6991 Commits

Author SHA1 Message Date
espie
fd1aeac43c FIX_EXTRACT_PERMISSIONS 2017-12-08 00:16:59 +00:00
espie
73fd7b4dc6 FIX_EXTRACT_PERMISSIONS 2017-12-08 00:09:18 +00:00
sthen
9a09c53881 Update to postfix snapshot to 3.3-20171028, from Brad. 2017-12-07 22:03:48 +00:00
bluhm
5c78718281 Fix CVE-2017-16844 in formail in procmail 3.22.
from Debian; via Matthias Pitzl; OK sthen@
2017-12-06 14:19:41 +00:00
ajacoutot
add50dd904 Update to gmime30-3.0.5. 2017-12-04 08:55:43 +00:00
espie
927d775ae1 fix permissions 2017-12-02 13:40:32 +00:00
edd
3bc18c7732 Update security/gpgme to 1.9.0 and deal with fallout across the tree.
Fallout stems from the removal of the gpgme-pthread shared object.

Initial diff by me, refreshed diff from jca@.

Tested in a bulk by ajacoutot@.

OK jca@, ajacoutot@. Thanks.
2017-12-02 12:44:33 +00:00
sthen
b24c690964 update to exim-4.89.1, fixing CVE-2017-16943 (previously handled in a patch)
and CVE-2017-16944, and other fixes.

Alternative workaround for these two CVEs: disable the SMTP CHUNKING extension
by adding "chunking_advertise_hosts =" to the main configuration section (empty
right-hand-side).
2017-12-01 14:38:24 +00:00
pascal
f7189a35d2 Update to nmh 1.7. Note that this moves some binaries from
${LOCALBASE}/libexec to ${LOCALBASE}/libexec/nmh.

feedback/ok bentley@
2017-11-30 11:14:53 +00:00
jca
eff41aae8e Fix build failure when libunistring is installed
mlmmj's unistr.h should come before libunistring's version in the
include search path

Reported by ajacoutot@, ok kevlo@
2017-11-30 00:46:17 +00:00
kevlo
c880a9c9dc Remove unnecessary file. 2017-11-28 03:45:02 +00:00
kevlo
a191283a56 Update to mlmmj-1.3.0, from Zhang Huangbin, tweak PLIST from me. 2017-11-28 03:43:07 +00:00
sthen
82bc31baad Add patch for Exim remote code execution in 4.88+.
https://lists.exim.org/lurker/message/20171125.034842.d1d75cac.en.html
https://bugs.exim.org/show_bug.cgi?id=2199

There is also another issue which is at least a DoS,
https://bugs.exim.org/show_bug.cgi?id=2201 that is *not* patched yet.
The workaround below would help both cases.

From upstream:

"With immediate effect, please apply this workaround: if you are running
Exim 4.88 or newer (4.89 is current, 4.90 is upcoming) then in the main
section of your Exim configuration, set:

chunking_advertise_hosts =

That's an empty value, nothing on the right of the equals. This
disables advertising the ESMTP CHUNKING extension, making the BDAT verb
unavailable and avoids letting an attacker apply the logic. "
2017-11-25 13:04:53 +00:00
robert
a257ac524c kopano_search requires a pexp to be set in the rc.d script 2017-11-25 10:59:19 +00:00
landry
f43c3fa4fb Properly fix WANTLIB after r1.257.
Reminded by naddy@
2017-11-24 18:04:38 +00:00
landry
8782c9a87f Update to thunderbird 52.5.0/lightning 5.4.5.
See https://www.mozilla.org/en-US/thunderbird/52.3.0/releasenotes/,
https://www.mozilla.org/en-US/thunderbird/52.4.0/releasenotes/
and https://www.mozilla.org/en-US/thunderbird/52.5.0/releasenotes/

Fixes https://www.mozilla.org/en-US/security/advisories/mfsa2017-20/,
https://www.mozilla.org/en-US/security/advisories/mfsa2017-23/
& https://www.mozilla.org/en-US/security/advisories/mfsa2017-26/ (pending)
2017-11-24 06:45:44 +00:00
ajacoutot
7f64b0e21e Update to gmime30-3.0.4. 2017-11-21 08:23:01 +00:00
naddy
1a87aebd2d mechanical replacement of the gettext module 2017-11-21 00:12:59 +00:00
jeremy
d0cb69b1ef Update HOMEPAGE so it doesn't reference Rubyforge
Rubyforge went away years ago.
2017-11-20 20:57:17 +00:00
naddy
5306d9fac1 replace gettext module 2017-11-19 00:53:16 +00:00
sthen
bc17fa635a update to pear-Mail-Mime-1.10.2 2017-11-18 19:46:38 +00:00
naddy
93deb26dec switch COMPILER from the old, confusing shortcuts to the more explicit format;
unclear whether these all match the author's intent
2017-11-17 00:22:39 +00:00
naddy
11e3dd67b3 switch COMPILER from the old, confusing shortcuts to the more explicit format 2017-11-16 23:20:37 +00:00
sthen
d579e1bf4e drop william@ as maintainer on his ports, per his request. 2017-11-15 21:28:05 +00:00
naddy
8472e38c51 replace gettext module; ok giovanni@ 2017-11-13 15:35:24 +00:00
naddy
ef3fc5132e replace gettext module, sync wantlib; ok danj@ 2017-11-12 22:01:46 +00:00
ajacoutot
a34932c42b www/gtkhtml4 is about to get removed, so regen DEPENDS/WANTLIB in
preparation.
2017-11-12 12:25:46 +00:00
sthen
3348ddfb37 update to postfix-3.2.4, from Brad 2017-11-09 21:52:09 +00:00
sthen
f3bc8ef405 update to rspamd-1.6.5, from Brad 2017-11-09 21:51:05 +00:00
landry
fe3528c808 Fix some WANTLIB after nss dependency change (sometimes, just remove
unneeded softokn3, sometimes replace it by nssutil3) - note that there
might be more WANTLIB to fix/remove from those ports, but i only
concentrated on the changes related to nss.
2017-11-09 19:44:12 +00:00
sthen
9eab8f48a7 security update to roundcubemail-1.3.3:
"Apparently this zero-day exploit is already being used by hackers to
read Roundcube’s configuration files. It requires a valid
username/password as the exploit only works with a valid session. More
details will be published soon under CVE-2017-16651.

In order to check whether your Roundcube installation has been
compromised check the access logs for requests like

?_task=settings&_action=upload-display&_from=timezone

As mentioned above, the file disclosure only works for authenticated
users and by finding such requests in the logs you should also be able
to identify the account used for this unauthorized access. For
mitigation we recommend to change the all credentials to external
services like database or LDAP address books and preferably also the
'des_key' option in your config."
2017-11-09 16:26:09 +00:00
bentley
6a725f6e98 Update moved homepage/master_sites.
Broken links reported by Jan Stary.
2017-11-09 12:14:12 +00:00
ajacoutot
393b73bae3 Fix build with libical >= 3.0.0. 2017-11-08 05:37:16 +00:00
ajacoutot
f229999da4 Replace icaltime_from_timet with icaltime_from_timet_with_zone (upstream).
This allows working with libical >= 3.0.0
2017-11-08 05:37:00 +00:00
giovanni
01f17f6bdd bugfix update to 1.9.8.3 2017-11-07 11:06:04 +00:00
giovanni
2f9fb73071 Add p5-Net-LibIDN as a run-dependency to let spamassassin work on idn tld
fix some regression tests
ok bluhm@
2017-11-07 07:39:07 +00:00
sthen
7a0a5540f3 update to Dovecot 2.2.33.2, from Brad.
- doveadm: Fix crash in proxying (or dsync replication) if remote is
running older than v2.2.33
- auth: Fix memory leak in %{ldap_dn}
- dict-sql: Fix data types to work correctly with Cassandra
2017-11-05 19:27:56 +00:00
naddy
7c32ef7b4e replace gettext module 2017-11-04 21:48:06 +00:00
naddy
ab7ad3bd83 replace gettext module 2017-11-04 16:54:24 +00:00
naddy
5609bcb1d7 Remove mixmaster. Security/crypto software from 14 years ago is no longer
useful.  ok fcambus@ jca@
2017-11-04 16:45:32 +00:00
remi
8e8e581893 Update to offlienimap-7.1.4
ok rsadowski@ sthen@ danj@
2017-11-03 14:49:54 +00:00
sthen
5ff1572aac update to roundcubemail-1.3.2 2017-11-02 10:57:37 +00:00
giovanni
c45521b491 unbreak, needs no-autoheader
spotted by naddy@, Thanks
2017-11-02 08:49:41 +00:00
ajacoutot
458f1fe6bd Sync WANTLIB. 2017-11-01 21:42:51 +00:00
ajacoutot
0c5768240d Update to evolution-ews-3.26.2. 2017-11-01 21:35:09 +00:00
ajacoutot
a0331ba565 Update to evolution-3.26.2. 2017-11-01 21:29:47 +00:00
naddy
c9e890c697 /dev/srandom has been removed, just use /dev/random as everywhere else 2017-11-01 17:24:54 +00:00
jeremy
9b88779082 Bump ports after default ruby version switch to ruby 2.4 2017-11-01 10:12:25 +00:00
giovanni
536d0d84e6 update to 2.9.2, remove a patch committed upstream 2017-10-31 07:46:37 +00:00
giovanni
706b262625 update to 4.18.2, remove a patch committed upstream 2017-10-31 07:45:04 +00:00