[owc] Weekly ports changes ending 2006-05-07

OWC auto at squish.net
Mon May 8 08:12:16 BST 2006


OpenBSD ports changes summary for 2006-04-30 to 2006-05-07 inclusive
====================================================================

archivers/zoo                           audio/mt-daapd
converters/p5-Convert-ASN1              databases
databases/directoryassistant            databases/mdbtools
databases/mysql                         databases/p5-DBIx-DBSchema
databases/p5-DBIx-SearchBuilder         devel
devel/p5-Module-CoreList                devel/p5-Want
devel/p5-capitalization                 devel/svk
emulators                               emulators/generator
graphics                                graphics/dia
graphics/luagd                          graphics/p5-Chart
graphics/p5-Image-ExifTool              infrastructure/db
infrastructure/plist                    infrastructure/templates
lang/jamvm                              mail/exim
mail/hashcash                           mail/mailman
mail/mozilla-thunderbird                mail/msmtp
net                                     net/curl
net/jabberd                             net/lftp
net/nagios                              net/nepenthes
net/nsd                                 net/openvpn
net/p5-Nmap-Parser                      net/pebrot
net/ssldump                             security
security/clamav                         security/gnupg
security/nessus                         security/p0f
security/p5-Authen-SASL                 security/p5-Crypt-CBC
security/p5-GSSAPI                      security/swatch
sysutils                                sysutils/ipmitool
sysutils/nut                            www/mediawiki
www/mozilla                             www/mozilla-firefox
www/nostromo                            www/p5-HTML-Mason
x11/kde                                 x11/mplayer
x11/rep-gtk                             

== archivers ========================================================= 01/15 ==

  http://www.openbsd.org/cgi-bin/cvsweb/ports/archivers

zoo

  ~ Makefile                              + patches/patch-misc_c
  + patches/patch-parse_c                 + patches/patch-portable_c

  TAGGED OPENBSD_3_9
  > MFC:
  > fix several buffer overflows/issues from gentoo/fedora, brought up
  > by Rui Reis <rui at rui.cx more exist for sure... (sturm@)

== audio ============================================================= 02/15 ==

  http://www.openbsd.org/cgi-bin/cvsweb/ports/audio

mt-daapd

  ~ Makefile                              ~ distinfo
  ~ patches/patch-configure               

  > update to mt-daapd-0.2.4
  > from maintainer Arnaud Bergeron <abergeron at gmail.com> (sturm@)

== converters ======================================================== 03/15 ==

  http://www.openbsd.org/cgi-bin/cvsweb/ports/converters

p5-Convert-ASN1

  ~ Makefile                              ~ distinfo

  > update to 0.20 (kevlo@)

== databases ========================================================= 04/15 ==

  http://www.openbsd.org/cgi-bin/cvsweb/ports/databases

databases

  ~ Makefile                              

  > +mdbtools (forgot to say, thx jasper for tests) (espie@)

  ~ Makefile                              

  > Add directoryassistant (alek@)

  ~ Makefile                              

  > +p5-DBIx-DBSchema (msf@)

directoryassistant

  + Makefile                              + distinfo
  + pkg/DESCR                             + pkg/PLIST

  > New import:
  >	Import directoryassistant 2.0

mdbtools

  + snapshot/distinfo                     + snapshot/Makefile
  + snapshot/pkg/PLIST                    + snapshot/pkg/PFRAG.shared
  + snapshot/pkg/DESCR                    + snapshot/pkg/PLIST-gmdb
  + snapshot/pkg/DESCR-gmdb               
  + snapshot/patches/patch-doc_Makefile_in
  + snapshot/patches/patch-src_libmdb_file_c
  + snapshot/patches/patch-src_gmdb2_sql_c

  > New import:
  >	read access database files (jet format 3.0 and 4.0)

  ~ snapshot/Makefile                     

  > you are here ---> . (naddy@)

mysql

  ~ Makefile                              ~ distinfo
  ~ patches/patch-configure_in            
  ~ patches/patch-mysql-test_mysql-test-run_sh
  ~ patches/patch-sql_mysqld_cc           ~ pkg/PLIST-server
  ~ pkg/PLIST-tests                       

  > upgrade to MySQL 5.0.20a (brad@)

p5-DBIx-DBSchema

  + Makefile                              + distinfo
  + pkg/PLIST                             + pkg/DESCR

  > New import:
  >	initial import of DBIx::DBSchema 0.31

p5-DBIx-SearchBuilder

  ~ Makefile                              ~ distinfo
  ~ pkg/PLIST                             

  > update to 1.43 (msf@)

== devel ============================================================= 05/15 ==

  http://www.openbsd.org/cgi-bin/cvsweb/ports/devel

devel

  ~ Makefile                              

  > +p5-capitalization (msf@)

p5-Module-CoreList

  ~ Makefile                              ~ distinfo

  > update to 2.04 from maintainer Jasper Lievisse (msf@)

p5-Want

  ~ Makefile                              ~ distinfo

  > update to 0.10 from maintainer Jasper Lievisse (msf@)

p5-capitalization

  + distinfo                              + Makefile
  + pkg/PLIST                             + pkg/DESCR

  > New import:
  >	initial import of capitalization 0.03

svk

  ~ Makefile                              ~ distinfo

  > update to svk 1.0.7 (kevlo@)

== emulators ========================================================= 06/15 ==

  http://www.openbsd.org/cgi-bin/cvsweb/ports/emulators

emulators

  ~ Makefile                              

  > +generator (jolan@)

generator

  + distinfo                              + Makefile
  + pkg/PLIST                             + pkg/DESCR

  > New import:
  >	generator-0.35r2, sega genesis emulator

== graphics ========================================================== 07/15 ==

  http://www.openbsd.org/cgi-bin/cvsweb/ports/graphics

graphics

  ~ Makefile                              

  > +p5-Image-ExifTool (steven@)

  ~ Makefile                              

  > Add LuaGD (pedro@)

dia

  ~ Makefile                              
  + patches/patch-plug-ins_xfig_xfig-import_c
  + patches/patch-plug-ins_xfig_xfig_h    

  TAGGED OPENBSD_3_9
  > MFC:
  > SECURITY FIX:
  > A voluntary security review of the importers by infamous41md has turned up
  > three buffer overflow errors in the xfig import code.
  > Details:
  > http://mail.gnome.org/archives/dia-list/2006-March/msg00149.html (sturm@)

luagd

  + distinfo                              + Makefile
  + patches/patch-luagd_c                 + files/init.lua
  + files/gd.lua                          + pkg/DESCR
  + pkg/PLIST                             + pkg/PFRAG.shared

  > New import:
  >	LuaGD, a binding of the GD library for Lua, prod and okay jolan@

p5-Chart

  ~ Makefile                              ~ distinfo
  ~ pkg/PLIST                             

  > update to Chart-2.4.1, which includes a manpage now (djm@)

p5-Image-ExifTool

  + Makefile                              + distinfo
  + pkg/DESCR                             + pkg/PLIST

  > New import:
  >	import p5-Image-ExifTool 6.00

== infrastructure ==================================================== 08/15 ==

  http://www.openbsd.org/cgi-bin/cvsweb/ports/infrastructure

db

  ~ systrace.filter                       

  > Permit __getcwd, noticed by uwe@, okay sturm@ (pedro@)

plist

  ~ arm                                   

  > add ion; aanriot (pvalchev@)

templates

  ~ network.conf.template                 

  > take out failing mirrors and introduce new ones for CPAN and GNU.
  > from Jim Razmus <jim at bonetruck.org>, thanks! (steven@)

== lang ============================================================== 09/15 ==

  http://www.openbsd.org/cgi-bin/cvsweb/ports/lang

jamvm

  ~ Makefile                              

  > unbreak mirror-maker, there should be no trailing slash in *_DEPENDS
  > (sturm@)

== mail ============================================================== 10/15 ==

  http://www.openbsd.org/cgi-bin/cvsweb/ports/mail

exim

  ~ Makefile                              ~ distinfo
  ~ patches/patch-scripts_exim_install    ~ pkg/DESCR
  ~ pkg/PLIST                             

  > update to exim 4.62
  > from maintainer Andreas Voegele <andreas at altroot.de> (sturm@)

hashcash

  ~ Makefile                              ~ distinfo

  TAGGED OPENBSD_3_9
  > MFC:
  > SECURITY update to hashcash 1.21
  > fix potential heap overflow bug reported by Andreas Seltenreich
  > from Armin Wolfermann (maintainer) (sturm@)

mailman

  ~ Makefile                              ~ distinfo
  ~ pkg/PLIST                             

  TAGGED OPENBSD_3_9
  > MFC:
  > upgrade to mailman 2.1.8; recommended upgrade as this fixes a cross-site
  > scripting security bug in the previous release (CVE-2006-1712). (sturm@)

mozilla-thunderbird

  - patch-toolkit_components_history_src_nsGlobalHistory_cpp
  - patch-xpfe_components_history_src_nsGlobalHistory_cpp
  ~ Makefile                              ~ distinfo

  > update to 1.5.0.2
  > fixes multiple critical vulnerabilities (wilfried@)

  - patches/patch-htmlparser_public_nsHTMLTagList_h
  - patches/patch-htmlparser_src_COtherElements_h
  - patches/patch-htmlparser_src_nsElementTable_cpp
  - patches/patch-htmlparser_src_nsHTMLTags_cpp
  - patches/patch-htmlparser_tools_gentags_pl
  ~ Makefile                              ~ distinfo

  TAGGED OPENBSD_3_8
  > update to mozilla-thunderbird 1.0.8
  > several security fixes (sturm@)

  - patches/patch-htmlparser_public_nsHTMLTagList_h
  - patches/patch-htmlparser_src_COtherElements_h
  - patches/patch-htmlparser_src_nsElementTable_cpp
  - patches/patch-htmlparser_src_nsHTMLTags_cpp
  - patches/patch-htmlparser_tools_gentags_pl
  ~ Makefile                              ~ distinfo

  TAGGED OPENBSD_3_7
  > update to mozilla-thunderbird 1.0.8
  > several security fixes (sturm@)

  - patches/patch-toolkit_components_history_src_nsGlobalHistory_cpp
  - patches/patch-xpfe_components_history_src_nsGlobalHistory_cpp
  ~ Makefile                              ~ distinfo

  TAGGED OPENBSD_3_9
  > MFC:
  > update to 1.5.0.2
  > fixes multiple critical vulnerabilities (sturm@)

msmtp

  ~ Makefile                              ~ distinfo

  > update to msmtp 1.4.5
  > from Simon Kuhnle <simonkuhnle at web.de>
  > maintainer timeout (sturm@)

== net =============================================================== 11/15 ==

  http://www.openbsd.org/cgi-bin/cvsweb/ports/net

net

  ~ Makefile                              

  > cjk flavor has been removed from pebrot (naddy@)

  ~ Makefile                              

  > +p5-Nmap-Parser (msf@)

curl

  ~ Makefile                              ~ distinfo

  TAGGED OPENBSD_3_9
  > MFC:
  > SECURITY: Update to 7.15.3.
  > Fixes TFTP packet buffer overflow vulnerability. (CVE-2006-1061) (sturm@)

jabberd

  ~ Makefile                              ~ distinfo

  TAGGED OPENBSD_3_9
  > MFC:
  > SECURITY: update to 2.0s11
  > http://jabberstudio.org/projects/jabberd2/releases/view.php?id=826
  > * Sending a stanza before an stanza during a SASL negotiation can
  > cause a c2s segfault. Leading to a remote DoS
  > http://jabberstudio.org/projects/jabberd2/releases/view.php?id=802
  > * fixed SASL anonymous, bug#126
  > * fixed edge cases with new dynamic jid code
  > * fixed incorrect free order in c2s, byg#125
  > * corrected debug logging, bug#119
  > * fixed s2s bus error on 64-bit architectures, bug#122
  > * fixed c2s collisions due to long jids, bug#118
  > * fixed error response to iq result, bug#110
  > * fixed roster pushing packets without id, bug#73
  > * applied new dynamic jid patch, bug#100
  > * fixed double free of nad in c2s and s2s, bug#97
  > * major memory enhancement, made jid structure dynamically allocated,
  > bug#100
  > * fixed glibc error with custom sql statements, bug#106
  > * fixed segfault with keepalives, bug#102 (sturm@)

lftp

  ~ Makefile                              ~ distinfo
  ~ pkg/PLIST                             

  > upgrade to lftp 3.4.6 (kevlo@)

nagios

  ~ plugins/Makefile                      ~ plugins/pkg/PLIST
  + plugins/files/README.OpenBSD          + plugins/pkg/MESSAGE

  > do not install check_dhcp and check_icmp suid root (this code is
  > too crappy), instead explain how to setup systrace with privilege
  > elevation (sturm@)

  ~ nagios/Makefile                       ~ nagios/distinfo

  > security update to nagios 2.3
  > from Changelog:
  > * Bug fix for negative HTTP content_length header in CGIs (sturm@)

  ~ nagios/Makefile                       + nagios/patches/patch-cgi_getcgi_c

  TAGGED OPENBSD_3_8
  > MFC:
  > backport a bug fix for negative HTTP content_length header in CGIs (sturm@)

  ~ nagios/Makefile                       + nagios/patches/patch-cgi_getcgi_c

  TAGGED OPENBSD_3_9
  > MFC:
  > backport a bug fix for negative HTTP content_length header in CGIs (sturm@)

nepenthes

  ~ Makefile                              
  + patch-modules_vuln-bagle_BagleDialogue_cpp
  + patch-modules_vuln-mydoom_MydoomDialogue_cpp

  > roll in two distribution patches which fix erroneous memory handling
  > from maintainer rui reis (jolan@)

nsd

  ~ Makefile                              ~ distinfo

  > update to version 2.3.4 - bugfix release (jakob@)

openvpn

  ~ Makefile                              ~ distinfo

  TAGGED OPENBSD_3_9
  > MFC:
  > Security update to openvpn-2.0.6.
  > * Security Vulnerability affecting OpenVPN 2.0 through 2.0.5.
  > An OpenVPN client connecting to a
  > malicious or compromised server could potentially receive
  > "setenv" configuration directives from the server which could
  > cause arbitrary code execution on the client via a LD_PRELOAD
  > attack.
  > Detailed information: http://openvpn.net/changelog.html (sturm@)

p5-Nmap-Parser

  + distinfo                              + Makefile
  + pkg/DESCR                             + pkg/PLIST

  > New import:
  >	initial import of Nmap::Parser 1.05

pebrot

  ~ Makefile                              ~ distinfo

  > - upgrade to pebrot 0.8.8
  > - switch to python 2.4 (kevlo@)

ssldump

  ~ Makefile                              + patches/patch-aes

  > add AES decryption support; contributed by tmclaugh at FreeBSD.org (jakob@)

== security ========================================================== 12/15 ==

  http://www.openbsd.org/cgi-bin/cvsweb/ports/security

security

  ~ Makefile                              

  > +p5-GSSAPI (steven@)

clamav

  ~ Makefile                              ~ distinfo

  > Update to ClamAV 0.88.2
  > This release improves virus detection and fixes zip handling on 64-bit
  > architectures.
  > SECURITY
  > This release fixes a possible security problem in freshclam.
  > See http://www.clamav.net/security/0.88.2.html for a full security report.
  > (mbalmer@)

  ~ Makefile                              ~ distinfo

  TAGGED OPENBSD_3_9
  > MFC:
  > Update to ClamAV 0.88.1.
  > 1) An unspecified integer overflow error exists in the PE header parser
  > in "libclamav/pe.c".
  > 2) Some format string errors in the logging handling in
  > "shared/output.c" may be exploited to execute arbitrary code.
  > 3) An out-of-bounds memory access error in the "cli_bitset_test()"
  > function in "ibclamav/others.c" may be exploited to cause a crash.
  > CVE reference: CVE-2006-1614, CVE-2006-1615, CVE-2006-1630
  > More info: http://secunia.com/advisories/19534/
  > -----------
  > Update to ClamAV 0.88.2
  > This release improves virus detection and fixes zip handling on 64-bit
  > architectures.
  > SECURITY
  > This release fixes a possible security problem in freshclam.
  > See http://www.clamav.net/security/0.88.2.html for a full security report.
  > (sturm@)

  ~ Makefile                              ~ distinfo

  TAGGED OPENBSD_3_7
  > MFC:
  > Update to ClamAV 0.88.2
  > This release improves virus detection and fixes zip handling on 64-bit
  > architectures.
  > SECURITY
  > This release fixes a possible security problem in freshclam.
  > See http://www.clamav.net/security/0.88.2.html for a full security report.
  > (sturm@)

  ~ Makefile                              ~ distinfo

  TAGGED OPENBSD_3_8
  > MFC:
  > Update to ClamAV 0.88.2
  > This release improves virus detection and fixes zip handling on 64-bit
  > architectures.
  > SECURITY
  > This release fixes a possible security problem in freshclam.
  > See http://www.clamav.net/security/0.88.2.html for a full security report.
  > (sturm@)

gnupg

  ~ Makefile                              ~ distinfo

  TAGGED OPENBSD_3_9
  > security update to gnupg-1.4.2.2
  > from gnupg.org:
  > Signature verification of non-detached signatures may give a positive
  > result but when extracting the signed data, this data may be prepended
  > or appended with extra data not covered by the signature.  Thus it is
  > possible for an attacker to take any signed message and inject extra
  > arbitrary data. (sturm@)

nessus

  ~ libnasl/Makefile                      
  + libnasl/patches/patch-nasl_nasl_text_utils_c

  > A buffer overflow vulnerability has been discovered in the
  > implementation of split() function in NASL, leading to consume a large
  > amount of CPU and memory resources before crashing. A solution is to
  > check for zero-length sep parameters.
  > CVE-2006-2093;
  > from ubuntu linux;
  > ok sturm@ (aanriot@)

  ~ libnasl/Makefile                      
  + libnasl/patches/patch-nasl_nasl_text_utils_c

  TAGGED OPENBSD_3_8
  > MFC:
  > A buffer overflow vulnerability has been discovered in the
  > implementation of split() function in NASL, leading to consume a large
  > amount of CPU and memory resources before crashing. A solution is to
  > check for zero-length sep parameters.
  > CVE-2006-2093;
  > from ubuntu linux; (sturm@)

  ~ libnasl/Makefile                      
  + libnasl/patches/patch-nasl_nasl_text_utils_c

  TAGGED OPENBSD_3_9
  > MFC:
  > A buffer overflow vulnerability has been discovered in the
  > implementation of split() function in NASL, leading to consume a large
  > amount of CPU and memory resources before crashing. A solution is to
  > check for zero-length sep parameters.
  > CVE-2006-2093;
  > from ubuntu linux; (sturm@)

p0f

  ~ Makefile                              ~ distinfo
  ~ patches/patch-mk_OpenBSD              ~ patches/patch-p0f_c

  > update to 2.0.6 .
  > from Rui Reis <rui at rui.cxnew maintainer;
  > ok jolan@ (aanriot@)

p5-Authen-SASL

  ~ Makefile                              ~ distinfo
  ~ pkg/PLIST                             

  > update to 2.10;  from maintainer jasper (steven@)

p5-Crypt-CBC

  ~ Makefile                              ~ distinfo

  TAGGED OPENBSD_3_9
  > MFC:
  > SECURITY update to Crypt::CBC 2.17
  > Versions of this module prior to 2.17 were incorrectly
  > using 8 byte IVs when generating the old-style RandomIV style header
  > (as opposed to the new-style random salt header). This affects data
  > encrypted using the Rijndael algorithm, which has a 16 byte blocksize,
  > and is a significant security issue.
  > The bug has been corrected in versions 2.17 and higher by making it
  > impossible to use 16-byte block ciphers with RandomIV headers. You may
  > still read legacy encrypted data by explicitly passing the
  > -insecure_legacy_decrypt option to Crypt::CBC->new(). (sturm@)

p5-GSSAPI

  + Makefile                              + distinfo
  + pkg/DESCR                             + pkg/PLIST

  > New import:
  >	import p5-GSSAPI 0.21

swatch

  ~ Makefile                              ~ patches/patch-swatch

  > make swatch work with perl 5.8.8 and Getopt::Long rev 1.8 .
  > "looks ok" steven@ (aanriot@)

  ~ Makefile                              ~ distinfo
  ~ patches/patch-swatch                  ~ pkg/DESCR
  ~ pkg/PLIST                             

  > - update to 3.1.1 .
  > - DESCR tweak.
  > - COMMENT tweak by Michael Knudsen.
  > - add PKG_ARCH (spotted by alek).
  > ok alek@ (aanriot@)

== sysutils ========================================================== 13/15 ==

  http://www.openbsd.org/cgi-bin/cvsweb/ports/sysutils

sysutils

  ~ Makefile                              

  > +ipmitool (wilfried@)

ipmitool

  + Makefile                              + distinfo
  + patches/patch-src_plugins_imb_imbapi_h
  + patches/patch-src_plugins_imb_imbapi_c
  + patches/patch-contrib_bmclanconf      + patches/patch-Makefile_in
  + patches/patch-contrib_collect_data_sh
  + patches/patch-contrib_create_rrds_sh
  + patches/patch-contrib_create_webpage_sh
  + patches/patch-contrib_create_webpage_compact_sh
  + pkg/PLIST                             + pkg/DESCR

  > New import:
  >	import of ipmitool-1.8.7

nut

  ~ Makefile                              ~ distinfo
  ~ patches/patch-clients_Makefile_in     ~ patches/patch-configure
  ~ patches/patch-drivers_fentonups_c     ~ patches/patch-drivers_fentonups_h
  ~ patches/patch-include_common_h        ~ pkg/PLIST

  > update to nut-2.0.3, last not leas bringing many format string fixes
  > preserve my changes to the fentonups driver, allowing the detection logic
  > to be bypassed and a model to be forced - for UPSes that do implement the
  > protocol except the identification command, which seems to be somewhat
  > common
  > the Xanto S3000R thing here behaves like that, and support for it is added
  > ok mbalmer (henning@)

== www =============================================================== 14/15 ==

  http://www.openbsd.org/cgi-bin/cvsweb/ports/www

mediawiki

  ~ Makefile                              ~ distinfo
  ~ pkg/PLIST                             

  TAGGED OPENBSD_3_9
  > MFC:
  > Security update to mediawiki-1.5.8.
  > A bug in decoding of certain encoded links could allow injection of raw
  > HTML into page output; this could potentially lead to XSS attacks.
  > More info:
  > http://mail.wikipedia.org/pipermail/mediawiki-announce/2006-March/000040.ht
  > ml (sturm@)

mozilla

  - patches/patch-htmlparser_public_nsHTMLTagList_h
  - patches/patch-htmlparser_src_COtherElements_h
  - patches/patch-htmlparser_src_nsElementTable_cpp
  - patches/patch-htmlparser_src_nsHTMLTags_cpp
  - patches/patch-htmlparser_tools_gentags_pl
  ~ Makefile                              ~ distinfo
  ~ patches/patch-modules_libpref_src_init_all_js

  > update to 1.7.13, ok kurt@
  > fixes multiple critical vulnerabilities
  > the last official release of the Mozilla Application Suite (wilfried@)

  ~ Makefile                              ~ distinfo

  TAGGED OPENBSD_3_8
  > MFC:
  > update to 1.7.13, ok kurt@
  > fixes multiple critical vulnerabilities
  > the last official release of the Mozilla Application Suite (sturm@)

  - patches/patch-htmlparser_public_nsHTMLTagList_h
  - patches/patch-htmlparser_src_COtherElements_h
  - patches/patch-htmlparser_src_nsElementTable_cpp
  - patches/patch-htmlparser_src_nsHTMLTags_cpp
  - patches/patch-htmlparser_tools_gentags_pl
  ~ Makefile                              ~ distinfo

  TAGGED OPENBSD_3_9
  > MFC:
  > update to 1.7.13, ok kurt@
  > fixes multiple critical vulnerabilities
  > the last official release of the Mozilla Application Suite (sturm@)

mozilla-firefox

  ~ Makefile                              ~ distinfo

  TAGGED OPENBSD_3_9
  > MFC:
  > update to 1.5.0.2
  > fixes multiple critical vulnerabilities (sturm@)

  ~ Makefile                              ~ distinfo
  ~ patches/patch-configure_in            
  ~ patches/patch-modules_libpref_src_init_all_js
  ~ patches/patch-nsprpub_config_rules_mk
  ~ patches/patch-nsprpub_configure_in    
  ~ patches/patch-xpcom_glue_standalone_Makefile_in

  TAGGED OPENBSD_3_9
  > Update to 1.5.0.3. Security fixes inside...
  > More info:
  > CVE-2006-1993
  > http://secunia.com/advisories/19802/
  > tested by many
  > "go ahead" jolan@ (bernd@)

  ~ Makefile                              ~ distinfo
  ~ patches/patch-configure_in            
  ~ patches/patch-modules_libpref_src_init_all_js
  ~ patches/patch-nsprpub_config_rules_mk
  ~ patches/patch-nsprpub_configure_in    
  ~ patches/patch-xpcom_glue_standalone_Makefile_in

  TAGGED OPENBSD_3_9
  > MFC:
  > Update to 1.5.0.3. Security fixes inside...
  > More info:
  > CVE-2006-1993
  > http://secunia.com/advisories/19802/ (sturm@)

nostromo

  ~ Makefile                              ~ distinfo

  TAGGED OPENBSD_3_9
  > MFC:
  > SECURITY: update to 1.7.9 which fixes a buffer overflow in the
  > http_header_comp() function (sturm@)

p5-HTML-Mason

  ~ Makefile                              ~ distinfo
  ~ pkg/PLIST                             

  > update to 1.32, a few performance improvements and bug-fixes.
  > okay maintainer. (espie@)

== x11 =============================================================== 15/15 ==

  http://www.openbsd.org/cgi-bin/cvsweb/ports/x11

kde

  ~ libs3/Makefile                        
  + libs3/patches/patch-kdeui_ksconfig_cpp

  > make the kspell library use aspell instead of ispell by default, since the
  > port already depends on aspell. prevents "cannot find ispell" errors.
  > go ahead espie@ (steven@)

  ~ network3/Makefile                     
  + network3/patch-kopete_plugins_connectionstatus_connectionstatusplugin_cpp
  + network3/patch-kopete_plugins_connectionstatus_connectionstatusplugin_h

  > backport fix for 101669
  > http://bugs.kde.org/101669
  > From KDE SVN (brad@)

mplayer

  ~ Makefile                              
  + patches/patch-libmpdemux_asfheader_c
  + patches/patch-libmpdemux_aviheader_c

  TAGGED OPENBSD_3_9
  > MFC:
  > Protect from integer overflows. See CVE-2006-1502 (sturm@)

rep-gtk

  ~ Makefile                              ~ patches/patch-gtk-compat_c
  ~ patches/patch-rep-gtk_h               

  > Fix issue with gtk_radio_menu_item_new_with_label_from_widget() and
  > gtk_radio_menu_item_new_with_mnemonic_from_widget() that was preventing
  > Sawfish from working correctly, okay sturm at .edro@)

===============================================================================



More information about the owc mailing list