Commit Graph

29640 Commits

Author SHA1 Message Date
naddy
bf7cc206f8 SECURITY:
CAN-2005-2491, http://securitytracker.com/id?1014744
"A remote or local user may be able to supply a specially crafted
regular expression to trigger a heap integer overflow in PCRE."

ok pvalchev@
2005-08-22 22:40:28 +00:00
naddy
b5ba305851 SECURITY:
Catch up with xpdf 3.00 pl2 and pl3 for various vulnerabilities, and a fix
for CAN-2005-2097 from Kristian Hoegsberg.
ok mbalmer@, pvalchev@
2005-08-22 22:37:12 +00:00
sturm
f10e13f8c4 SECURITY
Update to AcroRead 7.0.1 in order to fix a buffer overflow in one of
the core modules. Not really much more information at
http://www.adobe.com/support/techdocs/321644.html

ok pval
2005-08-20 09:02:16 +00:00
mbalmer
7f1e33b0c4 - Add a patch to prevent accessing a char[] array with a negative index.
- Bump package name.

Problem reported by Paul de Weerd, ok pvalchev@
2005-08-20 08:01:41 +00:00
sturm
df369a952d qt4-debug is too big for ftp
ok pval@
2005-08-17 21:06:48 +00:00
espie
f8b5e18776 belated bump.
okay pvalchev@
2005-08-17 16:23:16 +00:00
robert
613ac4d41a SECURITY: upgrade to 1.5.0;
fixes several secuirty vulnerabilities.
http://www.vuxml.org/openbsd/0dfcb310-0f38-11da-ba28-00065bd5b0b6.html

ok brad@ pvalchev@
2005-08-17 16:22:34 +00:00
espie
f1e7eab840 those packages have not changed names since 3.6, even though their
packing-lists was changes in significant ways, and they do not have
enough dependencies that pkg_add can detect they changed through their
signature.

Bump the pkgname, so that pkg_add -r will choose to update them.

okay pvalchev@
2005-08-17 16:10:02 +00:00
brad
eedc50c22b use the libtool that comes with silc-server for now since
it has a little hack to make it build and link against a
static libsilc.

ok pvalchev@
2005-08-17 16:02:08 +00:00
espie
bf3e9edf34 oops, noticed by Bernd Ahlers.
okay pvalchev@
2005-08-17 16:02:05 +00:00
pvalchev
db563a07ff mark as broken on sgi as well as hppa as it freaks out the machine too 2005-08-17 02:16:03 +00:00
robert
32b94333d3 SECURITY:
upgrade to version 200508R1;
This fixes several potential security problems, so everyone
should upgrade immidiately.

From Bernd Ahlers <bernd@ba-net.org>, Matthias Kilian <kili@outback.escape.de>
ok pvalchev@
2005-08-16 20:35:58 +00:00
espie
9571031547 fix conflicts with 3.6 packages, thus allowing updates.
Okay pvalchev@
2005-08-16 18:28:55 +00:00
sturm
52ca940508 work around an ICE by compiling single files with -O0 on sparc64
ok pval
2005-08-16 18:24:10 +00:00
sturm
20ad0f9bbe work around an ICE by compiling a file with -O0 on sparc64
ok pval
2005-08-16 18:22:26 +00:00
espie
fc92c52056 missing bump, okay pval 2005-08-16 13:22:51 +00:00
espie
f90faf868a conflicts from the past: history since 3.7.
As noted on ports@ recently, pkg_add -r relies on conflicts, and the
sheer existence of updates means we MUST take the past into account in
conflicts now.

Note the renaming of hugs98 to valid package names where versions are
concerned.

This commit shows clearly the renaming of the xfce4 plugin packages, the
ditching of eclipse flavors, the splitting of nessus into subpackages,
the splitting of various other software documentations, some packaging bugs
in kdeedu, and a lot of files moving around...

okay pvalchev@
2005-08-16 09:49:51 +00:00
pvalchev
4f74a44df2 gphoto2 works; robert 2005-08-16 02:04:13 +00:00
espie
0933f491aa some shared dirs, okay pvalchev@ 2005-08-15 22:56:44 +00:00
jolan
c7aee7ccf1 update to 1.0.9, ok jcs pval
most notably fixes an overflow in the management interface (which is not
enabled by default)
2005-08-15 17:36:06 +00:00
pvalchev
e6b718763f more stuff from robert 2005-08-15 00:07:02 +00:00
espie
dd7e097b7c remove duplicates, in case we're scanning the same package several times.
okay pvalchev@
2005-08-14 11:57:17 +00:00
sturm
b5851b9917 fix uids
ok pval
2005-08-14 01:10:31 +00:00
espie
5be7f8ae04 shared dirs.
okay pvalchev@
2005-08-13 18:20:23 +00:00
espie
87cb3293e4 missing dirs in PLIST
okay pvalchev@
2005-08-13 18:19:31 +00:00
pvalchev
e0f988c2d6 sync 2005-08-13 07:54:21 +00:00
espie
957b96a95f the linux realmedia codec can't work: our dlopen won't load them correctly.
More annoyingly, it abort()s the current process (thanks dale),
so comment them out, add the win32 codecs, and use them instead.

For some strange reason, the audio codec insists on being launched
from its own directory.

With this change, realmedia playing works.

okay sturm@, okay pvalchev@
2005-08-12 22:59:15 +00:00
pvalchev
31d18f916a Switch back to gtk1, as there are side-effects that need to be discussed
more and it's too close to release to be having such discussions, showing
this was not thought out very well.
Bump PKGNAME and shlibs again
2005-08-12 19:01:44 +00:00
kurt
33283fba1c -switch to gtk2 (originally from msf@) tested by many
some minor scrolling issues noticed my naddy@
-fix US master site

ok msf@, fine by me naddy@, go ahead wilfried@
2005-08-11 18:59:14 +00:00
naddy
02cc9e090f Update to 3.41; from maintainer Steven Mestdagh.
Relevant changes from the changelog:
  * added a .asy backend for Asymptote files (
    http://asymptote.sourceforge.net/ ). Thanks to John Bowman
  * fixed three bugs (one memory leak, two other minor problems)
    detected by the Coverity Prevent tool (http://www.coverity.com/)
  * PostScript frontend: fixed a bug in tracing the bounding box of
    raster images.
  * fixed a bug in sub path handling - thanks to Soren Henriksen.
  * fixed the handling of some special characters in the LaTeX2e
    format driver.
2005-08-11 17:32:06 +00:00
aanriot
1a0530705d fix dependencies.
ok pvalchev@
2005-08-11 17:28:12 +00:00
fgsch
4cd248672e ops, previous diff was wrong. correct one now. bump package again. sorry. 2005-08-11 16:58:52 +00:00
brad
b055c8dfd2 fix build if silc-toolkit is already installed and add USE_LIBTOOL
problem noticed by naddy@
2005-08-11 16:25:13 +00:00
naddy
e97353cf79 SECURITY:
pstopnm called the ghostscript interpreter on potentially untrusted
PostScript without specifying the -dSAFER option.  Not running under
-dSAFER allows PostScript code to do file IO and to open pipes to
arbitrary external programs, including /bin/sh.

Originally reported by Max Vozeler/Debian Linux; ok brad@
2005-08-11 15:54:46 +00:00
fgsch
76454c0159 fix more crashes. maintainer ok. also sent to gaim devs. 2005-08-11 15:54:24 +00:00
naddy
16c7c089d3 Fix denial of service vulnerability.
Check sanity of the TrueType "loca" table.  Specially crafted broken
tables caused disk space exhaustion due to very large generated glyph
descriptions when attempting to fix the table.  CAN-2005-2097.

http://www.kde.org/info/security/advisory-20050809-1.txt
2005-08-11 14:21:46 +00:00
naddy
9c8738ab34 Fix denial of service vulnerability.
Check sanity of the TrueType "loca" table.  Specially crafted broken
tables caused disk space exhaustion due to very large generated glyph
descriptions when attempting to fix the table.  CAN-2005-2097.

from Ubuntu Linux; ok brad@
2005-08-11 14:18:47 +00:00
espie
2076dcf323 typo in DESCR 2005-08-11 11:28:20 +00:00
brad
181161d50e - disable SSL support for the time being until it actually works.
http://trac.lighttpd.net/trac/ticket/93

- add USE_LIBTOOL
2005-08-11 04:38:44 +00:00
todd
fc1ebc4565 update to 0.7.1 (http://qemu.org/changelog.html)
add pcnet nic support
2005-08-11 01:15:17 +00:00
kurt
3a793e5c14 fix old zlib vuln http://www.zlib.net/advisory-2002-03-11.txt and
other bug fixes from the 1.5.0 jdk src.
2005-08-10 22:36:26 +00:00
naddy
5fde06cb73 sync patches 2005-08-10 20:27:25 +00:00
naddy
fe0fbad0d0 no more build problems on amd64; ok pvalchev@ 2005-08-10 15:49:01 +00:00
espie
943babf830 minor update to new version 2005-08-10 13:16:32 +00:00
espie
3146ff3563 libraries live in the first pass. 2005-08-10 13:09:17 +00:00
espie
b2acde38da adjust config.h to correspond to what gcc actually does.
Suppresses most of the warnings.
2005-08-10 09:59:13 +00:00
aanriot
241f525d5f forgot to bump PKGNAME.
spotted by sturm@
2005-08-10 08:53:26 +00:00
mbalmer
b6d3f9b168 Update to plan version 1.9
help & comments sturm@ and bernd ahlers, sturm@ ok
2005-08-10 07:53:44 +00:00
mbalmer
e3a8473ecd Add uid/gid 549, _netplan:_netplan for misc/plan 2005-08-10 07:48:49 +00:00
jolan
776dbd8a45 update to 2.0.2 2005-08-10 05:24:09 +00:00