Commit Graph

472347 Commits

Author SHA1 Message Date
Thomas Zander
ccc5d2337c MFH: r504636
Update to upstream release 3.0.7.1; Makefile fixes

Details:
- Update to newest upstream release 3.0.7.1
- Fix drive-by dependencies, reported in [1]
- Introduce new options for JPEG and OGGSPOTS [1]

PR:		238261 [1]
Reported by:	phascolarctos@protonmail.ch [1]

Approved by:	ports-secteam (riggs)
2019-06-20 16:29:09 +00:00
Christoph Moench-Tegeder
d3eaa5435e MFH: r504642
mail/thunderbird: update to 60.7.2 (rc1)

Release Notes (soon): https://www.thunderbird.net/en-US/thunderbird/60.7.2/releasenotes/

Approved by:	gecko@ (jbeich@, implicit)

Approved by:	portmgr (blanket: web browser alike)
2019-06-20 16:21:13 +00:00
Christoph Moench-Tegeder
6e5182fca2 MFH: r504640
www/firefox-esr: update to 60.7.2

Release Notes: https://www.mozilla.org/en-US/firefox/60.7.2/releasenotes/

Approved by:	gecko@ (jbeich@, implicit)

Approved by:	portmgr (blanket: web browser)
2019-06-20 16:18:16 +00:00
Christoph Moench-Tegeder
7e8391374f MFH: r504638
www/firefox: update to 67.0.4

Release Notes: https://www.mozilla.org/en-US/firefox/67.0.4/releasenotes/

PR:		236651
Approved by:	gecko@ (jbeich@, implicit)

Approved by:	portmgr (blanket: web browser)
2019-06-20 16:15:31 +00:00
Mathieu Arnold
f7c8eda317 MFH: r503380
Fix build with DNSTAP enabled.

PR:		238036
Reported by:	Artyom Davidov
Pointy hat:	mat, forgotten in the previous commit.
2019-06-19 22:58:48 +00:00
Mathieu Arnold
7831c2a97e Update to 9.11.8 and 9.14.3.
Security:	CVE-2019-6471
2019-06-19 22:46:46 +00:00
Brooks Davis
a155c6e389 MFH: r504435 r504436
Fix a bug when ${PREFIX} != /usr/local.[0]

As of LLVM 8.0.1, pre-releases have moved to github.  Chase this change.

PR:		238603 [0]
Submitted by:	mi [0]

Revert accidental update to distinfo.

Reported by:	Christoph Moench-Tegeder <cmt@burggraben.net>

Approved by:	portmgr (blanket fixes)
2019-06-18 17:46:41 +00:00
Dmitry Marakasov
e765f05a9e MFH: r504481
- Add missing depend for ancient python versions

PR:		238503
Submitted by:	john@saltant.com
Approved by:	ports-secteam (with hat)
2019-06-18 12:42:05 +00:00
Jan Beich
c346d88f1d MFH: r504472
www/firefox-esr: update to 60.7.1

Changes:	https://www.mozilla.org/firefox/60.7.1/releasenotes/
Approved by:	ports-secteam blanket
2019-06-18 10:14:08 +00:00
Jan Beich
5673fdd196 MFH: r504471
www/firefox: update to 67.0.3

Changes:	https://www.mozilla.org/firefox/67.0.3/releasenotes/
PR:		236651
Approved by:	ports-secteam blanket
2019-06-18 10:13:32 +00:00
Jan Beich
3e5caf5a86 MFH: r504455
games/openbor: update to 7056

Changes:	68a1c977...6de201a4
Approved by:	ports-secteam (feld, implicit for snapshots)
2019-06-18 00:56:28 +00:00
Tobias Kortkamp
c037d8bebe MFH: r504270
graphics/netpbm: Update to 10.86.04

Changes:	https://gitlab.com/tobiask/netpbm/raw/v10.86.04/doc/HISTORY

Approved by:	ports-secteam blanket
2019-06-15 22:25:44 +00:00
Jan Beich
cb13f14681 MFH: r504218
games/openbor: update to 7045

Changes:	0afa1f0d...68a1c977
Approved by:	ports-secteam (feld, implicit for snapshots)
2019-06-15 00:53:27 +00:00
Glen Barber
851eae18c0 MFH: r504215
Add 11.3-RC1 MANIFEST files.
Remove 11.3-BETA2 MANIFEST files.

Approved by:	portmgr (implicit, re blanket)
Approved by:	bdrewery (maintainer, implicit, re blanket)
Sponsored by:	The FreeBSD Foundation
2019-06-14 23:20:34 +00:00
Matthew Seaman
6cb0707f35 MFH: r504158
Security update to 4.9.0.1

Security:	a5681027-8e03-11e9-85f4-6805ca0b3d42

Approved by:	ports-secteam (joneum)
2019-06-14 12:49:07 +00:00
Tobias Kortkamp
bf6b7ec6c7 MFH: r504176
databases/mantis: Update to 2.21.1

Changes:	https://mantisbt.org/bugs/changelog_page.php?project=mantisbt&version=2.21.1

Approved by:	ports-secteam blanket
2019-06-14 11:37:55 +00:00
Jan Beich
cde7c0f82b MFH: r504160
www/firefox: switch to system aom/dav1d

Obtained from:	upstream (via Gentoo)
Approved by:	ports-secteam blanket
2019-06-14 08:41:42 +00:00
Kai Knoblich
b9c8dd646a MFH: r504076
devel/py-apptools: Enable Python 3.x builds

* Support for Python 3 was introduced with 4.4.0
* Pet portlint (reduce the overall usage of lines in the pkg-descr and
  separate the USES block).
* No bump of PORTREVISION due style changes only.

PR:		238435
Submitted by:	vladimir.chukharev@gmail.com (maintainer)
Approved by:	ports-secteam (miwi)
2019-06-13 18:43:31 +00:00
Adam Weinberger
87ebbe5db3 Update vim to patchlevel 1365
This is a direct commit to 2019Q2. The version in head contains many
other changes that are intentionally being tested there before
showing up in quarterly.

Security:     CVE-2019-12735
Approved by:  portmgr (with hat)
2019-06-13 18:32:55 +00:00
Adam Weinberger
547c713f13 MFH: r502923 r502963
Update neovim to 0.3.6
Update neovim to 0.3.7

Security:    CVE-2019-12735
Approved by: portmgr (with hat)
2019-06-13 18:26:28 +00:00
Marc Fonvieille
092944259f MFH: r498480 r503830
Update to r52910 from the FreeBSD docset.

Approved by:	doceng (implicit)

Update to r53120 from the FreeBSD docset (a.k.a. 11.3-R version)

Approved by:	doceng (implicit)

Approved by:	portmgr (blanket)
2019-06-13 16:17:44 +00:00
Christoph Moench-Tegeder
0ac63d5e0b MFH: r504100
mail/thunderbird: update to 60.7.1 (rc1)

Release Notes (soon):
  https://www.thunderbird.net/en-US/thunderbird/60.7.1/releasenotes/

Approved by:	jbeich (gecko@, implicit)

Approved by:	portmgr (blanket: web browser lookalike)
2019-06-13 15:32:01 +00:00
Antoine Brodin
8324c7fb66 MFH: r504058
Mark BROKEN on FreeBSD 12 and 13

Traceback (most recent call last):
  File "scripts/python/make-dist.py", line 294, in <module>
    Setup(InstallRoot_CompilerWithPrevious, InstallRoot_CompilerWithSelf)
  File "scripts/python/make-dist.py", line 268, in Setup
    reload(pylib) or FatalError()
  File "/wrkdirs/usr/ports/lang/modula3/work/cm3-b2ce705/scripts/python/pylib.py", line 655, in <module>
    if Host.endswith("_NT") or Host == "NT386":
AttributeError: 'NoneType' object has no attribute 'endswith'

Reported by:	pkg-fallout
2019-06-13 05:43:47 +00:00
Jan Beich
390e0800a2 MFH: r503790 r503811
devel/libevent2: update to 2.1.10

Changes:	https://github.com/libevent/libevent/releases/tag/release-2.1.10-stable
ABI:		https://abi-laboratory.pro/tracker/timeline/libevent/
PR:		238127
Reported by:	GitHub (watch releases)
Tested by:	pkubaj (powerpc64)
Approved by:	maintainer timeout (2 weeks)
Approved by:	ports-secteam (miwi)
2019-06-13 00:47:22 +00:00
Jochen Neumeister
baebb1d2f5 MFH: r504029
Update to 1.8.21

Changelog: https://blog.mybb.com/2019/06/10/mybb-1-8-21-released-security-maintenance-release/

Security:	13960f55-8d35-11e9-9ba0-4c72b94353b5
Sponsored by:	Netzkommune GmbH

Approved by:	ports-secteam (joneum)
2019-06-12 17:20:24 +00:00
Jung-uk Kim
d2bea8fc0f MFH: r503990
Update to 32.0.0.207.

https://helpx.adobe.com/security/products/flash-player/apsb19-30.html

Approved by:	ports-secteam (blanket)
2019-06-11 21:05:08 +00:00
Mathieu Arnold
ebf3b1076b MFH: r503955
Fix named when using plugins and chroot.

BIND9 introduced plugins and migrated the filter-aaaa feature to a
plugin.
As it loads its plugins late in the startup process (read after chroot),
the plugins need to be available in the chroot.

Also, refactor the code now that a second directory need to be handled.

PR:		238011
Reported by:	ryan@timewasted.me
2019-06-11 12:19:40 +00:00
Torsten Zuehlsdorff
6be6ec9da1 MFH: r503194
lang/php72: Upgrade from 7.2.18 7.2.19

Changelog:

    EXIF:
        Fixed bug #77988 (heap-buffer-overflow on php_jpg_get16) (CVE-2019-11040).
    FPM:
        Fixed bug #77934 (php-fpm kill -USR2 not working).
        Fixed bug #77921 (static.php.net doesn't work anymore).
    GD:
        Fixed bug #77943 (imageantialias($image, false); does not work).
        Fixed bug #77973 (Uninitialized read in gdImageCreateFromXbm) (CVE-2019-11038).
    Iconv:
        Fixed bug #78069 (Out-of-bounds read in iconv.c:_php_iconv_mime_decode() due to integer overflow) (CVE-2019-11039).
    JSON:
        Fixed bug #77843 (Use after free with json serializer).
    Opcache:
        Fixed possible crashes, because of inconsistent PCRE cache and opcache SHM reset.
    PDO_MySQL:
        Fixed bug #77944 (Wrong meta pdo_type for bigint on LLP64).
    Reflection:
        Fixed bug #75186 (Inconsistent reflection of Closure:::__invoke()).
    Session:
        Fixed bug #77911 (Wrong warning for session.sid_bits_per_character).
    SPL:
        Fixed bug #77024 (SplFileObject::__toString() may return array).
    SQLite:
        Fixed bug #77967 (Bypassing open_basedir restrictions via file uris).

Changelog taken from: https://www.php.net/ChangeLog-7.php#7.2.19

MFC after:	2019Q2

Approved by:	ports-secteam (joneum)
2019-06-11 08:37:18 +00:00
Jan Beich
cdd50a1ff6 MFH: r503931
emulators/citra: update to s20190610

Changes:	75ebf1fdf...73bf92fb3
Approved by:	ports-secteam (swills, implicit for snapshots)
2019-06-11 00:52:07 +00:00
Richard Gallamore
7ff71f7d57 MFH: r503784 r503787
Bumped seahub version for init script to fix gunicorn binary name
Fix checksum due to retagged version

Change currently unused init var seahub_host so
there is no breakage for current users of seahub.

Change hard coded 0.0.0.0 for gunicorn start to
seahub_host.

PR:		237366 237367
Approved by:	ports-secteam (joneum)
2019-06-10 17:08:16 +00:00
Antoine Brodin
64a47d110e MFH: r503904
Mark BROKEN: unfetchable

Reported by:	pkg-fallout
2019-06-10 16:13:29 +00:00
Jochen Neumeister
6302c91556 MFH: r503887
Update to 3.2.7

Changelogs
 https://www.phpbb.com/community/viewtopic.php?f=14&t=2509941
 https://www.phpbb.com/community/viewtopic.php?f=14&t=2510666

Sponsored by:	Netzkommune GmbH

Approved by:	ports-secteam (joneum)
2019-06-10 10:38:13 +00:00
Jan Beich
f276d24d26 MFH: r503865
www/firefox: force rebuild after r503861

Approved by:	ports-secteam blanket
2019-06-10 00:29:04 +00:00
Jan Beich
cf3a68e7ee MFH: r503861
www/firefox: switch to rc2

Changes:	https://hg.mozilla.org/releases/mozilla-release/pushloghtml?startdate=2019-06-07&enddate=2019-06-09
PR:		236651
Approved by:	ports-secteam blanket
2019-06-10 00:27:04 +00:00
Thomas Zander
a6cae37a4a MFH: r503813
Update to upstream release 1.2.0

Approved by:	ports-secteam (riggs)
2019-06-09 11:42:03 +00:00
Jan Beich
481e7159f0 MFH: r503766
emulators/citra: update to s20190608

Changes:	46b015bef...75ebf1fdf
Approved by:	ports-secteam (swills, implicit for snapshots)
2019-06-09 00:33:44 +00:00
Jochen Neumeister
55c90df9db MFH: r503762
Update to 7.67

Changelog:
 https://www.drupal.org/SA-CORE-2019-007
 https://www.drupal.org/project/drupal/releases/7.67

Security:	9b8a52fc-89c1-11e9-9ba0-4c72b94353b5
Sponsored by:	Netzkommune GmbH

Approved by:	ports-secteam (joneum)
2019-06-08 21:27:15 +00:00
Glen Barber
7aa5c980b1 MFH: r503651
Add the 11.3-BETA3 MANIFEST files.
Remove the 11.3-BETA2 MANIFEST files.

Approved by:	portmgr (implicit, re blanket)
Approved by:	bdrewery (maintainer, implicit, re blanket)
Sponsored by:	The FreeBSD Foundation
2019-06-07 22:24:52 +00:00
Thomas Zander
f761ac1b37 MFH: r503644
Update to upstream release 0.21.10

Details:
- Bugfix / regression fix release, see
  https://raw.githubusercontent.com/MusicPlayerDaemon/MPD/v0.21.10/NEWS

Approved by:	ports-secteam (riggs)
2019-06-07 18:54:57 +00:00
Torsten Zuehlsdorff
0f96eb9d5e MFH: r503195
lang/php73: Update from 7.3.5 to 7.3.6

Changelog:

    cURL:
        Implemented FR #72189 (Add missing CURL_VERSION_* constants).
    EXIF:
        Fixed bug #77988 (heap-buffer-overflow on php_jpg_get16) (CVE-2019-11040).
    FPM:
        Fixed bug #77934 (php-fpm kill -USR2 not working).
        Fixed bug #77921 (static.php.net doesn't work anymore).
    GD:
        Fixed bug #77943 (imageantialias($image, false); does not work).
        Fixed bug #77973 (Uninitialized read in gdImageCreateFromXbm) (CVE-2019-11038).
    Iconv:
        Fixed bug #78069 (Out-of-bounds read in iconv.c:_php_iconv_mime_decode() due to integer overflow) (CVE-2019-11039).
    JSON:
        Fixed bug #77843 (Use after free with json serializer).
    Opcache:
        Fixed possible crashes, because of inconsistent PCRE cache and opcache SHM reset.
    PDO_MySQL:
        Fixed bug #77944 (Wrong meta pdo_type for bigint on LLP64).
    Reflection:
        Fixed bug #75186 (Inconsistent reflection of Closure:::__invoke()).
    Session:
        Fixed bug #77911 (Wrong warning for session.sid_bits_per_character).
    SOAP:
        Fixed bug #77945 (Segmentation fault when constructing SoapClient with WSDL_CACHE_BOTH).
    SPL:
        Fixed bug #77024 (SplFileObject::__toString() may return array).
    SQLite:
        Fixed bug #77967 (Bypassing open_basedir restrictions via file uris).
    Standard:
        Fixed bug #77931 (Warning for array_map mentions wrong type).
        Fixed bug #78003 (strip_tags output change since PHP 7.3).

Changelog taken from: https://www.php.net/ChangeLog-7.php#7.3.6

Approved by:	ports-secteam (miwi)
2019-06-07 09:24:18 +00:00
Torsten Zuehlsdorff
0e300e5994 MFH: r503193
lang/php71: Update from 7.1.29 to 7.1.30

Changelog:

    EXIF:
        Fixed bug #77988 (heap-buffer-overflow on php_jpg_get16) (CVE-2019-11040).
    GD:
        Fixed bug #77973 (Uninitialized read in gdImageCreateFromXbm) (CVE-2019-11038).
    Iconv:
        Fixed bug #78069 (Out-of-bounds read in iconv.c:_php_iconv_mime_decode() due to integer overflow) (CVE-2019-11039).
    SQLite:
        Fixed bug #77967 (Bypassing open_basedir restrictions via file uris).

Changelog taken from: https://www.php.net/ChangeLog-7.php#7.1.30

Approved by:	ports-secteam (miwi)
2019-06-07 09:21:45 +00:00
Guido Falsi
25538aefc1 MFH: r503583
Import upstreamed patch to fix the Inhibit lock functionality.

Also add some required dependencies.

PR:		238348
Submitted by:	Olivier Duchateau <duchateau.olivier@gmail.com>

Approved by:	ports-secteam (joneum)
2019-06-06 22:07:17 +00:00
Christoph Moench-Tegeder
b5565ad0e7 MFH: r503579
update firefox to 67.0.2 (rc1)

Changes: https://www.mozilla.org/en-US/firefox/67.0.2/releasenotes/

PR:		236651
Approved by:	jbeich (gecko, implicit)

Approved by:	portmgr (web browser blanket)
2019-06-06 13:37:42 +00:00
Larry Rosenman
a821d92d41 MFH: r503367
databases/pointcloud: Backport upstream PR for PostgreSQL 11 support.

PR:		238302
Approved by:	lbartoletti@tuxfamily.org (maintainer)
Obtained from:	3e64c68dd4

Approved by:	ports-secteam(miwi)
2019-06-05 17:59:13 +00:00
Mathieu Arnold
ef99a88efc MFH: r503379
Fix a possible race between udp dispatch and socket code.

PR:		237640
Obtained from:	https://gitlab.isc.org/isc-projects/bind9/merge_requests/1992
2019-06-03 12:46:25 +00:00
Jan Beich
069f6aaaaa MFH: r503368
multimedia/svt-hevc: chase HTTP redirect

Approved by:	ports-secteam blanket
2019-06-03 10:50:56 +00:00
Kai Knoblich
eb241d8fa3 MFH: r503081
www/gitea: Update to 1.8.2

Changelog:

* Fix possbile mysql invalid connnection error
* Handle invalid administrator username on install page
* Disable arm7 builds
* Fix default for allowing new organization creation for new users
* SearchRepositoryByName improvements and unification
* Fix u2f registrationlist ToRegistrations() method
* Allow collaborators to view repo owned by private org
* Use AppURL for Oauth user link
* Escape the commit message on issues update
* Fix regression for API users search
* Handle early git version's lack of get-url
* Fix wrong init dependency on markup extensions

https://github.com/go-gitea/gitea/releases/tag/v1.8.2

PR:		238239
Submitted by:	stb@lassitu.de (maintainer)
Approved by:	ports-secteam (miwi)
2019-06-02 22:30:31 +00:00
Craig Leres
e28db1fea4 MFH: r503191
security/bro: Update to 2.6.2 and address several denial of service
vulnerabilities:

   https://raw.githubusercontent.com/zeek/zeek/bb979702cf9a2fa67b8d1a1c7f88d0b56c6af104/NEWS

 - Integer type mismatches in BinPAC-generated parser code and Bro
   analyzer code may allow for crafted packet data to cause
   unintentional code paths in the analysis logic to be taken due
   to unsafe integer conversions causing the parser and analysis
   logic to each expect different fields to have been parsed.  One
   such example, reported by Maksim Shudrak, causes the Kerberos
   analyzer to dereference a null pointer.  CVE-2019-12175 was
   assigned for this issue.

 - The Kerberos parser allows for several fields to be left
   uninitialized, but they were not marked with an &optional attribute
   and several usages lacked existence checks.  Crafted packet data
   could potentially cause an attempt to access such uninitialized
   fields, generate a runtime error/exception, and leak memory.
   Existence checks and &optional attributes have been added to the
   relevent Kerberos fields.

 - BinPAC-generated protocol parsers commonly contain fields whose
   length is derived from other packet input, and for those that
   allow for incremental parsing, BinPAC did not impose a limit on
   how large such a field could grow, allowing for remotely-controlled
   packet data to cause growth of BinPAC's flowbuffer bounded only
   by the numeric limit of an unsigned 64-bit integer, leading to
   memory exhaustion.  There is now a generalized limit for how
   large flowbuffers are allowed to grow, tunable by setting
   "BinPAC::flowbuffer_capacity_max".

Approved by:	ler (mentor, implicit)
Security:	177fa455-48fc-4ded-ba1b-9975caa7f62a

Approved by:	ports-secteam (miwi)
2019-06-02 15:41:13 +00:00
Matthias Andree
9115f51e95 MFH: r503235
Update e2fsprogs to new upstream release 1.45.2

Various bugfixes, and added Portuguese locale.
Update the Czech, Malay, Polish, Spanish, Swedish, and Ukarainian translations.

Release notes:
<http://e2fsprogs.sourceforge.net/e2fsprogs-release.html#1.45.2>

Approved by:	ports-secteam (miwi)
2019-06-02 09:38:08 +00:00
Jan Beich
dd22157637 MFH: r503206
games/openbor: update to 7032

Changes:	c5cfb660...0afa1f0d
Approved by:	ports-secteam (feld, implicit for snapshots)
2019-06-01 00:48:50 +00:00