Commit Graph

63 Commits

Author SHA1 Message Date
sthen
9980989f20 update to analog-6.0.17 2022-03-21 12:29:14 +00:00
naddy
ec14803114 drop RCS Ids 2022-03-11 20:09:36 +00:00
kirby
a5a34d842a switch HOMEPAGE and MASTER_SITES to HTTPS 2021-04-04 08:51:50 +00:00
sthen
77f7cc9c61 replace simple PERMIT_PACKAGE_CDROM=Yes with PERMIT_PACKAGE=Yes 2019-07-12 20:49:33 +00:00
naddy
65e305f38a replace libiconv module 2016-09-13 19:15:03 +00:00
bentley
6bf04ffd50 Update HOMEPAGE, prune mirrors, and use more specific license marker. 2015-06-15 08:32:15 +00:00
otto
c357662571 overlapping memcpy -> memmove; ok jasper@ 2014-12-11 12:43:50 +00:00
sthen
dcb445207e sync follow graphics/gd update 2014-03-17 23:21:26 +00:00
jasper
c38dcacc50 use ${VARBASE} instead of hardcoding /var 2013-07-05 09:34:35 +00:00
espie
eae66e4a7b PERMIT_* / REGRESS->TEST sweep 2013-03-11 11:35:43 +00:00
espie
e50b98837f new depends 2010-11-22 08:36:47 +00:00
sthen
89d5cdea52 new-style LIB_DEPENDS/REVISION/WANTLIB 2010-11-11 12:35:09 +00:00
naddy
437d585dc2 fix library order for static linking 2009-03-23 20:09:51 +00:00
merdely
ba8add3ebb Remove surrounding quotes from
COMMENT-*/ERRORS/NO_REGRESS/PERMIT_*/REGRESS_IS_INTERACTIVE

Change '.include "bsd.port.mk"' to '.include <bsd.port.mk>' while here
(ok naddy@)
2007-09-15 20:38:20 +00:00
naddy
5bba1ec7dd * recognize MS Windows Vista; from stephan.rickauer@ini.phys.ethz.ch
* fix PREFIX substitution
* regen patches
2007-05-30 22:33:11 +00:00
espie
17b77a4af2 new lib specs 2006-08-04 00:10:42 +00:00
david
f85600afe0 move any perl or sed substitutions from post-patch to pre-configure
(fixes make update-patches)
ok sturm@; "looks reasonable" steven@
2006-02-08 04:54:48 +00:00
fgsch
02bbd30eb7 license is GPL now; from Toni Mueller ( support at oeko dot net ). 2005-12-05 18:04:17 +00:00
fgsch
ab934bbefb sync with gd update. sturm@ ok. 2005-10-24 05:08:11 +00:00
fgsch
3dcfddd4c5 update to analog 6.0 mainly to cope with gd update. 2005-10-12 05:42:31 +00:00
naddy
0df4e2a409 use existing ports rather than building private copies of libgd, libpng, etc 2005-07-05 14:28:40 +00:00
naddy
a4e42829d8 fix DNS lookups on 64-bit archs; from James Strandboge <jamie@tpptraining.com> 2005-05-26 21:37:07 +00:00
naddy
da0859a09c Fix several out of bounds accesses.
Parts from Wolfgang S. Rupprecht via PR 4175; testing by Sam Smith.
2005-04-18 22:32:36 +00:00
alek
5364a42ec5 Add WANTLIB markers 2004-12-11 13:29:20 +00:00
alek
b068d3d2f4 - Kill DEINSTALL
- Replace INSTALL with @samples
- Remove @extra
- Bump PKGNAME

looks ok sturm@
2004-11-28 17:07:43 +00:00
sturm
e77d2a5175 license markers and some corrections 2003-10-18 19:44:41 +00:00
naddy
69107b5263 update to 5.32; from Stoyan Zhekov <zhware@saku2.com> 2003-06-22 21:29:24 +00:00
naddy
73b0998d3c No regression tests available. 2002-10-29 01:30:41 +00:00
mpech
a8924e572b Remove Oleg Safiullin from MAINTAINERS.
form@ ok
2002-09-01 18:49:00 +00:00
form
cb18d56d3a update to 5.24 2002-06-26 04:07:16 +00:00
form
d57fd5fdbc Upgrade to 5.23 (form interface security fix). 2002-05-15 02:14:19 +00:00
espie
d900d189e1 Bump NEED_VERSION 2002-03-21 21:25:50 +00:00
form
f77f85dd37 upgrade to 5.22
SECURITY ADVISORY                                      20th March 2002
----------------------------------------------------------------------
Program: analog
Versions: all versions prior to 5.22
Operating systems: all
----------------------------------------------------------------------
Yuji Takahashi discovered a bug in analog which allows a cross-site
scripting type attack.

It is easy for an attacker to insert arbitrary strings into any web
server logfile. If these strings are then analysed by analog, they can
appear in the report. By this means an attacker can introduce
arbitrary Javascript code, for example, into an analog report produced
by someone else and read by a third person. Analog already attempted
to encode unsafe characters to avoid this type of attack, but the
conversion was incomplete.

Although it is not known that this bug has been exploited, it is easy
to exploit, and all users are advised to upgrade to version 5.22 of
analog immediately. The URL for analog is http://www.analog.cx/
I apologise for the inconvenience.

Thank you to Yuji Takahashi, Motonobu Takahashi and Takayuki Matsuki
for their help with this bug.

                                                        Stephen Turner
                                         analog-author@lists.isite.net
2002-03-20 13:09:29 +00:00
form
c8e6ea89c9 upgrade to 5.21 2002-03-01 10:07:25 +00:00
form
b21de6366f upgrade to 5.1 2001-11-22 11:10:39 +00:00
form
9bd965814b upgrade to 5.03 2001-08-13 03:44:39 +00:00
form
bf1c914d7a upgrade to 5.02
http://www.reverse.net/analog/ -> http://redmoon.reverse.net/analog/
There seems to be a problem with analog.cx's website, so
put mirrors ahead and temporarily change HOMEPAGE.

Thanks to Jeff Bachtel <Jeff.Bachtel@isc.tamu.edu>
2001-07-03 02:24:13 +00:00
form
39d8f16d44 upgrade to 5.01 2001-05-20 05:56:36 +00:00
form
8c3046a465 move COMMENT to Makefile 2001-03-29 09:52:20 +00:00
form
0079eab07b Use SYSCONFDIR instead of hardcoded /etc; naddy@ 2001-02-27 03:46:23 +00:00
form
3ffad06f7c Update to 4.16.
Fixed buffer overflow.

>SECURITY ADVISORY                                   13th February 2001
>----------------------------------------------------------------------
>Program: analog
>Versions: all versions except 4.16 and 4.90beta3
>Operating systems: all
>----------------------------------------------------------------------
>There is a buffer overflow bug in all versions of analog released
>prior to today. A malicious user could use an ALIAS command to
>construct very long strings which were not checked for length.
>
>This bug is particularly dangerous if the form interface (which allows
>unknown users to run the program via a CGI script) has been installed.
>
>This bug was discovered by the program author, and there is no known
>exploit. However, users are advised to upgrade to one of the two safe
>versions immediately, especially if they have installed the form
>interface. The URL is http://www.analog.cx/
>
>I apologise for the inconvenience.
>                                                        Stephen Turner
2001-02-25 08:04:05 +00:00
form
e6b3c0df6c upgrade to 4.14 2001-01-23 11:37:44 +00:00
form
cf210ccbab Upgrade to 4.13 2000-12-22 10:55:03 +00:00
form
9e65d3c443 add full name to MAINTAINER 2000-10-09 06:50:25 +00:00
form
1c122d39ff fix compiling; turan@
add HOMEPAGE
2000-06-16 03:32:24 +00:00
form
bf7a0796c3 remove FAKE=yes 2000-06-15 05:37:11 +00:00
form
e6d76ad7f4 upgrade to 4.11
install examples
2000-05-31 18:48:37 +00:00
form
663876fb09 upgrade to 4.1 2000-04-01 17:23:54 +00:00
form
ecdca085b0 Upgrade 4.04. 2000-03-22 10:37:15 +00:00
form
4d5be7f9d8 Upgrade to 4.03.
Fake.
PERMIT_*
2000-03-20 11:04:48 +00:00