93967 Commits

Author SHA1 Message Date
zhuk
5e7f9396a6 Add @conflict markers for (removed) tcpcat and (old version of) freedt.
okay sthen@
2014-07-24 17:21:49 +00:00
zhuk
dbaff7f0bb The recordio script (simple "ratelimit -r" wrapper) being removed
to avoid conflict with net/ucspi-tcp. For the same reason the argv0
is renamed to fargv0.

okay sthen@
2014-07-24 17:20:46 +00:00
zhuk
60a462d56c Remove net/tcpcat. We have similar nc(1) in base, and it conflicts with
net/ucspi-tcp.

okay espie@ and sthen@
2014-07-24 16:06:55 +00:00
zhuk
98a6b659df Unlink tcpcat. 2014-07-24 16:03:41 +00:00
zhuk
873705a497 Two manual pages were forgotten in -main package, causing actual conflict.
okay@ sthen for the patch
2014-07-24 16:02:43 +00:00
zhuk
329ea089a6 Missing LDEP, spotted by naddy@. 2014-07-24 14:53:58 +00:00
landry
f872f3d7cb Mark BROKEN, because mono.. commiting on behalf of phessler@, sure
sthen@
2014-07-24 13:59:37 +00:00
robert
05791c9bfc security update to 2.2.5; fixes a local file inclusion via XXE attack
https://support.zabbix.com/browse/ZBX-8151

ok jasper@
2014-07-24 09:03:58 +00:00
edd
6a9e53e3b6 Mark math/wxMaxima broken. 2014-07-24 08:47:54 +00:00
robert
f5fde7083e fix middle button copy&paste; ok sthen@ 2014-07-24 08:37:40 +00:00
zhuk
6b2228e0fb Make sure no extra OpenCV libraries are picked up during linking.
Reduces WANTLIB-kipi back to something realistic. Went upstream already.

okay sthen@
2014-07-23 23:31:53 +00:00
zhuk
676cafa5c6 Nitpicking: set actual test names. Doesn't affect actual testing.
committing under sthen@'s okay for portcheck
2014-07-23 22:34:06 +00:00
zhuk
01c9f57f33 Missing function name between "&&" and arguments.
okay sthen@ since portcheck doesn't affect actual release
2014-07-23 22:12:41 +00:00
zhuk
0a5cf3f39d Fix FULLPKGNAME handling, it should be subpackage-dependent.
okay sthen@ since portcheck doesn't affect actual release
2014-07-23 22:11:20 +00:00
jca
13b07fb1e9 Entry for cherokee CVE-2014-4668. 2014-07-23 20:35:15 +00:00
rpe
1881b636f9 Update ansible to 1.6.7 which fixes these CVEs:
- CVE-2014-4966 (lookup function)
- CVE-2014-4967 (action arguments)

Noted by and OK jasper@
OK naddy@
2014-07-23 20:28:49 +00:00
jca
fcc8022549 SECURITY fix for CVE-2014-4668. The LDAP authenticator considered
successful LDAP bindings as a proper authentication, without checking
the length of the user's password.  But the LDAP server configuration
might allow password-less bindings to retrieve public information.
ok naddy@
2014-07-23 20:14:07 +00:00
naddy
5dc9caa8a7 add www/p5-CGI-Application CVE-2013-7329 2014-07-23 20:08:08 +00:00
naddy
1f16b96d9e Update www/p5-CGI-Application for CVE-2013-7329
Fix RT 84403 - 'Security problem: missing "start" mode dumps ENV to output
page'
https://github.com/markstos/CGI--Application/pull/15

While here remove groff and fix runtime depends.
www/p5-CGI-PSGI is optional, include it as people nowadays run PSGI and are
moving away from MOD_PERL.

From maintainer Ian McWilliam
2014-07-23 20:06:13 +00:00
naddy
cf2fbfa8fc do not pick up gmkdir in configure; ok espie@ 2014-07-23 18:02:27 +00:00
sthen
29ea32c1cc add a run dep for urlwatch on lynx, ok jasper@ 2014-07-23 13:27:09 +00:00
sthen
d34a7c3de5 quirk for exim vuln fix, reminded by espie 2014-07-23 12:03:53 +00:00
ajacoutot
0c5e9fcf25 w3m -> lynx
req. by naddy@
2014-07-23 11:41:56 +00:00
zhuk
de040783f8 Fix WANTLIB. 2014-07-23 10:50:43 +00:00
sthen
9f28de8726 update to Exim 4.83, fixes CVE-2014-2972 - more information at
https://lists.exim.org/lurker/message/20140722.152452.d6c019e8.en.html

ok naddy@
2014-07-23 10:36:24 +00:00
ajacoutot
ffdc0e9b4b This port needs a major update to work with Mono3; it seems we will not
have time to properly do this before lock so mark BROKEN.

ok jasper@ sthen@ robert@
2014-07-23 10:30:44 +00:00
espie
ab33cdac90 fix a remnant of MULTI_PACKAGES reorg, a few years ago: there's no reason
to count LIB_DEPENDS and WANTLIB in build-deps, only the actual subpackaged
version count (reminder: even single package ports are actually multi-packaged,
with SUBPACKAGE=-, hence we will count LIB_DEPENDS- and WANTLIB-).

This was actually a discrepancy between manual builds and dpb builds, as the
output of dump-vars won't show plain LIB_DEPENDS. This caused a bit of
confusion wrt multimedia/mlt. Hence the actual fix.
2014-07-23 10:19:08 +00:00
zhuk
ce8e98d6e3 Better fix for missing dependency, similar to devel/kdevelop one. 2014-07-23 10:17:40 +00:00
zhuk
69f5fdf42f Even better patch for missing dependency, operating at source file level. 2014-07-23 10:15:42 +00:00
ajacoutot
938e7bd130 Install missing @sample files; this unbreaks mono-basic.
ok sthen@ robert@ (maintainer)
2014-07-23 09:54:14 +00:00
sthen
88e8cf9af2 add -lexecinfo and remove the patch disabling backtrace() support, registering
the dependency (thus fixing an unregistered build dependency on execinfo.h and
adding support for the functionality). Build problem reported by naddy@,
ok jsg@ jasper@
2014-07-23 09:50:22 +00:00
ajacoutot
d53400a413 Unbreak after mono update (from Arch Linux).
ok espie@
2014-07-23 09:01:24 +00:00
pascal
554ab98a86 Do not pick up OpenCV if found.
noticed by naddy@ and sthen@, ok naddy@
2014-07-23 08:38:51 +00:00
jca
ae9aa81be3 Remove a dead link from the README.
From misc.nick at gmx dot com, ok dcoppa@ naddy@
2014-07-23 00:44:55 +00:00
zhuk
3d5475e9d0 Missing LIB_DEPENDS on nepomuk-core.
Detailed explanation: port-lib-depends-check won't complain, because this
port have RDEP on kde-runtime, which in turn has itself nepomuk-core as
a dependency. But at the build time RDEPs aren't installed, and sooner or
later things would break... And this finally happened at naddy@'s.
2014-07-22 18:56:39 +00:00
sebastia
6a59d2b89e Fix accessing the calendar on i386, bug introduced when i386 was switched to use clang.
OK jasper@
2014-07-22 18:46:43 +00:00
ajacoutot
142ee35e65 Depend on lynx instead of w3m (which depends on boehm-gc that is broken
on some arches).

ok sthen@
2014-07-22 17:19:04 +00:00
rpointel
433cda4721 Update minitube to 2.2 after the youtube API changes.
ok espie@ jca@.
2014-07-22 13:03:27 +00:00
ajacoutot
9d087a11f1 Tweak documentation according to recent rc changes.
ok jasper@
2014-07-22 10:55:40 +00:00
ajacoutot
ccfa6fa92a Remove net/unbound. It's been unlinked for a while and is now in base.
prodded by and ok sthen@, ok jasper@
2014-07-22 09:52:11 +00:00
jasper
d8711ceca2 add bozohttpd 2014-07-22 09:03:59 +00:00
jca
10dea71a20 Prevent the nrpe children from cleaning up the pidfile on
accept(2)/getpeername(2) errors, from Ubuntu.  ok sthen@
2014-07-22 08:55:45 +00:00
jasper
4b1452000e Security update to bozohttpd-20140708, addresses CVE-2014-5015
ok benoit@ (MAINTAINER), sthen@
2014-07-22 08:21:28 +00:00
sthen
53c19cce03 bdep on desktop-file-utils, ok landry 2014-07-21 22:19:06 +00:00
zhuk
67d01e978d Re-do the fix for "ui_custom_include_paths.h", should work now
(continues to work without problems on i386...)

Also, fix fallout from some recent headers tweaking in base.

Both fixes are build-time only, so no REVISION bump.
2014-07-21 21:25:11 +00:00
naddy
730956fe7a add net/transmission to the cve list; prodded/ok espie@ 2014-07-21 20:12:13 +00:00
zhuk
074554946e Add a note about updating KDE artwork packages on xscreensaver update.
okay sthen@
2014-07-21 20:11:37 +00:00
ajacoutot
155e65ffdc Do not output "Default dictionary has been set to `british'" each time the
pkg is updated; because that is not true.
Tweak the @exec line.
Move MESSAGE into a README.

after a comment by guenther@ on icb
2014-07-21 17:19:02 +00:00
jasper
66e37713d8 regen plist to include the openbsd implementation for the partitions fact...oops. 2014-07-21 15:51:16 +00:00
naddy
04b175f0aa update to 2.84: fix peer communication vulnerability
also tested by gonzalo@
2014-07-21 14:59:17 +00:00