Commit Graph

4859 Commits

Author SHA1 Message Date
espie
cba2887019 security fix "easter egg": old fckeditor is no longer supported, and the
new one tells you fckeditor-2.6.3 is holed... nasty
2010-03-05 10:07:59 +00:00
stephan
9076085bd6 security update to 5.22, addresses DRUPAL-SA-CORE-2010-001.
ok espie@
2010-03-05 09:39:52 +00:00
stephan
f691a20cad security update to 6.16, fixes DRUPAL-SA-CORE-2010-001.
ok jasper@, "I can vouch for it" @espie
2010-03-05 09:09:23 +00:00
stephan
b173411b8f security update to 1.4, fixes DRUPAL-SA-CONTRIB-2010-023.
ok jasper@ and espie@
2010-03-04 11:09:54 +00:00
jasper
28f9a1db02 - update statusnet to 0.8.3
among the many bugfixes is a security fix for a local file inclusion vulnerability.

ok sthen@
2010-03-03 14:17:33 +00:00
benoit
5ab72aa347 - update dillo to 2.2
- update patches
- regen PLIST

This update fixes security vulnerability.
Detailed information: http://secunia.com/advisories/38569/

ok jasper@
2010-03-01 14:53:31 +00:00
espie
816c0235eb a few more rotten eggs 2010-03-01 12:06:02 +00:00
espie
d5858ddd80 unprotect archive, so that clean works 2010-03-01 12:02:20 +00:00
william
efb25578f2 nginx-0.7.65; bugfixes
update from and reminded by Toni Mueller, thanks

ok jasper@
(reminder, ports is not fully open, do not commit without specific permission)
2010-03-01 04:04:50 +00:00
espie
7d1a6d8c2b oopsie 2010-02-28 23:56:20 +00:00
espie
6a383c71cd fix FULLPKGPATHs 2010-02-26 18:31:57 +00:00
sthen
3d9f13534b bump PKGNAMEs, the httpd abi changed, resulting in segfaults after
updating httpd until newly-built packages are installed.

ok espie@
2010-02-26 14:45:02 +00:00
robert
f43f8ed99e Install the tmp dir in the chroot with stricter permissions and change
owner to the www users.

ok ajacoutot@
2010-02-25 09:05:04 +00:00
naddy
2c0af6bc4f SECURITY update to 3.0.18:
MFSA 2010-05 XSS hazard using SVG document and binary Content-Type
MFSA 2010-04 XSS due to window.dialogArguments being readable cross-domain
MFSA 2010-03 Use-after-free crash in HTML parser
MFSA 2010-01 Crashes with evidence of memory corruption

Also fix some corrupted $OpenBSD keywords, pointed out by sthen@

ok sthen@
2010-02-24 18:17:23 +00:00
sthen
f13bb86663 SECURITY update to Firefox 3.5.8. Same diff from naddy@ and Daniel Dickman.
Update sqlite dependency while there.

ok naddy@
(reminder, ports is not fully open, do not commit without specific permission)
2010-02-24 16:59:49 +00:00
sthen
f2d5b5ba92 SECURITY fix, add patches from upstream to avoid a buffer overflow with
long URLs. Based on a diff from "iridium", similar diff from maintainer.
ok jasper@
2010-02-09 13:44:28 +00:00
jasper
d904463d52 saying pkg_arch=* when invoking cc is wrong wrong wrong
ok ajacoutot@
2010-02-06 22:15:21 +00:00
ajacoutot
c991d74a35 While I'm still unsure why gamin is needed at all, at least use a
correct run_depends: we mean gamin, not libgamin.

"go ahead" jasper@
2010-02-03 12:32:54 +00:00
jasper
82012ecbfd SECURITY FIX for CVE-2010-0308, "Squid DNS Packet Processing
Denial of Service Vulnerability"

brad (MAINTAINER) came up with the same diff
ok ajacoutot@ sthen@
2010-02-03 06:41:17 +00:00
pvalchev
7bfaeca2b9 gamin RUN_DEPENDS, from speedvin@archlinux.us; ok jasper espie 2010-02-03 01:05:41 +00:00
sthen
639fea5f60 SECURITY fix for CVE-2010-0295 DoS issue.
http://download.lighttpd.net/lighttpd/security/lighttpd_sa_2010_01.txt

From Brad, ok ajacoutot@ jasper@
2010-02-02 08:10:29 +00:00
espie
100f0c7870 SUBDIR += is wrong: it means the makefile will pick up SUBDIR from env, thus
breaking cd /usr/ports && SUBDIR=some/path make something for
category makefiles. While there, also put spaces around += uniformously.
okay naddy@, jasper@
2010-02-01 17:00:12 +00:00
jolan
ca7dbb81a7 fix MASTER_SITES, ok naddy@ 2010-01-30 19:08:30 +00:00
naddy
72b44c5513 bump PKGNAME for PLIST changes 4.6 -> 4.7 2010-01-27 21:43:27 +00:00
sthen
77516f5da3 Mention in MESSAGE that this package currently requires SSE2,
and show how to check. This should change sometime, but the
fix is fiddly and for now we should let people know. Committing
now to make sure something is in pre-4.7.

Discussed with pval, this diff ok jasper@ landry@
2010-01-26 15:48:21 +00:00
landry
1cbf5cc3c8 Add gstreamer plugins-ffmpeg & plugins-good to RUN_DEPENDS, somehow i
forgot it when updating to 1.1.18. This will be needed for the day HTML5
video actually works in webkit-based browsers..
ok espie@ jasper@
2010-01-23 10:14:37 +00:00
landry
26e100eda6 Add a patch to fix a use-after-free & a memory leak, from canacar@.
Fwded' and commited upstream.
ok jasper@ sthen@ no objection ajacoutot@
2010-01-19 14:25:08 +00:00
jasper
df30126d85 SECURITY FIX for CVE-2009-4427
phpLDAPadmin "cmd" Local File Inclusion Vulnerability

ok ajacoutot@
2010-01-13 14:36:52 +00:00
ajacoutot
d16d96252f SECURITY: CVE-2009-4489
http://www.vupen.com/english/advisories/2010/0090
(thanks fgsch@ for the link/notice)

Update to cherokee-0.99.39.
Remove debug FLAVOR and use ifdef DEBUG.
Add rrdtool to run_depends.
Byte-compile python modules so that they are registered in the PLIST.

Be careful as cherokee is not started using ${PREFIX}/sbin/cherokee, not
cherokee-guardian anymore.

Fernando Quintero (maintainer) ok
MESSAGE tweak and ok sthen@, ok jasper@
2010-01-13 08:47:57 +00:00
stephan
a4961caa75 - fix licence version
- tweak do-install (no change of PLIST)

ok sthen@ and landry@
2010-01-11 12:48:01 +00:00
stephan
84fdef559b use ${INSTALL_DATA} instead of @mv
reported by naddy@, almost identical diff + help from landry@
2010-01-11 10:45:53 +00:00
msf
1c9d24fcc9 bump PKGNAME again
requested by naddy@
2010-01-11 00:28:06 +00:00
landry
ca1f030fd3 Update to webkit 1.1.18:
- add a pair of patches to make it finally run without SIGBUS on sparc64
  (yay!), reported as https://bugs.webkit.org/show_bug.cgi?id=19775
- add a patch to disable some optimizations on ppc, so that it finally
  builds fine, reported as https://bugs.webkit.org/show_bug.cgi?id=33451
2010-01-10 20:06:17 +00:00
ajacoutot
977a59ba5c +py-htmltmpl 2010-01-10 13:59:14 +00:00
ajacoutot
61e32cf598 Import py-htmltmpl-1.22.
The purpose of the templating engine is to provide web application
developers, who need to separate program code and design (HTML code) of
their web application projects, with a templating tool that can be
easily used by cooperating webdesigners who have no programming skills.

Templating language provided by the engine is inspired by Perl
templating module HTML::Template. Templates created for HTML::Template
can be used with this engine in case they do not violate character case
rules of htmltmpl.

This package includes easydoc, a module which uses the templating engine
to generate HTML documentation from docstrings embedded in source files
of Python modules.


(needed by GNOME Development Monitor which I'm currently working on)
2010-01-10 13:58:06 +00:00
espie
b87f5ba044 update to more recent version, removes the waits during regress... 2010-01-10 13:45:03 +00:00
fgsch
f50c84fc13 Remove file imported by mistake. spotted by ajacoutot 2010-01-10 13:37:15 +00:00
fgsch
37dfdf0207 Enter py-mako and py-pylons. 2010-01-10 13:18:04 +00:00
fgsch
e1568d200f Import pylons 0.9.7, a rapid web application development framework. 2010-01-10 13:17:18 +00:00
fgsch
9f7f8fe969 Import Mako 0.2.5, a super-fast templating language. 2010-01-10 13:15:36 +00:00
fgsch
19a8400d7f Enter py-beaker 2010-01-10 13:01:51 +00:00
fgsch
c07da4e620 Import Beaker 1.5.1, a session and caching library with wsgi middleware 2010-01-10 12:59:22 +00:00
fgsch
f3c258c001 Update to WebOb 0.9.7.1. 2010-01-10 12:37:02 +00:00
fgsch
3b84802320 Update to WebTest 1.2 2010-01-10 12:36:35 +00:00
fgsch
399907446d Update to WSGIProxy 0.2 2010-01-10 12:36:06 +00:00
fgsch
7e30609618 Update to Routes 1.11 2010-01-10 12:35:28 +00:00
msf
0e3875c541 bump PKGNAME after MAINTAINER change
pointed out by naddy@
2010-01-10 08:46:49 +00:00
msf
16a1fd2dbf fix the dependency for dm-migrations and bump PKGNAME
pointed out by naddy@
2010-01-10 08:46:04 +00:00
fgsch
12329736e4 Update to repoze.profile 1.1. 2010-01-09 01:12:03 +00:00
fgsch
d016f18f8c Update to meld3 0.6.6 2010-01-09 01:11:23 +00:00
fgsch
eefd845627 Update to Tempita 0.4 2010-01-09 01:10:00 +00:00
kevlo
7d98d836e5 Update to 2.9.1
ok merdely@
2010-01-08 15:30:53 +00:00
stephan
5ac8dd3605 +mediawiki-httpauth 2010-01-08 13:22:28 +00:00
stephan
360c34a5c6 import mediawiki-httpauth-0.1
This extension works with MediaWiki instances setup behind HTTP
authentication. It pulls usernames from $_SERVER['PHP_AUTH_USER'].
The extension will then either log the user on to MediaWiki if the
user name exists in the database or create a new user if it does not.

"ok with me" jasper@, "yeah hell import it" landry@
2010-01-08 13:15:38 +00:00
jasper
7fe4d8bde1 - fix location of README.OpenBSD
spotted by viq
2010-01-06 21:54:04 +00:00
naddy
7ef0c5c7ee minor reliability update to 3.0.17 2010-01-06 14:37:35 +00:00
jasper
9dd125cf1b - add p5-WWW-Ebay 2010-01-06 09:46:37 +00:00
jasper
5c55f6991b import p5-WWW-Ebay 0.091
Collection of eBay-related modules.
2010-01-06 09:44:21 +00:00
jasper
deda363f2d - missing regress dependency 2010-01-06 09:32:46 +00:00
jasper
a00e7e92a2 - update WWW::Search::Ebay to 3.015 2010-01-06 09:27:38 +00:00
naddy
29007885ca minor reliability update to 3.5.7 2010-01-05 21:26:40 +00:00
jasper
0910a0a04f - hookup statusnet 2010-01-04 19:11:02 +00:00
jasper
20888a28da - remove flavors and tell the user how to enable mysql/pgsql in README.OpenBSD instead
- merge part of MESSAGE into the README

based on feedback from ajacoutot@, thanks.
2010-01-04 19:10:19 +00:00
jasper
9aa784ab71 - sort 2010-01-04 10:56:34 +00:00
ajacoutot
e26e4c59fd +community-id 2010-01-04 08:59:00 +00:00
ajacoutot
45594aefbb Import community-id-1.1.1
Community-ID is an OpenID implementation in PHP which is OpenID 2.0
compliant. Users can keep track of their trusted sites and manage them.
For Community-ID administrators statistics are available to track
registration of new users, authorized users per day or the number of
trusted sites. Administrators can set the site in maintenance mode or
send emails to all registered users.
2010-01-04 08:58:11 +00:00
ajacoutot
b20a9536c8 Flip categories. 2010-01-04 08:22:59 +00:00
ajacoutot
42b24e0d91 Some cleanups. 2010-01-04 08:15:49 +00:00
jasper
667cc8fd1b import statusnet 0.8.2
StatusNet (formerly Laconica) is a Free and Open Source microblogging
platform. It helps people in a community, company or group to exchange
short (140 character) messages over the Web. Users can choose which
people to "follow" and receive only their friends' or colleagues' status
messages. It provides a similar service to sites like Twitter, Jaiku,
Yammer, and Plurk.

not hooking it up to the builds yet, as it will need some more tweaking
to set up.
2010-01-03 17:29:35 +00:00
msf
198953c52f update to merb 1.0.15, which actually works with the version of datamapper
we have in tree. take maintainership

ok bernd@
2010-01-02 00:28:55 +00:00
robert
f98440fa15 - add mssql and pdo_dblib extensions from Antti Harri <iku@openbsd.fi>
- fix the odbc and soap configure args when they are disabled
2010-01-01 19:48:23 +00:00
eric
ebb1fdf249 update to 0.10.0
ok pea@
2009-12-31 12:34:45 +00:00
espie
7d383f48ef remove extra under-specified stdc++ libdepends. 2009-12-31 12:06:35 +00:00
kevlo
e5fa1b9d44 - update to 1.9.7; tested by Fred Crowson
- drop maintainership
2009-12-30 10:01:31 +00:00
naddy
3d0cae7c19 update to 2009.12.26: add support for format 37, 1920x1080 H.264/AAC MP4
ok pirofti@
2009-12-28 19:08:09 +00:00
stephan
52eb658617 update to 1.51, ok sthen@ and jasper@ 2009-12-28 09:09:55 +00:00
ajacoutot
b38975297f Update to timetrex-3.0.4.
"This release contains a couple new features, including additional weekly
overtime policy types and accrual milestone rollover limits, as well as
several bugfixes."
2009-12-27 18:17:47 +00:00
steven
a68eb4c3e0 fix README.OpenBSD path in message
noticed by Kent R. Spillner
2009-12-26 20:56:24 +00:00
landry
559d534fe0 update README.chroot : xcb and pthread-stubs are also needed 2009-12-23 18:58:54 +00:00
pirofti
833910e74f Add dmenu to RUN_DEPENDS. Now the URL-bar and the search-bar work.
`Go ahead' jasper@.
2009-12-23 11:42:09 +00:00
sthen
9998ef502d Use @unexec-delete instead of @unexec for the *-update-* goos.
prodded by espie@
discussed with espie@ ajacoutot@ landry@
2009-12-22 13:02:11 +00:00
giovanni
69154c4176 Update to 0.5.4 2009-12-22 10:41:45 +00:00
robert
cebc07826a Update to php-5.2.12 2009-12-22 10:39:28 +00:00
espie
039c8f0ce3 simpler poormanscron, backport from drupal7 2009-12-21 09:40:51 +00:00
espie
2a68d5ec19 new major version, lots of goodies 2009-12-21 09:38:23 +00:00
naddy
8ee6746f58 SECURITY update to 3.5.6. Fixes:
MFSA 2009-71 GeckoActiveXObject exception messages can be used to enumerate installed COM objects
MFSA 2009-70 Privilege escalation via chrome window.opener
MFSA 2009-69 Location bar spoofing vulnerabilities
MFSA 2009-68 NTLM reflection vulnerability
MFSA 2009-67 Integer overflow, crash in libtheora video library
MFSA 2009-66 Memory safety fixes in liboggplay media library
MFSA 2009-65 Crashes with evidence of memory corruption
2009-12-20 20:11:37 +00:00
ajacoutot
d83719c8d7 Move some LIB_DEPENDS to WANTLIB.
Regen PLIST.
2009-12-20 17:27:34 +00:00
ajacoutot
4f0da96839 Remove, this was imported under the wrong directory. 2009-12-20 14:19:59 +00:00
landry
acd818ba68 +p5-Net-SFTP-Foreign p5-WWW-IndexParser 2009-12-19 23:06:26 +00:00
landry
42d2ed28c0 Import p5-Net-SFTP-Foreign-1.55:
Net::SFTP::Foreign is a Perl client for the SFTP protocol version 3 as
defined in the SSH File Transfer Protocol IETF draft.
It uses any compatible ssh command installed on the system (for
instance, OpenSSH ssh) to establish the secure connection to the remote
server.
It is a lightweight alternative to p5-Net-SFTP.
2009-12-19 23:05:25 +00:00
landry
726d299233 Import p5-WWW-IndexParser-0.91:
WWW::IndexParser is a module that uses LWP to fetch a URL from a web
server. It then attempts to parse this page as if it were an auto
generated index page. It returns an array of WWW::IndexParser::Entry
objects, one per entry in the directory index that it has found. Each
Entry has a set of methods: filename(), time(), size(), and others if
supported by the autoindex generated: type() and size_units().
2009-12-19 23:02:07 +00:00
espie
9e940fe202 fix build 2009-12-19 16:56:07 +00:00
landry
fe5b625590 Update to midori 0.2.2, properly link to libnotify, and fix WANTLIB.
Note: this browser doesn't send your private informations to skynet.. :)
2009-12-19 12:59:41 +00:00
ajacoutot
74c13f9d8a Quotes around COMMENT are so 80's... 2009-12-18 23:26:34 +00:00
pvalchev
1cfd2c4b17 link chromium into the build 2009-12-18 22:28:53 +00:00
pvalchev
88e44963ff Initial import of Chromium for OpenBSD, a multi-month effort! :)
i386 and amd64 supported.

Chromium is an open-source browser project that aims
to build a safer, faster, and more stable way for all
Internet users to experience the web. http://www.chromium.org/

This is version 4.0.251.0 with a tarball already including hundreds
of patches by myself, Sprewell, Ben Laurie and others from the original
FreeBSD effort. See homepage for more details and known issue:
http://sightly.net/peter/openbsd/chromium/
(right now, there are i386 & amd64 -current packages there that can
be pkg_add'ed, links to the FreeBSD page for more info, etc)

The patches are being cleaned up and sent upstream in chunks, the
goal will be to have a clean tarball eventually. I _just_ got this
working earlier this week so it may crash and burn (especially on
amd64 as some parts do not appear 64-bit clean), let me know.

"commit it and let's work on it in-tree" espie@, robert@ & others
2009-12-18 22:25:56 +00:00
espie
68d5c7474a DRUPAL-SA-CORE-2009-009
Vulnerabilities in Contact module, XSS if malicious users can create menus.
2009-12-18 19:05:57 +00:00
naddy
9d0588f952 SECURITY update to 3.0.16:
MFSA 2009-71 GeckoActiveXObject exception messages can be used to enumerate installed COM objects
MFSA 2009-70 Privilege escalation via chrome window.opener
MFSA 2009-69 Location bar spoofing vulnerabilities
MFSA 2009-68 NTLM reflection vulnerability
MFSA 2009-65 Crashes with evidence of memory corruption
2009-12-17 22:08:13 +00:00
landry
6a2528063b Fix a nasty hardcoded /usr/local which wasn't patched away, use
TRUEPREFIX instead. spotted while looking at tabbed port..
2009-12-17 21:06:20 +00:00
ajacoutot
5885d79b57 Update to epiphany-2.28.2.
Regen wantlib while here.
2009-12-16 11:47:11 +00:00