108681 Commits

Author SHA1 Message Date
ajacoutot
880d21ceed Update to libgsf-1.14.35 (buffer underflow error).
ok jasper@
2016-02-07 10:54:10 +00:00
sthen
656ea8b751 security update to php-5.5.32, fixes include crashes, integer overflows,
and updating the bundled pcre (also security fixes).

add patches to use arc4random_buf instead of /dev/urandom (which is
typically not available on a normal OpenBSD php installation, with very
bad fallbacks in some cases).

ok robert@
2016-02-06 23:31:20 +00:00
sthen
1c71c809e0 security update to php-5.6.18, fixes include crashes, integer overflows,
and updating the bundled pcre (also security fixes).

add patches to use arc4random_buf instead of /dev/urandom (which is
typically not available on a normal OpenBSD php installation, with very
bad fallbacks in some cases).

testing of arc4random bits from martijn@, ok robert@
2016-02-06 23:30:25 +00:00
juanfra
ee2a034ac7 Disable temporally the JIT on PowerPC. 2016-02-06 20:41:01 +00:00
robert
6ce5b9c733 update to 48.0.2564.103 2016-02-06 18:02:18 +00:00
ajacoutot
ab1440db43 Unbreak the mixer.
from ratchov@, thanks!

req. by mpi@
ok sthen@ jasper@
2016-02-06 07:48:37 +00:00
ajacoutot
875a8331e4 Unbreak rc.d script.
reported by jung@
2016-02-06 07:45:08 +00:00
sthen
5f3cc60ff1 Add a patch to inkscape from Rafael Sadowski, fixing very frequent segfaults
with spinbuttons with malloc's "baby junking" default (indicating a likely
use-after-free). Additional testing from Laurence Tratt.
2016-02-05 22:27:25 +00:00
sthen
954e9e5dd3 Remove "use lib qw(lib)" which is useless and breaks startup if the cwd
is inaccessible. Specifically: fixes amavisd-new startup if razor-agents
is installed (rc.d cd's to the *startup* user's home, i.e. /root, but
this is normally unreadable for the unprivileged user). Remove a useless
FAKE_FLAGS while there.  ok ajacoutot@
2016-02-05 14:59:27 +00:00
rpe
a0114a457c - update security/py-M2Crypto to 0.23.0
- add pre-test target to enable make test

OK sthen@, aja@
2016-02-05 14:58:45 +00:00
rpe
a8b9bd547a update sysutils/ansible to 2.0.0.2
- has a work around for callback API change for v2_playbook_on_start

OK sthen@, aja@
2016-02-05 12:54:19 +00:00
rpe
9b5bdfc6dd update to devel/src 1.3
See http://www.catb.org/~esr/src/NEWS for what changed.

OK aja@
2016-02-05 12:51:46 +00:00
jung
22ef0edd29 update to latest snapshot 201602042118 which fixes multiple filter issues
ok giovanni
2016-02-04 22:27:38 +00:00
juanfra
ad57050b2d "cc1: out of memory allocating 1608 bytes".
Adding -O0 for the next bulk build. I don't have a machine where to
test the workaround. I will remove the comment when I know if that
helps with the bug or not.
2016-02-04 22:16:19 +00:00
naddy
02b7008896 Security update to 4.2.8p6. This addresses numerous security issues. 2016-02-04 19:55:13 +00:00
juanfra
129b213c8b Add core as a RUN_DEPENDS of the plugins. Change core COMMENT.
OK sthen@.
2016-02-04 18:08:17 +00:00
bluhm
a294b54f0e update p5-Regexp-Common to 2016020301 2016-02-04 16:08:37 +00:00
benoit
435b547fec Update to openfire-4.0.1.
from Marc Peters (maintainer)
2016-02-04 15:22:47 +00:00
sthen
80c0a1d7bb add a couple more commits from bmc-support to noVNC, replace ATEN iKVM
detection heuristic and cover additional supermicro X10/X11 iKVM.
2016-02-04 14:45:14 +00:00
sthen
9c4602dbfa Update pkg-readme and rc script for dnscrypt-proxy; "-R opendns" was the
package's old default but this has been replaced in the csv file since
the OpenDNS acquisition.

There is now no default; select a server yourself and configure it as shown
in the readme.
2016-02-04 14:29:25 +00:00
ajacoutot
b5d32276a3 SECURITY fix for CVE-2014-1748. 2016-02-04 13:34:20 +00:00
jasper
9141a6f973 drop MAINTAINER for i don't use this anymore 2016-02-04 13:14:15 +00:00
sthen
a474f01053 In OpenBSD 4.5 p5-Module-Pluggable moved to perl core, so a quirk was used to
remove the package if installed. This was then removed from perl core again,
a port was added, but the quirk wasn't removed, so people who *don't* clean
their /usr/libdata between updates would have the new version from packages
removed, and people who *do* clean would see a message like this,
"Not removing p5-Module-Pluggable-5.2 ,  /usr/libdata/perl5/Module/Pluggable.pm  not found"

Remove from quirks to fix.
2016-02-04 12:34:48 +00:00
tb
dcd1484562 Further pledge(2) fallout due to password protected archives.
Listing or checking the integrity may call readpassphrase(3)
and thus requires a "tty" promise.

Report and fix by provided by Andre S, thanks!

ok czarkoff@, Josh Grosse (MAINTAINER)
2016-02-04 10:38:26 +00:00
jasper
64baddda53 Security fix for CVE-2016-2089, patch from redhat bz.
ok sthen@
2016-02-04 10:08:07 +00:00
ajacoutot
87e8b65286 Add PORTROACH to limit this to version 2.X. 2016-02-04 09:38:03 +00:00
czarkoff
b1a830691f update to mpv-0.15.0
changes:

 - old-configure is gone, so use waf
 - instead of patching cd/dvd device names, use sed
 - explicitly disable dependencies we don't have but may get in future

ok, tweaks and testing bentley@, jasper@ and sthen@
2016-02-04 09:23:20 +00:00
benoit
59f05039c0 Update to p5-XML-XPath-1.29. 2016-02-04 07:55:40 +00:00
ajacoutot
141fc6168c Update to cups-pk-helper-0.2.6. 2016-02-04 06:55:48 +00:00
ajacoutot
de22159dcf Bugfix update to gnutls-3.3.21. 2016-02-04 06:55:18 +00:00
ajacoutot
956443bf3d Update to google-cloud-sdk-95.0.0.
- add support for subnets
2016-02-04 06:54:48 +00:00
sthen
d23b04c1f7 security update to asterisk-13.7.1 (if anyone has time to look at
pulling -stable up to 11.21.1, that would be appreciated..)

BEAST vulnerability in HTTP server
http://downloads.digium.com/pub/security/AST-2016-001.html

File descriptor exhaustion in chan_sip
http://downloads.digium.com/pub/security/AST-2016-002.html

Remote crash vulnerability when receiving UDPTL FAX data.
http://downloads.digium.com/pub/security/AST-2016-003.html
2016-02-04 02:56:29 +00:00
sthen
7f8b70082e Update to dnscrypt-proxy 1.6.1
- Security: malformed packets could cause the OpenDNS deviceid,
OpenDNS set-client-ip, blocking and AAAA blocking plugins to use
uninitialized pointers, leading to a denial of service or possibly
code execution. The vulnerable code is present since dnscrypt-proxy
1.1.0. OpenDNS users and people using dnscrypt-proxy in order to block
domain names and IP addresses should upgrade as soon as possible.
2016-02-04 00:20:09 +00:00
zhuk
6e9ec480f0 There is a special mdoc macro, .Lk, for hyperlinks like that. 2016-02-03 20:47:13 +00:00
giovanni
26a898b4d5 Security update to 4.4.15.4
Fixes:
PMSA-2016-[1-7], PMSA-2016-8 and PMSA-2016-9 do not affect us
2016-02-03 18:58:24 +00:00
giovanni
bf08166a65 Security update to 2.15.0 2016-02-03 18:49:09 +00:00
bluhm
84c90fcb10 update p5-Data-Validate-IP to 0.25 2016-02-03 15:06:08 +00:00
benoit
9c6bd78131 Update to p5-Lingua-Stem-Ru-0.02. 2016-02-03 11:16:01 +00:00
ajacoutot
c612bb3866 Update to salt-2015.8.5. 2016-02-03 07:24:15 +00:00
ajacoutot
54246909ec +vmdktool 2016-02-02 23:59:16 +00:00
ajacoutot
7e48e247e2 Import vmdktool-1.4.
The vmdktool utility converts raw filesystems to the VMDK format and vice versa.
It can also produce information for a given VMDK file.

req., tested by and OK reyk@
2016-02-02 23:58:38 +00:00
sthen
6d57f760c1 Add upstream patch to py-Pillow, fixing a buffer overflow in PcdDecode.c,
where the decoder writes assuming 4 bytes per pixel into a 3 byte per pixel
wide buffer, allowing writing 768 bytes off the end of the buffer. This
overwrites objects in Python's stack, leading to a crash.
https://github.com/python-pillow/Pillow/pull/1706

(There's also a newer upstream release but that will need additional
checking before it can go in).
2016-02-02 23:08:40 +00:00
sthen
4db10eb36a regen patches, no pkg change 2016-02-02 21:58:32 +00:00
rpointel
90f926efa6 update django to 1.9.2 and 1.8.9.
ok jasper@ benoit@
2016-02-02 20:23:09 +00:00
bluhm
794a6955aa update p5-Net-PcapWriter to 0.724 2016-02-02 16:17:13 +00:00
sthen
391c387260 security update to socat-1.7.3.1, ok jasper@ nigel@
- A stack overflow in vulnerability was found that can be triggered when
command line arguments (complete address specifications, host names,
file names) are longer than 512 bytes.

- In the OpenSSL address implementation the hard coded 1024 bit DH p
parameter was not prime. [..] Fix: generated a new 2048bit prime.
2016-02-02 10:40:32 +00:00
benoit
de742f3c97 Update to p5-Pango-1.227. 2016-02-02 10:22:30 +00:00
bentley
6dcf0c91e9 Update to alephone-1.2.1.
Release notes:
https://github.com/Aleph-One-Marathon/alephone/releases/tag/release-20150620

ok phessler@ (maintainer)
2016-02-02 10:17:44 +00:00
bentley
76764bb337 Update to apertium-dan-nor-1.2.2. 2016-02-02 10:13:04 +00:00
benoit
a6707ef358 Update to p5-Glib2-1.321. 2016-02-02 10:11:46 +00:00