whoops back out previous that wasn't supposed to go to pkgsrc-2007Q4
add/update patches to introduce LDFLAGS to links in the package
identified by Charles Zmudzinski in pr pkg/32275 - use EXPORT_SYMBOLS_LDFLAGS as suggested by salo@ - resolves pkg/32275
2008-02-19Tickets #2288, 2290.ghen1-1/+5
Pullup ticket 2290 - requested by obache
security update for RealPlayerGold
Update RealPlayerGold to Patch provided by Brian de Alwis in PR 37371. What's New in Security bugs fixes. Fixed crashes in the embedded player while playing songs from some music web sites.
Pullup ticket 2288 - requested by martti
latest update for clamav
Updated mail/clamav to 0.92.1
* Fix pkg/36853 with patch from Christos Zoulas (patch-ba)
* Lots of bug fixes since 0.92
2008-02-11Ticket #2287.ghen1-1/+3
Pullup ticket 2287 - requested by drochner
security fixes for mplayer and mencoder
add some patches from upstream which fix CVE-2008-0485, CVE-2008-0486 and two unnamed buffer overflows, bump PKGREVISION of affected pkgs
2008-01-29Tickets #2278, 2281, 2282.ghen1-1/+7
Pullup ticket 2282 - requested by tron
security update for apache22
Update to 2.2.8, please check for the list of changes.
Pullup ticket 2281 - requested by drochner
security fix for libsndfile
fix CVE-2007-4974 (buffer overflow), patch from Gentoo bump PKGREVISION
Pullup ticket 2278 - requested by taca
security update for apache2
Start update of apr0 pacakge to 0.9.17 and apache2 package to 2.0.63.
Update apr0 package to
Changes with APR 0.9.17
*) Fix DSO-related crash on z/OS caused by incorrect memory allocation. [David Jones <oscaremma>]
*) Define apr_ino_t in such a way that it doesn't change definition based on the library consumer's -D'efines to the filesystem. [Lucian Adrian Grijincu <lucian.grijincu>]
*) Cause apr_file_dup2() on Win32 to update the MSVCRT psuedo-stdio handles for fd-based and FILE * based I/O. [William Rowe]
*) Revert Win32 to the 0.9.14 behavior of apr_proc_create() for any of the three stdio streams which are not initialized, through either apr_procattr_io_set() or apr_procattr_child_XXX_set(), when given a procattr_t with one or two streams which were initialized through apr_procattr_child_XXX_set(). Once again, these do not inherit the parent process stdio stream to WIN32 child processes (passing INVALID_HANDLE_VALUE instead) as on Unix. Note APR 1.3.0 adopts the Unix behavior of inheriting any uninitialized streams as the parent's corresponding stdio stream, in such cases. [William Rowe]
Update apache package to 2.0.63.
Changes with Apache 2.0.63
*) winnt_mpm: Resolve modperl issues by redirecting console mode stdout to /Device/Nul as the server is starting up, mirroring unix MPM's. PR: 43534 [Tom Donovan <Tom.Donovan>, William Rowe]
*) winnt_mpm: Restore Win32DisableAcceptEx On directive and Win9x platform by recreating the bucket allocator each time the trans pool is cleared. PR: 11427 #16 (follow-on) [Tom Donovan <Tom.Donovan>]
Changes with Apache 2.0.62 (not released)
*) SECURITY: CVE-2007-6388 ( mod_status: Ensure refresh parameter is numeric to prevent a possible XSS attack caused by redirecting to other URLs. Reported by SecurityReason. [Mark Cox, Joe Orton]
*) SECURITY: CVE-2007-5000 ( mod_imagemap: Fix a cross-site scripting issue. Reported by JPCERT. [Joe Orton]
*) Introduce the ProxyFtpDirCharset directive, allowing the administrator to identify a default, or specific servers or paths which list their contents in other-than ISO-8859-1 charset (e.g. utf-8). [Ruediger Pluem]
*) log.c: Ensure Win32 resurrects its lost robust logger processes. [William Rowe]
*) mpm_winnt: Eliminate wait_for_many_objects. Allows the clean shutdown of the server when the MaxClients is higher then 257, in a more responsive manner [Mladen Turk, William Rowe]
*) Add explicit charset to the output of various modules to work around possible cross-site scripting flaws affecting web browsers that do not derive the response character set as required by RFC2616. One of these reported by SecurityReason [Joe Orton]
*) http_protocol: Escape request method in 405 error reporting. This has no security impact since the browser cannot be tricked into sending arbitrary method strings. [Jeff Trawick]
*) http_protocol: Escape request method in 413 error reporting. Determined to be not generally exploitable, but a flaw in any case. PR 44014 [Victor Stinner <victor.stinner>]
Add comment that this file is used by devel/apr0/Makefile detected by pkglint.
2008-01-15Tickets #2264-2268.ghen1-1/+11
Pullup ticket 2268 - requested by adrianp
security update for drupal
Update to 5.6 This release fixes security vulnerabilities. Sites are urged to upgrade immediately. For more details, please see the security announcement: SA-2008-005 - Drupal core - Cross site request forgery SA-2008-006 - Drupal core - Cross site scripting (UTF8) SA-2008-007 - Drupal core - Cross site scripting (register_globals) In addition to this security vulnerability, the following bugs have been fixed since the 5.5 release: 173858 by Gábor Hojtsy: skip UTF-8 BOM when importing locale files 179164 by Heine: sort modules by name on the module admin page 199640 by webernet: (usability) add option to select no taxonomy term in multiselect forms, not to rely on browser trickery 199084 by chx: better conformance with ISO date formats in our xmlrpc code 173459 by Dave Cohen. Backport of #78487 by FredCK, forngren and bjaspan: document support in url() and l() and proper active class support for . 89218 by Gábor Hojtsy. Properly initialize a counter variable and fix poll editing. 64388 by Gábor Hojtsy. Add missing db_rewrite_sql(); not a security issue since it is a count() query. 200338 by m3avrck and quicksketch: fix transparent GIF resizing 194652 by Heine: specify explicit accept-charset for forms to avoid browser guessing 182410 by greggles: HTTP Basic authentication username and password was parsed in drupal_http_request() but then not used in the request - Patch 201894 by David Rothstein: fixed typo in user output. 180126 by mmoreno, drewish and scor: add realpath() call to file_save_data(), so Windows will create temporary files properly 115689 by chx: new content types should not overwrite old ones. Backport by Pancho. 203727 by Arancaytar. More effectively use hook API. 204855 by webernet. Add missing * in documentation. 168315 by schuyler1d: previous active database name was not consistently returned in db_set_active() - Patch 199955 by saxofaan: file_upload_max_size() returns results in bytes, not in mega bytes. 194579 patch by pwolanin: clear filter cache when allowed HTML tags configuration changes in an input format #166433 by Ralf Stamm. Use correct menu item type for revsion confirm pages. 58806 by fwalch and wicksteedc. Do not override MENU_VISIBLE_IF_HAS_CHILDREN on editing. Partial backport of 112715 to fix 124641. Changes from 5.4 -> 5.5 Fixed missing missing brackets in a query in the user module. Fixed taxonomy feed bug introduced by SA-2007-031
Pullup ticket 2265 - requested by adrianp
security update for kronolith
Major changes compared to the Kronolith H3 (2.1.6) version are: * Fixed privilege escalation in the Horde API. * Fixed missing ownership validation on share changes. * Updated Japanese translation. * Small bugfixes and improvements.
Pullup ticket 2264 - requested by adrianp
security update for turba
Major changes compared to the Turba H3 (2.1.5) version are: * Fixed privilege escalation in the Horde API. * Updated Japanese translation.
Pullup ticket 2266 - requested by adrianp
security update for horde
Major changes compared to Horde 3.1.5 are: * Fixed privilege escalation in the Horde API. * Improved XSS filtering. * Fixed locked portal blocks. * Further improved webroot detection. * Updated Japanese translation.
Pullup ticket 2267 - requested by adrianp
security update for php4
Update to 4.4.8 Improved fix for MOPB-02-2007. Fixed an integer overflow inside chunk_split(). Identified by Gerhard Wagner. Fixed integer overlow in str[c]spn(). Fixed regression in glob when open_basedir is on introduced by 41655 fix. Fixed money_format() not to accept multiple %i or %n tokens. Addded "max_input_nesting_level" php.ini option to limit nesting level of input variables. Fix for MOPB-03-2007. Fixed INFILE LOCAL option handling with MySQL - now not allowed when open_basedir or safe_mode is active. Fixed session.save_path and error_log values to be checked against open_basedir and safe_mode (CVE-2007-3378). Fixed bug 43010 (Fixed regression in imagearc with two equivelent angles). Fixed bug 41765 (Recode crashes/does not work on amd64). Fixed bug 41630 (segfault when an invalid color index is present in the image data). Fixed bug 41628 (PHP settings leak between Virtual Hosts in Apache 1.3). Fixed bug 38798 (OpenSSL init corrected in php5 but not in php4).
2008-01-13Ticket #2260.ghen1-1/+3
Pullup ticket 2260 - requested by tron
security update for sun-jdk/jre15
security update for sun-jdk/jre15 - pkgsrc/lang/sun-jdk15/Makefile 1.28 - pkgsrc/lang/sun-jdk15/distinfo 1.17 - pkgsrc/lang/sun-jre15/Makefile 1.49 - pkgsrc/lang/sun-jre15/PLIST.linux-i386 1.6 - pkgsrc/lang/sun-jre15/PLIST.linux-x86_64 1.4 - pkgsrc/lang/sun-jre15/distinfo 1.18 Module Name: pkgsrc Committed By: tron Date: Mon Jan 7 19:56:28 UTC 2008 Modified Files: pkgsrc/lang/sun-jdk15: Makefile distinfo pkgsrc/lang/sun-jre15: Makefile PLIST.linux-i386 PLIST.linux-x86_64 distinfo Log Message: Update "sun-jre15" and "sun-jdk15" packages to vesion 5.0.14. Changes since version 5.0.12: 6457444 doclet stddoclet javadoc does not create html file correctly in 5.0u6 6519085 hotspot compiler2 JVM crashes executing test suite of JavaDB (derby) 6321689 hotspot compiler2 Ideal_DU_postCCP not conservative enough 6565138 hotspot compiler2 1.5.0_10 64-Bit SIGBUS with ParallelGC in MarkSweep::MarkAndPushClosure::do_oop 6545719 hotspot garbage_collector Regression : Infinite GC occurs after fix in CR 6370163 6558100 hotspot garbage_collector CMS crash following parallel work queue overflow 6515362 hotspot runtime_system fix for 6374419 suppresses real error message from the linker 6528763 hotspot runtime_system VM crashes because of something related to LoaderConstraintEntry in 6.0 6546278 hotspot runtime_system Synchronization problem in the pseudo memory barrier code 6553303 idl orb Corba application fails w/ org.omg.CORBA.COMM_FAILURE: vmcid: SUN minor code: 203 completed: No 6543815 java classes_2d Imageable area of PageFormat is ignored if values of imageable X/Y are negative. 6480378 java classes_awt Backport 5065001, 6259348 and others to 5.0 update release 6577717 java classes_awt Textboxes don't work in applets under windows and linux 6562716 java classes_awt focus request queue is not updated when rejecting focus on EmbeddedFrame (win32) 6542420 java classes_awt A cross-platform ModalityListener interface should be provided in 1.5.0 6593729 java classes_io After failed file close, do not repeat the close operation. 6525425 java classes_lang (ref) heavy lock contention during object serialization on Solaris10/T2000 6206527 java classes_net "cannot assign address" when binding ServerSocket on Suse 9 6601686 java classes_net InetAddress.isReachable(timeout) may not return after timout milliseconds 6599750 java classes_net InetAddress.isReachable implementation not completely thread safe 6518816 java classes_net Reduce the memory foot print for HttpURLConnection 6520665 java classes_net NTLM Authentication not requested, throws null exception 6587875 java classes_net InetAddress.isReachable() will not work for super users with "large" process ids 6314370 java classes_net Nightly: Jaws hang on "Starting application..." window 6469580 java classes_security 1.5.0_08 JVM crashes in SignatureHandlerLibrary::add on Fujitsu Primepower platform 6418433 java classes_security org.ietf.jgss.Oid constructor accepts invalid values (and rejects valid values) 6570062 java classes_security Kerberos authentication regression 6543940 java classes_security Exception thrown when signing a jarfile in java 1.5 6512054 java classes_security SUBJECTDOMAINCOMBINER DOES NOT COMBINE CODE-BASED GRANTS IN JAAS MODE 6520101 java classes_swing FileChooser will cause OutOfMemory when application will run long time 4743558 java classes_text [BI] test/java/text/BreakIterator/ fails in th locale. 6483402 java classes_util_i18n (date) calling java.util.Date.toString() slows down subsequent calls to the class 6531591 java classes_util_i18n Currency update for Sudan 6538601 java classes_util_i18n Periodical timezone display name revision 6554586 java classes_util_i18n (tz) Support tzdata2007f 6611886 java classes_util_i18n (tz) support tzdata2007h 6571205 java classes_util_i18n Currency data changes for ISO 4217 Amendment 139 6570259 java classes_util_i18n Currency data changes for ISO 4217 Amendment 138 6531593 java classes_util_i18n Currency update for Iceland 5088563 java classes_util_regex Matcher.find throws StringIndexOutOfBoundsException if pattern is missing ']' 6464451 java compiler javac in 5.0ux can not compile try-catch block which has a lot of "return" 6557713 java imageio Java unable to convert from gif to png format 6579208 java install FamilyVersionSupport removed when installing jre-6u2-windows-i586-p.exe 6476329 java localization PIT: additional sentence needs to be translated for 6267625 6531255 java localization Need to update timezone display names for en_CA locale 6534678 java localization l10n of 6525138 6547501 java localization There should be a space before % sign in French locale 6454676 java serviceability Need -XX:+HeapDumpOnCtrlBreak to trigger heap dump on ctrl-break or ctrl-\ 6494472 java serviceability jmap -permstat fails with Out of swap because uses too much memory 6494722 java serviceability SA: jstack throws get_thread_regs failed for lwp debugger exception. 6431847 java tools Memory overflow in java launcher for Linux 6502051 java_deployment update jusched crash: buffer overrun 6503510 java_plugin iexplorer Crash occurs during verification of 5.0u10b02 6555628 java_plugin iexplorer Repeatedly open and close an applet freezes IE 6572147 java_plugin iexplorer Browser hang as an applet open and close repeatedly in 0.5-sec interval 6578895 java_plugin iexplorer NPE null pData general exeception occured as applet reloading repeatedly 6579743 java_plugin iexplorer Regression : Java Console pops up unexpectedly in 5.0u13-b01 6576321 java_plugin iexplorer Browser hang by a deadlock with open and close applet repeatedly 6522028 java_plugin iexplorer The print dialog moves the current IE frame to background 6530198 java_plugin misc 1.5.0_10 focus is not correctly returned to a JFrame 6586045 java_plugin misc browser crashes on an XP japanese machine with 6u5 deploy nightly build 6502568 java_plugin other request header has garbage characters when size of cookie is greater than 4k 6556044 java_plugin other JRE SSL Handshake error in jdk1.5.0 6373274 javawebstart download_engine Jar resources nested in JRE resources block are broken. 6465756 javawebstart jnlp_file cannot use CDATA xml tag within the jnlp <argument> tag 6265713 javawebstart jnlp_file Having a query string to a jnlp file negates the SingleInstanceService 6484661 javawebstart other cannot launch application offline if https is used 6354969 jaxp other Bug in XPathFactory.newInstance() method 6219364 jaxp sax com.SAXParserImpl.setProperty("feature",null) throws NullPointerException 6594813 jaxp sax XML Parsing differences 6236727 jaxp xslt XSLTC never stops resolving imported stylesheets when outer stylesheet is a DOMSource 6536120 jaxp xslt HTML serializer puts no space between public and system doctype 6490921 jaxp xslt The transformer API sometimes ignores the property org.xml.sax.driver 6467921 jce pkcs11_csp Backport SunPKCS11 to a Tiger update on 64 bit AMD Linux platform 6560218 jgss krb5plugin Problem with credentials from non-default realm 5053708 jndi dns DNS provider does not cleanup resources properly 6585239 jndi dns Regression: 2 DNS tests fail with JDK 5.0u13 b01 and pass with 5.0u12fcs 6358629 jsse runtime SSLSocket.close() and deadlock 6447412 jsse runtime Issue with socket.close() for ssl sockets when poweroff on other system 6585736 java classes_security Add GlobalSign root certificates to JDK/JRE 6595137 java classes_util_i18n (tz) support tzdata2007g The x86_64 changes were done by Takahiro Kambe.
2008-01-10Tickets #2257, 2258, 2259.ghen1-1/+7
Pullup ticket 2259 - requested by adam
security updates for postgresql
Changes 8.0.15: This release contains a variety of fixes from 8.0.14, including fixes for significant security issues. This is the last 8.0.X release for which the PostgreSQL community will produce binary packages for Windows. Windows users are encouraged to move to 8.2.X or later, since there are Windows-specific fixes in 8.2.X that are impractical to back-port. 8.0.X will continue to be supported on other platforms.
Changes 8.1.11: This release contains a variety of fixes from 8.1.10, including fixes for significant security issues. This is the last 8.1.X release for which the PostgreSQL community will produce binary packages for Windows. Windows users are encouraged to move to 8.2.X or later, since there are Windows-specific fixes in 8.2.X that are impractical to back-port. 8.1.X will continue to be supported on other platforms.
Changes 8.2.6: This release contains a variety of fixes from 8.2.5, including fixes for significant security issues.
Pullup ticket 2258 - requested by sketch
build fix for libiconv
Remove the preprocessor test for 'long long int', it fails with SunPro causing later compile-time tests to break. Taken from gnulib change in
Pullup ticket 2257 - requested by joerg
build fix for openssl
Fix logic for thread feature if no native OpenSSL exists. Fixes PR pkg/37699 from Aleksey Cheusov.
2008-01-03Ticket 2255.ghen1-1/+3
Add CHANGES file for the pkgsrc-2007Q4 branch.
Pullup ticket 2255 - requested by joerg
build fix for erlang
Mark as broken on NetBSD/amd64 as configure will spin.
2008-01-02+ SDL-1.2.13, geda-, gmime-2.2.14, gthumb-2.10.8,wiz1-8/+10
libopensync-0.35, nut-13.1, tea-17.5.0, wxRemind-16, xterm-230.
Note update of opera-9.25 that someone did and did not update the
required files... a brick for him.
Add another REPLACE_PERL for a perl script to replace interpreter.
Skip an interpreter check for a python script (as the REPLACE_PERL is ignored because no python dependency yet). (Add a TODO for later: add an option for reStructuredText support to depend on python-docutils.) Bump PKGREVISION. Noticed in bulk builds. Fixed this during freeze so it will be built by some bulk builders and available with the upcoming quarterly branch packages. This is a leaf package.
Patches that replace the == argument to test(1) with a single = don't
need to be commented upon at all. Fixes PR 37167.
Look out for the case where audit-packages is already installed with the
base OS on NetBSD.
I don't have access to IRIX anymore.
Updated mail/dovecot to 1.0.10.
Add CHANGES file for 2008.
Update to Dovecot 1.0.10.
v1.0.8 and v1.0.9 were a bit bad releases. Hopefully one day I've managed to have written a proper test suite which can be run before doing any releases.. * Security hole with LDAP+auth cache: If base setting contained %variables they weren't included in auth cache key, which broke caching. This could have caused different users with same passwords to log in as each other. [pkgsrc: this was fixed in dovecot-1.0.9nb1] - LDAP: Fixed potential infinite
2008-01-01If one of the NO_*_ON_* variables contains something other thatrillig1-2/+7
${RESTRICTED}, print the variable name in the warning message. While here, added an explanation for the warning.
2008-01-01Make this package pass the check-interpreters part of the installationagc1-1/+22
process on NetBSD. XXX - more work required on other platforms.
2008-01-01Fix our lisp patch. I've checked building this package with both emacs20cjep2-6/+6
and emacs21. Addresses PR#30131.
2008-01-01Update ns-remote to 1.11nb4 - from PR/37624 by Eric Schnoebelen:abs2-4/+4
- Include seamonkey as a valid option in NETSCAPE_PREFERRED
2008-01-01xsltproc is needed for build.joerg1-1/+3
2008-01-01update alpine to 1.00nb1 - only pass --without-pthread on NetBSD 4.x and earlierabs1-2/+3
2008-01-01Fix build with scrollkeeper-config related changes.joerg2-1/+15
2008-01-01*MODE are also passed by framework automatically now.obache3-11/+3
2008-01-01Add more *ONW, *GRP and *MODE variables to BSD_MAKE_ENV for unprivileged build.obache1-1/+5
2008-01-01All characters in PLIST files are relevant, so make trailing white-spacerillig1-2/+6
an error. Who would ever want to install files whose name ends in white-space?
2007-12-31 Update to 1.0.6 (well, actually a release candidate, but it makes thebjs3-7/+14
most sense to me to bump the revision if there're changes). I thought it would be nice to have this in pkgsrc for the upcoming release. In this release: The author of psftools, John Elliot <>, has kindly written a utility for the NetBSD community which produces wsfont kernel headers from psf-format fonts-- and does a fantastic job of it, at that. If you're interested, install this package and see the psf2bsd(1) manual page. Also in this update: * psf2wyse: New utility to convert a PSF to a soft font that can be uploaded into a Wyse-60 or compatible terminal. * wyse2psf: Reverses psf2wyse; converts a Wyses soft font to PSF.
2007-12-31Add support for NetBSD 4.0 compatibility through installing compat40jlam18-8/+711
and netbsd32_compat40 packages. The compat40 packages are currently built by comparing the 4.0 release against the 20071230 version of HEAD. Commit approved by <agc>.
2007-12-31Add the script that I use to generate distfiles and PLISTs for NetBSDjlam1-0/+129
compat* packages.
2007-12-31Fix the description to refer to NetBSD-3.0 instead of NetBSD-2.0.jlam1-3/+3