} \;
           find /var/lib/squirrelmail/data/ -name *.pref -exec sed --in-place 's/trash_folder=Drafts/trash_folder=INBOX.Drafts/g' {} \;
           find /var/lib/squirrelmail/data/ -name *.pref -exec sed --in-place 's/trash_folder=Sent/trash_folder=INBOX.Sent/g' {} \;
       Or, for database-based preferences:
           UPDATE userprefs SET prefval = 'INBOX.Trash' WHERE prefkey = 'trash_folder' AND prefval = 'Trash';
           UPDATE userprefs SET prefval = 'INBOX.Drafts' WHERE prefkey = 'draft_folder' AND prefval = 'Drafts';
           UPDATE userprefs SET prefval = 'INBOX.Sent' WHERE prefkey = 'sent_folder' AND prefval = 'Sent';
       MAKE SURE to back up your user preferences first!
     - Optimized message highlighting rules; faster message list display
       and faster highlight rules management (thanks to C. Bensend for
       extensive effort helping diagnose)
     - New Mail plugin no longer removes normal organization title when
       putting the number of new messages in the browser title
     - Added clickjacking protection (thanks to Asbjorn Thorsen and Geir
       Hansen for bringing this to our attention). [CVE-2010-4554]
     - Fixed XSS holes in generic options inputs, XSS hole in the SquirrelSpell
       plugin, XSS hole in the Index Order page, and added anti-CSRF protection
       to the empty trash feature and the Index Order page (thanks to Nicholas
       Carlini for finding all these issues). [CVE-2010-4555]
     - Fixed XSS problem with unsanitized style tags in messages. [CVE-2011-2023]

12 years agoPullup ticket #3471.
tron [Tue, 12 Jul 2011 10:59:53 +0000 (10:59 +0000)]
Pullup ticket #3471.

12 years agoPullup ticket #3471 - requested by morr
tron [Tue, 12 Jul 2011 10:58:47 +0000 (10:58 +0000)]
Pullup ticket #3471 - requested by morr
www/wordpress: security update

Revisions pulled up:
- www/wordpress/Makefile                                        1.20
- www/wordpress/PLIST                                           1.9
- www/wordpress/distinfo                                        1.16

---
   Module Name: pkgsrc
   Committed By: morr
   Date: Mon Jul 11 22:53:50 UTC 2011

   Modified Files:
    pkgsrc/www/wordpress: Makefile PLIST distinfo

   Log Message:
   Update to newest version - 3.2.

   Highlights:

   * Refreshed Administrative UI - Admin redesign
   * New Default Theme "Twenty Eleven" - Uses the latest Theme Features
   * Full Screen Editor - Distraction free writing experience
   * Extended Admin Bar - More useful links to control the site

   * Enhanced Browser Compatibility -
     - Drop Internet Explorer 6 support
     - Start End-of-life (EOL) cycle for Internet Explorer 7
     - Browse Happy notify users of out-of-date browser

   * WordPress is Faster and Lighter -
     - Faster page loads -- We've gone through the most commonly loaded
     pages in WP and done improvements to their load time
     - Faster Upgrades -- The update system now support incremental
     upgrades so after 3.2 you'll find upgrading faster than ever
     - Optimizations to WP_Filesystem -- Updates over FTP are now much
     quicker and less error prone
     - Stream downloads to the filesystem -- Improves update times and
     lowers the memory footprint
     - Performance improvements for wptexturize()
     - Remove PHP4 compatibility including timezone support
     - More efficient term intersection queries
     - Some optimizations in the HTML sanitizer (kses)
     - Speed optimizations for is_serialized_string()
     - Cache the Dashboard RSS Widgets HTML output to reduce unnecessary
     Ajax requests as well as the memory footprint
     - And many other improvements and tweaks

   Contains also security fixes from wordpress 3.1.4.

12 years agoPullup ticket #3469.
tron [Mon, 11 Jul 2011 07:47:28 +0000 (07:47 +0000)]
Pullup ticket #3469.

12 years agoPullup ticket #3469 - requested by bsiegert
tron [Mon, 11 Jul 2011 07:47:02 +0000 (07:47 +0000)]
Pullup ticket #3469 - requested by bsiegert
devel/gmake: portability fix

Revisions pulled up:
- devel/gmake/Makefile                                          1.78

---
   Module Name:    pkgsrc
   Committed By:   bsiegert
   Date:           Sat Jul  9 16:25:35 UTC 2011

   Modified Files:
          pkgsrc/devel/gmake: Makefile

   Log Message:
   Do not use strndup on MirBSD, it used to be broken. Fixes lots of
   "mysterious" build failures on MirBSD.

   Reviewed by agc and joerg.

12 years agopullup #3468
spz [Sun, 10 Jul 2011 13:07:02 +0000 (13:07 +0000)]
pullup #3468

12 years agoPullup ticket #3468 - requested by mspo
spz [Sat, 9 Jul 2011 21:34:19 +0000 (21:34 +0000)]
Pullup ticket #3468 - requested by mspo
chat/bitlbee build fix

Revisions pulled up:
- chat/bitlbee/Makefile                                         1.52-1.53
- chat/bitlbee/distinfo                                         1.27

-------------------------------------------------------------------
   Module Name:    pkgsrc
   Committed By:   mspo
   Date:           Sat Jul  9 11:13:21 UTC 2011

   Modified Files:
           pkgsrc/chat/bitlbee: Makefile distinfo

   Log Message:
   Version 3.0.3:
   - Fixed Twitter compatibility. (The API call used to get the following list
     was deprecated.)
   - Twitter: Enable the show_ids setting to assign a two-digit short ID to
     recent tweets to use for retweets and replies (so you can RT/reply to more
     than just a person's last message).
   - Some other Twitter fixes/improvements.
   - "otr reconnect" command and some other fixes.
   - GnuTLS 2.12 compatibility fix.
   - Include "FLOOD=0/9999" in the 005/ISUPPORT line at login to hint the IRC
     client that rate limiting is not required. (Next step: Get IRC clients to
     parse it.)
   - Other stuff too small to mention.

   Finished 2 Jun 2011

   Version 3.0.2:
   - Fixed MSN login issues with @msn.com accounts.
   - /CTCP support: You can CTCP VERSION Jabber contacts, and CTCP NUDGE MSN
     contacts. More may come later, ideas are welcome.
   - By default, leave Twitter turned on for libpurple builds.
   - Allow using /OPER to identify/register as well. (Password security hack.)
   - Fixed proxy support with libpurple.
   - Some minor changes/fixes.

   To generate a diff of this commit:
   cvs rdiff -u -r1.51 -r1.52 pkgsrc/chat/bitlbee/Makefile
   cvs rdiff -u -r1.26 -r1.27 pkgsrc/chat/bitlbee/distinfo

-------------------------------------------------------------------
   Module Name:    pkgsrc
   Committed By:   drochner
   Date:           Sat Jul  9 13:37:51 UTC 2011

   Modified Files:
           pkgsrc/chat/bitlbee: Makefile

   Log Message:
   depend on libgcrypt explicitely
   (gnutls used to pull it in for us, but this will be cleaned up)

   To generate a diff of this commit:
   cvs rdiff -u -r1.52 -r1.53 pkgsrc/chat/bitlbee/Makefile

12 years agoAdd a file to record changes on the pkgsrc-2011Q2 branch
agc [Fri, 8 Jul 2011 08:21:50 +0000 (08:21 +0000)]
Add a file to record changes on the pkgsrc-2011Q2 branch

12 years agoRemoving files not present on branch pkgsrc-2011Q2:
branch-fixup [Fri, 8 Jul 2011 07:29:07 +0000 (07:29 +0000)]
Removing files not present on branch pkgsrc-2011Q2:
print/ted/files/README.ind
print/ted/files/md5
print/ted/patches/patch-aa
print/ted/pkg/COMMENT
print/ted/pkg/DESCR
print/ted/pkg/MESSAGE
print/ted/pkg/PLIST

12 years agoUpdated www/ikiwiki to 3.20110707
schmonz [Fri, 8 Jul 2011 03:16:23 +0000 (03:16 +0000)]
Updated www/ikiwiki to 3.20110707

12 years agoUpdate to 3.20110707. From the changelog:
schmonz [Fri, 8 Jul 2011 03:16:12 +0000 (03:16 +0000)]
Update to 3.20110707. From the changelog:

* userlist: New plugin, lets admins see a list of users and their info.
* aggregate: Improve checking for too long aggregated filenames.
* Updated to jQuery 1.6.1.
* attachment: Speed up multiple file uploads by storing uploaded files
  in a staging area until the page is saved/previewed, rather than
  refreshing the site after each upload.
  (Sponsored by The TOVA Company.)
* attachment: Files can be dragged into the edit page to upload them.
  Multiple file batch upload support. Upload progress bars.
  AJAX special effects. Impemented using the jQuery-File-Upload widget.
  (If you don't have javascript don't worry, I kept that working too.)
  (Sponsored by The TOVA Company.)
* Add libtext-multimarkdown-perl to Suggests. Closes: #630705
* headinganchors: Plugin by Paul Wise that adds ids to <hn> headings.
* html5 is not experimental anymore. But not the default either, quite yet.
* Support svg as a inlinable image type; svg images can be included on a
  page by simply linking to them, or by using the img directive.
  Note that sanitizing svg files is still not addressed.
* img: Generate png format thumbnails for svg images.
* Preserve mixed case in page creation links, and when creating a page
  whose title is mixed case, allow selecting between the mixed case and
  all lower-case names.
* Fix ikiwiki-update-wikilist -r to actually work.
* comments: collect metadata in a scan-phase preprocess hook, which
  fixes sorting comments by date. (smcv)
* Run scan hooks for internal pages (preprocess hooks already run in scan
  mode) (smcv)
* inline: Handle obfuscated urls, such as the mailto urls generated by
  markdown when forcing urls absolute.
* Bugfix for wikilink containing an email address not showing up in
  brokenlinks list.
* Bugfix for trying to attach files to a subpage of the index page.

Updating this leaf package during the freeze for bugfix purposes.

12 years agoRepo copy files
repo-copy [Fri, 8 Jul 2011 01:45:20 +0000 (01:45 +0000)]
Repo copy files

12 years agoFixup fromcvs/togit conversion
pkgsrc fixup [Fri, 8 Jul 2011 01:45:19 +0000 (18:45 -0700)]
Fixup fromcvs/togit conversion

12 years agoRepo copy files
repo-copy [Thu, 7 Jul 2011 21:13:11 +0000 (21:13 +0000)]
Repo copy files

12 years agoFixup fromcvs/togit conversion
pkgsrc fixup [Thu, 7 Jul 2011 21:13:10 +0000 (14:13 -0700)]
Fixup fromcvs/togit conversion

12 years agoadd an "upcoming retirals" section and add obache's list of
drochner [Thu, 7 Jul 2011 19:38:13 +0000 (19:38 +0000)]
add an "upcoming retirals" section and add obache's list of
useless pkgs

12 years agoMake sure that PYDISTUTILS_CREATES_EGGFILES is defined in all branches.
joerg [Thu, 7 Jul 2011 18:46:32 +0000 (18:46 +0000)]
Make sure that PYDISTUTILS_CREATES_EGGFILES is defined in all branches.

12 years agoavoid sign extension on right shift
drochner [Thu, 7 Jul 2011 17:02:12 +0000 (17:02 +0000)]
avoid sign extension on right shift
(there are more occurences, but they are followed by checks for result<0)
bump PKGREV

12 years agoRepo copy files
repo-copy [Thu, 7 Jul 2011 14:09:43 +0000 (14:09 +0000)]
Repo copy files

12 years agoFixup fromcvs/togit conversion
pkgsrc fixup [Thu, 7 Jul 2011 14:09:42 +0000 (07:09 -0700)]
Fixup fromcvs/togit conversion

12 years agoUse MACHINE_ARCH instead of MACHENE_GNU_ARCH, it may i?38 for i386.
obache [Thu, 7 Jul 2011 12:26:45 +0000 (12:26 +0000)]
Use MACHINE_ARCH instead of MACHENE_GNU_ARCH, it may i?38 for i386.

12 years agofixes build with curl>=7.21.7.
obache [Thu, 7 Jul 2011 11:46:31 +0000 (11:46 +0000)]
fixes build with curl>=7.21.7.

12 years agoAdd a hacks file to drop user-supplied -march values on GCC<4.4 i386.
tnn [Thu, 7 Jul 2011 11:04:35 +0000 (11:04 +0000)]
Add a hacks file to drop user-supplied -march values on GCC<4.4 i386.
Workaround for PR pkg/44912: gcc generates unaliged SSE2 references.

12 years agoUpdated net/sendfile to 2.1bnb1
mspo [Thu, 7 Jul 2011 03:07:08 +0000 (03:07 +0000)]
Updated net/sendfile to 2.1bnb1

12 years agoadding DIST_SUBDIR and PKGREVISION since the package has changed but distinfo and...
mspo [Thu, 7 Jul 2011 03:06:24 +0000 (03:06 +0000)]
adding DIST_SUBDIR and PKGREVISION since the package has changed but distinfo and version have not

12 years agoRepo copy files
repo-copy [Thu, 7 Jul 2011 01:45:08 +0000 (01:45 +0000)]
Repo copy files

12 years agoFixup fromcvs/togit conversion
pkgsrc fixup [Thu, 7 Jul 2011 01:45:07 +0000 (18:45 -0700)]
Fixup fromcvs/togit conversion

12 years agopropagate dependency on libXext (was introduced in the last update)
drochner [Wed, 6 Jul 2011 20:21:03 +0000 (20:21 +0000)]
propagate dependency on libXext (was introduced in the last update)

12 years agoRepo copy files
repo-copy [Wed, 6 Jul 2011 19:46:50 +0000 (19:46 +0000)]
Repo copy files

12 years agoFixup fromcvs/togit conversion
pkgsrc fixup [Wed, 6 Jul 2011 19:46:49 +0000 (12:46 -0700)]
Fixup fromcvs/togit conversion

12 years agoRepo copy files
repo-copy [Wed, 6 Jul 2011 15:16:04 +0000 (15:16 +0000)]
Repo copy files

12 years agoFixup fromcvs/togit conversion
pkgsrc fixup [Wed, 6 Jul 2011 15:16:03 +0000 (08:16 -0700)]
Fixup fromcvs/togit conversion

12 years agoUpdated devel/papaya to 0.1.7nb7
obache [Wed, 6 Jul 2011 13:18:01 +0000 (13:18 +0000)]
Updated devel/papaya to 0.1.7nb7

12 years ago* remove a redundant link in texinfo file.
obache [Wed, 6 Jul 2011 13:17:46 +0000 (13:17 +0000)]
* remove a redundant link in texinfo file.
* fixes build with texi2html-5.

Bump PKGREVISION, number of generated html files changed.

12 years agoUpdates confirmed from upstream:
mspo [Wed, 6 Jul 2011 11:31:58 +0000 (11:31 +0000)]
Updates confirmed from upstream:
frmstag@fex:~/sendfile/sendfile-2.1b/doc: head ChangeLog
2011-06-04  better POSIX compatibility and NETBSD support

12 years agoUpdated mail/cyrus-imapd24 to 2.4.10
obache [Wed, 6 Jul 2011 09:46:05 +0000 (09:46 +0000)]
Updated mail/cyrus-imapd24 to 2.4.10

12 years agoUpdate cyrus-imapd24 to 2.4.10.
obache [Wed, 6 Jul 2011 09:45:45 +0000 (09:45 +0000)]
Update cyrus-imapd24 to 2.4.10.

While here,
* Exactly enable/disable PCRE support with package option, enabled by default.
* Add workaround patches for PR#44275, sizeof(time_t) > sizeof(unsigned long).

Changes to the Cyrus IMAP Server since 2.4.9

      * fixed handling of unparsable emails during append (which would
        cause invalid cyrus.index records otherwise)
      * quota: fix a pile of bugs. #1801, virtdomain support; #2728, slow
        user delete; #3178, "file name too long" with big mailbox names;
        #3179, quota -f doubles usage.
      * Bug #3043 - parse multiple groups in headers correctly
      * Bug #3158 - lmtp backend connection timeout
      * Bug #3223 - limit MIME parsing depth to avoid stack overflows
      * Bug #3273 - add SORT=DISPLAY support (but note: still questions
        about correctness of unicode sorting)
      * Bug #3504 - convert all sieve scripts to \r\n line endings on
        upload
      * Bug #3402 - options to munge 8bit characters in headers during lmtp
        delivery to avoid backscatter
      * sync_client: fix broken keepalive TCP options (I doubt anyone ever
        tried to use it)
      * Bug #3482 - add "-o" option to ipurge to only purge messages with
        \Deleted flag set

12 years agoDon't compile those functions when using slang - they're not needed
is [Wed, 6 Jul 2011 06:24:38 +0000 (06:24 +0000)]
Don't compile those functions when using slang - they're not needed
and using an in this case undefined helper function.

12 years agoRepo copy files
repo-copy [Wed, 6 Jul 2011 01:45:54 +0000 (01:45 +0000)]
Repo copy files

12 years agoFixup fromcvs/togit conversion
pkgsrc fixup [Wed, 6 Jul 2011 01:45:53 +0000 (18:45 -0700)]
Fixup fromcvs/togit conversion

12 years agoRepo copy files
repo-copy [Tue, 5 Jul 2011 20:04:23 +0000 (20:04 +0000)]
Repo copy files

12 years agoFixup fromcvs/togit conversion
pkgsrc fixup [Tue, 5 Jul 2011 20:04:22 +0000 (13:04 -0700)]
Fixup fromcvs/togit conversion

12 years agoUpdated net/rabbitmq to 2.5.1
mspo [Tue, 5 Jul 2011 17:10:09 +0000 (17:10 +0000)]
Updated net/rabbitmq to 2.5.1

12 years agoupdate some numbers, add some markup about them
agc [Tue, 5 Jul 2011 16:48:18 +0000 (16:48 +0000)]
update some numbers, add some markup about them

12 years agostuff from yesterday
dholland [Tue, 5 Jul 2011 16:31:54 +0000 (16:31 +0000)]
stuff from yesterday

12 years agoAdd initial information for the pkgsrc-2011Q2 branch.
agc [Tue, 5 Jul 2011 16:06:47 +0000 (16:06 +0000)]
Add initial information for the pkgsrc-2011Q2 branch.

12 years agoAdd a patch to remove a non-standard option to cp;
schnoebe [Tue, 5 Jul 2011 15:06:28 +0000 (15:06 +0000)]
Add a patch to remove a non-standard option to cp;
Added a LICENSE clause to the Makefile.

12 years agoNote update of net/bind96 package to 9.6.3.1.ESV.4pl3.
taca [Tue, 5 Jul 2011 14:29:16 +0000 (14:29 +0000)]
Note update of net/bind96 package to 9.6.3.1.ESV.4pl3.

12 years agoUpdate bind96 package to 9.6.3.1.ESV.4pl3 (9.6-ESV-R4-P3), security release.
taca [Tue, 5 Jul 2011 14:28:06 +0000 (14:28 +0000)]
Update bind96 package to 9.6.3.1.ESV.4pl3 (9.6-ESV-R4-P3), security release.

The package name was selected as:

- Make sure to greater version from bind-9.6.3.
- Include "ESV" (Extended Support Version) string.

Since changes from BIND 9.6.3 are too may, please refer changes in detail:

ftp://ftp.isc.org/isc/bind/9.6-ESV-R4/CHANGES
ftp://ftp.isc.org/isc/bind/9.6-ESV-R4-P1/RELEASE-NOTES-BIND-9.6-ESV-R4-P1.html
ftp://ftp.isc.org/isc/bind/9.6-ESV-R4-P3/RELEASE-NOTES-BIND-9.6-ESV-R4-P3.html

12 years agoNote update of net/bind97 package to 9.7.3pl3.
taca [Tue, 5 Jul 2011 13:57:19 +0000 (13:57 +0000)]
Note update of net/bind97 package to 9.7.3pl3.

12 years agoUpdate bind97 package to bind-9.7.3pl3 (9.7.3-P3), security release.
taca [Tue, 5 Jul 2011 13:56:35 +0000 (13:56 +0000)]
Update bind97 package to bind-9.7.3pl3 (9.7.3-P3), security release.

--- 9.7.3-P3 released ---

3124. [bug] Use an rdataset attribute flag to indicate
negative-cache records rather than using rrtype 0;
this will prevent problems when that rrtype is
used in actual DNS packets.  [RT #24777]

--- 9.7.3-P2 released (withdrawn) ---

3123. [security] Change #2912 exposed a latent flaw in
dns_rdataset_totext() that could cause named to
crash with an assertion failure. [RT #24777]

12 years ago+ net-snmp-5.7, squid-3.1.13.
taca [Tue, 5 Jul 2011 13:36:57 +0000 (13:36 +0000)]
+ net-snmp-5.7, squid-3.1.13.

12 years agoNote update of net/bind98 package to 9.8.0pl4.
taca [Tue, 5 Jul 2011 13:36:21 +0000 (13:36 +0000)]
Note update of net/bind98 package to 9.8.0pl4.